ZeroFox Cyber Intelligence Daily Brief - February 20, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - February 20, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CISA and Partners Release Advisory on Ghost (Cring) Ransomware
- London Talent Agency Reports Cyberattack After Rhysida Ransomware Attack
- Phishing Attacks Use JavaScript Obfuscation Method to Target an American PAC
CISA and Partners Release Advisory on Ghost (Cring) Ransomware
What happened: CISA and partners have released an advisory addressing FBI’s observations about known Ghost ransomware indicators of compromise and tactics, techniques, and procedures identified through investigations as recently as January 2025. The joint advisory addresses threat actors using Ghost ransomware to obtain initial access to networks by exploiting applications associated with multiple CVEs.
Why it matters: The ransomware group has been proliferated since 2021 likely since it has specifically been targeting organizations with outdated versions of software and firmware on their internet-facing services, compromising organizations across more than 70 countries. Since Ghost actors have exploited well known vulnerabilities and target networks where available patches have not been applied, placing a greater focus on improving cyber security practices globally is likely to hinder from financially crippling key entities like critical infrastructure, technology, manufacturing, and government networks.
London Talent Agency Reports Cyberattack After Rhysida Ransomware Attack
Source: https://www.theregister.com/2025/02/19/london_celebrity_talent_agency_reports/
What happened: A London talent agency has notified the UK's data protection watchdog after the Rhysida ransomware group claimed responsibility for attacking the agency, which represents notable stage and screen figures. The group leaked sensitive data, including passport scans and internal documents, and set a deadline for extortion demands.
Why it matters: If the extortion demands are not met, the ransomware group will likely release more data or sell existing data–clients' financial, personal, and travel details–further exposing them to identity theft, fraud, and reputational damage. Additionally, sensitive information could be sold to paparazzi, who could use it to track down high-profile individuals, gaining access to their private lives in intrusive ways. The leak of clients' daily schedules and routines may also lead to physical stalking, harassment, or even more serious threats to personal safety, as malicious parties will likely use the information to track their targets.
Phishing Attacks Use JavaScript Obfuscation Method to Target an American PAC
What happened: A phishing campaign targeting associates of an American political action committee (PAC) is abusing a new JavaScript obfuscation method leveraging invisible Unicode characters to represent binary values.
Why it matters: These attacks enhance their undetectability by utilizing empty whitespaces, which reduces the possibility of security scanners labeling a malicious presence. Besides, researchers have observed two phishing domains in the campaign with close links to the Tycoon 2FA phishing kit, indicating that more attackers are likely to use this specific invisible obfuscation method. Additionally, the motivation behind targeting PAC associates in phishing campaigns is likely to gain access to sensitive information about political campaigns and employ the data in further malicious attacks.
DEEP AND DARK WEB INTELLIGENCE
Xss user Croco Siffredi: Untested threat actor "Croco Siffredi" has advertised a network access bundle to three unnamed U.S.-based and Swiss companies on predominantly Russian language dark web forum xss.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-22880: Delta Electronics CNCSoft-G2 versions 2.1.0.10 and earlier lack proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code. CISA has added this vulnerability to an ICS advisory.
Affected products: Delta Electronics CNCSoft-G2 versions 2.1.0.10 and earlier
Tags: DIB, tlp:green