zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 27, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 27, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CERT-UA Warns of UAC-0173 Phishing Attacks Targeting Ukraine Notaries
  • Crypto Firm Gotbit Founder Charged for Market Manipulation and Wire Fraud
  • GitVenom Malware Campaign Steals from Crypto Wallets of Gamers and Crypto Investors

CERT-UA Warns of UAC-0173 Phishing Attacks Targeting Ukraine Notaries

Source: https://thehackernews.com/2025/02/cert-ua-warns-of-uac-0173-attacks.html

What happened: An organized threat group dubbed UAC-0173 has begun targeting Ukraine’s notaries since early this year with a remote access trojan named DarkCrystal RAT (DCRat). The group reportedly engages in phishing employees with emails on behalf of one of the territorial divisions of the Ministry of Justice of Ukraine, containing links to download an executable file aiming to infect devices with malware.

Why it matters: The group has been observed to carry out cyberattacks to obtain covert remote access to notaries' computers in order to further make unauthorized changes to state registers. By compromising notary employees’ devices, the attackers are likely aiming to target government communications, exfiltrate confidential data, and spy on operations. It is unclear whether this group is affiliated with a government looking to attack rival nations in espionage campaigns to steal confidential information; however, Russia has in the past targeted Ukraine’s state registries, which contained citizen personally identifiable information.

Crypto Firm Gotbit Founder Charged for Market Manipulation and Wire Fraud

Source: https://www.justice.gov/usao-ma/pr/founder-cryptocurrency-financial-services-firm-gotbit-extradited-united-states-face

What happened: The founder of cryptocurrency financial Services firm “Gotbit” has been charged for allegedly orchestrating a wide-ranging conspiracy to manipulate cryptocurrency markets on behalf of client cryptocurrency companies. The charges include wire fraud and conspiracy to commit market manipulation.

Why it matters: Gotbit allegedly provided market manipulation services to create artificial trading volume for multiple cryptocurrency companies, including U.S.-based companies, resulting in proceeds of tens of millions of dollars. The firm allegedly marketed wash trading tactics to potential clients and explained how it utilized multiple accounts to evade detection of wash trading on the public blockchain. Such deceptive and fraudulent practices could endanger the financial assets of customers who have invested in these schemes and expose them to legal liabilities.

GitVenom Malware Campaign Steals from Crypto Wallets of Gamers and Crypto Investors

Source: https://www.bleepingcomputer.com/news/security/gitvenom-attacks-abuse-hundreds-of-github-repos-to-steal-crypto/

What happened: A recent campaign utilizing GitVenom malware has been stealing cryptocurrency from users. The malware tricked individuals into installing information stealers, remote access trojans (RATs), and clipboard hijackers, leading to losses of at least USD 456,600 in crypto assets.

Why it matters: GitVenom uses several GitHub repositories of fake projects with malicious codes, such as an automation tool for Instagram interactions, a Telegram bot to manage Bitcoin wallets, and a tool to hack the Valorant video game. These tools with seemingly attractive features lured users of popular digital platforms—such as a widely used social media site and a trending video game. The cyber arsenal used in the campaign enabled threat actors to collect various sensitive information—like passwords, bank account information, saved credentials, cryptocurrency wallet data, and web browsing history—exfiltrate them, and redirect digital assets to their networks.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user telecoms: Untested threat actor "telecoms" has advertised network access with user rights to two unnamed distinct UK and U.S.-based companies on predominantly English language dark web forum BreachForums.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-0631: This vulnerability arises from the use of HTTP in the affected version of PowerFlex 755, which causes credentials to be sent in clear text. This could enable attackers to potentially intercept and capture sensitive data.

Affected products: PowerFlex 755 versions 16.002.279 and prior

Tags: DIB, tlp:green