zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - March 21, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - March 21, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • North Korea’s New Hacking Unit Aims to Counteract Western Cybersecurity Systems
  • New Backdoor Discovered in Specific RansomHub Ransomware Group’s Attacks
  • Jury Convicts Individual in Mass Mailing Fraud Scheme Targeting Senior Citizens

North Korea’s New Hacking Unit Aims to Counteract Western Cybersecurity Systems

Source: https://techcrunch.com/2025/03/20/north-korea-launches-new-unit-with-a-focus-on-ai-hacking-per-report/

What we know: North Korea has established a special hacking unit called Research Center 227 that aims to develop and strengthen the country’s offensive hacking capabilities.

Context: Research Center 227, located in Pyongyang’s Mangyongdae District, officially began establishment efforts on March 9, 2025, within the intelligence agency Reconnaissance General Bureau (RGB). The unit aims to offset Western nations’ cybersecurity systems, develop AI-based tactics for stealing information, carry out digital asset theft, such as the recent cryptocurrency heist, and disrupt computer networks.

Analyst note: Research Center 227 is unlikely to be involved in direct information gathering and actual hacking, as its focus is reportedly to support existing overseas hacking capabilities. By gathering intelligence about Western nations’ cybersecurity infrastructure, it likely aims to make cyberattacks more sophisticated in the future.

New Backdoor Discovered in Specific RansomHub Ransomware Group’s Attacks

Source: https://www.bleepingcomputer.com/news/security/ransomhub-ransomware-uses-new-betruger-multi-function-backdoor/

What we know: RansomHub ransomware-as-a-service (RaaS) group has been observed deploying a new backdoor called Betruger, which has features like keylogging, network scanning, privilege escalation, and more.

Context: The group has been linked to data-theft extortion targeting major organizations, leaking data from healthcare companies, and breaching over 200 victims across other critical infrastructure entities.

Analyst note: The Betruger backdoor is customized to likely improve evasion detection, accelerate the attack process, and establish stronger persistence, especially during the initial attack stages, thereby enabling ransomware affiliates to undertake more sophisticated operations with fewer external dependencies.

Jury Convicts Individual in Mass Mailing Fraud Scheme Targeting Senior Citizens

Source: https://www.justice.gov/opa/pr/federal-jury-convicts-florida-resident-operating-mass-mailing-fraud-scheme-targeting-elderly

What we know: A federal jury in Central Islip, New York, has convicted an individual of conspiracy to commit mail fraud and four counts of mail fraud.

Context: The accused was charged with operating a mass mailing fraud scheme that tricked thousands of victims, many of whom were senior citizens, into providing the defendants with money by falsely promising prizes.

Analyst note: Scammers very likely target senior individuals, who are often perceived as less familiar with digital tools and online threats, using deceptive tactics. Victims of these scams are likely to face financial losses, emotional distress, and increased vulnerability to further exploitation.

DEEP AND DARK WEB INTELLIGENCE

BreachForums user Rey: Well-regarded threat actor "Rey" has claimed to sell a database associated with Affinitiv, a U.S.-based company that provides marketing technologies for the automotive industry, on predominantly English-language dark web forum BreachForums. The stolen data could be used for phishing, identity theft, and social engineering attacks, while the data sold to other cybercriminals could lead to further exploitation, including ransomware attacks, account takeovers, fraudulent transactions, and targeted cyberattacks on both individuals and businesses.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-23120: It is a deserialization vulnerability in the Veeam.Backup.EsxManager.xmlFrameworkDs and Veeam.Backup.Core.BackupSummary .NET classes, which enables remote code execution (RCE) by authenticated domain users. This flaw could enable attackers with domain user privileges to execute arbitrary code on affected systems, potentially compromising the entire network and escalating privileges for further malicious activities.

Affected products: Veeam Backup & Replication 12.3.0.310 and all earlier version 12 builds

Tags: DIB, tlp:green