Q2 2023 Public Sector Quarterly Threat Landscape Report
|by Alpha Team

ZeroFox Intelligence - Q2 2023 Public Sector Quarterly Threat Landscape Report
Product Serial: A-2023-09-01b
TLP:CLEAR
ZeroFox Intelligence is excited to announce the release of our Public Sector Quarterly Threat Landscape Scorecard for Q2 of 2023.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download View the full report here.
Scope Note
ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on July 10, 2023; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Key Findings
- The threat to public sector organizations from ransomware and digital extortion (R&DE) likely remained broadly consistent in Q2 2023, bucking an upward trend seen in almost all other sectors. This is likely driven by Clop operatives’ statement that they would not extort government organizations as part of their successful exploitation of a zero-day vulnerability in MOVEit file transfer software.
- The threat of nefarious actors exploiting Common Vulnerabilities and Exposure (CVEs) remained high in Q2 2023, with threat actors continuing to target commonly-used software modules and products reportedly utilized by multiple federal, national, and central government entities.
- Search Engine Optimization (SEO) poisoning and leveraging of malicious Google adverts to disseminate malware continued on an upward trajectory.
- ZeroFox Intelligence assesses with low confidence that the threat to the public sector from malware deployment increased in Q2 2023, underpinned by indications of increased Advanced Persistent Threat (APT) activity targeting government entities globally.
- Illicit access to public sector organizations advertised in dark web forums reduced in Q2 2023, bucking an overall upward trend seen in most other sectors.
Tags: tlp:clear, vulnerability/exploit, phishing & fraud, malware, government, MAL Ransomware