zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - April 9, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - April 9, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Scammers Pose as Officials of U.S. Attorney’s Office to Defraud Public
  • Kill Security Ransomware Group Claims CrushFTP Flaw Exploit, Future Data Leak
  • China’s Security Services Target Taiwanese and Tibetan Activists, Warn Intelligence Agencies

Scammers Pose as Officials of U.S. Attorney’s Office to Defraud Public

Source: https://www.justice.gov/usao-wdtx/pr/phone-scammers-falsely-claiming-be-us-attorneys-office-0

What we know: Scamsters are impersonating officials from the U.S. Attorney's Office to defraud people of money and credit card credentials, according to the U.S. Attorney’s Office for the Western District of Texas.

Context: During calls, scammers use actual names of officials, provide office addresses, and false badge numbers to request funds or credit card credentials using a false incident. Scammers also spoof their phone numbers to appear as a government agency on caller IDs.

Analyst note: It is very unlikely for officials from the U.S. Attorney’s Office or any other government organization to ask for money transfers, gift card purchase, or credit card credentials over call. The scam is likely to cause financial loss to victims.

Kill Security Ransomware Group Claims CrushFTP Flaw Exploit, Future Data Leak

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/84336

What we know: Kill Security ransomware group has claimed active global exploitation of CVE-2025-31161, an “unauthenticated HTTP(S) port access” vulnerability within CrushFTP servers.

Context: CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. Reportedly, there are 487 unpatched instances located in North America, and 250 located in Europe. Kill Security has said it will directly reach out to affected companies to discuss terms for removal of information related to them.

Analyst note: CrushFTP clients using versions before 10.8.4 and 11.3.1 are likely to be affected by a data breach. There is a roughly even chance that the breached data set contains sensitive files that were shared using CrushFTP servers.

China’s Security Services Target Taiwanese and Tibetan Activists, Warn Intelligence Agencies

Source: https://www.reuters.com/technology/cybersecurity/western-intelligence-agencies-warn-spyware-threat-targeting-taiwan-tibetan-2025-04-08/

What we know: Western intelligence agencies and an advisory signed by several cybersecurity agencies are warning that Chinese security services are using malicious mobile apps to target activists and minority groups in Taiwan and Tibet.

Context: The advisory warns that individuals involved with Taiwanese independence, Tibetan rights, Uyghur Muslims, Hong Kong democracy advocates, and the Falun Gong movement are most at risk amid geopolitical tensions associated with Taiwan and Tibet.

Analyst note: The threat is likely to impact privacy, information, and security of targeted activists and minority groups are at risk—all of which can be weaponized by state-sponsored actors to enable China to exert control and influence over dissenting voices.

DEEP AND DARK WEB INTELLIGENCE

Finnish airport cyberattack: Hacktivist group Dark Storm Team has claimed a distributed denial-of-service (DDoS) attack on the official website of Finnish Oripää Airport http[:]//turunlentokerho[.]fi/. The website is accessible as of writing this. DDoS attacks on airport websites are likely to cause travel disruptions. The pro-Palestine group is likely to continue targeting the West.

VULNERABILITY AND EXPLOIT INTELLIGENCE

Microsoft April 2025 Patch Tuesday: This month’s Patch Tuesday includes security updates addressing 126 vulnerabilities, including one zero-day flaw, CVE-2025-29824, that is currently being actively exploited. Among the fixes, eleven vulnerabilities are classified as "Critical," all of which are remote code execution flaws.

Affected products: The affected products have been listed in this update.

CVE-2024-48887: An unverified password change vulnerability in Fortinet FortiSwitch GUI could enable a remote unauthenticated attacker to change admin passwords via a specially crafted request. By changing admin passwords, threat actors could disable security settings and introduce backdoors into affected devices.

Affected products: The affected products have been listed in this update.

Tags: DIB, tlp:green