ZeroFox Weekly Intelligence Brief - February 3, 2025
|by Alpha Team

ZeroFox Weekly Intelligence Brief - February 3, 2025
TLP:GREEN
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the threat landscape, including digital, cyber, and physical threats. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EST) on January 31, 2025; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
DeepSeek: Cyberattack and Data Exposure
What happened: On January 28, Chinese artificial intelligence (AI) platform DeepSeek announced that it was “temporarily limiting registrations” to ensure continued service amid allegedly large-scale malicious cyberattacks. On January 29, DeepSeek updated its statement, saying it had identified the issue and was in the process of implementing a fix. Researchers also found a massive amount of sensitive data exposed on the internet. The leaked information included over a million lines of data, such as digital software keys and chat logs from users interacting with the company's AI assistant. DeepSeek took down the data within an hour of being notified of the exposure.
New Smishing Campaign Targets USPS Customers with Phishing PDFs
What happened: A new phishing campaign has emerged in which attackers impersonate the U.S. Postal Service (USPS) to trick people into revealing sensitive personal and financial information. The attackers use SMS messages that claim a package cannot be delivered due to "incomplete address information." These messages then direct recipients to click on a PDF file that contains a malicious phishing link. When opened, the link leads to a fake landing page that asks users to enter personal details such as their name, address, email, and phone number. It further redirects victims to a page asking for payment-card information, claiming it is necessary for completing the delivery.
Fraud Ring Members Charged in Multi-Million Dollar BEC and Money Laundering Scheme
What happened: The U.S. Department of Justice charged members of a global fraud ring with creating and using more than 1,000 fake businesses to open bank accounts, steal money through business email scams, and launder the funds. The ring caused over USD 60 million in losses and attempted to steal over USD 150 million. The members accomplished this primarily by wiring stolen money to banks in China, outside the reach of U.S. banks.
Tags: DIB