ZeroFox Cyber Intelligence Daily Brief - February 18, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - February 18, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Pro-Russian Hackers Target Italian Banks and Airports in Retaliation Attack
- Hackers Take Advantage of Telegram’s Infrastructure to Deploy Malware
- X Blocks Signal Contact Links amid Malware Warnings
Pro-Russian Hackers Target Italian Banks and Airports in Retaliation Attack
What happened: Alleged pro-Russian hacker group Noname057(16) has claimed to have targeted at least 20 Italian websites, including those of major banks and two airports, in a distributed denial-of-service (DDoS) attack. Italy’s cybersecurity agency has said the attack has not caused significant disruptions.
Why it matters: Noname057(16) has cited Italian President Sergio Mattarella’s remark, comparing Russia’s actions to Nazi Germany, as a motivation for this attack. The nature of the targets, including financial institutions and transportation hubs, indicates the actor’s likely intent to disrupt Italy’s critical infrastructure amid geopolitical tensions. This is the second time in recent months that Noname057(16) has targeted Italy, indicating there will likely be more such attacks against entities that are politically opposed to the group.
Hackers Take Advantage of Telegram’s Infrastructure to Deploy Malware
Source: https://hackread.com/hackers-exploit-telegram-api-spread-golang-backdoor/
What happened: A Golang-based backdoor is reportedly using Telegram for command and control (C2), allowing attackers to issue commands remotely. This malware, likely linked to Russia, exploits cloud services to evade detection.
Why it matters: Using cloud platforms like Telegram for C2 eliminates the need for attackers to set up and maintain their own servers, reducing costs, effort, and the risk of detection. They are likely not required to set up additional evasion mechanisms as Telegram already provides encrypted infrastructure, allowing threat actors to easily share malicious files as legitimate content.
X Blocks Signal Contact Links amid Malware Warnings
What happened: X (formerly Twitter) is reportedly blocking links to "Signal[.]me," a URL used by the Signal encrypted messaging app to share user account information. Attempts to post these links now trigger error messages, citing spam or malware risks.
Why it matters: Signal is a widely used encrypted messaging platform, and blocking links to its "Signal[.]me" domain could disrupt users' ability to connect securely. If users fall victim to malicious links involving "Signal[.]me," their personal data and Signal accounts could be compromised, leading to privacy breaches, identity theft, or further exploitation of sensitive information. At the time of writing, older posts containing these links remain accessible, though they display warnings that the links may be unsafe.
DEEP AND DARK WEB INTELLIGENCE
Threat group halts operations in some countries: Pro-Palestine hacktivist group “RipperSec” has declared a temporary halt to attacks countries like France, Germany, Brazil, Italy, UK, and Australia, expressing respect for the government's pursuit of peace while warning that if the government continues funding Israel, the attacks will resume.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-12356: A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products, which can allow an unauthenticated attacker to inject commands that are run as a site user.
Affected products: RS and PRA 24.3.1 and earlier
Tags: DIB, tlp:green