zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief – September 16, 2024

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief – September 16, 2024

TLP:GREEN

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on September 13, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

Polish Security Neutralizes Sabotage Attempts Linked to Russia and Belarus

What happened: Polish security services have successfully neutralized a cyber sabotage mission originating in Russia and Belarus reportedly aimed at destabilizing Poland. Saboteurs—allegedly based in Belarus and collaborating with Russia—infiltrated local and central government institutions, including state-owned companies that handle military contracts. The development comes amidst an increase in cyberattacks targeting states and entities supporting Ukraine in the Russia-Ukraine war. This particular sabotage effort is part of a broader surge in cyberattacks against Poland, a key aid supplier to Ukraine. Additionally, in the past week, German domestic intelligence agency Bundesamt für Verfassungsschutz (BfV) warned about military cyber group “UNC2589”, which is linked to Russian military intelligence (GRU) Unit 29155. The group, also referred to as “Cadet Blizzard” or “Ember Bear”, has conducted cyberattacks on NATO and European Union (EU) countries. The warning was a collaborative effort with international partners, including the Federal Bureau of Investigation, the Cybersecurity & Infrastructure Agency (CISA), and the National Security Agency. BfV highlighted the group’s activities involving espionage, website defacement, and data theft. UNC2589 is also linked to the 2018 Skripal poisoning, raising questions about Russian cyber aggression amid ongoing geopolitical tensions.

Two Terrorgram Leaders Charged for Inciting Hate Crimes

What happened: Two leaders of the white supremacist group Terrorgram Collective were indicted for using Telegram to promote violence and hate crimes. The U.S. Department of Justice (DOJ) stated that the group’s leaders used the platform to share ideologies, plan attacks on critical infrastructure, and call for assassinations of government officials. The DOJ asserted that Terrorgram Collective’s influence extends internationally, with individuals obtaining its guidance to carry out violent acts that have included shootings and stabbings in Slovakia and Turkey targeting LGBTQ+ and Muslim communities. The indictment charges that the defendants used Telegram to promote white supremacist "accelerationism" and solicit hate crimes targeting Black, immigrant, LGBT, and Jewish people, as well as government and corporate leaders. Their goal was to incite a race war and accelerate the collapse of the government to establish a white ethnostate. The defendants encouraged followers to identify and kill targets, providing instructions on how to commit attacks. They celebrated past mass shooters as "saints," inspiring future violence.

Russian Media Outlet Accused of Using U.S. and Other Personalities to Sway 2024 Election

What happened: Russian state media outlet RT is reportedly engaging American and other influencers to sway U.S. voters in favor of Republican presidential candidate Donald Trump over his Democratic rival, Kamala Harris. This information emerged during a briefing on foreign meddling in the upcoming presidential election as part of a wider U.S. government initiative to combat such interference. Recently, the DOJ charged two RT employees with money laundering, accusing them of being involved in a scheme to hire an American company to create online content aimed at influencing voter opinion. U.S. officials highlighted that Russia is the most aggressive foreign player in these efforts, while China is allegedly concentrating on influencing local elections. Meanwhile, Iran has ramped up its activities to impact U.S. voters as compared to previous election cycles. The DOJ disclosed that the RT employees used shell companies and fake identities to channel USD 10 million to a Tennessee firm that produced videos designed to exacerbate U.S. political divisions.

Tags: tlp:green