ZeroFox Daily Intelligence Brief - April 18, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - April 18, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - Dark Web Discussion Centers on BreachForums Outage
- ClickFix Remains Popular Among Nation-State Threat Actors in Malware Campaigns
- ResolverRAT Malware Used in Healthcare Phishing Campaigns
ZeroFox Intelligence Flash Report - Dark Web Discussion Centers on BreachForums Outage
Source: https://www.zerofox.com/advisories/32363/
What we know: ZeroFox has observed several discussions circulating among threat actors about BreachForums’ outage, including claims of the forum being “taken over” and hacktivists claiming responsibility for the disruption.
Context: Moderator “Tanaka” claimed a new BreachForums domain would be launched soon, along with similar speculation among threat actors. However, ZeroFox have found no evidence confirming these claims or connecting them to the forum’s outage.
Analyst note: BreachForums' downtime could set off a rise in fraudulent activity on the dark web, with opportunistic threat actors trying to take advantage of the confusion to lure former users into impersonated BreachForums domains to scam them.
ClickFix Remains Popular Among Nation-State Threat Actors in Malware Campaigns
Source: https://thehackernews.com/2025/04/state-sponsored-hackers-weaponize.html
What we know: Nation-state threat actors from Russia, Iran, and North Korea are increasingly using ClickFix social engineering tactics to deploy malware against targets.
Context: Threat actors initiate contact via fake personas or fake security update emails to lure the target into running a malicious code through tactics, such as completing a CAPTCHA verification.
Analyst note: More nation-state threat actors are likely to leverage the ClickFix tactic with rising geopolitical tensions. Individuals working in government, defense industrial complex, and think tanks are likely to be targeted by such campaigns for espionage purposes.
ResolverRAT Malware Used in Healthcare Phishing Campaigns
Source: https://www.hipaajournal.com/healthcare-orgs-targeted-resolverrat-malware/
What we know: Healthcare and pharmaceutical companies are being targeted with the ResolverRAT malware strain delivered through phishing emails disguised as urgent legal notices.
Context: ResolverRAT is a remote access trojan that runs in memory to avoid detection and is delivered through phishing emails using a trusted file. It obfuscates its activity by using Dynamic-Link Library side-loading, random communication times, and blends in with normal traffic.
Analyst note: ResolverRAT’s stealthy nature likely enables attackers to evade detection, leading to long-term access to sensitive patient and research data—compromising privacy, and exposing organizations to further cyberattacks.
DEEP AND DARK WEB INTELLIGENCE
Exploit user BR12345: On April 17, 2025, untested threat actor "BR12345" advertised an auction for Remote Desktop (RDWeb) access bundle to 57 unnamed companies worldwide on Exploit. There is a roughly even chance of the access being effective. If legitimate, the access is likely to enable threat actors to gain unauthorized access to the compromised company’s systems based on the level of user rights.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-32433: This vulnerability in the Erlang/OTP Secure Shell (SSH) implementation is likely to enable malicious actors to execute arbitrary code on affected systems without the need to log in. Systems in telecommunications, industrial control systems and others relying on SSH servers built on Erlang/OTP SSH are likely to be exposed. If an SSH daemon with root privileges is compromised, it will likely lead to complete system compromise.
Affected products: Unpatched versions of Erlang/OTP including OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20
Tags: DIB, tlp:green