ZeroFox Cyber Intelligence Daily Brief - February 23, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - February 23, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Pro-Russian Hackers Target Italian Banks and Airports in Retaliation Attack
- The Philippines Targeted in Foreign Cyberattacks
- CISA and Partners Release Advisory on Ghost (Cring) Ransomware
Pro-Russian Hackers Target Italian Banks and Airports in Retaliation Attack
What happened: Alleged pro-Russian hacker group Noname057(16) has claimed to have targeted at least 20 Italian websites, including those of major banks and two airports, in a distributed denial-of-service (DDoS) attack. Italy’s cybersecurity agency has said the attack has not caused significant disruptions.
Why it matters: Noname057(16) has cited Italian President Sergio Mattarella’s remark, comparing Russia’s actions to Nazi Germany, as a motivation for this attack. The nature of the targets, including financial institutions and transportation hubs, indicates the actor’s likely intent to disrupt Italy’s critical infrastructure amid geopolitical tensions. This is the second time in recent months that Noname057(16) has targeted Italy, indicating there will likely be more such attacks against entities that are politically opposed to the group.
The Philippines Targeted in Foreign Cyberattacks
What happened: The Philippines has detected a wide range of foreign state-sponsored attacks attempting to access its intelligence data. It includes several attempts from Advanced Persistent Threats (APTs) to infiltrate government systems, but with no success.
Why it matters: Threat actors likely view the Philippines as a prime target for its strategic alliances, military positioning, and economic assets—especially concerning its location in the South-China Sea, a heavily contested region, and its defense ties with the United States. To this end, the threat actors are very likely sponsored by states that are politically opposed to the Philippines and the United States. Chinese state-sponsored actors have been known to conduct such attacks targeting the Philippines’ defense, military, and diplomatic entities—likely to further China’s claims on the South China Sea.
CISA and Partners Release Advisory on Ghost (Cring) Ransomware
What happened: CISA and partners have released an advisory addressing FBI’s observations about known Ghost ransomware indicators of compromise and tactics, techniques, and procedures identified through investigations as recently as January 2025. The joint advisory addresses threat actors using Ghost ransomware to obtain initial access to networks by exploiting applications associated with multiple CVEs.
Why it matters: The ransomware group has been proliferated since 2021 likely since it has specifically been targeting organizations with outdated versions of software and firmware on their internet-facing services, compromising organizations across more than 70 countries. Since Ghost actors have exploited well known vulnerabilities and target networks where available patches have not been applied, placing a greater focus on improving cybersecurity practices globally is likely to hinder from financially crippling key entities like critical infrastructure, technology, manufacturing, and government networks.
Tags: DIB, tlp:green