ZeroFox Weekly Intelligence Brief – Jan 20, 2025
|by Alpha Team

ZeroFox Weekly Intelligence Brief – January 20, 2025
TLP:GREEN
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EST) on January 17, 2025; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
CISA Publishes Guidance on Priority Considerations in Product Selection for OT Owners and Operators
What happened: Cybersecurity and Infrastructure Security Agency (CISA)—along with the United States and international partners—released a Secure by Demand joint guidance. This guidance focuses on helping customers identify manufacturers dedicated to continuous improvement and achieving a better cost balance, as well as on how operational technology (OT) owners and operators should integrate Secure by Design elements into their procurement process. CISA and partners have warned that cyber threat actors, when compromising OT components, target specific OT products rather than specific organizations.
International LE Operation Removes Chinese Malware from Thousands of Computers
What happened: The U.S. Department of Justice and the Federal Bureau of Investigation, in partnership with international law enforcement (LE), launched a multi-month operation to remove the PlugX malware from thousands of infected computers worldwide. The malware, deployed by a group of hackers allegedly associated with the Chinese government and known as “Mustang Panda” and “Twill Typhoon,” was used to steal information from compromised systems. Court documents revealed that the Chinese government funded this hacking group to develop and deploy the malware, which has been active since at least 2014. This operation targeted computer systems in the United States, Europe, and Asia, as well as Chinese dissident groups.
Joint Collaboration on AI Cybersecurity
What happened: The AI Cybersecurity Collaboration Playbook provides guidance to organizations across the artificial intelligence (AI) community—including AI providers, developers, and adopters—for sharing AI-related cybersecurity information voluntarily with CISA and other partners through the Joint Cyber Defense Collaborative (JCDC). While focused on strengthening collaboration within the JCDC, the playbook also identifies actionable information-sharing categories applicable to broader critical infrastructure stakeholders and other sharing mechanisms. CISA encourages organizations to adopt the playbook’s guidance to enhance their own information-sharing practices, contributing to a unified approach to AI-related cybersecurity threats across critical infrastructure.
Tags: tlp:green