ZeroFox Physical Security Intelligence Daily Brief - December 4, 2023
|by Alpha Team

ZeroFox Physical Security Intelligence Daily Brief - December 4, 2023
ZeroFox physical security experts collect, curate, and analyze information derived from open and proprietary sources for comprehensive context of the circumstances surrounding global events. Here is today’s daily roundup of major developments.
Brief Highlights
- Israel-Hamas War: Fighting Resumes as Truce Talks Collapse
- Schools Evacuated after Bomb Threats in Bengaluru, India
- Ukrainian Parliament Agrees to Postpone Elections
Israel-Hamas War: Fighting Resumes as Truce Talks Collapse
Fighting in the Gaza Strip resumed during morning early hours local time on December 1, 2023, after talks to extend a week-long truce collapsed. Israeli officials blamed Hamas, asserting that the group carried out numerous ceasefire violations and did not “provide a list of hostages” to be released in the case of a further extension. Shortly after the resumption of hostilities, Israeli forces dropped leaflets urging residents in and around the city of Khan Yunis to evacuate their homes, indicating a southward shift in the Israel Defense Forces’ (IDF) operations.
Schools Evacuated after Bomb Threats in Bengaluru, India
On December 1, 2023, at least 45 schools in the Indian city of Bengaluru were evacuated after receiving emailed threats stating bombs had been planted on the premises and could be triggered at any time. Police are combing the affected schools and have so far not detected any suspicious objects. Similar threats were emailed to schools in Bengaluru in April 2022, but turned out to be a hoax.
Ukrainian Parliament Agrees to Postpone Elections
The newly discovered SugarGh0st trojan is reportedly targeting the Uzbekistan Ministry of Foreign Affairs as well as users in South Korea. SugarGh0st, which security researchers suspect to be a new version of Gh0st RAT, comes with new features in its reconnaissance capability, targeting specific Open Database Connectivity (ODBC) registry keys and employing tailored commands for remote administration tasks. To evade detection, it loads library files with specific extensions and function names, while modifying the C2 communication protocol.
Tags: DIB, tlp:green