zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - March 25, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - March 25, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Ukraine Rail Service Down After Cyberattack; Russia Suspected
  • Oracle Denies Data Leak as Hacker Attempts 6 Million User Data Sale
  • Chinese Threat Actor Found Lurking in Asian Telecom Network for Four Years

Ukraine Rail Service Down After Cyberattack; Russia Suspected

Source: https://www.reuters.com/world/europe/ukraine-railway-says-its-online-systems-targeted-large-scale-cyberattack-2025-03-24/

What we know: Ukrzaliznytsia, Ukraine's national railway operator, has suffered a cyberattack—suspected to be caused by Russia—disrupting online ticket sales, causing long lines and delays at stations.

Context: Ukrzaliznytsia is essential to Ukraine, transporting millions of passengers and tonnes of freight annually, especially since the start of the Ukraine-Russia war. Train operations remain unaffected in this cyberattack and efforts to restore the online ticketing system are still ongoing.

Analyst note: By infiltrating Ukrzaliznytsia’s online ticketing system, Russia could gain valuable intelligence on Ukraine’s military and civilian movements, as the railway transports large numbers of people and goods. This attack is likely to reveal vast swaths of passenger, military, and business data exposing payment, supply chain, and operational information.

Oracle Denies Data Leak as Hacker Attempts 6 Million User Data Sale

Source: https://www.theregister.com/2025/03/23/oracle_cloud_customers_keys_credentials/

What we know: Oracle has publicly denied claims made by threat actor rose87168 about stealing six million user data, including key files and encrypted passwords.

Context: The hacker demanded over USD 200 million in crypto from Oracle to reveal how they breached the servers, which the company refused to pay. Rose87168 is now demanding affected companies to pay to remove data related to them, and is also selling the data to other parties.

Analyst note: It is likely that there will be a surge in threat actors targeting CVE-2021-35587, which rose87168 claims to have exploited in the alleged breach. Immediate repercussions are unknown given the lack of veracity of the claims, but it is very likely that Oracle will ask its customers to reset passwords to the platform.

Chinese Threat Actor Found Lurking in Asian Telecom Network for Four Years

Source: https://www.darkreading.com/cyberattacks-data-breaches/china-nexus-apt-weaver-ant-caught-yearslong-web-shell-attack

What we know: China-linked threat actor “Weaver Ant” has been discovered lurking in the network of a major Asian telecommunications company for over four years, reportedly spying and collecting sensitive information.

Context: Weaver Ant used a number of web shells, including the China Chopper (developed by Chinese hackers), and other tools to gain persistent access and lateral movement in the network system, while avoiding detection. So far, the target telecom company or its location has not been revealed.

Analyst note: It is likely that Weaver Ant is among the ranks of Chinese state-sponsored actors, which engage in cyber espionage missions across the world, like the 2024 iSoon APT operation revealed. Critical infrastructure, especially in Asia, Europe, and North America, are the usual targets of such actors.

DEEP AND DARK WEB INTELLIGENCE

Xss user FantasticExploits: Moderately credible threat actor "FantasticExploits" has advertised an Opencart plugin zero-day SQL injection vulnerability on xss. An SQL injection vulnerability could impact the way information is sent and received by an application, which could enable threat actors to manipulate results and introduce malware into affected devices.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-24513: A security issue was discovered in ingress-nginx, an Ingress controller for Kubernetes, where attacker-provided data was included in a filename by the ingress-nginx Admission Controller feature, resulting in directory traversal within the container. Threat actors could exploit this vulnerability to modify rules, causing service outages or redirecting traffic to malicious sites, leading to credential theft, data interception, and more.

Affected products: kubernetes ingress-nginx affected from versions 0 through 1.11.4 and 1.12.0

Tags: DIB, tlp:green