ZeroFox Cyber Intelligence Daily Brief - March 31, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - March 31, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report: UK Confirms Chinese State-Sponsored Cyber Attacks
- Hackers Hit Indian Defense, Energy Sectors with Malware Posing as Air Force Invite
- Two Chinese APT Groups Ramp Up Cyber Espionage Against ASEAN Countries
ZeroFox Intelligence Flash Report: UK Confirms Chinese State-Sponsored Cyber Attacks
On March 25, the UK government warned the public about Chinese-state-sponsored entities, while two U.S. government agencies sanctioned alleged Chinese hackers linked to APT31. The UK government is wary of growing threats from Chinese-state-sponsored entities targeting and undermining the country’s democratic processes. The announcement attributed two cyber attacks against UK political entities to Chinese-State-sponsored actors. The U.S. Justice Department and the FBI unsealed an indictment against seven alleged Chinese hackers associated with APT31 involved in targeting United States-based critics, businesses, and political officials over approximately 14 years.
Hackers Hit Indian Defense, Energy Sectors with Malware Posing as Air Force Invite
Indian government entities and the energy industry have been hit with a cyberattack using a modified version of an open-source information stealer called HackBrowserData that can exfiltrate sensitive information. The information stealer was delivered via a phishing email, masquerading as an Indian Air Force invitation letter. The attacker used Slack channels as exfiltration points to upload confidential internal documents, private email messages, and cached web browser data after the malware's execution. The attack chain had a phishing message containing an ISO file, which contained a Windows shortcut (LNK), triggering the execution of a hidden binary present within the mounted optical disk image. The threat actor has successfully compromised private energy companies, harvesting financial documents, personal details of employees, and details about drilling activities in oil and gas. About 8.81 GB of data has been compromised throughout the campaign.
Two Chinese APT Groups Ramp Up Cyber Espionage Against ASEAN Countries
Cybersecurity researchers have observed increased activities involving advanced persistent threat (APT) groups associated with China targeting entities in connection with the Association of Southeast Asian Nations (ASEAN). The recent wave of attacks include Mustang Panda in attacks against Myanmar and other Asian countries where the actor reportedly targeted them with phishing emails to deliver two malware packages. Additionally the actor was observed to install backdoors called DOPLUGS, a variant of PlugX backdoor. Other threat actors and groups include Earth Krahang which has targeted more than 100 entities across 35 countries to deliver malware like PlugX, ShadowPad, and more.
Tags: DIB, tlp:green