ZeroFox Daily Intelligence Brief - March 24, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - March 24, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - Financial Scams Threaten U.S. Tax Returns
- Russian Company is Looking for Telegram Vulnerabilities; Offers up to USD 4 million
- Social Media Business Accounts Phished to Gain Access
ZeroFox Intelligence Flash Report - Financial Scams Threaten U.S. Tax Returns
Source: https://www.zerofox.com/advisories/31516/
What we know: ZeroFox Intelligence has identified a notable increase in financial fraud-related activity seeking to exploit the spike in use of government services such as the Internal Revenue Service (IRS) and private financial services, as the April 15 deadline of the 2024-2025 U.S. tax season nears.
Context: Historically, the end of the U.S. tax season has been perceived as a lucrative targeting opportunity by financially motivated threat actors seeking to obtain compromised account credentials, personally identifiable information (PII), or personal financial information (PFI) to exploit tax return processes.
Analyst note: It is likely that threat actors are looking to steal personal information like Social Security numbers, account information, and other personally identifiable information to file fraudulent tax returns, claim refunds, and commit financial fraud. Scammers are likely to also target larger entities filing tax like businesses, leading to unauthorized access to corporate financial data and fraudulent filings.
Russian Company is Looking for Telegram Vulnerabilities; Offers up to USD 4 million
What we know: A Russia-based company, Operation Zero, has put up a X/Twitter advertisement looking for Telegram vulnerabilities, with the highest offer being USD 4 million.
Context: Operation Zero is a zero-day purchase platform that exclusively sells to the Russian government and Russia-based entities. It is willing to offer USD 500,000 for one-click remote code execution (RCE) exploits, USD 1,500,000 for zero-click RCE exploits, and USD 4 million for a full chain of exploits, likely meaning the vulnerabilities lead to access to the whole device.
Analyst note: Operation Zero’s focus on the Telegram app likely indicates that the Russian government is looking to target Telegram users, either within Russia (like dissidents) or abroad. Ukraine banned the use of Telegram in 2024 for government and military personnel fearing such targeted attacks.
Social Media Business Accounts Phished to Gain Access
Source: https://hackread.com/phishing-scam-fake-instagram-chatbots-hijack-accounts/
What we know: A new phishing campaign targeting Instagram Business accounts- is impersonating Instagram chat support to trick users into adding a malicious authenticator app, granting unauthorized access.
Context: Hackers, through fake chat support, get access to user accounts by asking for screenshots and account details. They provide users a guide on implementing two-factor authentication (2FA) on their account for them to resolve issues with their accounts themselves.
Analyst note: Scammers likely prefer impersonating legitimate chat support to gain personal information required to access sensitive financial information, like payment details and passwords, to covertly hacking into devices and networks to gain access.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user Alcxtraze: Threat actor "Alcxtraze" is allegedly selling data associated with Bergstein Digital, a Netherlands-based manufacturer of industrial printers for direct product printing. The actor claims to have 9 million lines of information including details such as name and email address on dark web forum BreachForums. There is a roughly even chance of the data being used in social engineering and phishing attacks.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-2664: A vulnerability was found in CodeZips Hospital Management System 1.0. The manipulation of the argument ID leads to sql injection. The attack could be launched remotely. The exploit has been disclosed to the public, making it very likely that threat actors could use it to access, modify, and delete sensitive patient records, financial details, and hospital operational data, unless mitigations are put in place effectively.
Affected products: CodeZips Hospital Management System affected at version 1.0
Tags: DIB, tlp:green