zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief – April 8, 2024

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief – April 8, 2024

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on April 5, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

Indian Government Rescues 250 Citizens Forced into Cybercrime in Cambodia

What happened: The Indian government has rescued and repatriated 250 citizens in Cambodia who were forced to conduct cybercrimes. According to sources, there are more than 5,000 Indians trapped in Cambodia who are being forced to launch extortion scams. The U.S. Department of State has called out China-based organized crime syndicates for posing as labor brokers to recruit people with English proficiency from Africa and Asia via social media with promises of lucrative jobs in Southeast Asia. An investigation to locate and repatriate more victims is ongoing.

Massive Phishing Campaign Strikes Latin America; Venom RAT Targeting Multiple Sectors

What happened: The threat actor known as “TA558” has been connected to a new phishing campaign that targets a wide range of sectors in Latin America to deploy Venom RAT. The attacks primarily target hotel, travel, trading, financial, manufacturing, industrial, and government verticals in Spain, Mexico, the United States, Colombia, Portugal, Brazil, the Dominican Republic, and Argentina. Following the law enforcement takedown of QakBot last year, threat intelligence analysts have observed that threat actors have been increasingly using the DarkGate malware loader to target financial institutions in Europe and the United States.

Missouri County Hit by Ransomware

What happened: Jackson County, Missouri, disclosed a cyber incident that caused major disruptions to its IT systems, possibly due to a ransomware attack. Although investigations are ongoing to confirm the cause, the county has reportedly taken steps to contain the attack and is working on restoring services. The disruption has impacted various services, including tax payments, online property, and inmate search systems. As a mitigation measure, Assessment, Collection, and Recorder of Deeds offices at physical locations are closed until the issue is resolved.

Tags: tlp:green