zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - April 11, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - April 11, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Russia-Backed Spy Group Snooped on a Western Military Mission in Ukraine
  • Ransomware Attack Hits Sensata, Data Stolen and Operations Disrupted
  • Ongoing Campaign Steals Crypto Funds

Russia-Backed Spy Group Snooped on a Western Military Mission in Ukraine

Source: https://www.bleepingcomputer.com/news/security/russian-hackers-attack-western-military-mission-using-malicious-drive/

What we know: Russia-backed threat actor Shuckworm or Gamaredon was observed spying on a Western military unit stationed in Ukraine using an updated version of its GammaSteel malware.

Context: Shuckworm has been using PowerShell scripts to be more evasive compared to its earlier techniques, and procedures. It continues to use .LNK files in removable drives to spread the malware. The espionage campaign was observed from February 2025 till March 2025.

Analyst note: The info-stealing malware used by Shuckworm likely indicates that it remains committed to cyber espionage operations against Ukraine and allied forces. It is likely to improve its obfuscation tactics to evade detection in future attempts.

Ransomware Attack Hits Sensata, Data Stolen and Operations Disrupted

Source:https://www.theregister.com/2025/04/10/us_sensor_giant_sensata_ransomware/

What we know: U.S. sensor maker Sensata experienced a ransomware attack on April 6, disrupted operations, with the hackers encrypting devices and stealing data.

Context: Sensata provides critical sensing solutions for the automotive, aerospace, and industrial sectors. The attack has temporarily halted functions like shipping, production, and support services. No ransomware group has claimed responsibility for the attack yet.

Analyst note: Operational downtime is likely to delay product deliveries and disrupt supply chains. Stolen data could be used for extortion or to sell on dark web marketplaces—likely exposing customers, partners, or employees to further threats, like extortion and phishing.

Ongoing Campaign Steals Crypto Funds

Source: https://thehackernews.com/2025/04/malicious-npm-package-targets-atomic.html

What we know: A malicious npm package, called “pdf-to-office,” has been targeting Atomic Wallet and Exodus users to hijack specific app files and compromise wallets even when the app is deleted.

Context: In this campaign, threat actors are stealing funds from users’ accounts and maliciously redirecting funds without the victim noticing. Atomic Wallet is a decentralized platform that allows users to store, buy, and manage cryptocurrency.

Analyst note: In addition to redirecting funds as they happen, it is likely that threat actors are establishing long-term persistence by further modifying wallet application files, ensuring continued theft.

DEEP AND DARK WEB INTELLIGENCE

Exploit user reboot.inc: Untested threat actor "reboot[.]inc" has advertised HTML templates service for high-volume phishing emails on predominantly Russian language dark web forum Exploit. These HTML templates could increase the effectiveness and reach of phishing campaigns, potentially leading to credential theft, financial fraud, and malware infections.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-0132: NVIDIA’s patch for this critical container escape flaw was incomplete, leaving systems still vulnerable to attacks. The flaw enables attackers to access the host and run commands as root. Threat actors could gain root access and cause operational disruption by introducing backdoors and conducting distributed denial of service on affected devices.

Affected products: NVIDIA Container Toolkit versions up to and including 1.16.1 and GPU Operator versions up to and including 24.6.1

Tags: DIB, tlp:green