ZeroFox Weekly Intelligence Brief – April 1, 2024
|by Alpha Team

ZeroFox Weekly Intelligence Brief – April 1, 2024
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on March 29, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
Elite Russian Hackers Targeting German Politicians
APT29 (also known as Midnight Blizzard, NOBELIUM, and Cozy Bear), a hacking group associated with Russian intelligence, targeted multiple members of German political parties intending to infiltrate their networks and steal data. The hackers attempted to phish key German political figures by sending email invitations to a fictitious dinner event hosted by the Christian Democratic Union (CDU), Germany’s center-right political party. The CDU acknowledged the ongoing threat of digital attacks from both domestic and foreign sources and confirmed receiving prompt information about the attack, clarifying that the March 1 dinner event was fabricated.
CISA and FBI Release Secure by Design Alert to Urge Manufacturers to Eliminate SQL Injection Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have jointly released an alert in response to the recent, well-publicized exploitation of SQL injection (SQLi) defects in a managed file transfer application that impacted thousands of organizations. Additionally, the alert highlights the prevalence of this class of vulnerability. CISA and the FBI urge senior executives at technology manufacturing companies to mount a formal review of their code to determine its susceptibility to SQLi compromises. If found vulnerable, senior executives should ensure their organizations’ software developers begin immediate implementation of mitigations to eliminate this entire class of defect from all current and future software products.
Two Chinese APT Groups Ramp Up Cyber Espionage Against ASEAN Countries
China-linked advanced persistent threat (APT) group Mustang Panda has attacked Myanmar and other Asian countries via phishing emails to deliver malware. Additionally, the actor was observed installing a variant of the PlugX backdoor called DOPLUGS. Another group called Earth Krahang has targeted more than 100 entities across 35 countries to deliver malware such as PlugX, ShadowPad, and more.
Tags: tlp:green