ZeroFox Daily Intelligence Brief - April 22, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - April 22, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Increasing Threats from Bullet Proof Hosting Service
- North Korean Hackers are Using Zoom Remote Control Feature to Steal Crypto
- Hotel Staff Tricked by Fake Booking[.]com Emails to Install Malware
Increasing Threats from Bullet Proof Hosting Service
Source: https://thehackernews.com/2025/04/hackers-abuse-russian-bulletproof-host.html
What we know: Researchers have reported a spike in malicious activity—mass scanning, credential brute-forcing, and exploitation—linked to bulletproof hosting provider Proton66 since January 2025.
Context: Proton66 has been used to distribute malicious files, including ransomware. Additionally, phishing and other malware campaigns have been linked to attacks targeting Android and WordPress users in multiple languages.
Analyst note: Successful brute-force and exploit attempts could lead to threat actors gaining unauthorized access and exfiltrating data—later using the stolen information for extortion, espionage, and resale on dark web marketplaces—causing both financial and operational damage.
North Korean Hackers are Using Zoom Remote Control Feature to Steal Crypto
Source: https://www.darkreading.com/remote-workforce/elusive-comet-zoom-victims
What we know: North Korean hackers are reportedly repurposing Zoom’s remote control feature and social engineering tactics to steal cryptocurrency from targets over video calls in an ongoing campaign named “Elusive Comet.”
Context: The hackers pose as Venture Capital (VC) investors luring victims to give them remote control access while sharing screens on a Zoom call. The hackers have built legitimate looking online presence such as Aureon Capital and The OnChain Podcast as part of their deception.
Analyst note: Misuse of legitimate and innocuous tools like Zoom's remote control feature is likely to enable even amateur hackers to succeed in malware installation. Online cryptocurrency forums are likely to be infiltrated by hackers using elaborate online personas to seem more believable.
Hotel Staff Tricked by Fake Booking[.]com Emails to Install Malware
Source: https://hackread.com/booking-com-phishing-scam-fake-captcha-asyncrat/
What we know: A phishing campaign impersonating Booking[.]com is tricking hotel staff into executing a malicious command via a fake CAPTCHA page to deploy AsyncRAT, a powerful remote access trojan.
Context: The attack starts with a seemingly legitimate Booking[.]com email, urging managers to click a link that leads to AsyncRAT deployment, compromising hotel systems. This method bypasses email filters and relies on user interaction to trigger the malware.
Analyst note: The phishing campaign uses social engineering to deploy AsyncRAT, enabling keylogging, remote access, data theft, and persistent control. Victims are likely to face system compromise, data breaches, financial losses, and further malware installation.
DEEP AND DARK WEB INTELLIGENCE
New BreachForums domain: ZeroFox has identified a new BreachForums domain, breached[.]fi, which closely resembles the original user interface. Threat actor “Anastasia” claims that the infrastructure is new and that no unknown vulnerabilities exist from previous versions. The alleged new and improved platform could enable threat actors to operate with greater ease, attracting existing and new criminals.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2019-0708: North Korean advanced persistent threat (APT) group Kimsuky is running a new malicious campaign exploiting a now-patched vulnerability affecting Microsoft Remote Desktop Services. The exploit enables remote code execution giving hackers access to data and elevated user rights. The state-sponsored hackers are likely using the vulnerability to steal sensitive information, carry out financial theft, and/or maintain persistent access to systems.
Affected products: The affected products are listed in this advisory.
Tags: DIB, tlp:green