zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 25, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 25, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Cl0p Ransomware Unveils Fourth Victim List
  • Australia to Remove Kaspersky Products on Most Government-Facing Devices
  • Avast Customers to Claim Refunds on Deceptively Marketed Software

Cl0p Ransomware Unveils Fourth Victim List

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/81803

What happened: ZeroFox observed that Russia-based ransomware collective Cl0p has disclosed the full names of the fourth victim list. The fourth list contains names of many prominent multinational corporations and starts with the letters E, F, G,and H, continuing after the third list—which had victims' names beginning with C and D.

Why it matters: The group continues to reveal the victim names in alphabetical order and it will likely continue to follow this pattern to release additional victim lists. Further disclosures are very likely imminent, potentially affecting a wider range of companies and organizations with substantial financial and operational stakes. The group could use the current list of victims to demand higher ransoms, leveraging the significant market impact of the targeted corporations to force quicker payouts.

Australia to Remove Kaspersky Products on Most Government-Facing Devices

Source: https://www.bleepingcomputer.com/news/security/australia-bans-all-kaspersky-products-on-government-systems/

What happened: Fears over foreign interference have prompted the Australian government to ban all Kaspersky Lab products and web services from most devices under the Public Governance, Performance, and Accountability Act 2013. This move comes as other countries, including the Unites States, have also expressed their concerns over Kaspersky products endangering national security.

Why it matters: The decision to ban products from the Russian cybersecurity provider Kaspersky is likely a step toward improving Australia’s information and operation security, since Russia is known for several prolific cyber activities. It is likely that concerns emerge from Russia’s capacity to influence or direct Kaspersky’s operations and target its adversaries in cyber campaigns that involve data exfiltration of national secrets, establishing persistence, and remote control of government networks. Removing Kaspersky from devices could limit Australia’s exposure to Russia-linked actors, while protecting the personal information and privacy of Australians.

Avast Customers to Claim Refunds on Deceptively Marketed Software

Source: https://www.ftc.gov/news-events/news/press-releases/2025/02/ftc-announces-refund-claims-process-avast-customers-impacted-deceptive-privacy-claims

What happened: The Federal Trade Commission (FTC) has sent claim forms to 3,690,813 consumers who bought Avast anti-virus software, which falsely claimed to protect privacy but collected and sold user browsing data without consent or permission. The FTC alleged Avast sold that data to over 100 third parties through its subsidiary, Jumpshot.

Why it matters: Marketing protective software, like anti-virus, with deceptive claims about capabilities, could mislead users into installing software that fails to protect their systems. Moreover, selling user browser data without permission is a direct breach of privacy and confidentiality, exposing potentially sensitive information to malicious actors who will likely use such data for their profit. Third parties could also use the data to harass and coerce users with unwarranted communication requests and advertisements.

DEEP AND DARK WEB INTELLIGENCE

RAMP user cha0s: Untested threat actor "cha0s" has advertised network access bundles to eight unnamed distinct worldwide companies on predominantly Russian language dark web forum RAMP.

VULNERABILITY AND EXPLOIT INTELLIGENCE

MacOS Parallels Desktop Zero-Day Bug: The most recent version of Parallels Desktop virtualization software for macOS has an unpatched zero-day vulnerability that could enable root access. A proof-of-concept is also available for the bug.

Affected products: Parallels Desktop versions from 19.2.1 to 19.3.0

Tags: DIB, tlp:green