ZeroFox Cyber Intelligence Daily Brief - January 26, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 26, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - Cl0p Publishes Data of Cleo Compromise Victims
- Cryptocurrency Financial Services Firm Pleads Guilty to Market Manipulation and Wire
- Europol Holds Largest-Ever Operation to Increase Seizures of Criminal Assets Worldwide
ZeroFox Intelligence Flash Report - Cl0p Publishes Data of Cleo Compromise Victims
Source: https://www.zerofox.com/advisories/29580/
What happened: Between January 17 and 18, 2025, the ransomware group Cl0p published data allegedly belonging to three organizations that were targeted during the Q4 2024 compromise of Cleo secure managed file transfer (MFT) solutions. Previously, in December 2024, Cl0p added the obfuscated names of 66 alleged victim organizations to their leak site. The names of these organizations were unveiled on January 14 and 15, 2025, along with a blog post threatening to publish their data on January 18, 2025.
Why it matters: There is a very likely chance that Cl0p will begin publishing data stolen from other named organizations in the coming weeks, beginning with those that Cl0p perceives to be impeding negotiations or unlikely intending to meet demands. Also between January 17 and 18, 2025, Cl0p posted a seemingly-unrelated statement to their victim leaksite, alluding to the collective’s “downloading” of data belonging to organizations that use the MOVEit MFT solution, via a vulnerability. The meaning and intent behind Cl0p’s message to MOVEit customers is unclear.
Cryptocurrency Financial Services Firm Pleads Guilty to Market Manipulation and Wire Fraud
What happened: A financial services firm known in the cryptocurrency industry as a “market maker,” has agreed to resolve criminal charges relating to its fraudulent manipulation of cryptocurrency trading volume. The charges against the firm followed an undercover law enforcement operation targeting cryptocurrency “wash trading,” sham trading activity intended to attract investors.
Why it matters: The firm has admitted that it agreed to provide market-making services for the NexFundAI token, including “wash trading,” to fraudulently attract investors to purchase the token. Wash trading misleads investors and erodes trust in the market by distorting market prices and volumes, creating an illusion of demand or liquidity. Malicious actors could use wash trading to influence the market to confer unfair advantages upon themselves, causing financial losses for uninformed participants.
Europol Holds Largest-Ever Operation to Increase Seizures of Criminal Assets Worldwide
What happened: Europol is collaborating with 80 experts globally to participate in Project A.S.S.E.T.—Asset Search & Seize Enforcement Taskforce—to increase the number of criminal assets seized globally. In total, 43 law enforcement agencies from 28 countries joined the operation, which, among other events, resulted in the freezing of EUR 200,000 (USD 205,797) in cryptocurrencies.
Why it matters: A major element of Project A.S.S.E.T. is the participation of financial actors from the private sector, especially organizations from the banking sector and cryptocurrency exchanges. One of the most successful outcomes of this operation was the seizure of EUR 27 million (USD 27.8 million) in cryptocurrencies alone. This operation also resulted in the seizure of 83 cryptocurrency addresses and wallets, 53 properties, eight of which were valued EUR 38.5 million (USD 39.7 million), and more.
Tags: DIB, tlp:green