Concern Hacktivism Israel Hamas
Hacktivist activity tied to the Israel-Hamas conflict is raising concern among defenders as threat groups target organizations in the region.
Infosecurity Magazine reports growing concern over hacktivism linked to the Israel-Hamas conflict. The headline suggests ongoing geopolitically motivated attacks against organizations connected to the conflict. Full article text was unavailable, so specific groups, targets, and techniques are unconfirmed.
Disrupting a new covert influence campaign from Russia
OpenAI banned Russia-origin accounts that used AI tools to run a covert influence campaign behind a fake Israel-based think tank and pro-Russia sovereignty index.
OpenAI disrupted and banned accounts of Russia origin that were using its AI tools to conduct a covert influence operation. The campaign promoted a fictitious Israel-based think tank and a 'sovereignty' index praising Russia while criticizing Western countries. The action is part of OpenAI's ongoing monitoring and disruption of malicious uses of AI for influence operations.
Cardinal RAT Sins Again, Targets Israeli Fin
Unit 42 documents updated Cardinal RAT attacks against Israeli FinTech firms, using BMP steganography, MD5-hash obfuscation, and process injection to hinder analysis and detection.
Unit 42 tracked a series of attacks using an updated Cardinal RAT (version 1.7.2) targeting the Israeli financial technology sector. The .NET loader hides a second-stage DLL inside an embedded BMP image decrypted with a single-byte XOR key, and the payload renames functions, methods, and variables to MD5 hashes for obfuscation. The malware installs a startup-folder LNK file and injects its final payload into RegSvcs.exe or RegAsm.exe, communicating with affiliatecollective[.]club over port 443. A possible relationship with the EVILNUM JavaScript malware used against similar organizations was also noted.