zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 12, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 12, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • United States and Others Jointly Sanction Key Infrastructure that Enables Ransomware Attacks
  • FTC Orders “World’s First Robot Lawyer” to Stop Deceiving Users via Its AI Chatbot
  • Triplestrength’s Triple Attack Hits Organizations with Ransomware, Cloud Hijacking, and Crypto-Mining

United States and Others Jointly Sanction Key Infrastructure that Enables Ransomware Attacks

Source: https://home.treasury.gov/news/press-releases/sb0018

What happened: Law enforcement bodies from the United States, Australia, and the United Kingdom are jointly sanctioning Zservers, a Russia-based bulletproof hosting (BPH) services provider, for supporting LockBit ransomware attacks. The sanctions also designate two key administrators of Zservers, who have enabled ransomware attacks and other criminal activity.

Why it matters: Zservers has materially assisted threat actors to evade detection, while also providing services including leasing numerous IP addresses to LockBit affiliates to conduct ransomware attacks. Disrupting Zservers is likely to hinder ransomware operations by cutting off a key infrastructure provider. However, cybercriminals could seek alternative BPH services to maintain their activities.

FTC Orders “World’s First Robot Lawyer” to Stop Deceiving Users via Its AI Chatbot

Source: https://www.ftc.gov/news-events/news/press-releases/2025/02/ftc-finalizes-order-donotpay-prohibits-deceptive-ai-lawyer-claims-imposes-monetary-relief-requires

What happened: The Federal Trade Commission has ordered DoNotPay—a company that promoted its online subscription service as “the world’s first robot lawyer—” to stop making deceptive claims that its AI chatbot is an adequate substitute for a human lawyer.

Why it matters: DoNotPay did not test whether its “AI lawyer” operated to the level of a human lawyer when generating legal documents and giving advice, and the company did not hire or retain attorneys to test the quality and accuracy of the law-related features. Therefore, its deceptive claims about the chatbot giving reliable legal advice could have misled users to forgo qualified legal counsel, likely resulting in poor legal outcomes or harm in legal proceedings. Moreover, users relying on these unsubstantiated and unverified information could face financial and legal repercussions.

Triplestrength’s Triple Attack Hits Organizations with Ransomware, Cloud Hijacking, and Crypto-Mining

Source:https://www.theregister.com/2025/02/11/triplestrength_google/

What happened: Criminal gang Triplestrength has been targeting organizations with a multi-faceted attack, deploying ransomware to encrypt on-premises systems and demand a ransom for data decryption, while also hijacking cloud accounts to mine cryptocurrency illegally.

Why it matters: The group is reportedly highly active in hacking and cybercrime forums, advertising access to popular compromised digital and cloud services and recruiting criminals for extortion work, looking to profit from services widely used in companies across the world. The group’s multi-faceted attack bypasses double extortion, focusing only on encrypting data, likely to only disrupt operations and demand ransom for decryption rather than to leak sensitive information. Additionally, the hijacking of cloud accounts for cryptocurrency mining may lead to unforeseen costs for the targeted organizations, as it can consume considerable resources, degrade system performance, and potentially expose sensitive data or breach compliance requirements.

DEEP AND DARK WEB INTELLIGENCE

Xss user redblueapple2: Untested threat actor "redblueapple2" has advertised network access with domain administrator rights to an undisclosed Turkish company on xss.

VULNERABILITY AND EXPLOIT INTELLIGENCE

Microsoft Patch Tuesday February 2025: This month’s Patch Tuesday updates comprise security fixes for 55 flaws, including four zero-day vulnerabilities, with two actively exploited in attacks.

Affected products: Microsoft has listed all the addressed vulnerabilities and their affected products in its advisory.

CVE-2025-24200: Apple has released an emergency patch for this vulnerability that threat actors are exploiting in a targeted and “extremely sophisticated attack.” A physical attack could disable USB Restricted Mode on a locked device.

Affected products: The affected products are listed in this advisory.

Tags: DIB, tlp:green