ZeroFox Cyber Intelligence Daily Brief - January 28, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 28, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Cl0p Ransomware Reveals Dozens of New Names
- DeepSeek Suspends Registration to Mitigate Recent “Large-Scale” Cyberattack
- EU Sanctions Russian Hackers for Stealing Sensitive Estonian Data
Cl0p Ransomware Reveals Dozens of New Names
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/80110
What happened: ZeroFox has observed that Russia-based ransomware collective Cl0p has disclosed the full names of the second victim list, which likely is a continuation of their exploitation of the Cleo vulnerability. However, last week, the group also alluded to their possession of data from companies that use Progress MOVEit.
Why it matters: This disclosure follows an earlier announcement (reported by ZeroFox) made on January 22, 2025, in which the group revealed that they had compromised an additional 50 organizations. The involvement of MOVEit and the continued exploitation of Cleo vulnerability suggests that its attack strategy involves exploiting vulnerabilities across multiple platforms to maximize their reach and impact. However, ZeroFox cannot independently verify whether the victims from the second list were exploited via the MOVEit exploit or the Cleo exploit. The release of this new victim list could cause significant disruption for the affected organizations, many of which may have already been targeted by other ransomware groups.
DeepSeek Suspends Registration to Mitigate Recent “Large-Scale” Cyberattack
What happened: Chinese AI platform DeepSeek has disabled new registrations on its V3 chat platform due to “large-scale malicious attacks on DeepSeek's services.” The company further stated that while it is temporarily limiting registrations to ensure continued service, existing users can log in as usual.
Why it matters: The attacks, likely distributed denial of service (DDoS), targeted the platform’s API and web chat services. Researchers have discovered that this technology is more vulnerable than many popular AI platforms, making it extensively susceptible to exploitation given its high download rates. DeepSeek’s application has swiftly gained popularity with the number of downloads overtaking that of ChatGPT’s on the Apple store; moreover, DeepSeek reportedly uses less computing power and a fraction of the chips than its counterparts to train the model. At the time of reporting, the company stated that it is continuing to investigate the issue.
EU Sanctions Russian Hackers for Stealing Sensitive Estonian Data
What happened: The European Union (EU) sanctioned three Russian hackers from Unit 29155 of the GRU for cyberattacks on Estonian government agencies in 2020, leading to the theft of sensitive documents from various ministries, including Economic Affairs, Social Affairs, and Foreign Affairs.
Why it matters: Unit 29155 is responsible for cyberattacks against other EU member states and partners, such as Ukraine, and has been instrumental in destabilizing governments, spreading disinformation, and weakening regional security through coordinated, malicious cyber operations. By targeting key ministries, Russia’s GRU likely aimed to disrupt the functioning of vital state institutions and gain access to confidential data. The documents stolen could potentially be sold on the black market or used in further cyberattacks, such as phishing campaigns or espionage operations.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user IntelBroker: ZeroFox observed that well-regarded and established threat actor “IntelBroker” has decided to step down from their leadership position at BreachForums. The decision comes after a prolonged period of decreased involvement in community activities, which the outgoing "owner" attributed to increased personal commitments and a lack of sufficient time to dedicate to the forum.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-23086: On most desktop platforms, affected Brave browser included a feature to show a site's origin on the OS-provided file selector dialog when a site prompts the user to upload or download a file. However, the origin was not correctly inferred in some cases. When combined with an open redirector vulnerability on a trusted site, this could allow a malicious site to initiate a download whose origin in the file select dialog appears as the trusted site which initiated the redirect.
Affected products: Brave browser versions 1.70.117 before 1.70.117 and 1.74.48 before 1.74.48
Tags: DIB, tlp:green