zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 9, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 9, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Ugandan Officials Detained in Connection to Major Bank Theft
  • Cl0p Reveals a Third List of 50 Undisclosed Victims
  • ZeroFox’s Super Bowl LIX Event Assessment

Ugandan Officials Detained in Connection to Major Bank Theft

Source: https://www.reuters.com/world/africa/uganda-detains-9-finance-ministry-officials-over-central-bank-hack-2025-02-05/

What happened: Ugandan police detained nine finance ministry officials for their alleged involvement in the November 2024 hacking of the central bank’s electronic systems, resulting in the theft of 62 billion shillings (USD 16.87 million). The cybercriminals that carried out the attacks, reportedly called "Waste," accessed the Bank of Uganda’s IT systems to transfer the funds elsewhere, previously reported to be Japan.

Why it matters: The detention of Uganda's finance officials shows how corruption drives major criminal activities, which resulted in the diversion of substantial funds away from the country. The possible involvement of offshore accounts likely indicates the presence of a much larger operation involving other countries and criminals involved in money laundering schemes, possibly involving shell companies and offshore accounts. Without secure internal systems, insider activities like this could eventually target the country’s critical infrastructure.

Cl0p Reveals a Third List of 50 Undisclosed Victims

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/80717

What happened: On February 5, 2025, ZeroFox observed Russia-based ransomware collective Cl0p releasing a third list of 50 undisclosed victims. The group has asked the companies included in the list to reach out, likely for ransom negotiations.

Why it matters: The group is seemingly revealing the victim names in alphabetical order— the previous list had victims' names beginning with A and B, while the current list includes victims whose names start with C and D—likely to demonstrate its capabilities to conduct large-scale attacks. ZeroFox cannot independently verify whether the victims from the third list were exploited via the MOVEit or the Cleo exploit. The release of this new victim list could cause significant disruption for the affected organizations.

ZeroFox’s Super Bowl LIX Event Assessment

Source: https://www.zerofox.com/advisories/29956/

What happened: In this Intelligence Assessment, ZeroFox researchers cover physical and cybersecurity threats to Super Bowl LIX scheduled to take place on February 9, 2025, at the Caesars Superdome in New Orleans, Louisiana. The Super Bowl will kick off at 6:30 PM (EST), with Fox broadcasting the game and streaming available via Fubo TV.

Why it matters: At the time of writing, there were no credible threats associated with the Super Bowl. However, security officials are very likely concerned the city could again be targeted by lone wolf actors inspired by the January 1 New Orleans attack. Fans attending the game in person or watching remotely will likely face a range of fraudulent schemes, such as ticketing scams, phishing websites, payment-related fraud, betting-related schemes, counterfeit merchandise, accommodations fraud, and transportation or parking scams.

Tags: DIB, tlp:green