ZeroFox Cyber Intelligence Daily Brief - February 5, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - February 5, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Cl0p Reveals a Third List of 50 Undisclosed Victims
- Ransomware Groups Target Affected Company Employees to Leak Data
- North Korean “FlexibleFerret” Malware Hits MacOS via Fake Zoom and GitHub Scam
Cl0p Reveals a Third List of 50 Undisclosed Victims
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/80717
What happened: On February 5, 2025, ZeroFox observed Russia-based ransomware collective Cl0p releasing a third list of 50 undisclosed victims. The group has asked the companies included in the list to reach out, likely for ransom negotiations.
Why it matters: The group is seemingly revealing the victim names in alphabetical order— the previous list had victims' names beginning with A and B, while the current list includes victims whose names start with C and D—likely to demonstrate its capabilities to conduct large-scale attacks. ZeroFox cannot independently verify whether the victims from the third list were exploited via the MOVEit or the Cleo exploit. The release of this new victim list could cause significant disruption for the affected organizations.
Ransomware Groups Target Affected Company Employees to Leak Data
Source: https://www.darkreading.com/threat-intelligence/cybercriminals-traitorous-insiders-ransom-notes
What happened: Ransomware groups like Sarcoma and DoNex are now embedding ads in their ransom notes to recruit insiders for company access. These notes promise financial rewards for employees willing to leak credentials or install malware.
Why it matters: Ransomware actors typically focus on financial extortion, demanding payment to decrypt systems. However, a change in traditional ransomware tactics likely indicates a shift in objective, which is securing insider data that could enable deeper infiltration into company networks. Ransomware groups now soliciting employees for insider access by asking for credentials such as remote desktop protocol (RDP) logins, VPN passwords, and corporate email accounts could broaden the affected company’s attack surface to expose interconnected third-party services.
North Korean “FlexibleFerret” Malware Hits MacOS via Fake Zoom and GitHub Scam
Source: https://hackread.com/north-korea-flexibleferret-malware-macos-fake-zoom-job-scams/
What happened: A new North Korean macOS malware variant, “FlexibleFerret,” has targeted developers and job seekers via fake Zoom apps, job scams, and deceptive bug report comments. Linked to the “Contagious Interview” campaign, the campaign tricks targets into downloading a malicious dropper that installs itself stealthily and maintains persistence despite reboots.
Why it matters: The campaign uses valid Apple Developer signatures to bypass security checks, disguising the malware as legitimate software before Apple revokes the certificates. FlexibleFerret initially evaded detection despite Apple’s strengthened XProtect security tool, demonstrating how attackers can tweak old malware to bypass defenses. These campaigns leverage the anxiety around job seeking and bug reporting to trick job aspirants and developers into installing malware.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user nastya_miyako: Well-regarded threat actor "nastya_miyako" (also known as "miyako") has advertised network access with root rights to an unnamed U.S.-based internet services provider company.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-29059: CISA added this information disclosure vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. An attacker who successfully exploited this vulnerability could conduct remote code execution.
Affected products: The affected products have been listed in this advisory.
Tags: DIB, tlp:green