ZeroFox Cyber Intelligence Daily Brief - January 21, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 21, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Iranian Cyberespionage Hackers Use Spearphishing to Target High-Profile Researchers Across EU and U.S.
- ZeroFox Intelligence Flash Report - Dark Web Actors Promoting Maritime Data
- Citrix Warns of New Netscaler Zero-Days Exploited in Attacks
Iranian Cyberespionage Hackers Use Spearphishing to Target High-Profile Researchers Across EU and U.S.
A subset of Iranian-backed cyberespionage group APT 35 (alias Mint Sandstorm, Charming Kitten, and Phosphorus) is reportedly targeting individuals researching Middle Eastern affairs at universities in the European Union and the United States. The notorious threat group has been using customized phishing tactics to “socially engineer targets into downloading malicious files.” This campaign has been designed to steal sensitive data from compromised systems belonging to high-profile researchers.
ZeroFox Intelligence Flash Report - Dark Web Actors Promoting Maritime Data
ZeroFox has identified at least two instances in which threat actors are selling data that provides real-time information on maritime vessels, including the geographic positions of vessels, vessel details, journey details, and data on maritime infrastructure. The leaked data has little monetary value for the buyer or seller and may demonstrate that politically-motivated actors will forgo profit to achieve their ideological aims, and there will likely be continued convergence between geopolitical issues and cybersecurity threats. Houthi attacks targeting commercial vessels transiting the Red Sea have resulted in significant political gains for the group and have caused major disruptions to global supply chains. There are other important shipping lanes across the globe, and threat actors may view obtaining similar datasets as helpful to achieving their political aims or harming their political adversaries.
Citrix Warns of New Netscaler Zero-Days Exploited in Attacks
Cirix’s Netscaler ADC and Gateway appliances have recently been the target of two active zero-day exploits. Two vulnerabilities, CVE-2023-6548 and CVE-2023-6549, affect the Netscaler management interface, posing risks of remote code execution and denial-of-service attacks on unpatched Netscaler instances. A threat monitoring platform shows that over 1,500 Netscaler management interfaces are now exposed on the Internet. Citrix reports that only customer-managed NetScaler appliances are affected by these zero-days, with Citrix-managed cloud services and Citrix-managed Adaptive Authentication remaining unaffected. The company urges admins and users to install the patch as soon as possible. Admins unable to install the patch right away are advised to block network traffic to affected instances and ensure they are not exposed online.
Tags: DIB, tlp:green