ZeroFox Daily Intelligence Brief - April 21, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - April 21, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Malware Linked to Chinese APT Makes Comeback Targeting Mongolia and Russia
- SuperCard X Targets Android Users with NFC Relay Attacks
- Geopolitical Focus | Global Tensions and Deadly Weather Events
Malware Linked to Chinese APT Makes Comeback Targeting Mongolia and Russia
Source: https://hackread.com/chinese-apt-ironhusky-mysterysnail-rat-russia/
What we know: The MysterySnail RAT malware linked to Chinese-speaking advanced persistent threat (APT) IronHusky has reappeared, targeting Mongolian and Russian government entities.
Context: The recent MysterySnail RAT strain with new iterations is dubbed as MysteryMonoSnail. It functions on a reduced set of commands and uses the WebSocket protocol instead of HTTP. It originates through an infected fake government document.
Analyst note: The seeming reappearance of the malware likely indicates that such threat groups continue being active covertly. Infections are likely to be delivered via phishing and social engineering tactics using fake government documents.
SuperCard X Targets Android Users with NFC Relay Attacks
What we know: New malware-as-a-service platform SuperCard X—linked to Chinese-speaking threat actors—is targeting Android users through NFC relay attacks to steal payment card data, enabling unauthorized contactless transactions at stores and ATMs.
Context: The attack begins with fake messages and calls that trick victims into installing a malicious app. Once installed, the malware captures card data through NFC, allowing attackers to make small, undetectable contactless transactions.
Analyst note: Victims are likely to unknowingly install a malicious app, exposing sensitive information that allows attackers to make withdrawals. By mimicking legitimate NFC transactions, the attack could facilitate large-scale financial theft and fraud.
Geopolitical Focus | Global Tensions and Deadly Weather Events
- ZeroFox’s flash report addresses the UK government’s takeover of British Steel and the wider concerns involving foreign influence over critical industries.
- Ukraine has accused Russia of breaking a surprise Easter truce announced by Russian President Vladimir Putin. U.S President Donald Trump expressed hope that a possible ceasefire this week between the warring parties could lead to more trade with the United States.
- Severe flooding in Oklahoma has killed at least two people, including a child, after their vehicle was stranded in rising waters.
- In Australia, since April 18, at least six people have died and two others went missing after massive waves struck Australia’s east coast.
DEEP AND DARK WEB INTELLIGENCE
BreachForums update: ZeroFox has observed that "Shiny," a close associate of BreachForums, deleted their Telegram account without any prior notification. Meanwhile, untested threat actor "the_end_game" has claimed to have obtained verified intelligence identifying the principal operator behind BreachForums and Shiny Hunters group on Exploit. An X profile named “hasan” has allegedly claimed that BreachForums will be back online in about 10 hours.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-2492: This improper authentication control vulnerability in AiCloud can be triggered by a crafted request, risking unauthorized execution of functions on affected devices. If this vulnerability is not mitigated, threat actors could access sensitive user data and infiltrate other networks causing operational disruption.
Affected products: ASUS router firmware series
Tags: DIB, tlp:green