ZeroFox Daily Intelligence Brief - April 2, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - April 2, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Ongoing Cyber Espionage Campaign Targets Key APAC and LATAM Sectors
- North Korean IT Workers Target Europe to Secure Remote Jobs
- FTC Sends Warning Letters to EIN Service Providers over Potential Violations of Impersonation Rules
Ongoing Cyber Espionage Campaign Targets Key APAC and LATAM Sectors
Source: https://thehackernews.com/2025/04/china-linked-earth-alux-uses-vargeit.html
What we know: China-linked “Earth Alux” is targeting government, manufacturing, and telecommunication entities in the Asia-Pacific and Latin American (LATAM) regions. The campaign involves exploiting vulnerable internet-connected applications to deploy backdoors called VARGEIT and COBEACON.
Context: In Earth Alux’s campaign, VARGEIT involves establishing persistence while evading detection, data exfiltration, and lateral movement, while COBEACON establishes initial access for further exploitation.
Analyst note: By infiltrating key industries, the group could exfiltrate sensitive data, disrupt operations, and monitor communications for future attacks. This cyberespionage campaign likely supports China’s state-sponsored goals for economic and geopolitical advantage.
North Korean IT Workers Target Europe to Secure Remote Jobs
What we know: North Korea’s IT workers are increasingly targeting remote work opportunities in Europe following scrutiny in the United States, by falsifying their nationality.
Context: The North Korean “IT warriors” have targeted work opportunities in Germany, Portugal, and the United Kingdom, with DPRK-linked user accounts found on European job websites.
Analyst note: Organizations hiring for fully remote positions—especially with a bring your own device (BYOD) policy—are likely to be targeted by DPRK workers. Job adverts on Upwork, Freelancer, and Telegram are also likely to be DPRK targets. Successful infiltration is very likely to put an organization’s computer systems at risk of compromise, data theft, and other malicious activity.
FTC Sends Warning Letters to EIN Service Providers over Potential Violations of Impersonation Rules
What we know: FTC staff has sent letters to website operators offering Employer Identification Number (EIN) filing and delivery services, warning that their practices may violate the FTC Act and Impersonation Rule.
Context: Violations of the FTC Act and the Impersonation Rule are likely to lead to legal action, civil penalties of up to USD 53,088 per violation, and mandatory consumer refunds. Website operators are also advised to review their marketing practices, including online ads and promotions, to ensure compliance with the law.
Analyst note: The letters note that some services charge consumers up to USD 300 per EIN, even though EINs can be obtained for free directly from the IRS website. Consumers are advised to be cautious of scammers impersonating legitimate websites and fraudulent online ads.
DEEP AND DARK WEB INTELLIGENCE
BreachForums user GHNA: Untested threat actor "GHNA" has claimed to have leaked a database associated with Royal Mail, a UK-based postal service and courier company, on BreachForums. Allegedly, the dataset comprises 293 folders and 16,549 files, amounting to 144 GB, containing information such as names, addresses, postal codes, and more. If this claim is true, threat actors could use this leaked data to conduct financial fraud, identity theft, extortion, blackmail, deepfakes, and more.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-31579: Improper Neutralization of Special Elements used in an SQL Command (“SQL Injection”) vulnerability in EXEIdeas International WordPress (WP) AutoKeyword plugin allows SQL Injection. This flaw is likely to enable a malicious actor to directly access a website’s database, facilitating data theft.
Affected products: WordPress WP AutoKeyword Plugin versions 1.0 and before
Tags: DIB, tlp:green