zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - October 29, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - October 29, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Brief - Iranian APT Groups Increasing Cyber Espionage Activity
  • American Family Insurance Takes Down IT Systems Following Cyberattacks
  • Russia-Linked APT28 (Fancy Bear) Conducting Attacks on France Since 2021

ZeroFox Intelligence Brief - Iranian APT Groups Increasing Cyber Espionage Activity

Iranian state-affiliated advanced persistent threat (APT) groups APT33 and APT34 have conducted an increasing number of targeted cyberattacks in recent months. These APTs will likely continue to play a key role in the Israel-Hamas war to support Iran and Hamas’ mis-and disinformation campaigns and other cyber espionage and intelligence operations. The groups have a standing mandate to conduct cyber espionage on behalf of the Iran regime, and it is very likely these groups will mirror or exceed Iran’s operational pace vis-à-vis the conflicts in which Iran finds itself with its near-peer and regional geopolitical rivals.

American Family Insurance Takes Down IT Systems Following Cyberattacks

American Family Insurance shut down several of its IT systems and confirmed a cyberattack, after customers reported website outages in the company's phone service, building connectivity and online services. Customers were left unable to pay bills or file for insurance claims online. Upon investigation, technology teams detected unusual activity on their networks. The attack bears similarities with ransomware attacks targeting the industry, with many such attacks taking place on weekends to take advantage of reduced tech-support and monitoring personnel.

Russia-Linked APT28 (Fancy Bear) Conducting Attacks on France Since 2021

The National Cybersecurity Agency of France (ANSSI) has published an advisory detailing attacks conducted by Russia-linked APT 28 (a.k.a., Fancy Bear, STRONTIUM, etc.) since the second half of 2021. The group has been known to attack French governmental bodies, businesses, universities, research institutes, and think tanks. ANSSI reported that the attackers attempt to obfuscate their activity and reduce the rate of detection by targeting either poorly monitored systems or those located at the edge of a network. The advisory elaborates the tactics, techniques, and procedures (TTPs) used in these attacks and suggests protective measures.

Tags: DIB, tlp:green