ZeroFox Weekly Intelligence Brief – November 25, 2024
|by Alpha Team

ZeroFox Weekly Intelligence Brief – November 25, 2024
TLP:GREEN
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the threat landscape, including digital, cyber, and physical threats. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EST) on November 22, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
NSO Group Used Another WhatsApp Zero-Day After Being Sued
What happened: Israeli cyber intelligence firm NSO Group (NSO) allegedly exploited multiple zero-day vulnerabilities in WhatsApp, including a previously unknown exploit called "Erised," to install its Pegasus spyware on targeted devices using zero-click attacks. According to court documents, NSO repeatedly deployed a series of exploits targeting WhatsApp zero-days, despite WhatsApp proactively blocking NSO’s access to affected devices and patching the targeted vulnerabilities. These attacks occurred even after NSO was sued by WhatsApp for its surveillance practices. NSO has admitted that it developed and sold Pegasus spyware—specifically its zero-click installation vector called “Eden,” which was part of a family of WhatsApp-based vectors known collectively as “Hummingbird.” This is not the first instance in 2024 of NSO making headlines about operations involving its spyware. As a part of its quarterly update process, in July 2024, Apple reportedly notified users across 98 countries—including prominent journalists and politicians—about a possible “mercenary spyware” attack utilizing Pegasus.
Threat Actors Declare Cyberattack Against American Cyberspace
What happened: Pro-Palestine hacker group Hunt3r Kill3r, which has ties to several pro-Russian hacker factions, has issued a statement declaring its intention to retaliate against the United States. On November 21, 2024, Hunt3r Kill3r, along with several pro-Russian allies, launched an electronic operation called #RED_EYE_OP targeting American cyberspace. The operation includes groups such as Moroccan Dragons, Keymous, Eagle Cyber Was Here, Server Killers, and Fighter Black Hat. The alleged cyberattacks are presented as retaliation for recent events in the Middle East and in response to what Hunt3r Kill3r allegedly perceives as the United States’ decision to "expand" the ongoing Russia-Ukraine war.
U.S. Senate Panel Holds Hearing on Suspected Chinese Hacking Incidents
What happened: A U.S. Senate Judiciary subcommittee held a hearing to address the growing concerns surrounding Chinese hacking incidents, particularly focusing on recent attacks targeting U.S. telecom companies. The hearing aimed to assess the risks these cyberattacks pose to national security, democracy, and the economy.
Tags: tlp:green