ZeroFox Daily Intelligence Brief - April 1, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - April 1, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- American-Israeli Cybersecurity Firm Check Point Denies Recent Data Breach
- Phishing platform “Lucid” Targets 169 Entities in Global Campaign
- Lazarus Targets Crypto Companies, Snagging Job Applicants
American-Israeli Cybersecurity Firm Check Point Denies Recent Data Breach
Source: https://www.theregister.com/2025/03/31/check_point_confirms_breach/
What we know: American-Israeli cybersecurity firm Check Point has denied data breach by threat actor “CoreInjection” on BreachForums, claiming the hacker is recycling old data that did not include the details provided on the platform.
Context: A relatively new BreachForums user, CoreInjection is selling Check Point’s alleged data for approx USD 434,570 in Bitcoin, which includes internal project documents, source code of proprietary software, internal network maps, user credentials, and more. CoreInjection is likely to have directed its attack against Israel.
Analyst note: There is a roughly even chance that the latest claims are indeed about a new data breach as opposed to an old one. It is likely that CoreInjection is politically motivated in its attack against Check Point and may have links to hacker or hacktivist groups supporting Iran, Hezbollah, or Palestine.
Phishing platform “Lucid” Targets 169 Entities in Global Campaign
What we know: A phishing-as-a-service (PhaaS) platform, named “Lucid,” has been used to target 169 entities across 88 countries through iMessage (iOS) and RCS (Android).
Context: Lucid is a subscription-based PhaaS platform sold by the Chinese threat group “XinXin” to other cybercriminals, giving them access to phishing tools and domains. The group also uses the Darcula v3 platform, suggesting a link between the two PhaaS services.
Analyst note: The phishing pages steal personal and financial information from victims, affecting individuals and businesses globally, potentially leading to identity theft, financial fraud, and further cyberattacks. Encrypted messaging and large-scale device farms complicate detection efforts by hiding message content and source, while spreading attacks across multiple devices.
Lazarus Targets Crypto Companies, Snagging Job Applicants
What we know: North Korea’s Lazarus (APT38) hacking group is using “ClickFix” to deploy malware targeting cryptocurrency job seekers. It impersonates major cryptocurrency companies, tricking victims into running malicious PowerShell commands.
Context: Through ClickFix, users are tricked into responding to doctored error messages about security issues and downloading malicious files to solve these security issues themselves.
Analyst note: Victims likely unknowingly expose sensitive information when they download the malware. Lazarus is using stolen information and access to victims' bank information likely to exfiltrate funds to conduct further illicit activities or campaigns, aiding the state’s military and nuclear power.
DEEP AND DARK WEB INTELLIGENCE
Xss user Xaos: Untested threat actor "Xaos" has advertised Remote Desktop Protocol (RDP) access with administrator rights to an unnamed Bahrain construction company on xss. The exposure of RDP access with administrator rights could lead to data theft, system manipulation, and potential for further exploitation.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-26683: Improper authorization in Azure Playwright enables an unauthorized attacker to elevate privileges over a network. The high severity vulnerability has neither been disclosed publicly, nor has been exploited in the wild (EITW). There is currently no patch available; if the flaw is exploited it could compromise web application testing and source code.
Affected products: Affects Azure Playwright.
Tags: DIB, tlp:green