zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 26, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 26, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Employee Screening Company Breach Affects 3 Million
  • Cl0p Unveils Fifth List of 182 Victims
  • New Backdoor Targets Government and Educational Institutions

Employee Screening Company Breach Affects 3 Million

Source: https://techcrunch.com/2025/02/25/us-employee-screening-giant-disa-says-hackers-accessed-data-of-more-than-3m-people/

What happened: DISA Global Solutions—an employee screening service provider—hasconfirmed a data breach, where threat actors accessed a part of the company’s network, which affected more than 3 million people in the United States. The incident, which occurred last year, compromised Social Security numbers, financial account information, drivers license data, and more.

Why it matters: It is likely that the hackers have gotten enough personal information to exploit in other ways since there have not been any extortion attempts or ransom demands. Compromising 3 million employees across thousands of companies makes this breach a treasure trove of information for financially motivated threat actors who could sell access over the dark web to other threat actors. They could also access further information on affected individuals especially by using their Social Security numbers and drivers license in identity theft and phishing campaigns.

Cl0p Unveils Fifth List of 182 Victims

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/81921

What happened: Russia-based ransomware collective Cl0p has disclosed its fifth victim list, which includes allegedly 182 victims. The list, continuing the trend of the previous lists, is in alphabetical order with company names in the range of H to W.

Why it matters: Given the number and the alphabetical order of the victims, it is likely to be either the last or the next-to-last list of victims supposedly associated with the Cleo vulnerability exploit attack. Cl0p has also seemingly broken its pattern and has skipped the step of teasing a list, directly revealing the victim names.

New Backdoor Targets Government and Educational Institutions

Source: https://www.bleepingcomputer.com/news/security/new-auto-color-linux-backdoor-targets-north-american-govts-universities/

What happened: A newly discovered Linux backdoor dubbed “Auto-Color” has been targeting government and education institutions in North America and Asia. The backdoor is capable of running with and without root privileges, while being highly evasive, persistent, difficult to remove from affected devices, and provides threat actors remote control.

Why it matters: Given the backdoor’s features, government data is highly vulnerable to compromise by threat actors looking for financial gain and to state-linked actors achieving persistence to exfiltrate confidential information. This backdoor is likely particularly effective against government and educational institutions that use legacy systems, like end-of-life routers and devices that have not patched past vulnerabilities, making them more susceptible to cyberattacks like malware, phishing scams, and more.

DEEP AND DARK WEB INTELLIGENCE

RAMP user sec13b: Untested threat actor "sec13b" has advertised virtual private network (VPN) access to the Ministry of Justice of People's Democratic Republic of Algeria on RAMP, charging USD 1 for access.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2023-34192: This cross site scripting vulnerability in Synacor Zimbra Collaboration Suite (ZCS) enables a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function. A patch is available for the bug.

Affected products: ZCS version v.8.8.15

Tags: DIB, tlp:green