ZeroFox Weekly Intelligence Brief – December 11, 2023
|by Alpha Team

ZeroFox Weekly Intelligence Brief – December 11, 2023
TLP:GREEN
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on December 8, 2023; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here.
Agent Raccoon Backdoor Targets Organizations in the Middle East, Africa, and the United States
What happened: Cybersecurity researchers have observed an unknown threat actor distributing a new backdoor called Agent Raccoon. Agent Raccoon conducts backdoor attacks through scheduled tasks in the form of Google Updates, allowing command executions like file downloads and uploads. This threat actor is reportedly targeting education, real estate, retail, non-profit, telecom, and government organizations in the United States, the Middle East, and Africa.
AI-Driven Operation Doppelganger Propagates Disinformation to U.S., Ukrainian, and German Audience
What happened: Russia-origin AI-powered Doppelganger is disseminating disinformation among audiences in Ukraine, the United States, and Germany through an extensive network of fraudulent websites and social media, including approximately 800 inauthentic social media accounts. Reportedly, the operation has been crafted to curate content that propagates anti-LGBTQ+ sentiments and subverts Ukraine’s military and international relations. In a recent campaign, Doppelganger created genuine-looking fake news articles, likely with the help of generative AI.
ColdFusion Vulnerability Still Persists
What happened: On December 5, the Cybersecurity and Infrastructure Security Agency (CISA) released an advisory detailing the recent exploitation of a critical vulnerability in Adobe ColdFusion by unidentified threat actors, which granted them initial access to at least two U.S. federal government servers at an unnamed Federal Civilian Executive Branch (FCEB) agency. The vulnerability, identified as CVE-2023-26360, ultimately allowed the threat actors to drop malware using HTTP POST commands into the public-facing servers running versions 2018 Update 15 and earlier and 2021 Update 5 and earlier. Both of these versions were outdated when the compromises occurred between June and July of this year, despite the agency having been mandated to patch the vulnerability in May. CISA analysis indicates that the exploitation was likely aimed at obtaining information on the broader network infrastructures, and no successful data exfiltration or lateral movement could be confirmed.
Tags: tlp:green