ZeroFox Daily Intelligence Brief - April 4, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - April 4, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Brief Report- Remote IT Workers Fraud: Threats and Prevention
- USA and Allies Warn of “Fast Flux” Technique Being a National Security Threat
- Tax-Themed Phishing Campaign Targets U.S. Organizations
ZeroFox Intelligence Brief Report- Remote IT Workers Fraud: Threats and Prevention
Source: https://www.zerofox.com/advisories/31926/
What we know: Remote IT worker fraud, including deepfake-enhanced deception, is an emerging threat, with nation-state actors leveraging synthetic identities to infiltrate organizations. Traditional hiring practices are likely to be insufficient to detect synthetic applicants.
Context: Fraudulent applicants are using AI-generated profiles and deepfake technology to bypass identity checks and gain access to sensitive systems and data, which has become a notable national security concern.
Analyst note: Organizations are advised to strengthen their hiring protocols with multi-layered identity verification, live video interviews with real-time prompts, and behavioral screening. To mitigate these risks, organizations could adopt a layered strategy post-hire that includes continuous monitoring, insider threat detection, and continuous employee training on emerging fraud tactics to ensure long-term security.
USA and Allies Warn of “Fast Flux” Technique Being a National Security Threat
What we know: Four countries including the United States have warned organizations, cybersecurity companies, and internet service providers (ISPs), of the “fast flux” technique used by malicious actors to evade detection, calling it a national security threat.
Context: Fast flux obfuscates server location by rapidly changing Domain Name System (DNS) records. This technique has been used in Hive and Nefilim ransomware attacks. Fast flux variants are also used for legitimate purposes such as in content delivery networks.
Analyst note: Fast Flux is likely to be used by nation-state threat actors for espionage purposes among other cybercriminals. Municipal organizations are more likely to be targeted by fast flux due to a lack of robust cybersecurity infrastructure. Additionally, organizations are likely to face challenges in differentiating between legitimate fast flux users and cybercriminals.
Tax-Themed Phishing Campaign Targets U.S. Organizations
Source: https://thehackernews.com/2025/04/microsoft-warns-of-tax-themed-email.html
What we know: An ongoing campaign linked to Storm-0249 has been targeting U.S. organizations with multiple tax-themed phishing campaigns to steal credentials and deploy malware.
Context: The campaign takes advantage of the approaching tax filing deadline and phishes tax filers by creating a sense of urgency by impersonating trusted services and entities.
Analyst note: Threat actors are likely using stolen credentials to access financial platforms and corporate systems for malicious activities, like business email compromise, unauthorized wire transfers, identity theft, and credit card abuse. Threat groups like Storm-0249 function as initial access brokers, monetizing compromised systems by selling access to ransomware operators and other cybercriminals.
DEEP AND DARK WEB INTELLIGENCE
Exploit user BenjaminFranklin: Untested threat actor "BenjaminFranklin" has advertised an auction for VPN access with domain administrator rights to an unnamed freight and logistics services company based in Lebanon on Exploit. Threat actors buying the VPN access could use it to compromise sensitive company data, disrupt operations, and conduct more targeted attacks.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-22457: A China-backed threat actor, “UNC5221,” has been reportedly exploiting this remote code execution (RCE) flaw since mid-March, deploying variants of the Spawn software, along with two new malware strains.
Affected products: The list of affected products is available in this advisory.
CVE-2025-30065: This RCE vulnerability in Apache Parquet enables attackers to exploit unsafe deserialization in malicious Parquet files to take control of target systems. Threat actors exploiting it are likely to execute arbitrary code, exfiltrate or manipulate data, deploy ransomware, and disrupt services.
Affected products: Apache Parquet Java versions 0 through 1.15.0
Tags: DIB, tlp:green