zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - Feb 14 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 14, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • FBI Los Angeles Field Office Warns of Romance Scams on Valentine’s Day
  • China’s Salt Typhoon Strikes Repeatedly
  • Doxbin Administrators Deny Tooda’s Claims of Data Breach

FBI Los Angeles Field Office Warns of Romance Scams on Valentine’s Day

Source: https://www.fbi.gov/contact-us/field-offices/losangeles/news/fbi-los-angeles-field-office-warns-of-romance-scams-ahead-of-valentines-day-1

What happened: The FBI is warning the public about a surge in romance scams (also referred to as confidence fraud) around Valentine’s Day, where criminals create fake online personas to manipulate victims on dating websites, apps, or social media. Once trust is established, the scammer manipulates the victim into sending money for various fabricated emergencies or reasons.

Why it matters: Romance scams are one of the most financially damaging forms of online fraud, with victims losing nearly USD 700 million in 2023 alone. Beyond financial loss, these scams cause emotional harm, leaving victims feeling betrayed and vulnerable. The FBI’s warning stresses the importance of recognizing these scams to protect people from both financial and emotional harm.

China’s Salt Typhoon Strikes Repeatedly

Source: https://techcrunch.com/2025/02/13/chinas-salt-typhoon-hackers-continue-to-breach-telecom-firms-despite-us-sanctions/

What happened: China-linked Salt Typhoon continues to target telecommunications providers despite U.S. sanctions. The group exploited certain vulnerabilities to breach firms in the United States, Italy, South Africa, and Thailand, gaining access to sensitive communications and surveillance systems over the course of a few months.

Why it matters: Salt Typhoon's focus on U.S.-based telecommunications companies as well indicate a strategic effort to intercept sensitive communications, likely targeting government officials, law enforcement, and high-value corporate entities. The group's repeated success in breaching critical infrastructure despite sanctions likely indicates they are committed toward establishing persistence over a very long period, which makes further addressing the vulnerabilities (CVE-20232-0198 and CVE-2023-20273) essential. Salt Typhoon’s actions are highly likely in alignment with China’s broader aims of expanding its intelligence operations to strengthen its global influence, counter U.S. security interests, and steal trade secrets to boost its technology sector.

Doxbin Administrators Deny Tooda’s Claims of Data Breach

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/81204

What happened: After cybercrime group Tooda claimed to have hacked into doxxing platform Doxbin, the platform administrators stated that the data breach impacting its servers was not due to an external hack but an internal issue. The administrators noted that the exposed information was from a previously leaked database, compromising old user data.

Why it matters: The chatter surrounding this situation suggests that a verbal argument between Tooda members and Doxbin administrators was likely the motivation behind Tooda’s claims about the data breach. With respect to the leaked data, threat actors could cross-reference leaked emails with other data breaches to uncover real identities. On the other hand, any data breach affecting platforms like Doxbin could expose the activity of its users and help law enforcement curb cybercrimes.

DEEP AND DARK WEB INTELLIGENCE

Exploit user decider: Untested threat actor "decider" has advertised an auction for VPN and RDP access with domain administrator rights to an unnamed U.S.-based energy, utilities and waste company on Exploit.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-1094: This zero-day vulnerability in PostgreSQL is being exploited in attacks against BeyondTrust Remote Support systems, enabling SQL injection and potential remote code execution.

Affected products: The affected products are listed in this advisory.

Tags: DIB, tlp:green