zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - April 10, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - April 10, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - Speculation Unfolds Surrounding RansomHub Cessation
  • Five Cyber Criminals Detained in Follow-Up to 2024 Botnet Bust
  • AkiraBot AI Spam Campaign Targets 400,000 Websites

ZeroFox Intelligence Flash Report - Speculation Unfolds Surrounding RansomHub Cessation

Source: https://www.zerofox.com/advisories/32112/

What we know: RansomHub’s dark web victim leak site has been offline since April 1, 2025, and no new victims have been observed. Around April 4, a DragonForce account claimed that RansomHub “will be up soon” and that the collective had decided to move to DragonForce’s infrastructure.

Context: RansomHub had been conducting an average of approximately 20 attacks per week throughout Q1 2025, with February 2025 seeing more incidents than any other month. ZeroFox has observed DragonForce conducting an average of nine attacks per month since 2023.

Analyst note: It is yet unclear if the two collectives are collaborating and whether they plan on sharing resources to resume their criminal activities. DragonForce will likely leverage RansomHub’s resources and use their infrastructure, databases, and tools in future attacks. Entities that have been compromised earlier by either collectives are likely to face greater threats in terms of extortion from this potential collaboration.

Five Cyber Criminals Detained in Follow-Up to 2024 Botnet Bust

What we know: North American and European law enforcement agencies detained five cybercriminals who purchased the Smokeloader botnet in a follow up to May 2024 massive botnet takedown codenamed Operation Endgame.

Context: Europol’s press release stated that the law enforcement’s focus since May 2024, moved to focus on the demand side of the cybercrime ecosystem. The online personas and usernames of customers of crime-as-a-service were tracked to real-life individuals using a database found in Operation Endgame.

Analyst note: The successful cyber crime network bust likely indicates that the ecosystem is not as anonymous as the cybercriminals would like to be. Consistent government scrutiny is very likely to impact the modus operandi of such networks, as was seen in the case of the Hunters International ransomware group.

AkiraBot AI Spam Campaign Targets 400,000 Websites

Source: https://hackread.com/akirabot-abuses-openai-api-spam-website-contact-forms/

What we know: AkiraBot, a new AI-driven spamming bot, has targeted over 400,000 websites since September 2024, while spamming contact forms and chat widgets with personalized fraudulent SEO messages on at least 80,000 sites.

Context: AkiraBot uses AI models like GPT-4o-mini to craft personalized spam messages that bypass CAPTCHAs and evade detection. It targets small and medium-sized businesses (SMBs) on popular website builders like Shopify, Wix, GoDaddy, and Squarespace due to their widespread use and accessibility.

Analyst note: Standard spam filters are less likely to detect and block AkiraBot’s personalized spam messages, enabling it to create convincing messages that could threaten SMBs with fraud and disruption. Threat actors are likely to use AkiraBot in phishing, credential stuffing, and social engineering attacks.

DEEP AND DARK WEB INTELLIGENCE

Exploit user ProfessorKliq: Well-regarded threat actor "ProfessorKliq" has advertised an auction for RDWeb access bundle to four unnamed distinct U.S.-based, Canadian, and Australian companies on Exploit. Gaining RDWeb access to affected devices is likely to give interested threat actors remote and unauthorized access to these companies’ resources. They could exfiltrate this sensitive information to conduct further attacks or sell it for greater financial returns.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-29824: This now-patched vulnerability in Windows Common Log File System (CLFS) was exploited by a threat actor named “Storm-2460” to deliver a ransomware strain called PipeMagic, targeting entities in the United States, Venezuela, Spain, and Saudi Arabia. The exploitation of the CLFS bug could give malicious actors SYSTEM privileges. The flaw is likely to result in takeover of unpatched systems.

Affected products: Affects Windows Server up to 2025, Windows 10 and Windows 11. Windows 10 remains unpatched.

Tags: DIB, tlp:green