ZeroFox Cyber Intelligence Daily Brief - January 11, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 11, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Zero-Click Vulnerability in Samsung Devices Could Enable Remote Code Execution
- Ransomware Group Targets Greece’s Ministry of Development & Investments
- China-Linked MirrorFace Targeted Japan for Five Years
Zero-Click Vulnerability in Samsung Devices Could Enable Remote Code Execution
Source: https://thehackernews.com/2025/01/google-project-zero-researcher-uncovers.html
What happened: Cybersecurity researchers have detailed a patched high-severity zero-click remote code execution (RCE) vulnerability flaw in Samsung Monkey’s Audio (APE) decoder. CVE-2024-49415 impacts Android 12, 13, and 14 devices with a specific messaging application configured for rich communication services (RCS).
Why it matters: The vulnerability can enable attackers to remotely exploit compromised devices with no user interaction and execute arbitrary code on devices, threatening the contents and control of the system. Threat actors exploiting this bug are likely to launch an attack by sending a deliberately manipulated audio message through the messaging application. The message can malfunction and crash a function in any vulnerable device with its RCS turned on.
Ransomware Group Targets Greece’s Ministry of Development & Investments
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/78948
What happened: ZeroFox observed an update on the Funksec ransomware leak site targeting Greece’s Ministry of Development & Investments. The group has demanded a USD 50,000 ransom by January 20, 2025, threatening to release or sell the stolen data if payment is not made.
Why it matters: The ransomware group can likely gain access to critical governmental records, financial data, policy documents, and potentially confidential communications that is likely to damage Greece's economic and political standing by exposing sensitive national strategies. The group is likely to also leverage the data for espionage, blackmail, or sell it to foreign entities or competing organizations. The possibility of sensitive governmental data being sold to other parties suggests that the consequences of non-payment will extend far beyond the public release of data, likely hindering future investment opportunities and damaging diplomatic relations.
China-Linked MirrorFace Targeted Japan for Five Years
Source: https://www.darkreading.com/cyberattacks-data-breaches/chinese-apt-group-ransacking-japans-secrets
What happened: Japan’s National Police Agency and cybersecurity center confirmed a five year-long cyber campaign attributed to the China-backed group "MirrorFace," targeting government agencies, politicians, and industries. These attacks involved phishing, malware like LODEINFO, and exploitation of vulnerabilities.
Why it matters: Since the attacks lasted for several years, this campaign likely demonstrates sophisticated techniques, tactics, and procedures in targeting critical Japanese sectors. These attacks on Japan’s critical infrastructure is likely a strategic attempt to undermine Japan’s national security and economic stability. Through advanced techniques like abuse of a prominent directory service, exploitation of virtualization servers, and the deployment of custom malware, the attackers likely gained extensive access to sensitive data.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user X0Frankenstein: Threat actor "X0Frankenstein" has claimed to have leaked data associated with the Russia division of Kia, a South Korea-based automobile manufacturer, on predominantly English-language dark web forum BreachForums.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-12757: The affected product is missing authentication for critical functions that could allow an unauthenticated attacker to potentially execute malicious code.
Affected products: All versions of Ecoreader
Tags: DIB, tlp:green