zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief –December 23, 2024

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief –December 23, 2024

TLP:GREEN

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EST) on December 20, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

Iranian Company Founder Arrested for Supporting IRGC and Procuring U.S. Tech for Military Drones

What happened: An indvidual and their co-defendant (founder of an Iranian company) have been charged with conspiring to illegally export advanced electronic components from the United States to Iran. These components were allegedly used to help develop drone technology for the Iranian Revolutionary Guard Corps (IRGC). The two defendants have been charged with circumventing U.S. export controls and sanctions to supply sensitive technology to an Iranian company that develops technology the IRGC uses in its one-way attack drones.

Germany Disrupts BADBOX Malware

What happened: Germany's Federal Office of Information Security (BSI) [dismantled](https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2024/241212_Badbox_Sinkholing.html) a sophisticated malware operation called BADBOX. This malware strain was reportedly pre-installed on 30,000 devices, including phones, tablets, and smart home devices. BADBOX, likely originating from China, collected sensitive data, introduced additional malware, and was involved in ad fraud. The infected devices were also exploited as proxies to mask other cyberattacks. In a recent update, BadBox malware has now infected a total of 92,000 devices despite law enforcement action.

CISA and EPA’s Advisory on Internet-Exposed HMIs Risks to WWS Sector

What happened: Cybersecurity and Infrastructure Security Agency (CISA) and the Environmental Protection Agency (EPA) released a joint fact sheet providing Water and Wastewater Systems (WWS) facilities with recommendations for limiting the exposure of Human Machine Interfaces (HMIs) and securing them against malicious cyber activity. The EPA and CISA have urged WWS facilities to inventory internet-exposed devices, disconnect them from the internet when possible, and secure those that remain connected with strong usernames and passwords.

Tags: tlp:green