zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - February 28, 2025

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - February 28, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • China-Linked Actors Targeted OT Companies for Their Intellectual Property
  • Cybercriminal Arrested for Stealing and Leaking Data from 90 Organizations
  • U.S. DOJ Sentences Operator of Child Sexual Abuse Websites to 24 Years in Prison

China-Linked Actors Targeted OT Companies for Their Intellectual Property

Source: https://www.darkreading.com/ics-ot-security/chinese-apt-vpn-bug-worldwide-ot-orgs

What happened: China-linked cybercriminals have exploited a path traversal vulnerability (CVE-2024-24919) in certain security gateways targeting victim companies’ intellectual property. Attackers, likely linked to APT41, had gained initial access to dozens of operational technology (OT) organizations, with victims spanning multiple regions, including the United States, Latin America, Europe, the Middle East, and Africa.

Why it matters: It is likely that the attackers specifically targeted intellectual property for the purpose of stealing these companies’ sensitive manufacturing designs, proprietary processes, and supply chain data to benefit their home country’s military agendas. In this campaign, attackers could have established footholds within networks, enabling further exploitation, data exfiltration, or future attacks. This campaign likely posed more of a threat to small businesses with limited cybersecurity resources for attackers to take advantage of its outdated or unpatched systems.

Cybercriminal Arrested for Stealing and Leaking Data from 90 Organizations

Source: https://www.bleepingcomputer.com/news/security/suspected-desorden-hacker-arrested-for-breaching-90-organizations/

What happened: A cybercriminal operating under the aliases "DESORDEN Group" and "ALTDOS" was arrested in Bangkok for stealing and leaking over 13TB of personal data from more than 90 organizations globally since 2020. The cybercriminal's activities primarily targeted businesses in Thailand, Singapore, Malaysia, Indonesia, India, and several organizations in Europe and North America.

Why it matters: The threat actor's frequent alias changes likely caused delays in investigations—allowing them to continue their cybercrimes undetected—while their use of high-level blackmail and press involvement escalated financial and operational damage—potentially forcing companies to pay ransoms. The cybercriminal could have also used the stolen data in identity theft, financial fraud, sold sensitive information on the dark web, or sold it to other threat groups for exploitation. By apprehending this cybercriminal, authorities have likely stopped or at least delayed further exposure of sensitive data.

U.S. DOJ Sentences Operator of Child Sexual Abuse Websites to 24 Years in Prison

Source: https://www.justice.gov/opa/pr/man-sentenced-over-24-years-prison-running-multiple-dark-web-child-sexual-abuse-websites

What happened: The U.S. Department of Justice sentences an individual to 24 years and four months in prison for their role in operating four dark web websites dedicated to sharing images of child sexual abuse. The individual distributed explicit content online, assisted others in running the sites, and possessed 6,500 images of identified victims.

Why it matters: The dark web often facilitates criminal networks, allowing offenders to anonymously share and distribute illegal content. Such content could further expose victims of child sexual abuse to more threats, including even physical ones. Law enforcement’s use of digital forensics and multi-agency collaboration was key to dismantling these sites, likely indicating the complex nature of the operation the individual ran.

DEEP AND DARK WEB INTELLIGENCE

Exploit user x888: Moderately credible threat actor "x888" has advertised network (malware) access with user rights to an unnamed U.S.-based and Japanese manufacturing company on Exploit.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2021-29999: A possible stack overflow in dhcp server was discovered in Wind River VxWorks through 6.8. Successful exploitation of this vulnerability could allow a stack overflow attack, which could result in loss of confidentiality, integrity, and denial of service of the device.

Affected products: The affected products are listed in this Industrial Control Systems (ICS) advisory.

Tags: DIB, tlp:green