ZeroFox Weekly Intelligence Brief – June 3, 2024
|by Alpha Team

ZeroFox Weekly Intelligence Brief – June 3, 2024
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on May 31, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
U.S. Treasury Sanctions Individuals Behind Infamous 911 S5 Botnet
What happened: The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) has sanctioned three individuals and three Thai companies for their association with the malicious botnet tied to the residential proxy service known as 911 S5. The sanctions mandate blocking and reporting the assets of designated individuals and entities within the U.S. or controlled by U.S. persons to OFAC. Regulations prohibit U.S. persons and those in the U.S. from dealing with blocked entities. Furthermore, those who engage in specific transactions with these entities risk being designated themselves. The accused individuals and entities used the 911 S5 botnet for fraudulent economic assistance applications and laundered proceeds through luxury real estate purchases.
Bugged Minesweeper Clones Phish Financial Organizations
What happened: Hackers are exploiting a Python clone of Microsoft's Minesweeper game to hide malicious scripts targeting financial institutions in Europe and the United States. Ukrainian cybersecurity agencies link these attacks to UAC-0188, which uses this code to install SuperOps RMM software, enabling remote access to compromised systems.
Free Piano Phish Targets American University Students, Staff
What happened: A large-scale phishing campaign enticed recipients with a promise of a free Yamaha baby grand piano. The campaign targeted mainly North American university students and faculty, as well as healthcare and food and beverage service providers, and amassed over USD 900,000 through fraudulent shipping fees.
Tags: tlp:green