zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief - February 17, 2025

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief - February 17, 2025

TLP:GREEN

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the threat landscape, including digital, cyber, and physical threats. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EST) on February 14, 2025; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

8Base Leak Site Seized

What happened: An international law enforcement (LE) operation has successfully dismantled the 8Base ransomware group, which had been operating on the dark web since 2022. The operation, spanning the United States, Europe, and Asia, led to the seizure of the group’s dark web leak site and the arrest of four European suspects. These individuals are accused of stealing USD 16 million from over 1,000 victims worldwide. Authorities in Bavaria seized the group’s dark web portal, while Thai police conducted coordinated raids in Phuket, resulting in the capture of the European suspects.

United States and Others Sanction Key Infrastructure Enabling Ransomware Attacks

What happened: Law enforcement bodies from the United States, Australia, and the United Kingdom are jointly sanctioning Zservers, a Russia-based bulletproof hosting (BPH) services provider, for supporting LockBit ransomware attacks. The sanctions also designate two key administrators of Zservers for having materially assisted, sponsored, and supported LockBit ransomware in other ways to enable ransomware attacks and other criminal activities.

FTC Orders “World’s First Robot Lawyer” to Stop Deceiving Users via Its AI Chatbot

What happened: The Federal Trade Commission has finalized an order requiring DoNotPay, a company that promoted its online subscription service as “the world’s first robot lawyer,” to stop making deceptive claims about the abilities of its AI chatbot. In a complaint announced in September 2024, the FTC charged that DoNotPay’s so-called robot lawyer failed to live up to claims that it was an adequate substitute for the expertise of a human lawyer. The final order requires DoNotPay to pay USD 193,000 in monetary relief. The order also prohibits DoNotPay from advertising that its service performs like a real lawyer unless it has sufficient evidence to back it up.

Tags: DIB