ZeroFox Cyber Intelligence Daily Brief - January 10, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 10, 2025
ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- U.S. Location Tracking Company Gravy Analytics Targeted in Alleged Hack
- BayMark Health Services Notifies Affected Customers of Data Breach
- Fake CrowdStrike Job Offer Phishing Emails Lure Victims into Downloading Cryptominer
U.S. Location Tracking Company Gravy Analytics Targeted in Alleged Hack
What happened: An unknown hacker on dark web forum XSS has claimed to have breached Gravy Analytics, a U.S.-based location tracking firm, stealing a significant amount of data. The details of how the breach occurred or the exact data stolen remain unclear.
Why it matters: If the hacker’s claims are true, cybercriminals can use the stolen location data for stalking, unauthorized surveillance, and exploiting individuals' routines for blackmail or intimidation. It is also likely to lead to privacy violations, potential identity theft, and a loss of personal security. The recent settlement by the Federal Trade Commission (FTC) with Gravy Analytics and a data broker company reveals the growing concern over data misuse, as both the companies were accused of collecting location data without consent, putting individuals at risks of harm and exploitation.
BayMark Health Services Notifies Affected Customers of Data Breach
Source: https://baymark.com/notice-of-data-privacy-incident/
What happened: BayMark Health Services has begun notifying certain customers of a data breach whose information was involved in some of the company's services. ZeroFox observed that the RansomHub ransomware gang targeted BayMark Health Services late 2024, during which time, the attackers allegedly exfiltrated 1.5TB of sensitive patient and healthcare data.
Why it matters: The exposure of health information, especially that of patients being treated for substance abuse, can be among the most sensitive types of personal data. If exposed, it can likely be exploited for identity theft, financial fraud, and even targeted scams or blackmail. The breach could deter others from seeking necessary help due to fears of discrimination or the misuse of their information.
Fake CrowdStrike Job Offer Phishing Emails Lure Victims into Downloading Cryptominer
What happened: CrowdStrike has warned about a phishing scam involving fake job offer emails that trick targets into downloading a Monero cryptocurrency miner. The attack involved directing job seekers to a fraudulent website to download a malicious "employee CRM application," which infected their systems with the crypto miner after bypassing security checks.
Why it matters: The phishing campaign lures its target by using email designs similar to the legitimate ones used by CrowdStrike, creating a false sense of trust. The campaign enables the scammers to bypass detection techniques and then use the crypto miner to covertly mine Monero, a privacy-focused cryptocurrency. Such scams not only result in financial losses for the targets but also cause reputational damage to the firms they mimic.
DEEP AND DARK WEB INTELLIGENCE
- Telegram user userbin: Pro-India hacktivist group "userbin" has claimed to have gained access to the website "gov[.]cn" and alleged that they have obtained several sensitive files associated with the government of China under #OpChina.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-0103: An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. This vulnerability also enables attackers to create and read arbitrary files on the Expedition system.
Affected product: Palo Alto Networks Expedition from version 1 till before 1.2.101
Tags: DIB, tlp:green