zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - April 21, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - April 21, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Malware Linked to Chinese APT Makes Comeback Targeting Mongolia and Russia
  • SuperCard X Targets Android Users with NFC Relay Attacks
  • Geopolitical Focus | Global Tensions and Deadly Weather Events

Malware Linked to Chinese APT Makes Comeback Targeting Mongolia and Russia

Source: https://hackread.com/chinese-apt-ironhusky-mysterysnail-rat-russia/

What we know: The MysterySnail RAT malware linked to Chinese-speaking advanced persistent threat (APT) IronHusky has reappeared, targeting Mongolian and Russian government entities.

Context: The recent MysterySnail RAT strain with new iterations is dubbed as MysteryMonoSnail. It functions on a reduced set of commands and uses the WebSocket protocol instead of HTTP. It originates through an infected fake government document.

Analyst note: The seeming reappearance of the malware likely indicates that such threat groups continue being active covertly. Infections are likely to be delivered via phishing and social engineering tactics using fake government documents.

SuperCard X Targets Android Users with NFC Relay Attacks

Source: https://www.bleepingcomputer.com/news/security/supercard-x-android-malware-use-stolen-cards-in-nfc-relay-attacks/

What we know: New malware-as-a-service platform SuperCard X—linked to Chinese-speaking threat actors—is targeting Android users through NFC relay attacks to steal payment card data, enabling unauthorized contactless transactions at stores and ATMs.

Context: The attack begins with fake messages and calls that trick victims into installing a malicious app. Once installed, the malware captures card data through NFC, allowing attackers to make small, undetectable contactless transactions.

Analyst note: Victims are likely to unknowingly install a malicious app, exposing sensitive information that allows attackers to make withdrawals. By mimicking legitimate NFC transactions, the attack could facilitate large-scale financial theft and fraud.

Geopolitical Focus | Global Tensions and Deadly Weather Events

DEEP AND DARK WEB INTELLIGENCE

BreachForums update: ZeroFox has observed that "Shiny," a close associate of BreachForums, deleted their Telegram account without any prior notification. Meanwhile, untested threat actor "the_end_game" has claimed to have obtained verified intelligence identifying the principal operator behind BreachForums and Shiny Hunters group on Exploit. An X profile named “hasan” has allegedly claimed that BreachForums will be back online in about 10 hours.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-2492: This improper authentication control vulnerability in AiCloud can be triggered by a crafted request, risking unauthorized execution of functions on affected devices. If this vulnerability is not mitigated, threat actors could access sensitive user data and infiltrate other networks causing operational disruption.

Affected products: ASUS router firmware series

Tags: DIB, tlp:green