ZeroFox Cyber Intelligence Daily Brief - January 9, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 9, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Assessment - 2024 Ransomware and Digital Extortion Overview
- Ivanti Warns of Critical Vulnerability Exploited in Attacks
- Russian Internet Now Being Restored After Ukrainian Cyber Alliance Wiped Data
ZeroFox Intelligence Assessment - 2024 Ransomware and Digital Extortion Overview
Source: https://www.zerofox.com/advisories/29257/
What happened: ZeroFox observed at least 4,950 separate ransomware and digital extortion (R&DE) incidents throughout 2024—significantly more than the approximately 4,000 incidents observed during 2023. As this total accounts primarily for incidents in which a victim has either failed to pay or remains in negotiations with the attackers, the true total is almost certainly significantly higher.
Why it matters: R&DE collectives tend to target opportunistically, with patterns shaped most significantly by the network access that can be procured in deep and dark web forums and both the experience and preference of R&DE collective affiliates. However, North America is almost certainly perceived as a region comprising an abundance of lucrative, high-payoff potential targets. Both new and existing collectives will almost certainly continue to test new tactics, techniques, and procedures during 2025, such as an increased emphasis on data extraction over traditional encryption methods and opting for double or triple extortion tactics in a bid to increase the chance of ransom demands being met.
Ivanti Warns of Critical Vulnerability Exploited in Attacks
What happened: Ivanti has addressed one critical (CVE-2025-0282) and one high vulnerability (CVE-2025-0283) in Ivanti Connect Secure, Policy Secure, and ZTA Gateways—of which CVE-2025-0282 is currently under active exploitation. CISA has added CVE-2025-0282 to its Known Exploited Vulnerabilities Catalog.
Why it matters: Threat actors are likely to exploit CVE-2025-0282, which enables remote code execution, to deploy data-stealing malware, or to execute commands for data exfiltration directly. Ivanti has released a patch for the vulnerable versions of Ivanti Connect Secure, the product in which the company has evidence of exploitation. Given the widespread use of Ivanti Connect Secure, devices using vulnerable versions of this product must deploy the patch soon to avoid risks of exploitation.
Russian Internet Now Being Restored After Ukrainian Cyber Alliance Wiped Data
What happened: Russia is now restoring its internet connection from backus after Ukrainian hackers “destroyed” its network. Ukrainian Cyber Alliance took credit for hacking Russia’s internet service provider (ISP), Nodex, and for stealing sensitive data and wiping internal servers.
Why it matters: The Ukrainian Cyber Alliance, formed in 2016, has actively targeted Russia since the onset of the war in Ukraine. The group is observed to have been targeting Russia’s critical infrastructure, including the Ministry of Defense, the Donetsk People's Republic's Ministry of Coal and Energy, and the Commonwealth of Independent States Institute. Given Russia’s large physical size, which likely makes combat efforts difficult, cyber strategies—especially those focused on targeting the country’s critical infrastructure—are likely alternatives to destabilize Russia from within and fast track efforts to end the war.
DEEP AND DARK WEB INTELLIGENCE
Exploit user Fyodorovich: Untested threat actor "Fyodorovich" advertised SonicWall SSL VPN Preauth Root RCE (remote code execution) vulnerability on predominantly Russian language dark web forum Exploit.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-41713: A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab versions up to 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to perform a path traversal attack due to inadequate input validation. If exploited, this vulnerability could grant the attacker unauthorized access, potentially allowing them to view, alter, or delete user data and system configurations. CISA has added this vulnerability to its KEV catalog.
Affected products: MiCollab versions up to 9.8 SP1 FP2 (9.8.1.201)
Tags: DIB, tlp:green