ZeroFox Weekly Intelligence Brief – December 18, 2023
|by Alpha Team

ZeroFox Weekly Intelligence Brief – December 18, 2023
TLP:GREEN
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on December 15, 2023; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here.
Russian Cyber Actor Star Blizzard Continues Worldwide Spear-Phishing Campaigns
What happened: In a joint advisory, CISA and other international cybersecurity agencies are warning about Russia-based actor Star Blizzard (SEABORGIUM/CallistoGroup/TA446/COLDRIVER/TAG-53/ BlueCharlie) using spear-phishing attacks to academia, defense, and governmental organizations, NGOs, think tanks, and politicians in the United Kingdom and other geographical areas of interest.
China Continues to Target U.S. Critical Infrastructure via Volt Typhoon Campaign
What happened: This week, officials released more details on recent activity targeting U.S. critical infrastructure by threat actors affiliated with China’s People’s Liberation Army (PLA). The threat actors reportedly compromised the computer systems of approximately two dozen critical infrastructure entities over the past year, including transportation, communication, and water and power utilities. These compromises – part of an ongoing cyber campaign dubbed “Volt Typhoon” – are likely aimed at intelligence gathering to cause future logistical disruptions amid rising U.S.-China tensions in the Pacific. Notable targets of the campaign within the last year include a key shipping port on the West Coast and a water utility system in Hawaii. The U.S. government and Microsoft first detected the Volt Typhoon roughly a year ago and have since observed the threat actors predominately utilizing TTPs such as living-off-the-land (LOTL) binaries and hands-on keyboard activities to conduct their attacks.
Iran’s Parliament Approves Cooperation Bill with Russia
What happened: On December 10, 2023, the Iranian Parliament approved an Information Security Deal with Russia. The bill aimed at fostering cooperation with Russia in the realm of information security, as both countries are accused of extensive cyber attacks. The bill holds nine articles, focusing on combating cyber threats, fortifying information security measures, and fostering collaboration between Iran and Russia.
Tags: tlp:green