ZeroFox Cyber Intelligence Daily Brief - March 24, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - March 24, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - Sale of Custom Phishlets for Evilginx3 Tool
- FTC Warns of Scammers Pretending to Be Agency Staff
- APT28 Hacker Group Targeting Europe, Americas, Asia in Widespread Phishing Scheme
ZeroFox Intelligence Flash Report - Sale of Custom Phishlets for Evilginx3 Tool
On March 11, the well-regarded threat actor “blackdatabase” announced the sale of custom phishlets for Evilginx3 on the dark web forum xss. The phishlets for sale target multiple companies; prices start at USD 500 and range up to USD 5,000 for phishlets targeting specified financial sector entities. Evilginx3, when used in conjunction with phishlets, could enable attackers to steal session data, facilitate multi-factor authentication (MFA) bypass, and grant seamless access to sensitive data and funds stored in bank accounts.
FTC Warns of Scammers Pretending to Be Agency Staff
The Federal Trade Commission (FTC) is warning the public about scammers pretending to be affiliated with the agency to steal consumers’ money. The agency will never ask consumers to move their money, send them to a Bitcoin ATM, demand cash withdrawals, threaten to arrest or deport them or promise a prize. Scammers may use the names of real employees, offer free money from government grants, or claim that a family member is in trouble, and needs money. It is important to learn the signs of a scam and report it immediately. FTC has released an advisory to help the public identify and avoid imposter scams, including those involving business and government impersonators.
APT28 Hacker Group Targeting Europe, Americas, Asia in Widespread Phishing Scheme
Russian cyber espionage group APT28 has reportedly been engaged in multiple ongoing phishing campaigns across Europe, Americas, Asia. These campaigns use lure documents impersonating government and non-governmental organizations in sectors such as finance, critical infrastructure, cyber security, and healthcare. APT28 has targeted Ukrainian government entities and Polish organizations with phishing messages deploying customized decoys and information stealers like MASEPIE, OCEANMAP, and STEELHOOK. The phishing attacks impersonate entities from countries including Argentina, Ukraine, and the United States, using actual and doctored government documents to initiate infection chains. The scheme reportedly concludes with the execution of these tools, aimed at exfiltrating files, executing commands, and stealing browser data.
Tags: DIB, tlp:green