ZeroFox Cyber Intelligence Daily Brief - January 6, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 6, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- U.S. Sanctions Chinese Cybersecurity Firm Associated with State-Sponsored Hacks
- FireScam Sneaks into Certain Android Devices Via Fake Telegram App
- Unsecured Server at Online Gift Card Store Exposes Personal Identity Documents
U.S. Sanctions Chinese Cybersecurity Firm Associated with State-Sponsored Hacks
Source: https://home.treasury.gov/news/press-releases/jy2769
What happened: The United States has sanctioned Beijing-based cybersecurity firm Integrity Technology Group for its role in hacks—attributed to Chinese state-sponsored actor Flax Typhoon—targeting U.S. victims.
Why it matters: Between the summer of 2022 and the fall of 2023, Flax Typhoon actors used infrastructure tied to Integrity Technology Group during their computer network exploitation activities against multiple victims. Flax Typhoon, along with other Chinese state-sponsored actors like Volt Typhoon and Salt Typhoon, have been consistently targeting sensitive data and critical infrastructure, posing a risk to U.S. national security. Through such state-sponsored campaigns, adversarial states are likely to obtain confidential intelligence to gain a strategic upper hand over the targeted country.
FireScam Sneaks into Certain Android Devices Via Fake Telegram App
Source: https://hackread.com/firescam-infostealer-spyware-android-fake-telegram-premium/
What happened: Threat actors are impersonating Telegram Premium to install the FireScam malware strain in certain Android devices. Users are tricked into downloading this malicious application through phishing websites and social engineering tactics and unknowingly allowing the malware strain to monitor and access their data.
Why it matters: FireScam is reportedly a sophisticated information stealer that has advanced obfuscation techniques; and, among other functionalities, also hijacks compromised device’s unstructured supplementary service data (USSD). USSD is essential to a mobile device’s communication in real time with a server. Intercepting USSD responses likely provides threat actors with sensitive user data like financial information like financial credentials and transactions, leaving them susceptible to phishing attacks and financial scams.
Unsecured Server at Online Gift Card Store Exposes Personal Identity Documents
What happened: An online gift card store, MyGiftCardSupply, exposed over 600,000 identity documents, including passports and driving licenses, as well as 200,000 selfies of customers. These sensitive files were publicly accessible due to an unsecured storage server hosted on a popular cloud storage platform. The server lacked a password, allowing anyone on the internet to access the data.
Why it matters: As part of U.S. anti-money laundering regulations, companies like MyGiftCardSupply are required to conduct “Know Your Customer” (KYC) checks, which often involve collecting highly sensitive identity documents. The exposed data included government-issued IDs, which can be exploited for identity theft, fraud, and other malicious activities, enabling cybercriminals to impersonate customers, open accounts, or apply for loans in their names. The lack of password protection on the server left the data exposed to anyone on the internet, significantly increasing the risk of unauthorized access and malicious attacks.
DEEP AND DARK WEB INTELLIGENCE
Exploit user disk: Untested threat actor "disk" advertised an auction for RDWeb access with user rights to an undisclosed U.S.-based company on predominantly Russian language Dark Web forum Exploit.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-43405: A high-severity vulnerability has been revealed in ProjectDiscovery's Nuclei, a popular open-source vulnerability scanner. If exploited, this flaw can likely enable attackers to bypass signature checks and possibly execute malicious code.
Affected products: All versions of Nuclei later than 3.0.0
Tags: DIB, tlp:green