zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - March 7, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - March 7, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Mail Scam Targeting Corporate Executives Claims Ties to Ransomware
  • Popular Russian Crypto Exchange Dismantled
  • Cyberespionage group “Lotus Blossom” Targets South East Asian Critical Infrastructure

Mail Scam Targeting Corporate Executives Claims Ties to Ransomware

Source: https://www.ic3.gov/PSA/2025/PSA250306-2

What we know: The FBI has warned about a scam where cybercriminals posing as the “BianLian Group” target corporate executives with extortion letters, threatening to release sensitive information unless payment is made.

Context: The scam letter, stamped “Time Sensitive Read Immediately,” threatens to publish the victim's data on BianLian’s leak sites if a USD 250,000-USD 500,000 ransom is not paid via a Bitcoin wallet QR code within 10 days, with no further negotiation.

Analyst note: FBI assesses the letters are an attempt to scam organizations into paying a ransom. This scam could lead to financial losses and the potential exposure of sensitive data leading to operational disruptions, increased cybersecurity vulnerabilities, and likely more targeted attacks.

Popular Russian Crypto Exchange Dismantled

Source: https://www.theregister.com/2025/03/06/international_cops_seize_ransomware_gangs/

What we know: An international law enforcement operation shut down Russian cryptocurrency exchange Garantex, popular among threat actors like ransomware group Conti and other criminals for money laundering.

Context: The United States previously sanctioned Garantex in April 2022, linking it to over USD 100 million in illicit transactions, including USD 6 million from Conti and USD 2.6 million from Hydra—a dark web drug market.

Analyst note: Even though the takedown disrupts a key financial hub for cybercriminals— especially for Russian-linked actors—it is very likely that they will seek out other similar platforms to facilitate their illicit activities.

Cyberespionage Group “Lotus Blossom” Targets South East Asian Critical Infrastructure

Source: https://www.darkreading.com/threat-intelligence/espionage-lotus-blossom-south-east-asia

What we know: The espionage group Lotus Blossom is targeting entities associated with critical infrastructure in countries around the South China Sea region with a custom backdoor malware strain called Sagerunex.

Context: Sagerunex, in development since 2016, is a remote access tool that evolved from an older tool, Evora, and is executed directly in memory to evade detection.

Analyst note: The threat group is reportedly gathering user accounts, network configurations, and more from these companies, likely stealing information to monitor regional activities and gain strategic intelligence for political, economic, and military advantage in the South China Sea region.

DEEP AND DARK WEB INTELLIGENCE

RAMP user RATNICK: Untested threat actor "RATNICK" has advertised Mesh RMM access with domain administrator rights to an unnamed Mexican food company on RAMP. If RATNICK’s claims are true, an actor who acquires the access is likely to gain complete control over the network, facilitating malware installation, data exfiltration, security bypass, backdoor creation, and undetected presence.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-25015: This bug with a critical CVSS score causes prototype pollution in Kibana—which leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests. An attacker could exploit this bug to run any malicious code, take complete control of the system, and exfiltrate data.

Affected products: Kibana versions >= 8.15.0 and < 8.17.3

Tags: DIB, tlp:green