ZeroFox Weekly Intelligence Brief – January 8, 2024
|by Alpha Team

ZeroFox Weekly Intelligence Brief – January 8, 2024
TLP:GREEN
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on January 5, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here.
Hackers Attack United Kingdom’s Nuclear Waste Services Through LinkedIn
What happened: The United Kingdom’s Radioactive Waste Management (RWM) company recently faced a cyberattack attempt that targeted the organization through LinkedIn. The RWM manages the 50 billion GBP Geological Disposal Facility (GDF) project, which aims to create an underground nuclear waste repository in the United Kingdom. Specific details, whether it involved phishing or an attempt to trick employees into installing malware, are unknown. The company's multi-layered defense systems detected and thwarted the attack, preventing unauthorized access.
Researchers Develop New Black Basta Decryptor to Recover Files
What happened: Cybersecurity researchers have developed a new decrypting tool that leverages a vulnerability in Black Basta Ransomware, letting victims recover their encrypted files for free. The decryptor Black Basta Buster exploits an encryption algorithm flaw in the ransomware’s encryptor tools.
Pro-Russian Hacktivist Group “UserSec” Claims Web Defacement Attack Against NATO Countries
What happened: On December 29, 2023, the pro-Russian hacktivist group UserSec announced that they were forming a DDoS squad to attack European and North Atlantic Treaty Organization (NATO) countries. The group planned to recruit those with specific requirements. On January 1, 2024, the group claimed to have defaced a few websites from NATO countries such as Romania, Canada, Poland, Holland, and Germany.
Tags: tlp:green