ZeroFox Cyber Intelligence Daily Brief - January 2, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 2, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- New Timing-Based Attack Evades Clickjacking Defenses
- Prolific Threat Actor Group Observed Leveraging Compromised Cloud
- Suspect Accused of Hacking Trump's AT&T Call Records Arrested
New Timing-Based Attack Evades Clickjacking Defenses
Source: https://thehackernews.com/2025/01/new-doubleclickjacking-exploit-bypasses.html
What happened: A new timing-based vulnerability called "DoubleClickjacking" reportedly enables attackers to bypass clickjacking defenses using a double-click sequence. Threat actors deploy clickjacking to deceive users into clicking on an element on a webpage that appears harmless by manipulating the user interface, leading to clickers downloading malicious files.
Why it matters: DoubleClickjacking tricks users into unknowingly giving access to sensitive accounts or systems, bypassing existing defenses like X-Frame-Options and SameSite cookies. By exploiting user interactions, such as double-clicking, attackers can approve malicious permissions, like harmful OAuth apps. The technique can likely allow further malicious activities such as account takeovers and approval of harmful permissions with minimal user interaction.
Prolific Threat Actor Group Observed Leveraging Compromised Cloud Environment Credentials
Source: https://hackread.com/fortiguard-labs-ec2-grouper-aws-credential-exploits/
What happened: Researchers have identified a threat actor group, EC2 Grouper, that frequently leverages compromised credentials using tools associated with a widely popular provider of cloud environments and APIs.
Why it matters: In its attacks, EC2 Grouper uses API to conduct reconnaissance, create security groups, and provision resources, bypassing direct actions like inbound access configuration. Moreover, compromised cloud environment credentials can expose their owners to further malicious attacks while also threatening the security of sensitive information likely stored in those cloud environments.
Suspect Accused of Hacking Trump's AT&T Call Records Arrested
Source: https://www.theregister.com/2025/01/01/us_army_soldier_att_call_logs/
What happened: An individual in Texas has been arrested on charges of unlawfully transferring confidential phone records. The accused is suspected of being a cybercriminal known as Kiberphant0m, who allegedly breached at least 15 telecommunications firms, including AT&T and Verizon.
Why it matters: The charges suggest Kiberphant0m knowingly sold and shared sensitive phone records without permission, which likely can lead to identity theft, extortion, and other crimes. Kiberphant0m even bragged on BreachForums about stealing AT&T call logs for President-elect Donald Trump and Vice President Kamala Harris. The individual is suspected to be connected to a larger group of cybercriminals, working together to profit from stolen data.
DEEP AND DARK WEB INTELLIGENCE
New Alliance of Hacktivists on Telegram: Pro-Palestine threat actor group "LulzSec Black" has announced an alliance with "Almoravid Cyber Brigade," another pro-Palestine threat actor group, to strengthen their cyber forces.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-0168: A vulnerability has been found in code-projects Job Recruitment 1.0. This affects an unknown part of a PHP file. The manipulation of the argument leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected products: Code-projects Job Recruitment version 1.0
Tags: DIB, tlp:green