ZeroFox Cyber Intelligence Daily Brief - January 19, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 19, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Black Basta-Style Attack Floods Inboxes with Phishing Emails
- Ensuring U.S. Security and Economic Strength in the Age of Artificial Intelligence
- Russian SORM Technology Expands in Central Asia and Latin America
Black Basta-Style Attack Floods Inboxes with Phishing Emails
Source: https://hackread.com/black-basta-cyberattack-hits-inboxes-with-1165-emails/
What happened: Threat actors are mimicking Black Basta ransomware group’s tactics in a cyberattack, sending 1,165 emails to 22 inboxes in just 90 minutes. The attacks used a ransomware scam and flooded inboxes with emails about fake accounts and subscriptions to trick employees into installing remote access software.
Why it matters: The attacker likely mimicked Black Basta's tactics, aware of the group’s reputation as a prolific operator that has targeted numerous victims and leveraged methods like psychological manipulation to bypass security defenses. This attack represents a form of phishing, where attackers overwhelm targets with a rapid barrage of emails designed to confuse and exploit human error. By using familiar platforms, deceptive subject lines, and bypassing security filters, the attacker makes it difficult for users to distinguish legitimate communications from malicious ones, potentially leading to data breaches, financial losses, and operational disruptions.
Ensuring U.S. Security and Economic Strength in the Age of Artificial Intelligence
What happened: The Biden-Harris Administration aims to secure U.S. security and economic strength by releasing an Interim Final Rule on Artificial Intelligence (AI) Diffusion. It builds on previous chip controls by thwarting smuggling, closing other loopholes, and raising AI security standards.
Why it matters: The rule takes significant steps against countries of concern, constraining them from accessing advanced AI systems and the computing power used to train them. Powerful AI systems have the potential to exacerbate significant national security risks, including by enabling the development of weapons of mass destruction, supporting powerful offensive cyber operations, and aiding human rights abuses, such as mass surveillance. It is important to work with AI companies and foreign governments to put in place critical security and trust standards in their AI ecosystems.
Russian SORM Technology Expands in Central Asia and Latin America
Source: https://www.darkreading.com/threat-intelligence/russia-commercial-surveillance-success-globally
What happened: Several governments in Central Asia and Latin America have acquired the System for Operative Investigative Activities (SORM) wiretapping technology from Russian suppliers, potentially enabling Russian intelligence agencies to access wiretapped systems as well. The technology involves the installation of surveillance equipment within telecommunications facilities, enabling the client government’s intelligence agency to access sensitive data from citizens' communications.
Why it matters: SORM wiretapping technology allows local intelligence agencies to monitor communications without consent, enabling them to track dissidents, activists, and opposition, while Russian authorities can potentially exploit this data for espionage or influence. Adversarial nations are also likely to gain access to critical government data, threatening national security by compromising sensitive military, intelligence, and diplomatic operations, while suppressing free speech in regions where dissent is already repressed. For travelers and business people, the increased risk of surveillance, identity theft, and espionage is likely to expose them as targets during trips to countries with SORM technology.
Tags: DIB, tlp:green