zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - March 18, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - March 18, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • RansomHub Targets U.S. Banking and Consulting Firms
  • 10,000 Attacks on ChatGPT Flaw in a Week, Financial Institutions Susceptible
  • Scammers Impersonate Cl0p to Extort Businesses

RansomHub Targets U.S. Banking and Consulting Firms

Source: https://www.darkreading.com/cyberattacks-data-breaches/ransomhub-fakeupdates-government-sector

What we know: RansomHub is targeting U.S. firms in a campaign involving the FakeUpdates malware-as-a-service (MaaS)—SocGholish, multiple threat actors, and compromised websites.

Context: RansomHub employs common ransomware TTPs like phishing and vulnerability exploitation and utilizes a double extortion model of exfiltrating information, deleting shadow volume copies and encrypting systems as a means of extorting its victims. More about RansomHub is profiled in ZeroFox’s recent publishing.

Analyst note: RansomHub is observed to be successful in its operations likely because of its strategic collaboration with other threat actors and deploys malware strains to evade detection and more. RansomHub’s activities have been on the rise and has amassed a large swath of victims since last year.

10,000 Attacks on ChatGPT Flaw in a Week, Financial Institutions Susceptible

Source: https://hackread.com/hackers-exploit-chatgpt-cve-2024-27564-10000-attacks/

What we know: Over 10,000 exploit attempts targeting a medium severity flaw (CVE-2024-27564) in ChatGPT were recorded in one week from a single IP address, targeting government and financial institutions in several countries, primarily in the United States.

Context: The exploit, aka Server-Side Request Forgery (SSRF) attack, enables hackers to make unauthorized server requests to collect sensitive data, potentially causing data leaks. Separately, ChatGPT was down for several users globally for a few hours between March 17 and 18, displaying Error 504, a server side problem.

Analyst note: Organizations operating ChatGPT / OpenAI-driven services and integrations with vulnerable systems, are likely to be susceptible to data breaches, and system compromise. Additionally, the ChatGPT downtime could have been the result of a server attack exploiting the bug, but OpenAI is yet to reveal the reason.

Scammers Impersonate Cl0p to Extort Businesses

Source: https://hackread.com/scammers-pose-cl0p-ransomware-fake-extortion-letters/

What we know: New incidents have emerged of scammers falsely claiming to be affiliated with the Cl0p ransomware gang to extort businesses and coerce companies into making payments.

Context: These scammers craft extortion emails—mimicking the language and tactics of real ransomware groups like Cl0p—claiming to have infiltrated the target’s network and exfiltrated sensitive data, often citing public details from actual attacks to add credibility.

Analyst note: Scammers likely impersonate ransomware groups to exploit fear and extort money by deceiving organizations into believing the threats are legitimate, leading to unnecessary payments and increased financial losses.

DEEP AND DARK WEB INTELLIGENCE

Exploit user exodus-AB: Untested threat actor "exodus-AB" has advertised an auction for RDP access with domain user rights to an unnamed U.S.-based finance company on predominantly Russian language dark web forum Exploit. This can likely lead to data breaches, financial loss, and potential exploitation of sensitive customer information.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-24813: This is a remote code execution and information disclosure vulnerability in Apache Tomcat’s handling of the partial PUT method. This vulnerability could enable attackers to manipulate file uploads and potentially execute malicious code to exploit it for remote code access, installing malware on affected devices.

Affected products: Apache Tomcat versions 11.0.0-M1 to 11.0.2, 10.1.0-M1 to 10.1.34, and 9.0.0.M1 to 9.0.98

Tags: DIB, tlp:green