zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - March 31, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - March 31, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Threat Actor Claims New Data Leak of X Users
  • Oracle Health Breach Exposes U.S. Patient Data, Threat Actor Demands Ransom in Crypto
  • CISA Releases Malware Analysis Report on RESURGE Malware Associated with Ivanti Connect Secure

Threat Actor Claims New Data Leak of X Users

Source: https://hackread.com/twitter-x-of-2-8-billion-data-leak-an-insider-job/

What we know: A Threat actor on dark web forum BreachForums, “ThinkingOne,” has posted data supposedly belonging to 2.8 billion X (formerly Twitter) users that was allegedly stolen by a disgruntled X employee during mass lay-offs.

Context: The 2025 data leak has allegedly been merged with data leak from 2023 by ThinkingOne. The 2025 leak includes profile metadata such as user IDs, screen names, and locations. The 2.8 billion user data possibly includes bot accounts, inactive and deleted accounts, along with the current 335.7 million users.

Analyst note: While the data contains publicly available information, it is likely that such a massive amount of data could be used in impersonation attacks or phishing campaigns against X users.

Oracle Health Breach Exposes U.S. Patient Data, Threat Actor Demands Ransom in Crypto

Source: https://www.bleepingcomputer.com/news/security/oracle-health-breach-compromises-patient-data-at-us-hospitals/

What we know: Oracle Health has reportedly notified customers about a data breach that exposed patient data from legacy servers used by multiple U.S. healthcare organizations. According to sources, threat actor “Andrew” has claimed the breach.

Context: Oracle Health and its systems migrated to Oracle Cloud after an acquisition process in 2022. Oracle has also said that the threat actor leveraged compromised customer details to breach the affected servers and exfiltrate data.

Analyst note: The Oracle Health breach closely follows reports of another breach targeting Oracle Cloud's federated SSO login servers that the company has denied. Affected Oracle Health users are likely to face identity theft, extortion, and potential misuse of their health records.

CISA Releases Malware Analysis Report on RESURGE Malware Associated with Ivanti Connect Secure

Source: https://www.cisa.gov/news-events/alerts/2025/03/28/cisa-releases-malware-analysis-report-resurge-malware-associated-ivanti-connect-secure

What we know: CISA has published a Malware Analysis Report (MAR) that includes analysis and associated detection signatures on a new malware variant identified as RESURGE.

Context: RESURGE exploits the stack-based buffer overflow vulnerability, CVE-2025-0282, in Ivanti Connect Secure appliances. The RESURGE malware variant contains capabilities of the SPAWNCHIMERA malware variant and contains distinctive commands that alter its behavior.

Analyst note: The RESURGE malware variant enables attackers to create web shells, manipulate integrity checks, modify files, and escalate permissions, potentially compromising Ivanti Connect Secure appliances. Exploiting the vulnerability likely enables widespread credential harvesting, account manipulation, and system modifications.

DEEP AND DARK WEB INTELLIGENCE

Exploit user K3MP3R: Untested threat actor "K3MP3R" has advertised an auction for RDWeb (Remote Desktop Web Access) access with local administrator rights to an unnamed U.S.-based housing administration company on Exploit. Threat actors with these rights are likely to gain unauthorized access to sensitive housing data, potential exploitation of personal information, and financial harm to both the company and its clients.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-1219: In certain versions of PHP, when requesting a web resource using DOM or SimpleXML extensions, a wrong content-type header is used during redirects. This can cause the document to be read incorrectly, leading to data errors or bypassing security checks.

Affected products: Affects PHP versions 8.1.* before 8.1.32, 8.2.* before 8.2.28, 8.3.* before 8.3.19, and 8.4.* before 8.4.5.

Tags: DIB, tlp:green