ZeroFox Weekly Intelligence Brief – June 24, 2024
|by Alpha Team

ZeroFox Weekly Intelligence Brief – June 24, 2024
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on June 21, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
Ukraine Dismantles Pro-Russia Spyware Operation amid Rising Cybersecurity Threats
What happened: The Security Service of Ukraine (SSU) dismantled infrastructure used by two pro-Russia Ukrainian residents to hack soldiers' devices and deploy spyware. Ukrainian authorities discovered thousands of mobile numbers and Telegram accounts under the control of SIM farm–like infrastructure that were abused by Russian intelligence services. One of the pro-Russia residents targeted Ukrainian soldiers with phishing SMS messages that contained spyware links, leading to compromised data and communications. The second individual managed a similar operation, running 15,000 social media accounts and selling access on dark web forums, primarily to Russian intelligence.
Barriers to Single Sign-On (SSO) Adoption for Small and Medium-Sized Businesses
What happened: CISA released a report to help small and medium businesses deal with the challenges of single-sign-on (SSO) adoption. The report also summarizes views of vendors and customers and provides a set of recommendations for encouraging SSO adoption.
IntelBroker Leaks Database Allegedly Belonging to AMD
What happened: On June 18, ZeroFox Intelligence observed threat actor “IntelBroker” leaking a database allegedly associated with Advanced Micro Devices (AMD), a well-known U.S.-based semiconductor manufacturing company, on BreachForums. The actor claims the compromised data includes future AMD products, spec sheets, employee databases, customer databases, property files, ROMs, source code, firmware, and finances. AMD is currently investigating these claims.
Tags: tlp:green