zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 8, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 8, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Malicious App Exfiltrates Victim’s Sensitive Information
  • Threat Actors Impersonate DeepSeek Websites
  • CISA Adds 7-Zip Vulnerability to KEV Catalog Used in Hacks Against Ukrainian Entities

Malicious App Exfiltrates Victim’s Sensitive Information

Source: https://www.theregister.com/2025/02/07/infected_apps_google_apple_stores/

What happened: A malicious app called ComeCome was found on two popular app stores, secretly using optical character recognition (OCR) spyware, dubbed SparkCat, to steal cryptocurrency wallet recovery phrases from screenshots. The infected apps were reportedly downloaded over 240,000 times, primarily targeting users in Europe and Asia.

Why it matters: The app reportedly secretly steals the keys of victims' cryptocurrency wallets and exfiltrates them to cybercriminals. With these keys, the attackers can gain full control over the victims' wallets and transfer their funds. The malware can also adapt to several languages like Latin, Korean, Chinese, or Japanese, which could enable the strain's OCR to exfiltrate a large user base's sensitive data and funds.

Threat Actors Impersonate DeepSeek Websites

Source: https://www.darkreading.com/cyber-risk/deepseek-phishing-sites-pursue-user-data-crypto-wallets

What happened: Threat actors are now exploiting DeepSeek's popularity by setting up phishing sites to steal credentials and distribute malware. These fraudulent sites impersonate DeepSeek's domain, targeting users with scams, including fake investments and cryptocurrency fraud.

Why it matters: Although these sites are being taken down, the delayed takedown of fraudulent sites allows cybercriminals to persistently exploit user interest in DeepSeek, increasing the risk of identity theft, financial fraud, and malware infections. Unsuspecting users and organizations face growing threats to their credentials, personal data, and system security. The discovery of these phishing websites also come at a time when U.S. lawmakers have introduced a bill to ban DeepSeek from federal devices, citing national security and data privacy risks.

CISA Adds 7-Zip Vulnerability to KEV Catalog Used in Hacks Against Ukrainian Entities

Source: https://cybersecuritynews.com/7-zip-vulnerability-actively-exploited-in-the-wild-in-cyber-attacks/

What happened: CISA has added a 7-Zip Mark-of-the-Web (MoTW) bypass vulnerability, which Russian hackers exploited to target the Ukrainian government and other entities, to its Known Exploited Vulnerabilities Catalog.

Why it matters: The threat actors were very likely politically motivated, given their alleged Russian origins. They delivered malware, such as SmokeLoader, to targeted systems by bypassing MoTW security protections and then likely exfiltrated sensitive documents and data, especially from the affected government systems. The flaw has been patched in version 24.09.

DEEP AND DARK WEB INTELLIGENCE

Xss user Sec13B: Threat actor "Sec13B" advertised a VPN brute force tool on predominantly Russian language dark web forum xss. According to Sec13B, the tool supports custom username and password credentials.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-20124: This vulnerability, in an API of Cisco ISE, could allow an authenticated, remote attacker to execute arbitrary commands as the root user on an affected device.

Affected products: The affected products have been listed in this advisory.

Tags: DIB, tlp:green