zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - March 20, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - March 20, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Hackers Deploy Signal Spear Phishing to Target Ukraine Military
  • ZeroFox Intelligence Flash Report - GitHub Repositories Targeted in Malicious Cyber Activity
  • SpyX Breach Exposes Close to 2 Million

Hackers Deploy Signal Spear Phishing to Target Ukraine Military

Source: https://www.bleepingcomputer.com/news/security/ukrainian-military-targeted-in-new-signal-spear-phishing-attacks/

What we know: Private and government employees and entities associated with Ukraine Defense Forces were targeted by a spear phishing campaign on messaging app Signal in recent attacks.

Context: In March 2025, CERT-UA, discovered threat actors distributing archived messages reportedly containing minutes of meetings on military technologies, through compromised accounts of trusted contacts on Signal app. The messages would contain a “.pdf” file and an executable file for a remote control software tool.

Analyst note: The Signal spear phishing tactic is one among several instances of highly targeted cyberattacks, very likely emanating from Russia-linked hackers. Cyberattacks against individuals and groups linked to the Ukrainian military are very likely to become more sophisticated with hackers deploying newer tactics.

ZeroFox Intelligence Flash Report - GitHub Repositories Targeted in Malicious Cyber Activity

Source: https://www.zerofox.com/advisories/31426/

What we know: At least 12,000 separate GitHub repositories have reportedly been targeted in a phishing campaign that leverages OAuth abuse to deceive users into granting attackers access to accounts and credentials.

Context: Since approximately March 14, 2025, GitHub repositories have been targeted in two likely separate malicious cyber campaigns, resulting in the likely compromise of sensitive information associated with continuous integration (CI) and continuous development (CD) tools.

Analyst note: This OAuth abuse campaign threatens critical code and internal systems, very likely allowing scammers to steal sensitive data, make unauthorized changes, or compromise account security. Compromised CI/CD tools would further allow attackers to inject malicious code, disrupt pipelines, or enable further breaches and data theft.

SpyX Breach Exposes Close to 2 Million

Source: https://techcrunch.com/2025/03/19/data-breach-at-stalkerware-spyx-affects-close-to-2-million-including-thousands-of-apple-users/

What we know: Spyware application SpyX and its two other clone apps suffered a data breach in June 2024, exposing close to 2 million account records, including 17,000 Apple iCloud plaintext credentials.

Context: SpyX is a consumer-grade spyware compatible with Android and Apple devices, primarily advertised for parental control and is generally used as stalkerware because it enables covert surveillance of individuals without their consent.

Analyst note: Threat actors with access to this data could track a victim’s real-time location and movements, placing vulnerable individuals, including children, at risk of kidnapping and human trafficking, compromising their privacy and safety.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user dauxanh: Untested threat actor "dauxanh" claimed to have leaked data associated with ZoomInfo, a U.S.-based go-to-market platform that provides data and insights to help businesses find and grow customers. This leak could lead to privacy violations, potential identity theft, and targeted phishing attacks, impacting both individuals and businesses relying on the platform.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-1316: Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on affected devices. Since the Edimax IC-7100 is a network camera, attackers could exploit the vulnerability to access video feeds and establish persistence, compromising user privacy. CISA has added this vulnerability to its KEV catalog.

Affected products: All versions of Edimax IC-7100 IP Camera

Tags: DIB, tlp:green