ZeroFox Cyber Intelligence Daily Brief - February 2, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - February 2, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - Threat Actors Seeking to Exploit California Wildfire Recovery Funds
- FBI’s Operation Talent Hunts Down Illegal Dark Web Forums
- UAC-0063 Espionage Campaign Targets Organizations Across Central Asia and Europe
ZeroFox Intelligence Flash Report - Threat Actors Seeking to Exploit California Wildfire Recovery Funds
Source: https://www.zerofox.com/advisories/29717/
What happened: ZeroFox has identified threat actors actively discussing methodologies to exploit California wildfire recovery funds for financial gain on the dark web. In a thread identified on the Dread forum, threat actors discussed methodologies for successful scams, stating that this is “free money”, as well as the importance of exercising patience to avoid early scrutiny during the verification process.
Why it matters: Based on previous behavior and attitudes towards disaster relief funds, it is very likely that a broader array of threat actors are interested in exploiting these funds than those identified to date. Although ZeroFox has identified no evidence that threat actors are actively—and successfully—leveraging wildfire recovery funds in financial scams, such activity could result in financial and reputational damage for state or local government authorities and reduce the availability of relief funds for those legitimately affected by the wildfires, as well as perpetuate the idea that these funds are a viable attack vector.
FBI’s Operation Talent Hunts Down Illegal Dark Web Forums
Source: https://hackread.com/operation-talent-fbi-seizes-nulled-to-cracked-to-sellix-io/
What happened: The FBI, in coordination with international law enforcement agencies, has seized multiple cybercrime-related domains, including cracked[.]io, nulled[.]to, starkrdp[.]io, mysellix[.]io, and sellix[.]io, as part of "Operation Talent." Seizure banners confirming the action were reportedly placed on the websites, stating that customer and victim information has been secured by the authorities.
Why it matters: The targeted sites were known for facilitating cybercrime activities, including password cracking, credential stuffing, and selling stolen data. An official notification has not been released to the public yet, which likely indicates that more law enforcement action, like arrests, can likely be expected in the near future. Although these domains have been seized by law enforcement authorities, Cracked[.]io’s administrator reportedly still remains active, signaling a likely resurfacing of criminal activities under different domain names, unless arrests are not made in time.
UAC-0063 Espionage Campaign Targets Organizations Across Central Asia and Europe
Source: https://thehackernews.com/2025/01/uac-0063-expands-cyber-attacks-to.html
What happened: Cybersecurity researchers have discovered a prolonged espionage campaign by the Russia-linked APT group UAC-0063, targeting high-value organizations across Central Asia and Europe. The group employs various malware strains, including HATVIBE and custom-built tools, to penetrate networks and sustain long-term access.
Why it matters: The campaign exploits a malicious word processing document to spread malware, infiltrating key entities such as government agencies, diplomatic missions, and private companies, which can likely lead to data breaches, intellectual property theft, or disruption of critical services. The use of scheduled tasks for persistent malware execution also increases the likelihood of long-term infiltration, making it more difficult to detect and mitigate. The group further exploits compromised victims to spread the infection, allowing it to rapidly expand its reach, and increase the chances of successful breaches across multiple networks.
Tags: DIB, tlp:green