ZeroFox Weekly Intelligence Brief – March 4, 2024
|by Alpha Team

ZeroFox Weekly Intelligence Brief – March 4, 2024
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on March 1, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
CISA, NCSC-UK, and Partners Release Advisory on Russian SVR
What happened: CISA and other international cybersecurity organizations have issued a joint advisory that provides an overview of recent tactiques, techniques, and procedures (TTPs) deployed by Russian Foreign Intelligence Service (SVR) cyber actors, also known as APT29, the Dukes, CozyBear, and NOBELIUM/Midnight Blizzard. In addition to outlining the TTPs used to gain initial access into the cloud environment, the advisory also includes advice to detect and mitigate such activities. The authoring agencies urged network defenders and organizations to review the joint advisory for recommended mitigations.
The White House Issues Executive Order to Protect Americans’ Sensitive Personal Data
What happened: The White House has issued an Executive Order to protect Americans’ sensitive personal details including genomic, biometric, personal health, geolocation, and financial data and certain kinds of personally identifiable information—from exploitation by countries of concern. The Department of Justice (DOJ) and the Department of Homeland Security (DHS) are to work together to set high security standards to prevent access by countries of concern to Americans’ data through other commercial means, such as data available via investment, vendor, and employment relationships.
Iran-Linked UNC1549 Hackers Target Middle East Aerospace & Defense Sectors
What happened: A cyber espionage campaign targeting aerospace, aviation, and defense industries in the Middle East, including Israel and the United Arab Emirates (UAE), has been attributed to Iran-nexus threat actor “UNC1549.” Sources indicate other targets of the cyber espionage activities likely include Turkey, India, and Albania. The attacks use Microsoft Azure cloud infrastructure for command-and-control (C2) and social engineering to disseminate two backdoors: MINIBIKE and MINIBUS. The spear phishing emails contain links to fake websites or phony job offers to deploy a malicious payload. The custom backdoors, upon establishing C2 access, act as a conduit for intelligence collection and further access into the targeted network. Tunneling software called LIGHTRAIL is also deployed to communicate with Azure cloud infrastructure.
Tags: tlp:green