zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief – March 25, 2024

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief – March 25, 2024

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on March 22, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

Chinese APT Conducts Widespread Operation; Breaches 70 Organizations Worldwide

What happened: Chinese advanced persistent threat (APT) group Earth Krahang has breached 70 organizations and targeted at least 116 across 45 countries in a sophisticated campaign active since early 2022. The threat group has reportedly compromised 48 government institutions, 10 of which are Foreign Affairs ministries, and targeted another 49 government agencies. The attackers exploit vulnerabilities in internet-connected servers and send spear-phishing emails to trick targets into installing custom backdoors for cyberespionage. Researchers have observed the adversary mainly targeting government, education, and communication sectors extensively.

FTC Warns of Scammers Pretending to Be Agency Staff

What happened: The Federal Trade Commission (FTC) is warning the public about scammers pretending to be affiliated with the agency to steal consumers’ money. The agency will never ask consumers to move their money, send them to a Bitcoin ATM, demand cash withdrawals, threaten to arrest or deport them, or promise a prize. Scammers may use the names of real employees, offer free money from government grants, or claim that a family member is in trouble and needs money. It is important to learn the signs of a scam and report it immediately. FTC has released an advisory to help the public identify and avoid imposter scams, including those involving business and government impersonators.

Spa Grand Prix Email Account Hacked to Phish Banking Info From Fans

What happened: Hackers recently targeted the Belgian Grand Prix event in a phishing attack that lured fans with the promise of a EUR 50 gift voucher to a fake website resembling its official site. The attackers hijacked the official contact email to send victims malicious emails with an embedded link directing them to the site where victims entered their payment information. The phishing attack is being contained as investigations are trying to determine the cause and the scale after SPA GP responded to the attack in a few hours.

Tags: tlp:green