zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - Feb 15, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 15, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Dutch Police Dismantles Illegal Hosting Platform
  • Nation-State Hackers Moonlight as Ransomware Players
  • Cl0p Announces Fourth Victim List

Dutch Police Dismantles Illegal Hosting Platform

Source: https://www.politie.nl/nieuws/2025/februari/13/politie-amsterdam-ontmantelt-digitaal-crimineel-netwerk-127-servers-offline-gehaald.html

What happened: Dutch police dismantled the ZServers bulletproof hosting operation, taking down 127 servers, which reportedly involved ransomware, botnet, and malware. The service, linked to LockBit and Conti ransomware, was also recently sanctioned by U.S., UK, and Australian authorities.

Why it matters: Bulletproof hosting services enable global cybercrime by providing safe havens for threat actors to operate anonymously. Zservers has materially assisted threat actors to evade detection, while also providing services including leasing numerous IP addresses to cybercriminal affiliates to conduct ransomware attacks. Stricter regulations, including KYC policies, are likely to discourage cybercriminals looking for anonymity to conduct their illicit activities.

Nation-State Hackers Moonlight as Ransomware Players

Source: https://www.darkreading.com/cyberattacks-data-breaches/chinese-apt-emperor-dragonfly-ransomware-attack

What happened: A Chinese government-backed espionage group appears to be moonlighting as ransomware attackers, using a previously seen toolset in the RA World ransomware attack on an Asian software company. The attackers deployed a Toshiba executable to install a PlugX backdoor, encrypting the company’s systems and stealing data, demanding a USD 2 million ransom.

Why it matters: The use of a well-known espionage toolset for ransomware deployment signals a changing cybersecurity environment, where threat actors are increasingly turning to cybercrime tactics, such as ransomware, to generate financial gain, in addition to their focus on intellectual property theft. The attackers exploited a vulnerability in Palo Alto PAN-OS (CVE-2024-0012) to gain access, later stealing critical administrative credentials that enabled them to penetrate the company's network. Additionally, the use of cloud credentials to exfiltrate data, alongside the ransomware encryption, reveals multi-layered attacks that target multiple vulnerabilities simultaneously to disrupt operations and steal sensitive information.

Cl0p Announces Fourth Victim List

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/81313

What happened: On February 14, ZeroFox observed Cl0p teasing another list of victims, adding that the list will be released next week. This will be the fourth such list of victims, with the first, second, and third lists being disclosed on January 15, January 28, and February 5.

Why it matters: As previously predicted in ZeroFox’s advisory, Cl0p has continued to publish names of victims, all likely impacted in the Cleo vulnerability exploit data breach, creating chaos and anxiety around the incident. It was also previously observed that the lists are in alphabetical order, which is likely to demonstrate Cl0p’s capabilities and its reach. There will likely be more such lists in the upcoming weeks.

DEEP AND DARK WEB INTELLIGENCE

Exploit user con: Untested threat actor "con" has advertised hidden VNC malware dubbed "TRINITY" on predominantly Russian language dark web forum Exploit.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-1283: The Dingtian DT-R0 Series is vulnerable to an exploit that allows attackers to bypass login requirements by directly navigating to the main page. Successful exploitation of this vulnerability could allow an unauthenticated attacker to modify the device settings and gain administrator access.

Affected products: The following versions of Dingtian DT-R0 Series are affected:

  • DT-R002: Version V3.1.3044A
  • DT-R008: Version V3.1.1759A
  • DT-R016: Version V3.1.2776A
  • DT-R032: Version V3.1.3826A

Tags: DIB, tlp:green