zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 25, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - January 25, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • GhostGPT: The Malicious AI Chatbot Driving Cybercrime and Scams
  • New Ransomware Attacking VMware ESXi Hosts Via SSH Tunneling
  • HSI Investigation Leads to Guilty Pleas for Chinese Nationals in Fraudulent Gift Card Conspiracy

GhostGPT: The Malicious AI Chatbot Driving Cybercrime and Scams

Source: https://hackread.com/ghostgpt-malicious-ai-chatbot-fuel-cybercrime-scams/

What happened: A new AI chatbot named GhostGPT was uncovered by security researchers in late 2024, which was specifically designed to assist cybercriminals in creating sophisticated phishing emails and developing malicious malware. Available through platforms like Telegram, the tool operates without ethical guidelines, enabling users to generate harmful content quickly and easily.

Why it matters: Unlike traditional AI models, GhostGPT operates without the ethical safeguards, enabling cybercriminals to leverage advanced capabilities for illegal activities like crafting convincing phishing schemes and developing malware to steal sensitive data, disrupt operations, and execute attacks. GhostGPT's design is built around a jailbroken version of an AI model that allows it to provide unfiltered, harmful responses to malicious queries. Additionally, its focus on user anonymity shields criminals from detection, making it harder for authorities to trace and disrupt their activities.

New Ransomware Attacking VMware ESXi Hosts Via SSH Tunneling

Source: https://cybersecuritynews.com/ransomware-attacking-vmware-esxi-hosts/

What happened: New ransomware strains are targeting VMware ESXi hosts by setting up SSH tunnels to conceal malicious traffic. This stealth approach allows attackers to access critical virtual machines and exfiltrate or encrypt data without detection.

Why it matters: Rather than relying on obvious attack vectors that would trigger alarms, attackers are now using more subtle methods, such as tunneling through SSH, to hide their activity. Since ESXi hosts mostly remain poorly monitored or lack proper visibility, the attackers can bypass conventional security mechanisms that would otherwise identify suspicious traffic, allowing them to exfiltrate data or lock virtual machines with minimal detection. The ability to conceal malicious activity means that critical systems may remain vulnerable for extended periods, making them easy targets for ransomware that can lock or destroy essential data.

HSI Investigation Leads to Guilty Pleas for Chinese Nationals in Fraudulent Gift Card Conspiracy

Source: https://www.dhs.gov/hsi/news/2025/01/23/hsi-investigation-leads-guilty-pleas-chinese-nationals-fraudulent-gift-card

What Happened: Three Chinese nationals pleaded guilty for their roles in a large-scale fraud conspiracy based in China after their activity was uncovered during a Homeland Security Investigations (HSI) probe.

Why it matters: According to HSI’s investigation, organized criminal elements in China acquire gift cards through multiple fraudulent means. For example, gift cards are obtained by hacking U.S. companies and targeting U.S. citizens through romance and elder fraud schemes. The criminal elements then send the gift card data to multiple cells of Chinese nationals operating in the United States through a Chinese-based messaging platform. Gift card fraud has become a growing concern for consumers and businesses alike, prompting the HSI to investigate how Chinese organized crime groups are exploiting gift cards to launder money.

DEEP AND DARK WEB INTELLIGENCE

Telegram user Team BD Cyber Ninja: Bangladesh-based hacker group "Team BD Cyber Ninja" announced an alliance with pro-Palestine threat actor "AnonPioneers." The group claims that it has "come together to raise the flag of Islam in the cyber world."

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-11139: An improper restriction of operations within the bounds of a memory buffer vulnerability exists, which could allow local attackers to potentially execute arbitrary code when opening a malicious project file.

Affected products: The affected products have been listed in CISA’s advisory.

Tags: DIB, tlp:green