ZeroFox Daily Intelligence Brief - March 14, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - March 14, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Websites Seized, 10 Arrested, in Prison Drug Distribution Scheme in the Eastern District of Texas
- New Ransomware Gang Mora_001 Targeting Fortinet Firewall Appliances
- FBI Atlanta Warns of Road Toll Smishing Scam Regarding Peach Pass
Websites Seized, 10 Arrested, in Prison Drug Distribution Scheme in the Eastern District of Texas
What we know: Three internet domains have been seized and ten individuals arrested in a scheme to provide drugs in prison, announced the U.S. Department of Justice.
Context: On March 6, 2025, the domains HerbalIncenseUSA[.]com, Herbal-Biz[.]com, and Herbal-Empire[.]com were seized following an investigation into drug distribution via the internet and the U.S. Mail. The websites allegedly sold a variety of controlled substances, marketed as fake legal mail to smuggle drugs into prisons with the help of corrupt guards.
Analyst note: The seized websites are clearnet domains that could be accessed by any one with internet connectivity, indicating how such websites likely pose a high threat to the general public. It is evidence of the likely involvement of digital assets and clearnet infrastructure in illegal drug networks.
New Ransomware Gang Mora_001 Targeting Fortinet Firewall Appliances
What we know: Novel ransomware group, “Mora_001”––with probable links to LockBit––has been exploiting two bugs (CVE-2024-55591 and CVE-2025-24472) affecting Fortinet firewall appliances with ransomware strain SuperBlack.
Context: Mora_001’s ransom note includes the same Tox chat identifier that is used by the notorious LockBit ransomware gang. On March 13, 2025, the United States extradited a dual Russian and Israeli national, an alleged developer for the LockBit ransomware group.
Analyst note: Data theft, double extortion owing to file encryption, and potential disruptions are very likely on compromised devices. Mora_001, traced in Russia, is likely a current associate or only sharing a chat ID with LockBit, which was also first encountered on Russian-language cybercrime forums.
FBI Atlanta Warns of Road Toll Smishing Scam Regarding Peach Pass
What we know: FBI is warning of an ongoing SMS phishing (smishing) campaign—amassing a total of USD 3,643.42 in losses—where actors are impersonating Georgia’s electronic toll collection system, Peach Pass, to send toll users unpaid toll notifications.
Context: The “outstanding toll amount” is similar among the complaints and that the link provided within the text impersonates the state’s toll service name, while the phone numbers appear to change between states.
Analyst note: Smishing attempts like this one urge unsuspecting targets by creating a believable and urgent message to get them to make transactions they normally would not, while also revealing their financial information to bad actors.
DEEP AND DARK WEB INTELLIGENCE
Telegram user Arab Ghosts Hackers: Pro-Palestine threat actor group "Arab Ghosts Hackers" in collaboration with "Lulzsec Arabs," announced their intentions to target Argentine infrastructure. It is likely that Arab Ghosts Hackers is collaborating with Lulzsec Arabs to draw attention to their cause by targeting government-related entities and launch distributed-denial-of-service on devices as hacktivists often do.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-25291: An authentication bypass vulnerability was found in an authentication library due to a parser differential. This vulnerability could enable an attacker to be able to execute a signature wrapping attack to modify messages without invalidating signatures and gain unauthorized access to sensitive information.
Affected products: SAML-Toolkits ruby-saml versions before 1.12.4 and after 1.13.0 till 1.18.0
Tags: DIB, tlp:green