zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 7, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - January 7, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Eagerbee Backdoor Now Hits Middle East
  • Chinese Hackers Target Philippine Government in Ongoing Espionage Campaign
  • Moxa Issues Urgent Patches for Vulnerabilities in Industrial Networks

Eagerbee Backdoor Now Hits Middle East

Source: https://www.darkreading.com/cyberattacks-data-breaches/eagerbee-backdoor-middle-east-isps-government-targets

What happened: An updated version of the Eagerbee backdoor is now being deployed against internet service providers (ISPs) and government organizations in the Middle East. It is still unknown how the threat actor gained entry to these systems, but the remote code execution vulnerability—CVE-2021-26855—was reportedly exploited in attacks at two other Asian companies.

Why it matters: The malware was observed to have gathered operating system details and network addresses on infected devices, indicating that the threat actors are likely monitoring these companies’ activities to steal sensitive data. Although the initial access vector could not be determined, researchers observe that this backdoor is sophisticated and can evade detection through traditional endpoint security solutions. This backdoor has also been observed in Japan, which likely means that the threat actors are aiming for a global trajectory.

Chinese Hackers Target Philippine Government in Ongoing Espionage Campaign

Source: https://www.bloomberg.com/news/articles/2025-01-07/chinese-hackers-target-philippine-president-steal-military-data?srnd=homepage-asia

What happened: Chinese-state sponsored hackers infiltrated the executive branch of the Philippines government, stealing sensitive data as a part of an ongoing espionage campaign. This breach, which included military documents related to the South China Sea dispute, occurred over the course of several months in 2023 and 2024, with tactics linked to the Chinese hacking group APT 41.

Why it matters: The attack impacted government agencies and hospital networks, with hackers using stolen credentials to deploy malware and erase traces of their activities to evade detection. The stolen data, particularly regarding military matters related to the South China Sea, can potentially be further sold to financially motivated groups seeking to exploit it for profit or shared with other state-backed threat actors seeking to advance their geopolitical interests, strengthen military position, counter rival nations, or gain strategic advantages in the region. The tactics used by APT41, including credential theft and malware deployment, reflect a sustained espionage campaign.

Moxa Issues Urgent Patches for Vulnerabilities in Industrial Networks

Source: https://www.bleepingcomputer.com/news/security/vulnerable-moxa-devices-expose-industrial-networks-to-attacks/

What happened: Moxa, an industrial networking and communications provider, has issued an urgent warning regarding two bugs in various models of its cellular routers, secure routers, and network security appliances. The bugs, CVE-2024-9138 and CVE-2024-9140, can enable threat actors to gain root privileges on vulnerable devices and to execute arbitrary commands.

Why it matters: The bugs will likely expose several systems using Moxa devices to arbitrary code execution or remote exploitation. Moxa devices are present in industrial automation and control systems in transportation, utilities, energy, and telecommunications, all considered critical infrastructures. Threat actors are likely to exploit any vulnerability in such devices to gain control over them, exfiltrate sensitive data, or even conduct cyber espionage.

DEEP AND DARK WEB INTELLIGENCE

Telegram user Anonymous Sudan: Sudan-based religiously and politically motivated hacktivist group "Anonymous Sudan" has made a comeback. The cybercrime group is well known for launching powerful distributed denial-of-service (DDoS) against the West.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-21616: Plane is an open-source project management tool. A cross-site scripting (XSS) vulnerability has been identified in Plane versions prior to 0.23. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image.

Affected products: Plane versions prior to 0.23

Tags: DIB, tlp:green