zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - March 13, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - March 13, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CISA and Partners Release Cybersecurity Advisory on Medusa Ransomware
  • Chinese Spy Volt Typhoon’s Cyberattack on U.S. Power Utility Lasted a Year
  • Geopolitical Focus: U.S. Policy Shift in Ukraine Upends European Defense Sector

CISA and Partners Release Cybersecurity Advisory on Medusa Ransomware

Source: https://www.cisa.gov/news-events/alerts/2025/03/12/cisa-and-partners-release-cybersecurity-advisory-medusa-ransomware

What we know: A joint report—#StopRansomware: Medusa Ransomware—details tactics, techniques, and procedures (TTPs), indicators of compromise, and detection methods associated with known Medusa ransomware activity.

Context: Medusa is a ransomware-as-a-service variant that enables threat actors to conduct ransomware attacks using common techniques like phishing campaigns and exploiting unpatched software vulnerabilities.

Analyst note: Medusa actors have deployed malware and conducted double extortion, while also using legitimate remote access software to tailor their choice based on any remote access tools already present in the victim environment to evade detection.

Chinese Spy Volt Typhoon’s Cyberattack on U.S. Power Utility Lasted a Year

Source: https://www.darkreading.com/cyberattacks-data-breaches/volt-typhoon-strikes-massachusetts-power-utility

What we know: Chinese espionage group Volt Typhoon was observed stealing critical infrastructure data, including geographical distribution of energy, from a U.S. power utility grid for 300 days in 2023.

Context: Littleton Electric Light and Water Departments (LELWD) in Massachusetts, powering two towns with a collective population of 15,000, is a small and unusual target, which neither owns transmission nor has access to large critical infrastructure.

Analyst note: The nature of the target very likely suggests that Volt Typhoon was seeking to pre-position itself into critical infrastructure networks, modify their TTPs to match the victim’s environment for similar future attacks on possible larger targets, and prepare to disrupt operations, in case of a major conflict with the United States.

Geopolitical Focus: U.S. Policy Shift in Ukraine Upends European Defense Sector

Source: https://www.zerofox.com/advisories/31216/

Trump administration officials have signaled their priority is to end the conflict between Russia and Ukraine—and return Russia to the global economy—rather than to continue to lend military and financial support to assist Ukraine’s war efforts with Russia. European states have responded to this drastic policy shift from post-World War II security arrangements with significant alterations to their defense spending and military postures.

Analyst note: ZeroFox has observed an increase in financially motivated threat actors targeting European defense companies, who will likely benefit from the additional trillions in defense spending.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user dashoar: Untested threat actor "dashoar" has advertised VPN access to an unnamed South Korean automotive parts manufacturing company on predominantly English language dark web forum BreachForums. This unauthorized VPN access can likely lead to data breaches, intellectual property theft, and supply chain disruptions.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-21590: China-linked UNC3886 has targeted this vulnerability in end-of-life (EOL) Juniper MX routers. CVE-2025-21590 is an improper isolation or compartmentalization vulnerability in the kernel of Juniper Networks Junos OS and enables a local attacker with high privileges to compromise the integrity of the device. EOL devices no longer receive updates and support as they reach the end of their lifecycle, but users with such devices that do not replace older models for newer ones likely expose themselves to unmitigated risks.

Affected products: The affected products and platforms are listed in this advisory.

Tags: DIB, tlp:green