zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief – February 24, 2025

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief – February 24, 2025

TLP:GREEN

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EST) on February 21, 2025; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

New Malware Used in Cyber Espionage Campaign Against a South American Ministry

What happened: Threat actors have been using a new malware strain called FinalDraft in a sophisticated cyber espionage campaign to target the foreign ministry of a South American country. The malware is known to exploit email drafts for covert communication, enabling attackers to exfiltrate data, inject malicious code, and access different systems while avoiding detection.

Russian Threat Actor Targets Cloud Service Accounts with Device Code Phishing

What happened: A Russian-linked threat actor tracked as Storm-237 has been targeting user accounts of a popular cloud-based subscription service through device code phishing, impersonating trusted individuals to gain access to sensitive information across multiple sectors.

Venture Capital Firm Targeted in Social Engineering Attack

What happened: Investigations continue as venture capital firm Insight Partners recently suffered a social engineering attack. The company confirmed third-party access to its information systems but has not yet determined the entire scope of the incident.

Tags: tlp:green