ZeroFox Weekly Intelligence Brief – February 26, 2024
|by Alpha Team

ZeroFox Weekly Intelligence Brief – February 26, 2024
TLP:GREEN
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on February 23, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
Winter Vivern Cyber Espionage Campaign Targets Critical Infrastructure of EU Countries
What happened: In October, the Russia-linked Winter Vivern group exploited cross-site scripting (XSS) flaws in Roundcube webmail servers across Europe in a campaign targeting government, military, and critical infrastructure in Georgia, Poland, and Ukraine. The threat group (aliases: TAG-70, TA473, and UAC-0114) used a Roundcube zero-day exploit, employing sophisticated social engineering to gain unauthorized access to mail servers in over 80 organizations. The campaign aimed to gather intelligence on European political and military affairs, potentially undermining security and alliances.
Iranian Hackers Target Middle East Policy Experts with New BASICSTAR Backdoor
What happened: Iran-based threat actor Charming Kitten, known for its social engineering attacks, has reportedly targeted Middle East policy experts with a new backdoor called BASICSTAR. The threat actor deploys the backdoor through a fake webinar portal. The attack strategy often involves RAR archives containing LNK files, enticing recipients to join fake webinars on topics of interest.
North Korean Hackers Linked to Defense Sector Supply Chain Attack
What happened: German and South Korean federal agencies have jointly issued a warning about an ongoing cyber espionage campaign orchestrated by North Korea that is targeting the global defense sector. These attacks aim to steal advanced military technology data, aiding North Korea in modernizing its conventional arms and developing new military capabilities. The threat actor initially infiltrated the target by compromising a web server maintenance firm, employing tactics like stealing SSH credentials, lateral network movement, and exploiting vulnerabilities.
Tags: tlp:green