ZeroFox Cyber Intelligence Daily Brief - January 30, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 30, 2025
ZeroFox intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- FBI’s Operation Talent Hunts Down Illegal Dark Web Forums
- Fraud Ring Members Charged in Multi-Million Dollar BEC and Money Laundering Scheme
- UAC-0063 Espionage Campaign Targets Organizations Across Central Asia and Europe
FBI’s Operation Talent Hunts Down Illegal Dark Web Forums
Source: https://hackread.com/operation-talent-fbi-seizes-nulled-to-cracked-to-sellix-io/
What happened: The FBI, in coordination with international law enforcement agencies, has seized multiple cybercrime-related domains, including cracked[.]io, nulled[.]to, starkrdp[.]io, mysellix[.]io, and sellix[.]io, as part of "Operation Talent." Seizure banners confirming the action were reportedly placed on the websites, stating that customer and victim information has been secured by the authorities.
Why it matters: The targeted sites were known for facilitating cybercrime activities, including password cracking, credential stuffing, and selling stolen data. An official notification has not been released to the public yet, which likely indicates that more law enforcement action, like arrests, can likely be expected in the near future. Although these domains have been seized by law enforcement authorities, Cracked[.]io’s administrator reportedly still remains active, signaling a likely resurfacing of criminal activities under different domain names, unless arrests are not made in time.
Fraud Ring Members Charged in Multi-Million Dollar BEC and Money Laundering Scheme
What happened: The U.S. DOJ charged members of a global fraud ring for creating and using more than 1,000 fake businesses to open bank accounts, steal money through business email scams, and launder the funds. The ring caused over USD 60 million in losses and attempted to steal over USD 150 million.
Why it matters: This scheme caused significant financial losses and affected major organizations, city governments, and businesses. The ring members leveraged the international banking system to launder the stolen money by wiring it to Chinese banks, bypassing American authorities and preventing victims from recovering their losses. Such fraud campaigns could cause critical disruptions in financial business transactions and essential services, leading to loss of public trust and damage to brand reputation.
UAC-0063 Espionage Campaign Targets Organizations Across Central Asia and Europe
Source: https://thehackernews.com/2025/01/uac-0063-expands-cyber-attacks-to.html
What happened: Cybersecurity researchers have discovered a prolonged espionage campaign by the Russia-linked APT group UAC-0063, targeting high-value organizations across Central Asia and Europe. The group employs various malware strains, including HATVIBE and custom-built tools, to penetrate networks and sustain long-term access.
Why it matters: The campaign exploits a malicious word processing document to spread malware, infiltrating key entities such as government agencies, diplomatic missions, and private companies, which can likely lead to data breaches, intellectual property theft, or disruption of critical services. The use of scheduled tasks for persistent malware execution also increases the likelihood of long-term infiltration, making it more difficult to detect and mitigate. The group further exploits compromised victims to spread the infection, allowing it to rapidly expand its reach, and increase the chances of successful breaches across multiple networks.
DEEP AND DARK WEB INTELLIGENCE
- Xss/BreachForums user EnergyWeaponUserBF: Untested threat actor "EnergyWeaponUserBF" (also known as "EnergyWeaponUser") has advertised a dataset allegedly belonging to Pakistani company PostEx on xss. The same data breach was previously announced on December 17, 2024, on predominantly English language dark web forum BreachForums.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-55416: Voyager’s /admin/compass endpoint fails to sanitize input, letting attackers inject JavaScript into popups. If an admin clicks a malicious link, the script runs in their browser, potentially leading to remote code execution.
Affected product: Open-source PHP package Voyager
CVE-2025-22604: This critical flaw in the Cacti network monitoring tool allows authenticated attackers to execute remote code by exploiting a bug in its Simple Network Management Protocol (SNMP) parser, which lets them inject malformed Object Identifiers (OIDs).
Affected product: Cacti versions 1.2.8 and lower
Tags: DIB, tlp:green