zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief – July 15, 2024

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief – July 15, 2024

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on July 12, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

Hackers Call It Quits After Releasing Data Allegedly Associated with the Heritage Foundation

What happened: “SiegedSec”, a hacktivist collective, released 2 GB of data supposedly associated with the American conservative think tank Heritage Foundation. This data dump included full names, email addresses, passwords, and usernames of individuals linked to the organization. SiegedSec's campaign, dubbed OpTransRights, targets entities supporting anti-trans and anti-abortion laws. The group targeted the Heritage Foundation supposedly due to its Project 2025 plans, perceived as a blueprint for far-right reforms under Donald Trump. Soon after announcing the leak, the group posted its plans for disbandment on its Telegram channel, adding it is trying to avoid the attention of law enforcement.

CISA and Partners Release Advisory on PRC State-Sponsored Group APT 40

What happened: The Cybersecurity and Infrastructure Security Agency (CISA) and other global security agencies have released an advisory titled “People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action.” The advisory provides information about PRC state-sponsored cyber group APT40 (also known as Kryptonite Panda, GINGHAM TYPHOON, Leviathan, and Bronze Mohawk). CISA urges all organizations and software manufacturers to review the advisory to help identify, prevent, and remediate APT 40 intrusions.

U.S. Justice Department Disrupts Covert Russian Government-Operated Social Media Bot Farm

What happened: The U.S. Department of Justice (DOJ) has announced the seizure of two domain names and investigated nearly 1,000 social media accounts linked to a Russian-operated, artificial intelligence (AI)-driven bot farm. This campaign utilized AI to fabricate fake social media profiles, often posing as Americans, to spread pro-Russian propaganda and disinformation. The Federal Bureau of Investigation (FBI) and the Cyber National Mission Force (CNMF), in collaboration with global allies, issued a joint cybersecurity advisory that outlines the technology used by the social media bot farm, including insights into how its operators utilized a customized AI system to advance its disinformation campaign. X (formerly Twitter) also suspended additional bot accounts identified in the operation for violating terms of service.

Tags: tlp:green