zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief – April 5, 2025

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief – April 5, 2025

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the threat landscape, including digital, cyber, and physical threats. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 6:00 AM (EDT) on April 3, 2025; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

Phishing Platform “Lucid” Targets 169 Entities in Global Campaign

What we know:

  • Lucid, a phishing-as-a-service (PhaaS) platform, has been used in attacks across 169 entities and 88 countries.
  • Lucid automates these phishing attacks by deploying customizable phishing websites, primarily through SMS-based lures.
  • By using Apple iMessage and Android’s Rich Communication Services (RCS), the Lucid platform effectively bypasses traditional SMS spam filters.

FTC Sends Warning Letters to EIN Service Providers over Potential Violations of Impersonation Rules

What we know:

  • Federal Trade Commission (FTC) staff have sent letters to website operators offering Employer Identification Number (EIN) filing and delivery services, warning that their practices may violate the FTC Act and the Impersonation Rule.

New Android Malware Crocodilus Targeting Spain and Turkey for Financial Theft

What we know:

  • A novel Android banking malware, Crocodilus, has been discovered targeting users in Spain and Turkey. The malware is designed to steal credentials, including crypto wallet keys, which are used for theft of victims’ assets.

Tags: tlp:green