ZeroFox Daily Intelligence Brief - March 12, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - March 12, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- SideWinder APT Expands Reach Across Multiple Industries Across Asia, Middle East, and Africa
- Apple Patches for Zero-Day Bug Likely Targeting Specific Individuals
- PSI Roundup—Major Geopolitical Happenings Around the World
SideWinder APT Expands Reach Across Multiple Industries Across Asia, Middle East, and Africa
Source: https://thehackernews.com/2025/03/sidewinder-apt-targets-maritime-nuclear.html
What we know: APT group SideWinder has been targeting entities across multiple countries, targeting maritime, logistics, and other industries, exploiting a vulnerability within a mathematical tool in a popular documentation application to deploy StealerBot.
Context: SideWinder has suspected Indian roots, with its attacks spreading to regions such as South Asia, Southeast Asia, the Middle East, and Africa.
Analyst note: The attacks impacted a wide range of sectors, including critical infrastructure, diplomatic entities, and private companies. StealerBot facilitates post-exploitation activities, such as stealing sensitive data, credential harvesting, and enabling further system compromise, potentially leading to significant financial, operational, and strategic damage.
Apple Patches for Zero-Day Bug Likely Targeting Specific Individuals
What we know: Apple has released patches for a zero-day bug (CVE-2025-24201) in an “extremely sophisticated attack against specific targeted individuals.”
Context: The vulnerability affects WebKit of browsers like Safari, Chrome, and Firefox on Apple devices (with exceptions for alternate browsers in EU). The bug has been patched in iOS 18.3.2, iPadOS 18.3.2, and Apple Vision Pro visionOS 2.3.2.
Analyst note: Without the patches, it is very likely hackers could—or are already tracking—user activity on browsers, and may attempt to target systems beyond browsers. Politically-inclined persons or government officials are likely to be targeted, as similar flaws have been allegedly exploited by threat actors like Russian-backed Cozy Bear (aka APT29) in the past.
PSI Roundup—Major Geopolitical Happenings Around the World
The U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) has issued a Geographic Targeting Order requiring money services businesses in 30 ZIP codes near the U.S.-Mexico border to report cash transactions over USD 200 in an effort to combat cartel-related money laundering. On March 11, the United States agreed to resume military aid and intelligence sharing with Ukraine as the latter agreed to a 30-day ceasefire with Russia. Before discussions leading to the ceasefire agreement, Ukraine launched over 340 drones on Moscow and surrounding areas, killing three and injuring 17 people. In retaliation, Moscow is considering launching the intermediate-range ballistic "Oreshnik" hypersonic missile.
In a train in Pakistan’s southwestern province of Balochistan, nine security personnel and the train driver were killed after separatists hijacked it.
Off the coast of England, in the North Sea, a cargo ship’s crash with an oil tanker has resulted in one person missing and presumed dead, with 30 others being rescued.
DEEP AND DARK WEB INTELLIGENCE
Hacktivist Link Suspected in X Outage: ZeroFox reports on the multiple service outages of X, affecting a reported 1.6 million users worldwide and lasting several hours, and the possibilities of what the reason of these attacks could have been.
VULNERABILITY AND EXPLOIT INTELLIGENCE
Microsoft March 2025 Patch Tuesday: Microsoft has released its March 2025 Patch Tuesday security updates, addressing 57 vulnerabilities, including patches for six actively exploited zero-day bugs. This advisory is essential for organizations and users to deploy the latest patches to minimize their attack surfaces and better secure sensitive information.
Affected products: The affected products have been listed in this update.
Tags: DIB, tlp:green