ZeroFox Weekly Intelligence Brief – November 11, 2024
|by Alpha Team

ZeroFox Weekly Intelligence Brief – November 11, 2024
TLP:GREEN
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on Novemeber 8; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
Pro-Palestine Hacktivist Groups Targeting Turkey
On November 3 and 4, 2024, ZeroFox observed several pro-Palestine hacktivist groups coordinating cyberattacks targeting Turkish entities. Groups like LulzSec Black, 1915 Team, and Anonymous Syria defaced a Turkish online store, linking their actions to Turkish military operations in Kurdish regions. Another group, Sylhet Gang, targeted the Turkish Armed Forces Foundation website as part of a campaign labeled #op_turkey. Additionally, the groups EvilByte Algeria, Anonymous Syria, PARADOX 17, and LulzSec Muslims pledged to unite with other pro-Arab hacktivist actors. Moroccan Soldiers claimed they breached some databases of a Turkish furniture company, and the Moroccan Black Cyber Army reportedly launched attacks on Turkish media, hospitals, and health centers.
North Korean Hackers Target macOS Users
A recent cyberattack campaign led by the North Korean hacking group BlueNoroff has been targeting macOS users, particularly those in the cryptocurrency and decentralized finance (DeFi) sectors. The attackers are using phishing emails with fraudulent news headlines or stories about cryptocurrency trends to lure victims into downloading malicious applications. These applications, disguised as links to PDF documents on topics like Bitcoin price surges or the future of stablecoins, are designed to infect macOS systems with malware. The campaign, dubbed “Hidden Risk,” relies on these deceptive emails to gain initial access, which is followed by the execution of malicious code on the victim’s device.
Custom "Pygmy Goat" Malware Used in Firewall Hack on Government Network
The UK National Cyber Security Centre (NCSC) has released a report on a Linux malware strain called Pygmy Goat that is targeting specific network firewall devices via a sophisticated backdoor. The malware, likely linked to a Chinese threat actor, uses deceptive techniques to blend into systems and access devices remotely. Featuring advanced persistence and evasion methods, Pygmy Goat compromises devices by exploiting CVE-2022-1040 and is often deployed on high-level government and technology partner networks. The malware’s structure mirrors known nation-state tactics, leveraging complex execution paths to avoid detection and maintain long-term access.
Tags: DIB