zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 19, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 19, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • The Philippines Targeted in Foreign Cyberattacks
  • Indian Authorities Seize USD 200 Million in BitConnect Crypto-Fraud Scheme
  • Venture Capital Firm Targeted in Social Engineering Attack

The Philippines Targeted in Foreign Cyberattacks

Source: https://www.reuters.com/technology/cybersecurity/philippines-reports-foreign-cyber-intrusions-targeting-intelligence-data-no-2025-02-18/

What happened: The Philippines has detected a wide range of foreign state-sponsored attacks attempting to access its intelligence data. It includes several attempts from Advanced Persistent Threats (APTs) to infiltrate government systems, but with no success.

Why it matters: Threat actors likely view the Philippines as a prime target for its strategic alliances, military positioning, and economic assets—especially concerning its location in the South-China Sea, a heavily contested region, and its defense ties with the United States. To this end, the threat actors are very likely sponsored by states that are politically opposed to the Philippines and the United States. Chinese state-sponsored actors have been known to conduct such attacks targeting the Philippines’ defense, military, and diplomatic entities—likely to further China’s claims on the South China Sea.

Indian Authorities Seize USD 200 Million in BitConnect Crypto-Fraud Scheme

Source: https://www.theregister.com/2025/02/18/india_bitconnect_seizures/

What happened: Indian authorities have seized over USD 200 million in assets from the BitConnect crypto-fraud and Ponzi scheme scheme, which made deceptive promises to investors about high returns through an automated trading bot. The funds were tracked through devices containing crypto wallets and traced from online to real-world locations.

Why it matters: In 2022, the U.S. Securities and Exchange Commission (SEC) labeled the BitConnect scheme a Ponzi scheme, alleging that investors' cryptocurrency was diverted into wallets controlled by the founder, rather than being invested as promised. Such "too-good-to-be-true" investment schemes take advantage of lack of regulation in commitment processes on cryptocurrency platforms. Additionally, implementing Ponzi scheme features in a crypto-fraud operation could expose investors to financial losses and legal risks as the deceptive cycle collapses without new investments.

Venture Capital Firm Targeted in Social Engineering Attack

Source: https://www.bleepingcomputer.com/news/security/venture-capital-giant-insight-partners-hit-by-cyberattack/

What happened: Investigations continue as venture capital firm Insight Partners recently suffered a social engineering attack. The company confirmed third-party access to its information systems, but it is yet to determine the entire scope of the incident.

Why it matters: Insight Partners is a venture capital firm managing over USD 90 billion in regulatory assets with investments in more than 800 software companies that can attract threat actors looking to target data related to its employees, financial processes, and trade secrets. If the threat actor gains access to the company’s databases, they are likely to exfiltrate it and use this information to leverage against the company in ransomware attacks. Additionally, the threat actor is likely to advertise possession of data or initial access on the deep and dark web forums to get the attention of other financially motivated actors.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user miyak0: Well-regarded threat actor "miyak0" has advertised VPN access to an alleged EMP systems contractor for a U.S. federal agency on predominantly English language dark web forum BreachForums.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-21589: An Authentication Bypass using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may allow a network-based attacker to bypass authentication and take administrative control of the device.

Affected products: The affected products are listed in this advisory.

Tags: DIB, tlp:green