ZeroFox Daily Intelligence Brief - March 4, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - March 4, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Cybercriminals Use Tech Support Scam to Deploy Ransomware
- North Korean “Job Seekers” Obfuscates Origins with Astrill VPN
- Geopolitical Focus | U.S. Aid to Ukraine Halted Temporarily
Cybercriminals Use Tech Support Scam to Deploy Ransomware
Source: https://hackread.com/fake-it-support-calls-microsoft-teams-users-install-ransomware/
What we know: Cybercriminals are impersonating tech support to gain access to victims' computers, deploying ransomware like Black Basta and Cactus once inside.
Context: Victims initially receive numerous emails, followed by contact with the perpetrator posing as IT support through popular collaborative platforms or phone calls. The impersonator then persuades the victims to provide remote access to their computer, often using a legitimate tool for remote troubleshooting.
Analyst note: If cybercriminals gain access to the victims’ computer, they could likely install ransomware to lock files and demand ransom. They could also steal sensitive data, monitor activities, or use the compromised system for further attacks.
North Korean “Job Seekers” Obfuscates Origins with Astrill VPN
Source: https://cybersecuritynews.com/north-korean-it-workers-using-astrill-vpn/
What we know: North Korean IT workers have been using Astrill VPN to mask their identities by obfuscating their IP addresses when looking for jobs in foreign companies.
Context: It is highly likely that these IT workers have been using online freelance platforms or job marketplaces to generate revenue for the Democratic People's Republic of Korea (DPRK or North Korea). Additionally, researchers have observed that the Lazarus cybercriminal group also used Astrill VPN, which was discovered during investigations into the Bybit incident.
Analyst note: Tracking these cybercriminals’ IP activities is likely to provide security teams with clues on their behavior, including infiltration attempts. Monitoring traffic from these IP addresses is likely to guide companies dealing with international applicants into implementing necessary verification and security processes.
Geopolitical Focus | U.S. Aid to Ukraine Halted Temporarily
According to a senior administration official, the United States is temporarily halting all aid to Ukraine till Ukraine demonstrates its commitment to peace negotiations with Russia. The order is reported to take effect immediately. It will impact more than USD 1 billion in arms and ammunition plus aid worth millions of dollars that could facilitate the purchase of military equipment directly from U.S. defense companies. Meanwhile, the Cybersecurity and Infrastructure Security Agency has clarified misunderstandings regarding a directive to halt offensive cyber operations against Russia, stating that it continues to monitor “all cyber threats to U.S. Critical Infrastructure, including from Russia.”
DEEP AND DARK WEB INTELLIGENCE
Clearnet Marketplace ScanInfoga Allegedly Selling RATs: On March 3, 2025 ZeroFox observed an online platform "ScanInfoga," offering a wide range of cybersecurity tools, including remote access trojans (RATs), malware, and viruses. Such forums have a roughly even chance of attracting buyers because clearnet websites could be exposed to external scrutiny and cybersecurity defenses much more easily than dark web markets.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2022-43939: The affected versions of Hitachi Vantara Pentaho Business Analytics Server contain security restrictions using non-canonical URLs, which could be circumvented. Threat actors are exploiting this bug in attacks that manipulate a URL to "trick" the app into accessing a restricted, likely malicious, path.
Affected products: Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x
Tags: DIB, tlp:green