ZeroFox Cyber Intelligence Daily Brief - December 22, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 22, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ISA Releases Best Practice Guidance for Mobile Communications
- “Bitter” Cyberspies Target Defense Orgs with New MiyaRAT Malware
- FBI Warns Against HiatusRAT Malware
CISA Releases Best Practice Guidance for Mobile Communications
What happened: CISA released Mobile Communications Best Practice Guidance in response to cyber espionage activities by People’s Republic of China (PRC) government-affiliated threat actors targeting commercial telecommunications infrastructure, senior government, and political figures with sensitive information.
Why it matters: These actors target both commercial telecommunications infrastructure and highly valuable individuals, amplifying the risk of critical information theft or manipulation. Such breaches can lead to serious geopolitical consequences, from diplomatic tensions to national security risks. To mitigate these threats, CISA strongly urges highly targeted individuals to immediately review and apply the best practices provided in the guidance, including the consistent use of end-to-end encryption, to protect mobile communications.
“Bitter” Cyberspies Target Defense Orgs with New MiyaRAT Malware
What happened: A cyberespionage group named “Bitter” targeted defense organizations in Turkey using a new malware strain, MiyaRAT, alongside the previously used WmRAT. The attack was initiated through a malicious email, luring victims with a fake foreign investment project, which triggered the deployment of the malware.
Why it matters: Bitter is a long-running South Asian cyberespionage group, active since 2013, with a history of targeting government and critical organizations in Asia. By deploying both MiyaRAT and WmRAT, the threat group gains advanced capabilities like data exfiltration, remote control, and system monitoring, posing serious risks to sensitive military and defense data. Additionally, reports indicate that MiyaRAT is likely reserved for critical sectors, deployed infrequently to maximize its impact, making it a highly effective tool for targeted, strategic cyberattacks.
FBI Warns Against HiatusRAT Malware
Source: https://www.ic3.gov/CSA/2024/241216.pdf
What happened: The FBI has warned of a new wave of HiatusRAT malware attacks targeting vulnerable web cameras and Digital Video Recorders (DVRs), particularly Chinese-branded devices. The attackers exploit known vulnerabilities to gain access to devices, steal data, and create a botnet for further malicious activities.
Why it matters: HiatusRAT is a Remote Access Trojan (RAT) whose latest iteration has likely been employed since July 2022. The Hiatus campaign originally targeted outdated network edge devices. It is also observed that these actors use the malware to target a range of Taiwan-based organizations and to carry out reconnaissance against the U.S. government server used for submitting and retrieving defense contract proposals.
Tags: DIB, tlp:green