ZeroFox Weekly Intelligence Brief - February 10, 2025
|by Alpha Team

ZeroFox Weekly Intelligence Brief - February 10, 2025
TLP:GREEN
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the threat landscape, including digital, cyber, and physical threats. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EST) on February 7, 2025; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
Phishing Campaign Hijacks High-Profile Users’ X Accounts
What happened: An ongoing phishing campaign is targeting high-profile X accounts (formerly, Twitter), including political figures, journalists, and tech organizations, in an attempt to hijack them for fraudulent purposes. While primarily focused on X, the attackers also target other social media platforms to achieve financial gain. Phishing lures include fake login alerts that trick users into clicking malicious links in order to steal their credentials. Other tactics involve copyright violation scams, prompting victims to enter their X credentials on fraudulent sites. The attackers were observed stealing credentials, locking out the owner, and then posting fraudulent crypto schemes to target more victims.
CISA Releases Guidance on Edge Devices
What happened: Cybersecurity and Infrastructure Security Agency (CISA)—in partnership with international and U.S. organizations—released guidance to help organizations protect their network edge devices and appliances, such as firewalls, routers, Virtual Private Network (VPN) gateways, Internet of Things (IoT) devices, internet-facing servers, and internet-facing operational technology (OT) systems. Edge devices are network hardware or software components that bridge internally managed networks and external, untrusted networks such as the internet. These devices can connect corporate networks to the internet and provide controlled connectivity to protected internal networks, as well as enable traffic flow.
WhatsApp Flags Zero-Click Attack Attributed to Spyware Firm
What happened: WhatsApp recently revealed that a targeted spyware campaign affected approximately 90 individuals, including journalists and members of civil society organizations. The attack was traced back to Paragon Solutions, an Israeli spyware firm, which reportedly used a zero-click exploit to compromise users without requiring them to click any malicious links. The attack was carried out by sending infected PDF files through WhatsApp groups. WhatsApp has taken immediate steps to address the issue, notifying the affected users and rolling out a security update to patch the vulnerability. The company has not disclosed the specific locations or identities of the targeted individuals, including whether any were based in the United States.
Tags: DIB