zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief – March 15, 2025

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief – March 15, 2025

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on March 13, 2025; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

SideWinder APT Expands Reach Across Multiple Industries in Asia, the Middle East, and Africa

**What we know: **

  • SideWinder, an advanced persistent threat (APT) group, has focused its attacks on maritime and logistics companies across South and Southeast Asia, the Middle East, and Africa.
  • Recent attacks follow a pattern whereby spear phishing emails distribute infected documents that exploit a vulnerability within a mathematical tool in a popular documentation application.
  • These attacks initiate a multi-phase process leading to the use of a .NET downloader called ModuleInstaller that ultimately deploys StealerBot, a post-exploitation toolkit.

Chinese Spy Volt Typhoon’s Cyberattack on U.S. Power Utility Lasted a Year

What we know:

  • Chinese espionage group Volt Typhoon was observed stealing critical infrastructure data, including information on geographical distribution of energy, from a U.S. power utility grid for 300 days in 2023.

FBI Denver Warns of Online File Converter Scam

What we know:

  • The FBI Denver Field Office is warning online users that threat actors are exploiting free online document converter and downloader tools to load malware onto victims’ computers, leading to incidents such as ransomware and identity theft.

Tags: tlp:green