zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 12, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - January 12, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • U.S. Location Tracking Company Gravy Analytics Targeted in Alleged Hack
  • ICAO Investigates Potential Cyberattack After Hacker Claims to Steal 42,000 Documents
  • Eagerbee Backdoor Now Hits Middle East

U.S. Location Tracking Company Gravy Analytics Targeted in Alleged Hack

What happened: An unknown hacker on dark web forum XSS has claimed to have breached Gravy Analytics, a U.S.-based location tracking firm, stealing a significant amount of data. The details of how the breach occurred or the exact data stolen remain unclear.

Why it matters: If the hacker’s claims are true, cybercriminals can use the stolen location data for stalking, unauthorized surveillance, and exploiting individuals' routines for blackmail or intimidation. It is also likely to lead to privacy violations, potential identity theft, and a loss of personal security. The recent settlement by the Federal Trade Commission (FTC) with Gravy Analytics and a data broker company reveals the growing concern over data misuse, as both companies were accused of collecting location data without consent, putting individuals at risk of harm and exploitation.

ICAO Investigates Potential Cyberattack After Hacker Claims to Steal 42,000 Documents

What happened: The United Nations' aviation agency, International Civil Aviation Organization (ICAO), is investigating a potential cyberattack after a hacker, operating under the alias "Natohub," claimed to have stolen 42,000 documents from its systems. The hacker alleges the data includes sensitive personal information.

Why it matters: Cybercriminals or hostile state actors are likely to leverage this sensitive data to carry out identity theft, phishing attacks, or unauthorized access to critical aviation systems and databases, potentially leading to fraud, theft of intellectual property, and severe threats to aviation security and public safety. Furthermore, the stolen data can likely expose vulnerabilities in systems, enabling cyberattacks on air traffic control, airport operations, or aircraft safety mechanisms. This can lead to widespread disruptions in global air travel, financial losses, and an increased risk of terrorist or criminal activities, particularly if the information is linked to government operations or international intelligence sharing.

Eagerbee Backdoor Now Hits Middle East

What happened: An updated version of the Eagerbee backdoor is now being deployed against internet service providers (ISPs) and government organizations in the Middle East. It is still unknown how the threat actor gained entry to these systems, but the remote code execution vulnerability—CVE-2021-26855—was reportedly exploited in attacks at two other Asian companies.

Why it matters: The malware was observed to have gathered operating system details and network addresses on infected devices, indicating that the threat actors are likely monitoring these companies’ activities to steal sensitive data. Although the initial access vector could not be determined, researchers observe that this backdoor is sophisticated and can evade detection through traditional endpoint security solutions. This backdoor has also been observed in Japan, which likely means that the threat actors are aiming for a global trajectory.

Tags: DIB, tlp:green