ZeroFox Cyber Intelligence Daily Brief - February 21, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - February 21, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Black Basta Ransomware Operation’s Internal Chats Leaked Online
- AI Bots Disrupt Germany's Election with Pro-Russia, Anti-Conservative Posts
- Europol: Violent Online Communities Threaten Children, Others
Black Basta Ransomware Operation’s Internal Chats Leaked Online
What happened: Ransomware operation Black Basta’s internal Matrix chat logs were leaked online on a telegram channel, revealing various functioning details, including tactics, victims’ credentials, cryptocurrency addresses, phishing templates, and data drops.
Why it matters: The revelation of tactics could help determine the near-future course of action the group is likely to take. The leaks also contain information about the members and operators. Such data could aid law enforcement operations in taking down Black Basta—who has claimed several high-profile entities like governments and healthcare firms—to dismantle its operations and warn its victims.
AI Bots Disrupt Germany's Election with Pro-Russia, Anti-Conservative Posts
What happened: In the final week of Germany’s election campaign, over 700 fake social media accounts were uncovered, pushing pro-Russian messages and attacking Friedrich Merz, the leading conservative candidate. The bots, dubbed "Geist," used AI-generated images to spread anti-conservative and anti-war content, attempting to sway voter opinion.
Why it matters: Though the campaign has not garnered substantial interaction, its scale highlights the lengths to which both domestic and foreign actors could go to influence elections. The manipulation of social media campaigns through fake accounts can significantly alter the narrative surrounding candidates and issues, as seen in the attacks on Merz, a pro-Ukraine candidate–which reflect the broader geopolitical tension over Russia's invasion of Ukraine. The influence of such narratives could weaken support for policies that align with European unity and the defense of Ukraine.
Europol: Violent Online Communities Threaten Children, Others
What happened: Europol issued a notification calling attention to the rise of violent online communities dedicated to the serious harm of children and other individuals. A variety of groups use digital platforms to normalize acts of extreme cruelty, extort victims, and groom individuals into performing acts of extremism.
Why it matters: Digital platforms enable communications globally, violent extremist online communities also leverage this opportunity. It is highly likely that children are at an increased risk of encountering online predators given that digital device usage is becoming increasingly common among them. Organised crime groups likely choose to target children as they can be easily trafficked through popular online hubs like gaming and mental health forums.
DEEP AND DARK WEB INTELLIGENCE
Exploit/xss user TT0xicc and Kernel: Untested threat actor "TT0xicc" has advertised two Windows Race Condition and Logic LPE (local privileges escalation) exploits bypassing Windows Defender on predominantly Russian language dark web forum Exploit. Another untested threat actor "Kernel" has announced the same offer on predominantly Russian language dark web forum xss.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-1265: An OS command injection vulnerability exists in Vinci Protocol Analyzer that could allow an attacker to escalate privileges and perform code execution on affected systems.
Affected products: Vinci Protocol Analyzer versions prior to 3.2.3.19
Tags: DIB, tlp:green