zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - March 5, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - March 5, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Operator of Darknet Market Nemesis Sanctioned for Synthetic Opioid Sales
  • Attackers Target 86,000 IoT Devices Spreading Malware
  • U.S. DOJ Sentences Operator of Romance Scam to Two Years in Prison

Operator of Darknet Market Nemesis Sanctioned for Synthetic Opioid Sales

Source: https://home.treasury.gov/news/press-releases/sb0040

What we know: The U.S. Treasury Department has sanctioned the sole administrator of darknet market Nemesis, which facilitated the sale of nearly USD 30 million worth of drugs around the world between 2021 and 2024—including to the United States.

Context: Nemesis was the subject of an international law enforcement operation and was taken down in 2024. Before its takedown by law enforcement, the market—with built-in money laundering features—had over 30,000 active users and 1,000 vendors, including narcotics traffickers and cybercriminals who openly traded in illegal drugs and services.

Analyst note: Darkweb marketplaces are accessed via anonymity-enhancing browsers, which facilitate illicit activities that are not restricted to the cyber realm and extend to crimes such as drug and human trafficking, physical violence services, and the sale of false identification documents. There are very likely more marketplaces akin to Nemesis that engage in malicious activities, which could have physical repercussions for targeted victims.

Attackers Target 86,000 IoT Devices Spreading Malware

Source: https://www.bleepingcomputer.com/news/security/new-eleven11bot-botnet-infects-86-000-devices-for-ddos-attacks/

What we know: The Eleven11bot botnet, likely Iran-linked, has infected over 86,000 internet of things (IoT) devices—including security cameras and network video recorders (NVRs)—to conduct distributed denial-of-service (DDoS) attacks.

Context: Researchers have identified 1,400 internet protocol addresses, with over 90 percent linked to real compromised devices. The botnet has attacked telecommunication providers and online gaming servers, with traffic volumes reaching hundreds of millions of packets per second over multiple days.

Analyst note: The attackers have been brute-forcing weak admin credentials and scanning for exposed Telnet and secure shell (SSH) ports, allowing them to expand the botnet rapidly. Given that they are targeting security cameras and NVRs of telecommunication providers and gaming servers, the attackers could harvest vast swaths of video and audio data—leading to convincing deepfake scams, phishing campaigns, identity theft, and credential stuffing attacks.

U.S. DOJ Sentences Operator of Romance Scam to Two Years in Prison

Source: https://www.justice.gov/usao-ednc/pr/wake-county-woman-involved-2-million-international-romance-scam-sentenced-two-years

What we know: The U.S. Department of Justice (DOJ) sentenced an individual to two years in prison for engaging as a money mule or “middleman” to defraud multiple victims in an international romance fraud scheme. They have been sentenced to 24 months, three years supervised release, and ordered to pay USD 109,119 in restitution to the Internal Revenue Service.

Context: The individual received over USD 2 million from the international romance fraud scheme and deposited it into fictitious bank accounts located at 16 separate financial institutions. They converted the funds into virtual currency, which they wired to overseas accounts controlled by their coconspirators located in Nigeria.

Analyst note: Romance scammers take advantage of people's emotional vulnerability and trust to financially extort them, causing the victims not just material losses but also psychological distress. The scale of this particular scam indicates that the operation was well planned, and the perpetrator is likely connected to other threat actors who are involved in facilitating such scams.

DEEP AND DARK WEB INTELLIGENCE

Xss user brown: Untested threat actor "brown" has advertised Fortinet VPN access with user rights to an unnamed U.S.-based business services company on predominantly Russian language dark web forum xss. Threat actors with user rights to a company’s VPN could enable them to monitor sensitive business dealings, access proprietary information, client information, and more.

VULNERABILITY AND EXPLOIT INTELLIGENCE

VMware bugs fixed: Patches have been released for three previously exploited VMware zero-day vulnerabilities—CVE-2025-22224 (VCMI heap overflow), CVE-2025-22225 (ESXi arbitrary write), and CVE-2025-22226 (HGFS flaw allowing memory leaks). These flaws could have enabled attackers with admin or root access to escape the virtual machine sandbox, leading to full control over affected VMware environments, including ESXi, vSphere, Workstation, Fusion, and cloud-based platforms.

Affected products: The affected products and platforms are listed in this advisory.

Tags: DIB, tlp:green