zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - March 17, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - March 17, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Brief - Introduction to Social Engineering: Romance Scams
  • Recent Phishing Campaign Uses ClickFix and Impersonates Booking[.]com
  • Akira-Encrypted Files Retrieved in 10 Hours Without Paying Hackers

ZeroFox Intelligence Brief - Introduction to Social Engineering: Romance Scams

Source: https://www.zerofox.com/advisories/31302/

What we know: Sextortion and romance scam threat actors are very likely to continue evolving their attack techniques in 2025, circumventing security hygiene measures and capitalizing upon the challenges faced by national and international law enforcement (LE) bodies.

Context: Romance scams are a type of confidence scheme whereby a threat actor seeks to exploit a victim’s romantic emotions—usually to achieve a financial objective. While the specific tactics, techniques, and procedures (TTPs) vary, romance scams generally follow an attack chain composed of five fundamental pillars—victim selection, initial contact, developing a trusting relationship, isolation, and exploitation.

Analyst note: Romance scams prey on emotional vulnerabilities, leaving victims with psychological trauma and significant financial losses, often causing a deep sense of personal violation. Threat actors will very likely continue to capitalize upon established techniques to achieve high success rates, and increasing financial payoffs.

Ongoing Phishing Campaign Uses ClickFix and Impersonates Booking[.]com

Source: https://www.darkreading.com/threat-intelligence/threat-actor-booking-com-clickfix-phishing-scheme

What we know: A threat actor dubbed Storm-1865 is impersonating Booking[.]com webpages in an ongoing campaign to trick victims into downloading malware through a technique called ClickFix.

Context: Through the ClickFix technique, users are tricked into responding to doctored error messages about security issues and downloading malicious files to solve these security issues themselves.

Analyst note: Storm-1865’s campaign targets the hospitality sector globally, increasing the scale and reach of the threat. This could lead to further attacks like ransomware, business email compromise (BEC), and data breaches of Booking.com customers and partners.

Akira-Encrypted Files Retrieved in 10 Hours Without Paying Hackers

Source: https://www.bleepingcomputer.com/news/security/gpu-powered-akira-ransomware-decryptor-released-on-github/

What we know: The Akira ransomware encryption on Linux/ESXi systems has been cracked using sixteen RTX 4090 GPUs, and can be reportedly used to retrieve locked data of victims, without having to pay the hackers.

Context: The Akira ransomware, first discovered in 2023, has targeted North American, European, and Australian businesses and critical infrastructure entities. According to CISA, till January 1, 2024, the group has claimed about USD 42 million in ransomware proceeds, affecting 250 organizations.

Analyst note: The decryptor is available on GitHub with instructions on how to use it to recover Akira-encrypted files. There is a roughly even chance of the decryptor’s effectiveness.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user MIYAK000: Well-regarded threat actor "MIYAK000" has advertised VPN access to an unnamed U.S.-based medical revenue cycle management company on predominantly English language dark web forum BreachForums. Potential buyers are likely to be interested in this advertisement to access this company’s patent information, proprietary data, prescriptions, and more to extort the company and patients.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-2345: A vulnerability was found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. The manipulation leads to improper authorization, allowing remote attackers to potentially access sensitive user data, control device settings, or exploit the camera for malicious purposes. It is possible to initiate the attack remotely.

Affected products: IROAD Dash Cam X5 and Dash Cam X6 up to 20250308

Tags: DIB, tlp:green