zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief – April 22, 2024

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief – April 22, 2024

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on February 9, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

LockBit Strikes Unidentified Organization in West Africa with a New Variant

What happened: According to researchers, LockBit has targeted an unidentified organization in West Africa with a sophisticated attack leveraging a new variant of the LockBit 3.0 builder. Under the guise of being a system administrator, threat actors infected several of the victim’s systems with the LockBit 3.0 builder variant. This new variant can generate custom, self-propagating ransomware to disable defense software on target systems, encrypt network shares, and bypass detection by deleting Windows Event Logs. The malware strain can also orchestrate attacks on select systems and corrupt documents or spreadsheets.

Hackers Hide Malicious Codes in Images to Target 320 Organizations Globally

What happened: Researchers have observed threat actor “TA558” using images infected with malicious code to deploy malware tools on targeted systems in over 320 organizations globally. The campaign initiates with emails containing seemingly harmless attachments that exploit a seven-year-old patched remote control execution (RCE) vulnerability in Microsoft Office. The attachments comprise a Visual Basic Script (VBS) that fetches an image file (JPG). The image comes with PowerShell code that downloads the final payload, delivering a diverse range of malware families. One way to fortify against this malware-delivery campaign is to update Microsoft Office to the latest versions.

Cisco Warns of Large-Scale Brute Force Attacks Against VPN Services

What happened: Cisco has warned of a large-scale credential brute-forcing campaign that is targeting VPN and SSH services on devices worldwide. The attackers use a combination of valid and generic employee usernames related to specific organizations in order to gain access to the internal network or hijack a device. The affected devices are manufactured by multiple companies, including Cisco, CheckPoint, Fortinet, SonicWall, and Ubiquiti.

Tags: tlp:green