ZeroFox Daily Intelligence Brief - March 19, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - March 19, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Leaked Logs Expose Black Basta’s Possible Russian Official Connections
- Organized Crime Abuse Digital Infrastructure
- Cybercriminals Spreading Malware Disguised as DeepSeek AI App, Website, Installer
Leaked Logs Expose Black Basta’s Possible Russian Official Connections
Source: https://www.darkreading.com/threat-intelligence/black-basta-league-russian-officials-chat-logs
What we know: According to a new analysis of leaked Black Basta chat logs, Russian officials likely assisted the group’s leader, aka GG or Tramp, in escaping custody after they were detained in Armenia last June.
Context: Black Basta’s internal Matrix chat logs were leaked on a Telegram channel last month exposing over 200,000 messages, tactics, credentials, and other details, and was reportedly triggered by Black Basta's alleged attack on Russian banks.
Analyst note: The likely involvement of Russian officials and the Black Basta’s operations from Moscow offices suggests state-backed support for cybercrime—providing resources, protection, and intelligence access—enabling them to conduct more strategic and widespread attacks. Also, the leak revealed the group’s use of AI tools like ChatGPT for phishing, malware, and data collection likely to automate and refine attacks, increasing the effectiveness, scale, and potential for widespread damage.
Organized Crime Abuse Digital Infrastructure
What we know: The EU Serious and Organised Crime Threat Assessment (EU-SOCTA) 2025 details cybercrime threats and cybercrime evolution within the European Union via reshaping of tactics, tools, and structures employed by criminal networks through abuse of artificial intelligence (AI) and other digital infrastructure.
Context: Criminal networks are increasingly exploiting digital infrastructure to conceal their activities from law enforcement, while increasingly stealing, trading, and exploiting sensitive data.
Analyst note: As threat actors diversify their capabilities, the proliferation of dark web marketplaces and their related processes is likely to further impact national security and critical infrastructure, as ransomware attacks, AI-driven fraud, and online child exploitation continue to rise.
Cybercriminals Spreading Malware Disguised as DeepSeek AI App, Website, Installer
Source: https://hackread.com/fake-deepseek-ai-installers-websites-apps-malware/
What we know: Cybercriminals are exploiting DeepSeek AI’s popularity to spread malware by disguising themselves as DeepSeek web and mobile app installers for Windows, Mac, and Android.
Context: Malicious actors are deploying SEO poisoning tactics, like using trending search terms such as DeepSeek AI, to redirect users to fake websites to spread malware—like captcha pages urging command execution, crypto miners, keyloggers, and password stealers.
Analyst note: SEO poisoning of widely searched emerging technologies could be used by cybercriminals for malicious activities. It is advisable that users remain alert about website or application clones, and sham installers for both personal computers and mobile phones.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user Digileak: Untested threat actor "Digileak" has advertised web panel access with administrator rights to an unnamed Ukrainian advanced large-scale medical management platform on predominantly English language dark web forum BreachForums. If nation-state actors acquire this access, sensitive medical data could be used for intelligence gathering, and targeting high-profile individuals.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-10442: An off-by-one error vulnerability in the transmission component of Synology Replication Service and Synology Unified Controller (DSMUC) allows remote attackers to execute arbitrary code. This can potentially lead to a broader system compromise, enabling unauthorized access or manipulation of sensitive data.
Affected products: Synology Replication Service before 1.0.12-0066, 1.2.2-0353, and 1.3.0-0423 and Synology Unified Controller (DSMUC) before 3.1.4-23079
Tags: DIB, tlp:green