ZeroFox Weekly Intelligence Brief – January 15, 2024
|by Alpha Team

ZeroFox Weekly Intelligence Brief – January 15, 2024
TLP:GREEN
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on January 12, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here.
After Injecting Cancer Hospital with Ransomware, Criminals Threaten to Swat Patients
What happened: Cybercriminals are turning their attention to patients in an attempt to have their ransomware demand fulfilled by threatening them with bogus police reports if medical centers do not pay their ransomware. These reports have the potential to bring swat teams to patients' homes and elicit potentially dangerous outcomes. After a cyberattack on Fred Hutchinson Cancer Center, where medical records were stolen, criminals threatened to make bomb threats or false reports to law enforcement about patients. Similar threats were reported by Integris Health in Oklahoma.
Threat Actor ‘sandocan’ Continues to Promote Remote Desktop Access to Companies Across the Globe
What happened: On January 9, 2024, esteemed threat actor ‘sandocan’ advertised an auction for RDWeb access with domain user rights to an unnamed U.S.-based insurance company on the predominantly Russian language dark web forum, Exploit. According to ‘sandocan’, the targeted insurance company generates USD 10 million in revenue. Just a day earlier, on January 8, 2024, the threat actor advertised an auction for RDWeb access with domain user rights to an unnamed Brazilian non-profit organization with a stated worth of USD 247 million.
Ukraine Claims Revenge Hack Against Moscow Internet Provider
What happened: The Ukrainian Blackjack hacker group conducted a cyberattack on Moscow-based Internet provider M9 Telecom. The attack resulted in the destruction of M9 Telecom's servers, wiping off approximately 20 terabytes of data, including the company's official website, branch sites, mail server, and cyber protection services. Following the cyberattack, some residents in Moscow experienced disruptions in internet and television services. The hackers have reportedly warned that this attack is the start of a larger attack, which will be “serious revenge for Kyivstar.”
Tags: tlp:green