ZeroFox Weekly Intelligence Brief – November 13, 2023
|by Alpha Team

ZeroFox Weekly Intelligence Brief – November 13, 2023
TLP:GREEN
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on November 10, 2023; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here.
HC3 Analyst Note: BlackSuit Ransomware
What happened: The U.S. Health Sector Cybersecurity Coordination Center (HC3) has published an advisory stating that the relatively new BlackSuit ransomware will likely be a credible threat to the public health sector. The advisory notes how this double-extortion (data encryption and exfiltration) group shares similarities with Royal ransomware, which is believed to be a direct successor to the notorious Russia-based Conti operation.
Sandworm APT Group Targets Ukrainian Power Grid Once Again
What happened: A Russian state APT group successfully targeted a Ukrainian power grid for the third time. Sandworm, a prominent APT group with ties to Russia's military intelligence agency (GRU), conducted an attack that took an unnamed power grid offline. Of note, this attack coincided with a missile strike during a Russian military offensive.
Ransomed.vc Shutting Down Operations
What happened: Ransomed.vc announced it was shutting down operations instead of selling its infrastructure due to several affiliates allegedly being arrested. The operator claimed the affiliates had a lack of operational security.
Tags: tlp:green