ZeroFox Weekly Intelligence Brief – March 11, 2024
|by Alpha Team

ZeroFox Weekly Intelligence Brief – March 11, 2024
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on March 8, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
North Korean Hackers Target South Korean Semiconductor Firms Using LoTL Tactics
The National Intelligence Service (NIS) of South Korea has issued a press release highlighting its discovery of North Korean hackers targeting domestic semiconductor firms from the second half of 2023 until recently. The press release details cyberattacks that occurred in December 2023 and February 2024 targeting two companies that had their configuration management server and security policy server hacked. The attackers also stole product design drawings and facility site photos. They used Living off the Land (LoTL) techniques to conduct the attacks. These techniques minimize malicious code usage and target systems via programs already installed, making the attacks difficult to detect.
Content Farm Impersonating over 60 Prominent English Media Outlets
Cybersecurity researchers have analyzed a content farm impersonating over 60 prominent English-language media outlets based in the United States and the United Kingdom. The research has identified over 60 domains reposting articles from credible media and research organizations without proper attribution and traced the websites’ proprietor in India. The proprietor has been observed spamming comments sections of various websites with backlinks to the domains to improve their credibility. Some of the comments also appear to be advertisements for the sale of slots for press releases and product reviews; prices start at USD 50 per post and range to "bulk deal" pricing of USD 1,000.
BEC-Specialized Hackers Mimic U.S. Government Entities to Steal Sensitive Information
TA4903, a hacker group specializing in business email compromise (BEC) attacks, has been impersonating several U.S. government agencies to deliver files with malicious links that redirect targets to fake bidding processes. Cybersecurity researchers have observed the threat actor masquerading as the U.S. Department of Transportation, the U.S. Department of Agriculture, and other federal departments. From mid-2023 through 2024, researchers have also observed the actor spoofing small and medium-sized businesses (SMBs) in several industries, including construction, manufacturing, food and beverage, energy, and finance. TA4903 reportedly carries out these financially-motivated attacks to steal corporate credentials, infiltrate mailboxes, and conduct follow-on BEC activity.
Tags: tlp:green