zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief - January 27, 2025

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief - January 27, 2025

TLP:GREEN

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the threat landscape, including digital, cyber, and physical threats. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EST) on January 24, 2025; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

President Trump Issues Executive Order to Delay TikTok Ban

What happened: U.S. President Donald Trump has ordered a pause on the Protecting Americans from Foreign Adversary Controlled Applications Act (the “Act”) for 75 days to determine the appropriate course of action concerning TikTok. On January 19, TikTok issued a statement on the X platform that it was restoring its services after going “dark” for a brief period for its American customer base, comprising 170 million users. A previous statement posted to TikTok’s website on January 18 had asked for a “definitive statement to satisfy the most critical service providers, assuring non-enforcement” from the Biden administration.

Philippine Authorities Arrest Three on Espionage Charges

What happened: Philippines authorities have arrested a Chinese national and two Filipino accomplices on suspicion of espionage. The Chinese individual, believed to be affiliated with the Army Engineering University of the People’s Liberation Army (PLA) in Nanjing, was found with equipment thought to be intended for spying on military facilities. The group had been under surveillance by the Philippine National Bureau of Investigation (NBI) based on intelligence reports that indicated they had arrived in the country to monitor critical infrastructure—including military installations where U.S. forces have access under a mutual defense agreement.

Telegram CAPTCHATricks Users into Running Malicious PowerShell Scripts

What happened: Threat actors are exploiting the name of Ross Ulbricht (founder of the illicit online market place Silk Road) and recent news of his pardon to spread malware via fake verified accounts on X (formerly Twitter). Victims are lured to malicious Telegram channels, where they are tricked into running a PowerShell command disguised as a "verification process." This command downloads malware, likely a Cobalt Strike loader. The campaign mimics recent tactics where CAPTCHAs or fake verifications are used to deliver malware through PowerShell commands.

Tags: DIB