zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 29, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - January 29, 2025

ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Text-Based Scams Impersonate IRS During Tax Season
  • Unknown Hackers Target Smiths Group; Investigations Continue
  • New Smishing Campaign Targets USPS Customers with Phishing PDFs

Text-Based Scams Impersonate IRS During Tax Season

Source: https://content.govdelivery.com/accounts/USTREASTIGTA/bulletins/3ce93ce

What happened: Scammers are impersonating the Internal Revenue Service (IRS) and texting taxpayers that they are eligible for an “Economic Impact Payment,” tricking them into providing sensitive personal information. The IRS states that eligible taxpayers are not required to take action to receive these payments.

Why it matters: Scammers often leverage the attention surrounding specific situations, including natural disasters, elections, sports events, and tax seasons, to target the vulnerable for financial extortion or to steal confidential information. This particular tax scam is preying on the IRS’s recent announcement to issue automatic payments to eligible people who did not claim the Recovery Rebate Credit (also known as an Economic Impact Payment) on their 2021 tax returns. It is important to note that the IRS does not request personal or financial information by text.

Unknown Hackers Target Smiths Group; Investigations Continue

Source: https://www.bleepingcomputer.com/news/security/engineering-giant-smiths-group-discloses-security-breach/

What happened: Engineering company Smiths Group disclosed a security breach involving unauthorized access to its systems by unknown attackers. The company isolated affected systems and is investigating the nature of the incident and whether the attackers accessed sensitive information.

Why it matters: Since Smiths Group is a large company with a large employee and client base, such attacks can endanger large-scale sensitive information like proprietary data, plans, and financial systems. Although investigations continue, it is likely that attackers targeted the company to access information to sell on the dark web to other threat actors like ransomware actors. This can likely open the company up for extortion if the situation is not mitigated efficiently.

New Smishing Campaign Targets USPS Customers with Phishing PDFs

Source: https://www.darkreading.com/endpoint-security/usps-impersonators-pdfs-smishing-campaign

What happened: Attackers impersonating the U.S. Postal Service (USPS) launched a large-scale smishing campaign, using malicious SMS messages and PDF files to steal personal and financial information. The SMS messages falsely claim delivery issues and direct victims to malicious PDF links that lead to phishing pages.

Why it matters: The campaign—involving over 630 phishing pages and 20 malicious PDFs—is likely to lead to identity theft, stolen financial data, and privacy violations for anyone who clicks the malicious links. By exploiting common delivery notifications, attackers are leveraging anxiety and concern about missing packages to trick users into clicking malicious links. The use of PDFs and a multi-step process, adds an extra layer of stealth, making the scam harder to detect by both security software and unsuspecting users.

DEEP AND DARK WEB INTELLIGENCE

  • Xss user SGL: Well-regarded threat actor "SGL" has advertised Citrix access with domain user rights to an undisclosed U.S.-based company on predominantly Russian language dark web forum xss.

VULNERABILITY AND EXPLOIT INTELLIGENCE

  • CVE-2025-22217: Avi Load Balancer contains an unauthenticated blind SQL Injection vulnerability, which can likely allow an actor with network access to use specially crafted SQL queries to gain database access. Patches are available to remediate this vulnerability in affected VMware products.

  • Affected product: VMware AVI Load Balancer 30.1.x and VMware AVI Load Balancer 30.2.x

Tags: DIB, tlp:green