ZeroFox Weekly Intelligence Brief – December 30, 2024
|by Alpha Team

ZeroFox Weekly Intelligence Brief – December 30, 2024
TLP:GREEN
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EST) on December 27, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
After Exploiting Cleo’s File Transfer Platforms, Cl0p Ransomware Claims 66 Victims
What happened: ZeroFox Intelligence has observed Russia-based criminal ransomware collective Cl0p claiming responsibility for exploiting alleged zero-day vulnerabilities (CVE-2024-55956 and CVE-2024-50623) in Cleo file transfer tools to target 66 organizations in data theft attacks. In the leak site post, the group further warned that it would publicize the names of the companies if they failed to meet its demands within 48 hours from the initial posting. Cl0p was also responsible for the May 2023 exploitation of CVE-2023-34362, a zero-day vulnerability in the MOVEit file transfer software that affected at least 2,600 organizations. Although Cl0p operates primarily as a ransomware group, it also uses the ransomware-as-a-servicem (RaaS) model, selling access to its brand of malware.
Lazarus Group Targets Nuclear Industry with CookiePlus Malware
What happened: The North Korea-linked Lazarus Group has escalated its cyberattacks by targeting the nuclear industry, shifting away from previous focuses on defense, aerospace, and cryptocurrency. Over the course of a month, the group sent malicious files to at least two employees of a nuclear organization through fake job postings, a tactic known as the “DeathNote campaign” or “Operation DreamJob.” Victims were lured by fraudulent job offers and tricked into opening files disguised as job assessments. These files, often appearing as legitimate tools like VNC viewers or ZIP archives, contained malicious payloads that, when executed, granted the attackers unauthorized access to the victims' systems.
U.S. Law Enforcement Officials Release Final “Don’t Click December” PSA
- What happened: U.S. law enforcement authorities have released a fourth public service announcement (PSA) as part of their joint “Don’t Click December” Consumer Protection Campaign. The PSA warns residents about the surge in online scams and fraud schemes during the holiday season. With additional support from the American Association of Retired Persons (AARP), the initiative aims to raise awareness and help consumers avoid falling victim to phishing emails, fake websites, and other common online scams.
Tags: tlp:green