zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 7, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 7, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Alleged Zero-Day Hack Reveals Users of Illicit Pornography Forum Based in South Korea
  • U.S. Law Enforcement Agencies Arrests Electronic Benefit Transfer Card Fraudsters
  • Individual Admits to Running Unlicensed Business in Multi-State Email Fraud Scheme

Alleged Zero-Day Hack Reveals Users of Illicit Pornography Forum Based in South Korea

Source: https://hackread.com/s-koreas-crime-hub-ya-moon-hacked-user-data-leak/

What happened: A threat actor on predominantly English-language dark web forum BreachForums has claimed to leak a database allegedly associated with Ya-moon, a notorious South Korean private pornography site. The breach seemingly occurred via a zero-day exploit, and the leaked data supposedly comprises 326,000 lines of data.

Why it matters: The leak allegedly reveals usernames, IP addresses, plain-text passwords, incriminating activity logs, and other evidence of illegal activities. If the authorities are able to verify this data, it could aid them in identifying and prosecuting users involved in crimes like child exploitation, unlawful distribution of sexual abuse material, discussions of sexual abuse, and sexual violence. Online sex crimes remain a serious issue in South Korea, with past scandals like the Nth Room and a recent surge in deepfake threats targeting women.

U.S. Law Enforcement Agencies Arrests Electronic Benefit Transfer Card Fraudsters

Source: https://www.dhs.gov/hsi/news/2025/02/05/arrests-foreign-nationals-made-electronic-benefit-transfer-card-fraud-scheme

What happened: Homeland Security Investigations (HSI) and other U.S. agencies conducted a large-scale enforcement action arresting 11 foreign nationals. The two-day operation recovered over 300 cloned Electronic Benefit Transfer (EBT) cards and over USD 30,000 in cash.

Why it matters: The goal of this operation was to arrest individuals perpetrating access device fraud through unauthorized cash withdrawals from victim EBT cards. This type of fraud victimizes recipients of government sponsored relief programs, which are some of the most vulnerable members of the public. Historically, this type of criminal activity has been widely perpetrated by elements of foreign organized crime who have no legal status in the United States or are prior deportees.

Individual Admits to Running Unlicensed Business in Multi-State Email Fraud Scheme

Source: https://www.justice.gov/usao-sdtx/pr/out-state-man-pleads-guilty-laundering-email-scam-proceeds

What happened: An individual has admitted to operating an unlicensed money-transmitting business from 2021 to 2022 that facilitated funds from a business email compromise (BEC) scheme.

Why it matters: The individual used shell companies to open bank accounts, collected money from at least two victims—a Georgia healthcare liability insurance company and a New Jersey township—and transmitted the fraud proceeds to co-conspirators for a fee. By using shell companies and fraudulent wire transfers, the individual was able to manipulate the firms to send large sums of money. The scam directly impacted essential services by diverting funds from a healthcare insurer and a township, which could have disrupted healthcare liability coverage and local government operations.

DEEP AND DARK WEB INTELLIGENCE

Xss user Armagedon: Moderately credible threat actor "Armagedon" has advertised a VPN access bundle with domain user rights to two unnamed U.S.-based customer relationship management software and consumer services companies on xss.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-48510: This vulnerability in drive composer could enable attackers unauthorized access to the file system on the host machine. An attacker could exploit this flaw to run malicious code to compromise the affected system.

Affected products: Drive Composer entry versions 2.9.0.1 and prior; Drive Composer pro versions 2.9.0.1 and prior

Tags: DIB, tlp:green