zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief – August 26, 2024

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief – August 26, 2024

TLP:GREEN

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on February 9, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

OpenAI Disrupts Covert Iranian Influence Operation Leveraging ChatGPT to Target U.S. Elections

What happened: OpenAI has taken down a set of ChatGPT accounts generating content used to further a covert Iranian influence operation dubbed Storm-2035 that is targeting the upcoming U.S. elections. OpenAI states the action is part of its ongoing efforts to detect and stop covert influence operations (IO). It identified 12 X (formerly Twitter) accounts contributing to Storm-2035 that purported to represent both sides of the U.S. political spectrum. The majority of social media posts the campaign published received few or no likes, shares, or comments and, hence, did not achieve any meaningful engagement. The operation ranked at the low end of Category 2 of the Brookings’ Breakout Scale, which assesses the impact of covert IO on a scale from one (lowest) to six (highest). Additionally, an extensive operation was observed in the past week in which pro-Russia websites masquerading as U.S. news outlets are posting incendiary, misleading disinformation, such as unsubstantiated claims of the Democratic Party’s involvement in a plot to kill former President Donald Trump, ahead of the high-stakes U.S. elections. The content is re-posted in various languages across several social media platforms and repeated by AI chatbots, increasing the operation’s reach and engaging a diverse audience.

Cyber Threats to U.S. Critical Food Infrastructure

What happened: The Federal Bureau of Investigation (FBI)’s second annual Agriculture Threats Symposium in Omaha, Nebraska, focused on rising cyber threats to the U.S. agriculture sector, (including ransomware attacks, intellectual property theft, and bioterrorism) exacerbated by increased digital connectivity in farming operations. Over 400 farmers, cybersecurity experts, and policymakers from 30 states attended the symposium. In the past year, ZeroFox has observed more than 200 cyber incidents against agriculture and food-related entities. The attacks were primarily conducted by the LockBit and Play ransomware groups; 45 percent of the attacked entities were in the North American region.

Blind Eagle Hackers Exploit Spear Phishing to Deploy RATs in Latin America

What happened: Cybersecurity researchers have identified a threat actor group called “Blind Eagle” (aka APT-C-36) that has consistently targeted organizations and individuals across Latin American countries, including Colombia, Ecuador, Chile, and Panama. This group, suspected to be Spanish-speaking, has been active since at least 2018. Its attacks affect various sectors (including government, financial services, and energy) and primarily involve spear phishing to distribute various remote access trojans (RATs), including AsyncRAT, BitRAT, Lime RAT, NjRAT, Quasar RAT, and Remcos RAT.

Tags: tlp:green