zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 17, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 17, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • New Malware Used in Cyber Espionage Campaign Against a South American Ministry
  • Thousands Targeted in South Korea in Emerging Phishing Campaign
  • Russian Threat Actor Targets Cloud Service Accounts with Device Code Phishing

New Malware Used in Cyber Espionage Campaign Against a South American Ministry

Source: https://cybersecuritynews.com/ref7707-hackers-attacking-windows-linux-machines/

What happened: Threat actors have been using a new malware strain called FinalDraft in a sophisticated cyber espionage campaign to target the foreign ministry of a South American country. The malware is known to exploit email drafts for covert communication, enabling attackers to exfiltrate data, inject malicious code, and access different systems while avoiding detection.

Why it matters: FinalDraft evades traditional security measures by hiding commands in email drafts instead of sending them to receivers, thereby also making forensic analysis difficult. The attackers also stored stolen OAuth tokens in databases comprising settings information for persistent access, enabling long-term espionage. Infrastructure analysis revealed links to telecommunications providers and a Southeast Asian university’s storage system, likely suggesting that the campaign orchestrators have breached and compromised other supply chains, indicating a wider scale of attack.

Thousands Targeted in South Korea in Emerging Phishing Campaign

Source: https://hackread.com/n-korean-hackers-deep-drive-attacks-against-s-korea/

What happened: A phishing campaign named DEEP#DRIVE, allegedly tied to North Korea’s Kimsuky group, is targeting South Korean entities for espionage. The attackers are reportedly using tailored phishing lures compromising thousands of victims across businesses, government entities, and cryptocurrency users.

Why it matters: The attackers have been using popular file formats and cloud services to bypass security defenses, making their phishing attempts appear legitimate. They have reportedly been relying on hidden scripts and disguised shortcut files to install malware, steal information, and maintain access to compromised systems. By evading detection and using automated tasks to stay active, they can secretly extract sensitive data to likely target victims in future attacks and sell their information on the dark web to other actors.

Russian Threat Actor Targets Cloud Service Accounts with Device Code Phishing

Source: https://www.bleepingcomputer.com/news/security/microsoft-hackers-steal-emails-in-device-code-phishing-attacks/

What happened: A Russian-linked threat actor, tracked as Storm-237, has been targeting user accounts of a popular cloud-based subscription service through device code phishing, impersonating trusted individuals to gain access to sensitive information across multiple sectors.

Why it matters: This phishing campaign has been ongoing since August 2024 and primarily targets individuals in government, NGO, IT services, defense, telecommunications, health, and energy sectors in Europe, North America, Africa, and the Middle East. The attackers impersonate prominent individuals relevant to the victim's organization via messaging platforms like WhatsApp, Signal, or the organization’s collaboration application, building rapport before sending fake meeting invitations—making it harder for victims to recognize malicious intent. By exploiting a commonly used authentication method, this attack bypasses security measures, targeting critical sectors—leaving them vulnerable to data theft, espionage, or disruption.

DEEP AND DARK WEB INTELLIGENCE

Xss user hinkim: Untested threat actor "hinkim" has advertised web panel access with administrator rights to Odoo ERP logistics management system on predominantly Russian language dark web forum xss.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-0108: Hackers are exploiting a high-severity vulnerability (CVE-2025-0108) in Palo Alto Networks PAN-OS firewalls to bypass authentication and execute unauthorized actions. Palo Alto Networks urges admins to upgrade to patched versions immediately to prevent potential security breaches.

Affected products: Palo Alto Networks PAN-OS versions 10.1.0 before 10.1.14-h9, 10.2.0 before 10.2.13-h3, 11.1.0 before 11.1.6-h1, 11.1.6-h1, and 11.2.0 before 11.2.4-h4

Tags: DIB, tlp:green