ZeroFox Weekly Intelligence Brief – March 22, 2025
|by Alpha Team

ZeroFox Weekly Intelligence Brief – March 22, 2025
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the threat landscape, including digital, cyber, and physical threats. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 6:00 AM (EDT) on March 20, 2025; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
Ongoing Phishing Campaign Uses ClickFix and Impersonates Booking[.]com
What we know:
- A threat actor dubbed “Storm-1865” is impersonating Booking[.]com webpages in an ongoing campaign to trick victims into downloading malware through a technique called ClickFix.
- Storm-1865 sends targets an email pretending to be Booking[.]com, raising fake issues such as negative reviews left by customers and asking them to respond to the issue by clicking on a link.
- The link deploys a social engineering tactic that uses a fake CAPTCHA page with a blurred background mimicking Booking[.]com webpage, along with instructions for the user to launch a command on Windows to install the malware.
Cybercriminals Spreading Malware Disguised as DeepSeek AI Web and App Installers
What we know:
- Cybercriminals are exploiting DeepSeek AI’s popularity to spread malware by disguising themselves as DeepSeek web and mobile app installers for Windows, Mac, and Android.
ChatGPT Flaw Sees 10,000 Attacks in a Week; Financial Institutions Susceptible
What we know:
- Over 10,000 exploit attempts on a medium severity flaw (CVE-2024-27564) in ChatGPT were recorded in one week from a single IP address; the attacks targeted government and financial institutions in several countries but were primarily focused in the United States.
Tags: DIB