HomeCybersecurity NewsNews roundup February 17, 2025
February 17, 2025

News roundup February 17, 2025

San Mateo, CA, February 17, 2025 — Stories, events, and developments that impacted the cybersecurity landscape last week, including emerging threats, policy changes, and industry responses.

Italian spyware behind malicious Android app

SIO, an Italian spyware maker known for selling its products to government customers, is behind malicious Android apps that pose as popular software but steal user data, according to an exclusive report from TechCrunch. Because the apps and the sites distributing them are in Italian, researchers believe that the spyware within them was used by Italian law enforcement. The spyware, called Spyrtacus, “can steal text messages, as well as chats from Facebook Messenger, Signal, and WhatsApp; exfiltrate contacts information; record phone calls and ambient audio via the device’s microphone, and imagery via the device’s cameras; among other functions that serve surveillance purposes.” The news comes at a time when the Italian government is under fire for its alleged use of Paragon spyware against a journalist and the two founders of an NGO that provides aid to immigrants in the Mediterranean. Read more.

Salt Typhoon hackers hack U.S. telecoms

Salt Typhoon hackers continue to target telecoms globally and, according to Recorded Future’s Insikt Group threat research division, are still successfully breaching U.S. providers by exploiting flaws in unpatched Cisco IOS XE routers. Salt Typhoon has targeted more than 1,000 Cisco network devices between December 2024 and January 2025. “Although over 1,000 Cisco devices were targeted, Insikt Group assesses that this activity was likely focussed, given that this number only represents 8% of the exposed devices and that RedMike engaged in periodic reconnaissance activity, selecting devices linked to telecommunications providers,” the division said. The flaws the threat actors exploit were among the top four most frequently exploited in 2023 and were used to compromise more than 50,000 Cisco IOS XE devices. Read more.

Paragon spyware targets Italian immigration organization

Beppe Caccia, a co-founder of Mediterranea Saving Humans, an Italian non-governmental organization that assists migrants, has stated that he was targeted in the recent Paragon spyware campaign executed via WhatsApp. Before Caccia, three other individuals also came forward, saying that they received a notification from WhatsApp informing them that they were among approximately 90 individuals targeted with spyware developed by Paragon. The other three victims include Francesco Cancellato, the director of the news website Fanpage.it; Libyan activist Husam El Gomati, who lives in Sweden and works on immigration issues related to Italy and Libya; and Mediterranea Saving Humans co-founder Luca Casarini. The Italian government has denied any involvement in the campaign, stating that legally protected individuals, such as journalists, had not been targeted by Italian intelligence agencies. Casarini has filed a complaint to determine who targeted him and his organization, stating, “We don’t have anything to hide. Those who spy have a lot to hide.” Read more.

North Korean hackers trick targets into running PowerShell

North Korean threat group Kimsuky is conducting a campaign that deceives users into running PowerShell and then malicious code. “To execute this tactic, the threat actor masquerades as a South Korean government official and over time builds rapport with a target before sending a spear-phishing email with a [sic] PDF attachment,” the Microsoft Threat Intelligence team said on X. To get users to read the PDF, they are tricked into clicking a URL that contains step-by-step instructions on how to launch PowerShell and then copy/paste malicious code into the terminal. “The code then sends a web request to a remote server to register the victim device using the downloaded certificate and PIN. This allows the threat actor to access the device and carry out data exfiltration,” Microsoft said. Attacks that rely on the victim to do the heavy lifting are becoming popular, as they can bypass security features that may otherwise stand in the way of the hackers. Read more.

2.7 billion records exposed in massive IoT breach

Wifi passwords, network names, IP addresses, system details, API tokens, app versions, and device IDs have been compromised in a massive IoT breach. The information was stored in an unprotected database linked to Mars Hydro, a Chinese company offering IoT grow lights, and LG-LED solutions, a firm registered in California. The database contains 1.17 terabytes of data across 13 folders that include more than 100 million records each, likely belonging to Mars Hydro’s Pro app users. Mars Hydro restricted database access upon disclosure, although concerns about whether the information was accessed and questions about the duration of the exposure remain unanswered. The data exposed could be used to gain unauthorized network access and potentially launch “nearest neighbor” attacks. Read more.

