ZeroFox Cyber Intelligence Daily Brief - January 3, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 3, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- “Secret and Classified” FSB Documents for Sale on Underground Forum
- New "Bad Likert Judge" Attack Enables Harmful Content Generation in AI Systems
- Malicious NPM Package Sneaks In Quasar RAT; Downloaded 66 Times
“Secret and Classified” FSB Documents for Sale on Underground Forum
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/78487
What happened: On January 2, 2025, ZeroFox observed a threat actor advertising what they claimed to be sensitive and confidential documents belonging to the Russian Federal Security Service (FSB) on a hacking forum called DarkForums. The actor posted the leaked sample data along with a password.
Why it matters: The FSB is Russia's principal security agency and if the actor's claims are true, the allegedly leaked files will likely expose sensitive details regarding the country’s security apparatus to various interested parties. It is likely to draw the attention of both financially motivated and politically motivated nation-state actors. The actors are likely to use such data for malicious attacks—including blackmail and extortion—or to give their states a strategic upper hand.
New "Bad Likert Judge" Attack Enables Harmful Content Generation in AI Systems
What happened: A new jailbreak technique, called the “Bad Likert Judge” attack, exploits the Likert scale used by large language models (LLMs) like OpenAI to rate the harmfulness of generated content. This manipulation allows attackers to bypass cybersecurity guardrails and prompt the model into generating harmful content.
Why it matters: The Bad Likert Judge attack allows attackers to bypass safety filters by manipulating the Likert scale, potentially generating harmful content like hate speech, self-harm, explicit material, and illegal instructions. This exploitation of vulnerabilities challenges current AI security methods, increasing the risk of malicious content, including malware generation. Additionally, OpenAI has previously confirmed that Chinese and Iranian threat actors have leveraged the technology to enhance their cyberattacks.
Malicious NPM Package Sneaks In Quasar RAT; Downloaded 66 Times
Source: https://thehackernews.com/2025/01/malicious-obfuscated-npm-package.html
What happened: Cybercriminals have created a fake npm package named ethereumvulncontracthandler to mislead developers into believing it as a legitimate tool for identifying security flaws in Ethereum smart contracts. The obfuscation leads unsuspecting developers into installing an open-source remote access trojan called Quasar RAT to exfiltrate information from affected devices.
Why it matters: Open-source malware like Quasar RAT can evade detection, deploy further malicious tools, and grant attackers complete control of infected devices. The rise of fake popularity metrics, such as inflated GitHub stars, further deceives users into trusting and downloading these malicious repositories. Quasar RAT has reportedly been downloaded 66 times since its release on December 18, 2024, indicating that these devices are likely under the surveillance and control of the threat actor deploying the malicious packages.
DEEP AND DARK WEB INTELLIGENCE
Actors offering holiday season discounts and deals: The holiday season regularly sees an increase in cybercrime activity, with the surge in online shopping providing an opportunity for criminals to launch numerous fake, alluring advertisements and phishing campaigns. Threat actors like Dark Storm Team, Sylhet Gang, and Turk Hack Team have been observed offering giveaways, cheaper security courses, discounts on their DDoS and hacking services, etc.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2022-23227: NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user[.]php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite arbitrary files under the web root and achieve code execution as root.
Affected products: NUUO NVRmini2 versions through 3.11
Tags: DIB, tlp:green