zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief – March 3, 2025

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief – March 3, 2025

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the threat landscape, including digital, cyber, and physical threats. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 6:00 AM (EST) on February 28, 2025; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

North Korea’s Lazarus Steals from Bybit in Major Attack

What happened: North Korea’s Lazarus Group stole USD 1.4 billion Ethereum (ETH) from a major global cryptocurrency exchange, Bybit. Investigations found that over 920 wallet addresses were involved in the laundering process. A coordinated effort by crypto security teams led to the freezing of USD 42.89 million in stolen assets. Bybit warned users about scammers impersonating employees and said that they would never request personal information, deposits, or passwords. The company also assured users that deposits and withdrawals have resumed despite the major hack.

New Backdoor Targets Government and Educational Institution

What happened: A newly discovered Linux backdoor dubbed “Auto-Color” has been targeting government and education institutions in North America and Asia. The backdoor is capable of running with and without root privileges, while being highly evasive and persistent; is difficult to remove from affected devices; and provides threat actors remote control.

Crypto Firm Gotbit Founder Charged for Market Manipulation and Wire Fraud

What happened: The founder of cryptocurrency financial services firm Gotbit has been charged for allegedly orchestrating a wide-ranging conspiracy to manipulate cryptocurrency markets on behalf of client cryptocurrency companies. The charges include wire fraud and conspiracy to commit market manipulation.

Tags: DIB, tlp:green