CISA election security officials placed on leave

The Department of Homeland Security has confirmed that CISA has placed 17 election security team members on administrative leave. The members were working on matters involving election integrity and foreign election interference. “The agency is undertaking an evaluation of how it has executed its election security mission with a particular focus on any work related to mis-, dis-, and malformation,” said Tricia McLaughlin, assistant secretary of the Department of Homeland Security. “While the agency conducts the assessment, personnel who worked on mis-, dis-, and malinformation, as well as foreign influence operations and disinformation, have been placed on administrative leave.” The development has increased unease among those who fear that the future of CISA may see the agency gutted. A CISA director has yet to be named by the Trump administration. Read more.

Serious iPhone security vulnerability

Apple has issued an urgent advisory for all iPhone and iPad users to update to iOS 18.3 immediately, addressing critical security vulnerabilities that can be exploited via “extremely sophisticated” attacks that would allow a threat actor to gain administrative access to the devices by disabling USB Restricted Mode. The nature of the flaw implies that an attacker would need physical access to the device to compromise it, as USB Restricted Mode “prevents an Apple iOS and iPadOS device from communicating with a connected accessory if it has not been unlocked and connected to an accessory within the past hour.” Apple has released no details about the flaw, but the company said it is “aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.” USB Restricted Mode was developed to prevent forensics tools, primarily those used by law enforcement, from accessing a confiscated device’s sensitive data. Read more.

LockBit’s service provider sanctioned

The United States, United Kingdom, and Australia have imposed sanctions on Zservers. This Russia-based company has provided crucial infrastructure support to the LockBit ransomware group via bulletproof hosting (BPH) services, which are internet services designed to protect cybercriminals from detection and shutdown. Additionally, two Russian nationals, Alexander Mishin and Aleksandr Bolshakov, were identified as key figures supporting LockBit by facilitating virtual currency transactions. “BPH providers like ZSERVERS protect and enable cybercriminals, offering a range of purchasable tools which mask their locations, identities, and activities. Targeting these providers can disrupt hundreds or thousands of criminals simultaneously,” read a statement from the UK government. The sanctions prevent citizens of the three countries imposing them from doing business with the individuals and company named while also freezing assets linked to them. Read more.

DeepSeek-V3 compromised hours after release

DeepSeek-V3, an advanced AI model released on December 25, 2024, was compromised within hours after launch by cybercriminals integrating it into OpenAI Reverse Proxy (ORP) systems using stolen credentials to enable unauthorized access. This exploitation is part of a growing trend known as “LLMjacking,” where attackers hijack Large Language Models (LLMs) by stealing API keys to skirt high operational costs. LLMjacking has resulted in a thriving black market where users can purchase access to stolen LLM accounts for as little as $30 per month. To evade detection, ORP operators employ dynamic domains, password protections, logging modifications, and CSS obfuscation. The financial toll of this new scheme is significant, with one ORP using stolen credentials generating nearly $50,000 in costs in less than 5 days. The almost instant exploitation of DeepSeek-V3 further highlights the need to enforce stronger protections against LLMjacking. Read more.

Brave Browser allows users to customize browsing experience

Brave Browser has introduced a new feature in its desktop version 1.75 that allows users to inject custom JavaScript into websites, enabling greater control and customization over browsing the web. Initially developed for debugging its ad-blocking capabilities, this “custom scriptlets” feature lets users modify website behavior similar to extensions like TamperMonkey and GreaseMonkey. Potential use cases include blocking trackers, improving privacy, forcing dark mode even on sites that don’t support it, hiding intrusive elements, preventing video autoplay, and creating custom keyboard shortcuts. Users can enable this feature by activating “Developer mode” in Brave’s settings and adding new scriptlets, which follow a filter rule syntax similar to ad-blocking extensions like uBlock Origin. Brave warns against using unverified scripts due to potential security risks. Read more.

More cybersecurity news

Ben Walker
Ben Walker
Ben Walker is a freelance research-based technical writer. He has worked as a content QA analyst for AT&T and Pernod Ricard.

Popular Articles