ZeroFox Weekly Intelligence Brief – March 18, 2024
|by Alpha Team

ZeroFox Weekly Intelligence Brief – March 18, 2024
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on February 9, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
French Government Targeted in Denial-of-Service Attacks by Pro-Russian Hackers
What happened: On March 11, the French government said that cyberattacks of “unprecedented intensity” had targeted several of its services, prompting it to activate a special crisis center to restore online services. A French official noted that it was a series of distributed denial-of-service (DDoS) attacks. A statement from Prime Minister Gabriel Attal’s office added that the attacks had impacted multiple French state bodies but that the government had been able to contain the impact of the cyberattacks and restore access to its targeted websites.
Fortinet Warns of Severe SQLi Vulnerability in FortiClientEMS Software
What happened: Fortinet has issued a warning about a critical security vulnerability affecting its FortiClientEMS software, potentially allowing attackers to undertake code execution on affected systems. The flaw (CVE-2023-48788) has a CVSS rating of 9.3 out of 10 and impacts several versions of FortiClientEMS. The vulnerability in FortiClientEMS involves an SQL injection flaw, which is categorized under CWE-89.
New Banking Trojan CHAVECLOAK Targets Brazilian Users via Phishing Tactics
What happened: A new banking trojan called CHAVECLOAK is targeting users in Brazil through phishing emails that contain PDF attachments. The phishing emails use DocuSign lures related to contracts to trick users into opening the PDF files, which contain a button to read and sign the documents. However, clicking the button triggers the retrieval of an installer file from a shortened remote link, which installs the CHAVECLOAK trojan on victims’ systems.
Tags: tlp:green