zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief – September 23, 2024

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief – September 23, 2024

TLP:GREEN

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on September 20; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

U.S. Sanctions Key Players in Intellexa Consortium for Predator Spyware Distribution

What happened: The U.S. Treasury Department imposed sanctions on five individuals and one entity tied to the Intellexa Consortium, the developer of Predator spyware and manager of entities supplying spyware tools to foreign governments. The Intellexa Consortium is a complex international web of decentralized companies that built and commercialized a comprehensive suite of highly invasive spyware products, primarily marketed under the “Predator.” The sanctions target the consortium's efforts to evade previous sanctions and continue selling the spyware through complex corporate structures. In March 2024, the United States issued sanctions against the founder of the Intellexa consortium—a former Israeli military officer who had founded the company—and other entities, including North Macedonia-based Cytrox AD, Hungary-based Cytrox Holdings ZRT and Ireland-based Thalestris Limited, for developing and distributing Predator.

Chinese National Charged for Multi-Year “Spear-Phishing” Campaign

What happened: A Chinese national was indicted on charges of wire fraud and aggravated identity theft for a multi-year spear phishing campaign. He allegedly impersonated U.S.-based researchers and engineers to fraudulently obtain restricted computer software and source code from the National Aeronautics and Space Administration (NASA), research universities, and private companies. The accused was employed as an engineer at the Aviation Industry Corporation of China (AVIC)—one of the largest global defense contractors and a major manufacturer of both civilian and military aircraft—and conducted these activities while working there.

CISA Releases Analysis of FY23 Risk and Vulnerability Assessments

What happened: CISA has published an analysis detailing the findings from the 143 risk and vulnerability assessments (RVAs) conducted across multiple critical infrastructure sectors in fiscal year 2023 (FY23). The analysis details a sample attack path, including tactics and steps a cyber threat actor could follow to compromise an organization with weaknesses representative of those CISA observed in FY23 RVAs. To defend against the abuse of valid accounts, Critical Infrastructure (CI) entities should implement strong password policies and phishing-resistant multi-factor authentication (MFA). Identity Access Management (IAM) solutions and granular access controls should be utilized to protect privileged accounts and credentials. Monitoring access logs for abnormal activity and responding swiftly to detected anomalies is crucial to limiting damage. Additionally, CI entities should deploy intrusion prevention strategies, such as using a centralized cyber threat intelligence platform and adopting a secure, layered network architecture with firewalls, encryption, and segmentation. CISA encourages organizations to tailor these recommendations to their environments to mitigate high-level vulnerabilities.

Tags: tlp:green