zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 27, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - January 27, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - Threat Actors Seeking to Exploit California Wildfire Recovery Funds
  • 12 Indicted in Multi-Million Dollar Business Email Compromise Scheme
  • Slovak Alleges Ukraine’s Hand in Recent Cyberattack

ZeroFox Intelligence Flash Report - Threat Actors Seeking to Exploit California Wildfire Recovery Funds

Source: https://www.zerofox.com/advisories/29717/

What happened: ZeroFox has identified threat actors actively discussing methodologies to exploit California wildfire recovery funds for financial gain on the dark web. In a thread identified on the Dread forum, threat actors discussed methodologies for successful scams, stating that this is “free money”, as well as the importance of exercising patience to avoid early scrutiny during the verification process.

Why it matters: Based on previous behavior and attitudes towards disaster relief funds, it is very likely that a broader array of threat actors are interested in exploiting these funds than those identified to date. Although ZeroFox has identified no evidence that threat actors are actively—and successfully—leveraging wildfire recovery funds in financial scams, such activity could result in financial and reputational damage for state or local government authorities and reduce the availability of relief funds for those legitimately affected by the wildfires, as well as perpetuate the idea that these funds are a viable attack vector.

12 Indicted in Multi-Million Dollar Business Email Compromise Scheme

Source: https://www.justice.gov/usao-sc/pr/12-indicted-multi-million-dollar-business-email-compromise-scheme

What happened: A federal grand jury in Columbia returned a 12-count indictment alleging conspiracy, wire fraud, bank fraud, and money laundering against 12 individuals for defrauding multiple victims in a nationwide scheme.

Why it matters: The indictment alleges that the defendants were involved in a business email compromise (BEC) scheme that defrauded the victims out of millions of dollars, targeting both companies and individuals. The defendants accessed victims' systems to monitor financial communications, used spoofed emails to impersonate trusted parties, and redirected funds to accounts they controlled, leading to substantial financial losses for the victims. They then laundered the stolen money by moving it between their own accounts and transferring it overseas, exposing businesses to fraud, financial instability, operational disruptions, and more.

Slovak Alleges Ukraine’s Hand in Recent Cyberattack

Source: https://databreaches.net/2025/01/25/slovak-pm-accuses-ukraine-without-any-evidence-of-involvement-in-alleged-massive-cyberattack/

What happened: Slovak Prime Minister Robert Fico claimed—reportedly without evidence—that Ukraine was behind a "massive cyberattack" on Slovakia's national insurance company, allegedly aimed at disrupting medical care. Slovakia reportedly faced a phishing attack, but it remains unclear yet who was responsible for this attack.

Why it matters: Fico's statements appear to be based on little evidence and are likely to be an attempt to push a narrative that external forces, including Ukraine, are interfering in Slovak affairs. Ukraine responded by denying the allegations and urged Slovakia to stop looking for “imaginary enemies in Ukraine” since it claims to be an ally to Slovakia. Suspicions are ramping up against Ukraine seemingly ever since Ukraine cut off Russian gas transit through Slovakian territory, prompting Fico to claim that Ukraine was interested in the “sabotage” of Slovakia’s economy.

DEEP AND DARK WEB INTELLIGENCE

Exploit user blink: Untested threat actor "blink" has advertised an auction for VPN access with domain user and local administrator rights to an unnamed U.S.-based freight and logistics services company on predominantly Russian language dark web forum Exploit.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-23006: This bug in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.

Affected products: SMA1000 AMC and CMC versions 12.4.3-02804 (platform-hotfix) and earlier versions

Tags: DIB, tlp:green