ZeroFox Daily Intelligence Brief - March 28, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - March 28, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Hamas-Linked Cryptocurrency Worth USD 200,000 Seized by U.S. DOJ
- Solar Inverter Vulnerabilities Risk Power Grid Stability
- Pakistan-Linked APT Group Impersonates India Post to Infect Users with Malware
Hamas-Linked Cryptocurrency Worth USD 200,000 Seized by U.S. DOJ
What we know: The U.S. Department of Justice (DOJ) recently seized approximately USD 200,000 in cryptocurrency intended to support activities of Palestinian terrorist organization Hamas.
Context: The FBI had traced at least 17 crypto wallet addresses allegedly belonging to individuals residing in Turkey and elsewhere, which were used to launder over USD 1.5 million in cryptocurrency since October 2024. The donations were collected through an alleged Hamas-associated group chat on an unnamed encrypted messaging platform.
Analyst note: There is a roughly even chance that donations being sought in the name of aid to Palestinians affected by the Israel-Hamas war are likely being misused for terrorist activities. It is also likely that hacktivist groups aligned with Palestine are part of the fundraising efforts.
Solar Inverter Vulnerabilities Risk Power Grid Stability
What we know: Forty-six vulnerabilities in solar inverters from three manufacturers could have risked grid infrastructure to potential instability and cyberattacks. All three companies have issued patches to mitigate the risks.
Context: Modern solar inverters are internet-connected for remote monitoring and control and are often connected to cloud platforms that can pose security risks if not properly secured.
Analyst note: These vulnerabilities could enable attackers to disrupt power grids, hijack devices, steal data, execute remote code, and create botnets for large-scale cyberattacks, affecting components along the supply chain.
Pakistan-Linked APT Group Impersonates India Post to Infect Users with Malware
Source: https://thehackernews.com/2025/03/apt36-spoofs-india-post-website-to.html
What we know: APT36, allegedly tied to Pakistan, has been attributed to creating and using a fake website posing as India’s public postal system to infect Windows and Android systems in India with malware.
Context: The fake website, with the url “postindia[.]site,” delivers a malicious PDF file with ClickFix tactics to Windows systems to compromise them, while Android users are tricked into installing an app that steals sensitive data and maintains persistent access.
Analyst note: Compromised devices and stolen data from this campaign are likely to lead to espionage or further attacks.The ClickFix tactic has been observed in other campaigns as well, such as threat actor Storm-1865 impersonating Booking[.]com to trick victims into downloading malware.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user thisisb: On March 26, 2025, untested threat actor "thisisb" advertised VPN access with administrator rights to an unnamed Iranian airlines company on BreachForums. The user is at “God” level on BreachForums indicating that their previous sales were deemed legitimate by other users. The admin rights, if genuine, could be misused for disrupting flight operations, travel bookings, and surveilling passengers.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-20229: In affected versions of Splunk Enterprise and Splunk Cloud Platform, a least-privileged user without admin access could exploit missing security checks. After gaining unauthorized access, a threat actor could maliciously upload files, execute remote code, install malware, and steal data, likely disrupting operations.
Affected products: The affected products are listed in this advisory.
Tags: DIB, tlp:green