ZeroFox Weekly Intelligence Brief - June 10, 2024
|by Alpha Team

ZeroFox Weekly Intelligence Brief - June 10, 2024
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on June 7, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here.
CYBERSECURITY NEWS
Russia Amps up Efforts to Disrupt Paris Olympics with Disinformation: Researchers have observed Russian threat actors, including “Storm-1679” and “Storm-1099”, ramp up disinformation campaigns to target France, French President Emmanuel Macron, the International Olympic Committee (IOC), and the upcoming 2024 Paris Olympic Games. The campaign aims to besmirch the IOC while creating an impression of potential violence disrupting the international event. Storm-1679 released a feature-length film, Olympics Has Fallen, using artificial intelligence (AI) to impersonate Tom Cruise and discredit the IOC. Additionally, Storm-1679 has been disseminating false videos to incite fear of violence at the Games, while Storm-1099 has amplified anti-Olympics messaging through multiple fake news sites. Chinese State-Backed Cyber Espionage Targets Southeast Asian Government: A Chinese state-sponsored cyberespionage operation called Crimson Palace has been observed targeting a high-profile government organization. The threat group reportedly accessed critical IT systems, collected military and technical information, and conducted command-and-control (C2) communications in the interest of furthering state agendas.
UPDATES FROM THE DEEP AND DARK WEB
Threat Actor Advertises New Multi-Threaded Brute Force Tool: On June 5, 2024, untested threat actor “S O V A” advertised a new, multi-threaded brute force tool on the predominantly Russian-language dark web forum xss. In the post, the actor claims that the unnamed tool—which it is charging USD 3,000 for access to—automatically generates strings for testing and uploads data to an unlimited number of servers. S O V A further touts the tool’s easy set-up process and friendly graphical user interface.
PHYSICAL SECURITY INTELLIGENCE
Excluding the United States, there was a one percent decrease in mass casualty events this week from the previous week, with the top contributing countries being Palestine, Israel, and Mexico (in that order); approximately 77 percent of these events were explosions. This week, Mexico had the third-highest mass casualty rate internationally and was the top contributor to gun violence, which saw a significant increase from the previous week. This is undoubtedly due to Mexico hosting its presidential election on June 2, which resulted in Claudia Sheinbaum becoming the country's first female president after one of the deadliest campaigns in Mexico's history. In the past week, the top three most-alerted incident subtypes were gun violence, natural disaster, and police activity. While gun violence and natural disasters remained the top two alerted subtypes, police activity is once again in third place, with cities such as Los Angeles and Atlanta accounting for a significant amount of instances.
Tags: tlp:green