ZeroFox Daily Intelligence Brief - April 8, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - April 8, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Actor Defaces Everest Ransomware Leak Site
- Ukraine Warns of New Cyber Espionage Method Targeting Government Employees
- New Hacking Assistant Xanthorox AI Emerges
Actor Defaces Everest Ransomware Leak Site
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/84332/
What we know: Everest ransomware group has taken down its leak site after an unknown actor defaced its site with a sarcastic message.
Context: The attacker defaced the leak site with a message saying, “Don't do crime CRIME IS BAD xoxo from Prague." Researchers suspect that a vulnerability in WordPress, which the leak site is based on, was likely exploited in the attack.
Analyst note: ZeroFox has observed that Everest has conducted at least 150 attacks since 2021, primarily targeting the healthcare and government sectors. With the ransomware group’s leak site currently offline, it is likely that their operations will slow down until a new site is established.
Ukraine Warns of New Cyber Espionage Method Targeting Government Employees
Source: https://cert.gov.ua/article/6282946
What we know: Threat actor “UAC-0226” is targeting Ukraine’s government and military employees with phishing emails containing malware designed to take over targeted systems and steal sensitive information like browser history and saved passwords.
Context: The target is urged to run a malicious Excel macros (.xlsm) file contained in the phishing email imitating real Ukrainian government messages. The macros execution leads to malware deployment with two distinct payload types—PowerShell Reverse Shell and GIFTEDCROOK Stealer.
Analyst note: It is likely that the malicious emails come from accounts of trusted sources that have been compromised. A single successful account compromise is likely to give a threat actor access to larger government entities.
New Hacking Assistant Xanthorox AI Emerges
Source: https://hackread.com/xanthorox-ai-dark-web-full-spectrum-hacking-assistant/
What we know: A sophisticated new AI platform, Xanthorox AI, has recently been observed circulating in cybercrime communities and forums and is reportedly modeled on five AI models.
Context: This AI platform reportedly offers a fully custom-built, modular system for code generation, vulnerability exploitation, data analysis, voice and image processing, and more. Unlike previous malicious AI tools, Xanthorox reportedly operates on private servers with proprietary models, enhancing attack precision and scalability.
Analyst note: This advanced AI tool is likely to assist malware creation, vulnerability exploitation, and live voice-based social engineering campaigns. Additionally, attackers with little technical skill could automate complex tasks, making it easier for less experienced threat actors to launch attacks.
DEEP AND DARK WEB INTELLIGENCE
Exploit user 303security: Untested threat actor "303security" is advertising Secure Shell (SSH) access with root rights to an unnamed Taiwanese telecommunications company on Russian language dark web forum Exploit for USD 1,300. There is a roughly even chance of the threat actor’s claims being true. The high level access is likely to enable disruption and manipulation of the telecom company’s operations.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-11859: This is a now-patched dynamic link library (DLL) search order hijacking vulnerability in ESET’s antivirus software that is being exploited by suspected China-backed advanced persistent threat group “ToddyCat”. The group is likely to leverage this bug in attacks targeting government and defense entities to steal data from compromised devices.
Affected products: The list of affected products are listed in this advisory.
Tags: DIB, tlp:green