ZeroFox Cyber Intelligence Daily Brief - February 11, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - February 11, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - Innovative Loader-as-a-Service Announced
- Ministry of Defence of the Netherlands Uncovers COATHANGER, a Stealthy Chinese FortiGate RAT
- Hong Kong Company Loses USD 25 Million to Deep Fake Scam Targeting an Employee
ZeroFox Intelligence Flash Report - Innovative Loader-as-a-Service Announced
Since its announcement on January 25, 2024, by untested actor “Null14”, an innovative malware loader-as-a-service offering has been gaining traction on the predominantly Russian-speaking dark web community exploit[.]in. The currently unnamed loader allegedly targets Windows operating systems and is signed using valid certificates, enabling its deployment to remain undetected by various Windows systems as well as VirusTotal. Although ZeroFox can neither confirm nor disconfirm the credibility of the service, positive indicators add credence to the legitimacy of this loader service as an innovative malware-spreading technique. Malware distribution based on emulating credible software is likely on an upward trajectory, and this trend is expected to continue in the first half of 2024.
Ministry of Defence of the Netherlands Uncovers COATHANGER, a Stealthy Chinese FortiGate RAT
In 2023, the Ministry of Defence (MOD) of the Netherlands experienced a cyberattack on one of its networks, although the impact was mitigated due to prior network segmentation. Incident response efforts uncovered a previously undisclosed malware, a remote access trojan (RAT) tailored for FortiGate appliances, known as COATHANGER. This malware, functioning as second-stage malware, is reportedly stealthy and persistent, evading detection by concealing itself through various methods, including hooking system calls and surviving reboots and firmware upgrades.
Hong Kong Company Loses USD 25 Million to Deep Fake Scam Targeting an Employee
The Hong Kong branch of a multi-national company suffered a loss of USD 25 million after scammers used deepfake technology to trick one of its employees. The targeted finance department employee reportedly received a message from an individual claiming to be the company's UK-based chief financial officer. They then attended a video conference with deepfake versions of the company's CFO and other company employees. After this, the employee, acting on instructions received on the call, supposedly transferred USD 25.6 million to various Hong Kong bank accounts across 15 transactions.
Tags: DIB, tlp:green