ZeroFox Cyber Intelligence Daily Brief - January 31, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - January 31, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CISA Releases Fact Sheet Detailing Embedded Backdoor Function of Contec CMS8000 Firmware
- Law Enforcement Seizes Hacking Tools Websites Catering to Transnational Organized Crime Groups
- Investigation Ongoing After Ransomware Attack Disrupts NYBC Services
CISA Releases Fact Sheet Detailing Embedded Backdoor Function of Contec CMS8000 Firmware
What happened: CISA has released a report detailing a backdoor (CVE-2025-0626) discovered in the Contec CMS8000 patient monitor used in the U.S. Healthcare and Public Health (HPH) sector. The backdoor is present in all versions of the monitor, which connects to a specific IP address, allowing unauthorized access.
Why it matters: The embedded backdoor can likely allow attackers to manipulate devices, leading to remote code execution or altered configurations, compromising patient monitoring accuracy. CISA assesses that inclusion of this backdoor in the firmware of the patient monitor can create conditions for remote code execution and device modification with the ability to alter its configuration. This likely endangers patient safety as a malfunctioning patient monitor can lead to an improper response to patient vital signs.
Law Enforcement Seizes Hacking Tools Websites Catering to Transnational Organized Crime Groups
What happened: A coordinated law enforcement operation has seized 39 domains and their associated servers of a Pakistan-based network of online marketplaces selling hacking and fraud-enabling tools operated by a group known as Saim Raza (also known as HeartSender).
Why it matters: Saim Raza has sold phishing toolkits and other fraud-enabling tools to transnational organized crime groups, who used them to target numerous victims in the United States, resulting in over USD 3 million in victim losses. Even though they are not directly involved, such websites aid and abet in malicious activities that could disrupt critical functions and lead to severe financial damages and encourage to-be hackers and threat actors by training them. On the other hand, LE operations targeting websites and campaigns like Saim Raza are likely to lead authorities to the customer base and, thereby, disrupt more cyber threat actors in the process.
Investigation Ongoing After Ransomware Attack Disrupts NYBC Services
What happened: In a statement released on January 29, the New York Blood Center (NYBC) disclosed that a ransomware attack disrupted its operations and forced it to reschedule some blood donor appointments. The organization discovered suspicious activity on its IT systems and engaged cybersecurity experts to contain the threat.
Why it matters: Given NYBC’s role in the U.S. healthcare system—collecting nearly 4,000 units of blood daily to serve over 75 million people—the ransomware attack is likely to disrupt essential services, potentially impacting countless patients who rely on the center for treatment. The ransomware attack has led to the cancellation of appointments and blood drives, which is likely to worsen the already limited blood supply, delaying critical treatments and affecting hospitals' ability to meet urgent patient needs. While the full scope of the attack is still under investigation, attackers are likely to have stolen personal and health information, which raises further concerns, especially if the data is used for extortion.
DEEP AND DARK WEB INTELLIGENCE
RAMP user ambassador: Untested threat actor "ambassador" has advertised new Ransomware-as-a-Service malware dubbed "A1project" on predominantly Russian language dark web forum RAMP.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-40891: If exploited, the vulnerability could enable threat actors to run arbitrary commands on compromised devices, potentially leading to system breaches, network infiltration, and data leaks.
Affected products: Zyxel CPE Series devices
Tags: DIB, tlp:green