zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - March 10, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - March 10, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • FBI Denver Warns of Online File Converter Scam
  • Theft of Cryptocurrency Worth USD 716 Million Linked to 2022 Breach of Password Management Platform
  • U.S. Cities Warn of Fake Parking Violation Texts

FBI Denver Warns of Online File Converter Scam

Source: https://www.fbi.gov/contact-us/field-offices/denver/news/fbi-denver-warns-of-online-file-converter-scam

What we know: The FBI Denver Field Office is warning online users that threat actors are exploiting free online document converter and downloader tools to load malware onto victims’ computers, leading to incidents such as ransomware and identity theft.

Context: These cybercriminals are using free online tools that scrape submitted documents for personally identifiable information, banking data, and more.

Analyst note: In this ongoing campaign, scammers are likely stealing financial information, including cryptocurrency account details, to make unauthorized transfers, conduct social engineering attempts like phishing, and maintain persistent access to these accounts to target entities transacting with affected users.

Theft of Cryptocurrency Worth USD 716 Million Linked to 2022 Breach of Password Management Platform

Source: https://www.forbes.com/sites/thomasbrewster/2025/03/07/lastpass-hackers-stole-150-million-in-crypto-from-single-person-now-worth-715-million/

What we know: Hackers of the 2022 breach affecting LastPass, a password management service, have been attributed to the theft of 283 million XRP cryptocurrency—worth USD 150 million at the time of theft and now valued at USD 716 million—from a single compromised account.

Context: The victim's crypto assets were stolen in January 2024 via a compromised account, with the hackers allegedly using tactics similar to the 2022 breach and leaving no evidence of other device compromises.

Analyst note: The operation very likely involved several malicious actors working together with the stolen funds being transferred across several obscure channels to avoid detection. Moreover, breaches impacting password managing services could have long-term repercussions, which might not show up until very late, making it crucial for users to update their passwords and other security measures consistently.

U.S. Cities Warn of Fake Parking Violation Texts

Source: https://www.bleepingcomputer.com/news/security/us-cities-warn-of-wave-of-unpaid-parking-phishing-texts/

What we know: A widespread mobile phishing campaign impersonating city parking’s violation departments is targeting U.S. residents to steal personal and financial information.

Context: The scam involving fake texts about unpaid parking tickets and escalating fines has prompted numerous U.S. cities, including Annapolis, Boston, Greenwich, Denver, Detroit, Houston, Milwaukee, Salt Lake City, Charlotte, San Diego, and San Francisco, to issue warnings.

Analyst note: Threat actors are leveraging the anxiety around unresolved parking tickets to exploit public trust and urgency—tricking victims into revealing personal and financial information, which could then be used for further targeted attacks, including identity theft.

DEEP AND DARK WEB INTELLIGENCE

New Data Extortion Group Emerges: On March 7, 2025, ZeroFox observed a new data extortion group named "Weyhro." The group reportedly takes a more strategic approach by prioritizing and analyzing sensitive data before publishing it, which could be an indication of the authenticity of the data it publishes, drawing the attention of other threat actors interested in the data.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2023-0286: Exploitation of this OpenSSL security vulnerability could enable an attacker to access or decrypt sensitive data, crash the device application, or cause a denial-of-service condition. CISA addressed this vulnerability in an Industrial Control Systems (ICS) advisory.

Affected products: PCU400: Version 6.5 K and prior PCU400: Version 9.4.1 and prior PCULogger: Version 1.1.0 and prior

Tags: DIB, tlp:green