zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 3, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 3, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Super Bowl LIX Event Assessment
  • WhatsApp Flags Zero-Click Attack Attributed to Spyware Firm
  • Indian Tech Giant Tata Technologies Launches Investigation Following Ransomware Attack

Super Bowl LIX Event Assessment

Source: https://www.zerofox.com/advisories/29956/

What happened: In this Intelligence Assessment, ZeroFox researchers cover physical and cybersecurity threats to Super Bowl LIX scheduled to take place on February 9, 2025, at the Caesars Superdome in New Orleans, Louisiana. The Super Bowl will kick off at 6:30 PM (EST), with Fox broadcasting the game and streaming available via Fubo TV.

Why it matters: At the time of writing, there were no credible threats associated with the Super Bowl. However, security officials are very likely concerned the city could again be targeted by lone wolf actors inspired by the January 1 New Orleans attack. Fans attending the game in person or watching remotely will likely face a range of fraudulent schemes, such as ticketing scams, phishing websites, payment-related fraud, betting-related schemes, counterfeit merchandise, accommodations fraud, and transportation or parking scams.

WhatsApp Flags Zero-Click Attack Attributed to Spyware Firm

Source: https://hackread.com/israeli-spyware-firm-paragon-whatsapp-zero-click-attack/

What happened: WhatsApp has flagged a zero-click spyware attack—allegedly linked to spyware firm Paragon Solutions—targeting 90 individuals using malicious PDF files sent through WhatsApp groups. The campaign requires no user interaction and has claimed journalists and civil society members as victims.

Why it matters: This spyware campaign directly threatened press freedom and exploited user trust, which is a widely used communication platform to conduct surveillance. The campaign has likely exposed sensitive communication data, contributing to concerns about commercial spyware usage eventually being used to gather government intelligence. Similar to the NSO group responsible for the infamous Pegasus spyware campaign, Paragon Solutions will likely face scrutiny if the allegations against it are true.

Indian Tech Giant Tata Technologies Launches Investigation Following Ransomware Attack

Source: https://www.bleepingcomputer.com/news/security/indian-tech-giant-tata-technologies-hit-by-ransomware-attack/

What happened: Tata Technologies Ltd., one of India’s key tech developers and state project contractors, suffered a ransomware attack that temporarily impacted its IT services. Although client delivery services remained unaffected, the company suspended some internal IT services while investigating the incident.

Why it matters: If the attackers managed to gain access to sensitive information, it could sell or exploit Tata Technologies' intellectual property, use client data for fraud, or leak confidential project details, likely leading to financial losses, legal consequences, and more. Moreover, the company's involvement in state projects increases national security risks if sensitive data is compromised, potentially exposing critical infrastructure or defense systems to espionage, sabotage, or manipulation by hostile actors. Even though no ransomware group has taken responsibility for the attack yet, it is likely that the attackers are financially motivated, given Tata technologies’ status and the potential value of its intellectual property and sensitive data.

DEEP AND DARK WEB INTELLIGENCE

Telegram user AnonPioneers: Pro-Palestine threat actor group "AnonPioneers" announced an alliance with pro-Palestine threat actor group "Spider-X."

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-24891: Dumb Drop has a path traversal vulnerability allowing users to overwrite system files. This can lead to root access for unprivileged users or those with a PIN, exploiting scheduled actions or services.

Affected products: Dumb Drop

Tags: DIB, tlp:green