ZeroFox Weekly Intelligence Brief – November 20, 2023
|by Alpha Team

ZeroFox Weekly Intelligence Brief – November 20, 2023
TLP:GREEN
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on November 17, 2023; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here.
LockBit Ransomware Spills Over 40 GB of Boeing Data
What happened: On October 26, 2023, ZeroFox Intelligence observed Russia-linked ransomware group LockBit listing Boeing as a victim on its darknet leak site. LockBit claimed to have stolen a “tremendous amount of data'' from the aerospace company. On November 2, Boeing reportedly confirmed that it was aware of the attack. Boeing’s name was removed from the list thereafter, indicating that negotiations between the two parties had begun. However, on November 12, LockBit published over 43 GB of data allegedly stolen from Boeing, including backups for various systems, after the company reportedly refused to pay a ransom.
DP World Cyberattack Blocks Thousands of Containers in Ports
What happened: International logistics firm DP World Australia has reportedly disclosed that a cyberattack is affecting normal operations in several Australian ports. The company is currently collaborating with cybersecurity professionals to re-establish landside freight operations at its ports. DP World has engaged the Office of the Australian Information Commissioner in response to the incident and is investigating the nature of data access, exfiltration, and the possibility of personal information compromise.
New Phishing Campaign Targeting Middle Eastern Governments
What happened: Government entities in the Middle East are the targets of a new phishing campaign employing the IronWind downloader. The activity is attributed to threat actor TA402 (aka Molerats and Gaza Cyber Gang), which shares TTP overlap with pro-Hamas hacking group APT-C-23.
Tags: tlp:green