ZeroFox Intelligence Flash Report - Actor Seeks Access to Government and Critical Infrastructure Networks
|by Alpha Team

ZeroFox Intelligence Flash Report - Actor Seeks Access to Government and Critical Infrastructure Networks
Product Serial: F-2024-04-02a
TLP:CLEAR
In this flash report, ZeroFox researchers report on an untested threat actor seeking illicit access to the networks of government and critical infrastructure entities in a deep and dark web forum.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- On March 27, 2024, untested threat actor “Nikazon” posted in the deep and dark web (DDW) forum RAMP advertising their search for affiliates able to provide illicit access to the networks of industrial, military, justice, and political targets.
- ZeroFox observed an approximately 55 percent increase in the number of ransomware and digital extortion (R&DE) attacks targeting organizations within the defense, government, and critical infrastructure sectors between Q1 2023 and Q1 2024.
- This advertisement is likely supportive of an ongoing shift in DDW norms manifested by financially-motivated R&DE threat actors punitively seeking victim organizations—the targeting of which would traditionally be frowned upon by other groups, affiliates, and platform moderators.
Tags: tlp:clear, dark web, geo-political, DDW Ransomware