ZeroFox Cyber Intelligence Daily Brief - March 2, 2025
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - March 2, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Cl0p Unveils Fifth List of 182 Victims
- CERT-UA Warns of UAC-0173 Phishing Attacks Targeting Ukraine Notaries
- Crypto Firm Gotbit Founder Charged for Market Manipulation and Wire Fraud
Cl0p Unveils Fifth List of 182 Victims
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/81921
What happened: Russia-based ransomware collective Cl0p has disclosed its fifth victim list, which includes allegedly 182 victims. The list, continuing the trend of the previous lists, is in alphabetical order with company names in the range of H to W. Why it matters: Given the number and the alphabetical order of the victims, it is likely to be either the last or the next-to-last list of victims supposedly associated with the Cleo vulnerability exploit attack. Cl0p has also seemingly broken its pattern and has skipped the step of teasing a list, directly revealing the victim names.
CERT-UA Warns of UAC-0173 Phishing Attacks Targeting Ukraine Notaries
Source: https://thehackernews.com/2025/02/cert-ua-warns-of-uac-0173-attacks.html
What happened: An organized threat group dubbed UAC-0173 has begun targeting Ukraine’s notaries since early this year with a remote access trojan named DarkCrystal RAT (DCRat). The group reportedly engages in phishing employees with emails on behalf of one of the territorial divisions of the Ministry of Justice of Ukraine, containing links to download an executable file aiming to infect devices with malware.
Why it matters: The group has been observed to carry out cyberattacks to obtain covert remote access to notaries' computers in order to further make unauthorized changes to state registers. By compromising notary employees’ devices, the attackers are likely aiming to target government communications, exfiltrate confidential data, and spy on operations. It is unclear whether this group is affiliated with a government looking to attack rival nations in espionage campaigns to steal confidential information; however, Russia has in the past targeted Ukraine’s state registries, which contained citizen personally identifiable information.
Crypto Firm Gotbit Founder Charged for Market Manipulation and Wire Fraud
What happened: The founder of cryptocurrency financial Services firm “Gotbit” has been charged for allegedly orchestrating a wide-ranging conspiracy to manipulate cryptocurrency markets on behalf of client cryptocurrency companies. The charges include wire fraud and conspiracy to commit market manipulation.
Why it matters: Gotbit allegedly provided market manipulation services to create artificial trading volume for multiple cryptocurrency companies, including U.S.-based companies, resulting in proceeds of tens of millions of dollars. The firm allegedly marketed wash trading tactics to potential clients and explained how it utilized multiple accounts to evade detection of wash trading on the public blockchain. Such deceptive and fraudulent practices could endanger the financial assets of customers who have invested in these schemes and expose them to legal liabilities.
Tags: DIB, tlp:green