ZeroFox Weekly Intelligence Brief - February 5, 2024
|by Alpha Team

ZeroFox Weekly Intelligence Brief – February 5, 2024
TLP:GREEN
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EST) on February 2, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here.
Scammers Use Couriers to Retrieve Cash and Precious Metals from Victims of Scams
What happened: The Federal Bureau of Investigation (FBI) released an advisory that warns the public about scams in which criminals pose as tech support or U.S. government officials. These scammers employ various tactics, such as claiming financial accounts are hacked or at risk, convincing the victims to liquidate assets into cash or to buy precious metals for protection. The scammers may use passcodes for authentication and to assure victims that their assets will be safeguarded in a protected account.
“Secure by Design” Alert Urges Manufacturers to Eliminate Defects in SOHO Routers
What happened: The U.S. CISA and the FBI have published guidelines on security design improvements for small office/home office (SOHO) device manufacturers. The advisory focuses on eliminating exploitable defects during the product design and development phases in web management interfaces, as well as implementing secure default device configurations.Schneider Electric’s Sustainability Business division reportedly suffered a ransomware attack by the Cactus hacker group. The ransomware group gained access, stole terabytes of data, and is now extorting the company by threatening to leak the stolen data if a ransom demand is not paid.
Energy Giant Schneider Electric Hit by Cactus Ransomware Attack
What happened: On January 17, 2024, the actor KernelMode advertised a malware for sale that can kill most antivirus and EDR products on the Exploit forum. The actor claimed the malware was successfully tested on Microsoft Windows 7-11 operating systems to terminate processes for several AV and EDR products. The malware was priced at USD 5000 a month with a limit of five clients.
Tags: tlp:green