ZeroFox Cyber Intelligence Daily Brief - February 4, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - February 4, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Hackers Abuse DeepSeek’s PyPI Packages to Push Malware
- U.S. Convicts Chinese Executives for Fentanyl Precursor Trafficking, Seizes Crypto Assets
- Phishing Campaign Hijacks X Accounts of High-Profile Users
Hackers Abuse DeepSeek’s PyPI Packages to Push Malware
Source: https://hackread.com/hackers-hide-malware-fake-deepseek-pypi-packages/
What happened: Malicious DeepSeek packages on PyPI targeted developers by stealing sensitive data like API keys and credentials. The malware, reportedly downloaded over 200 times before removal, exfiltrated system information to a C2 server.
Why it matters: Recently, state-sponsored threat actors have been observed using AI chatbots for reconnaissance, malware development, and vulnerability research. Attackers exploiting repositories like PyPI likely distribute malicious packages, compromising the software supply chain leading to widespread distribution of malware, affecting numerous projects and organizations. As the malicious use of AI proliferates, developers and other users looking to use or integrate these models into their projects risk unintentionally exposing sensitive data or systems to cyber threats.
U.S. Convicts Chinese Executives for Fentanyl Precursor Trafficking, Seizes Crypto Assets
What happened: The U.S. Department of Justice (DOJ) convicted two individuals for conspiring to import fentanyl precursors from China into the United States and for laundering payments through cryptocurrency. Authorities seized seven websites and four cryptocurrency accounts linked to their company, Amarvel Biotech, effectively dismantling part of their digital operation. Why it matters: With President Donald Trump declaring a national emergency on drugs, especially fentanyl, the United States is intensifying efforts to combat the fentanyl crisis by targeting global supply chains and seizing digital assets tied to illicit drug trade. The two convicted individuals relied on cryptocurrency to obscure their payments from law enforcement while advertising "100% stealth shipping" online, using digital assets to evade detection. Through Amarvel Biotech, they also sold fentanyl precursors online to Mexican cartels and buyers in the U.S., contributing to the opioid crisis.
Phishing Campaign Hijacks X Accounts of High-Profile Users
Source:https://www.darkreading.com/endpoint-security/one-click-phishing-campaign-high-profile-x-accounts
What happened: An ongoing phishing campaign is targeting high-profile X accounts, including those of journalists, political figures, and an X employee, to commit cryptocurrency fraud. Through phishing emails with fake login alerts and copyright violation notices, attackers steal credentials, lock out the owner, and then post fraudulent crypto schemes to target more victims.
Why it matters: This campaign exploits the trust that followers have in high-profile accounts, making it easier for attackers to deceive them into falling for cryptocurrency scams. Additionally, the campaign's tools can bypass email security filters, allowing it to target even cautious users. This indicates that besides being vigilant about opening suspicious emails, it is important to also verify URLs and not rely on platform security alone.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user IntelBroker: Well-regarded and established threat actor "IntelBroker," in collaboration with "EnergyWeaponUser," has claimed to have leaked a database allegedly associated with Daxium, a France-based company that provides a customizable software platform for users.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-24957: An SQL Injection vulnerability was discovered in an endpoint of the WeGIA application. This vulnerability could enable an authorized attacker to execute arbitrary SQL queries, allowing access to or deletion of sensitive information. This issue has been addressed in version 3.2.12 and all users are advised to upgrade.
Affected products: WeGIA versions before 3.2.12
Tags: DIB, tlp:green