zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 21, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - January 21, 2025

ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - Cl0p Publishes Data of Cleo Compromise Victims
  • President Trump Issues Executive Order to Delay TikTok Ban
  • Philippine Authorities Arrests Three on Espionage Charges

ZeroFox Intelligence Flash Report - Cl0p Publishes Data of Cleo Compromise Victims

Source: https://www.zerofox.com/advisories/29580/

What happened: Between January 17 and 18, 2025, the ransomware group Cl0p published data allegedly belonging to three organizations that were targeted during the Q4 2024 compromise of Cleo secure managed file transfer (MFT) solutions. Previously, in December 2024, Cl0p added the obfuscated names of 66 alleged victim organizations to their leak site. The names of these organizations were unveiled on January 14 and 15, 2025, along with a blog post threatening to publish their data on January 18, 2025.

Why it matters: There is a very likely chance that Cl0p will begin publishing data stolen from other named organizations in the coming weeks, beginning with those that Cl0p perceives to be impeding negotiations or unlikely intending to meet demands. Also between January 17 and 18, 2025, Cl0p posted a seemingly-unrelated statement to their victim leaksite, alluding to the collective’s “downloading” of data belonging to organizations that use the MOVEit MFT solution, via a vulnerability. The meaning and intent behind Cl0p’s message to MOVEit customers is unclear.

President Trump Issues Executive Order to Delay TikTok Ban

Source: https://www.whitehouse.gov/presidential-actions/2025/01/application-of-protecting-americans-from-foreign-adversary-controlled-applications-act-to-tiktok/

What happened: President Donald Trump has ordered a pause on the Protecting Americans from Protecting Americans from Foreign Adversary Controlled Applications Act (the “Act”) for 75 days to determine the appropriate course of action concerning TikTok. On January 19, TikTok issued a statement saying it was restoring its services after it went “dark” for a brief period for its American customer base.

Why it matters: The Act regulates “foreign adversary controlled applications,” specifically those operated by TikTok and any other subsidiary of its China-based parent company, ByteDance Ltd., on national security grounds. A temporary pause on the enforcement of the Act will enable the Trump administration to review and pursue a resolution that protects national security while saving a platform used by 170 million Americans, including those for whom the platform is the primary source of income.

Philippine Authorities Arrests Three on Espionage Charges

Source: https://www.reuters.com/world/asia-pacific/philippines-arrests-chinese-national-suspicion-espionage-2025-01-20/

What happened: Philippine law enforcement arrested a Chinese national and two Filipino accomplices on suspicion of espionage after discovering surveillance equipment they allegedly used to monitor military sites. The Chinese individual is reportedly linked to the Army Engineering University of the People’s Liberation Army (PLA), and the group was under surveillance for conducting operations near critical infrastructure, including U.S. military-accessed areas.

Why it matters: The arrest comes amid strained relations between China and the Philippines, particularly over the South China Sea, where both countries have overlapping claims. The campaign was likely designed to expose vulnerabilities in the Philippine military defense systems and infrastructure, potentially facilitating more cyberattacks, compromising U.S. military access points, and increasing China's leverage in the South China Sea. The extracted data is also likely to aid China’s strategic position in the South China Sea, while creating more challenges for international shipping lanes in the Asia-Pacific region.

DEEP AND DARK WEB INTELLIGENCE

  • Xss user Droid: Untested threat actor "Droid" advertised Nillious Android Rat (remote access trojan) malware on predominantly Russian language dark web forum xss.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2025-0585: This SQL Injection vulnerability can enable an unauthenticated remote attacker to inject arbitrary SQL commands with specific parameters to read, modify, and delete database contents.

  • Affected product: a+HRD version 7.5 and below

Tags: DIB, tlp:green