zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - April 24, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - April 24, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • U.S. Online Marketplace Operator Charged with Trafficking Synthetic Opioids
  • Russian Threat Actors Target Ukraine-Linked Political and Human Rights Organizations
  • NSA Publishes Recommendations for Smart Controller Security Controls

U.S. Online Marketplace Operator Charged with Trafficking Synthetic Opioids

Source: https://www.justice.gov/opa/pr/us-online-marketplace-operator-charged-trafficking-deadly-synthetic-opioids-stronger

What we know: Authorities have seized and shut down ecommerce firm eWorldTrade’ website, which allegedly facilitated the drug trade. EWorldTrade allegedly conspired to distribute synthetic opioids, like isotonitazene and carfentanyl for unlawful import.

Context: EWorldTrade is a global business-to-business marketplace that connects international buyers and suppliers.

Analyst note: Threat actors are likely to exploit ecommerce marketplaces that lack strict advertisement and sale regulations for illicit activities, such as the sale of illegal substances and counterfeit goods. This recent law enforcement action could lead to stricter oversight and increased monitoring of similar online platforms.

Russian Threat Actors Target Ukraine-Linked Political and Human Rights Organizations

Source: https://thehackernews.com/2025/04/russian-hackers-exploit-microsoft-oauth.html

What we know: Russia-linked threat actors have been found misusing the legitimate OAuth 2.0 authentication to steal account credentials to a collection of productivity apps popularly used in organizations associated with Ukraine and human rights.

Context: The threat actors are impersonating European officials to invite targets to join an event centred around Ukraine. Targets are tricked into providing authorization codes in the pretext of scheduling video conferences and dubious verification protocols.

Analyst note: Organizations and individuals engaged in political discourse surrounding the Ukraine-Russia war, especially in Europe, are likely to be targets of Russia-backed social engineering attacks aimed at conducting disinformation campaigns using stolen accounts.

NSA Publishes Recommendations for Smart Controller Security Controls

Source: https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4163002/nsa-publishes-recommendations-for-smart-controller-security-controls-and-techni/

What we know: The National Security Agency (NSA) has published a report that aims to strengthen the security of smart controllers in National Security Systems, amid rising threats from operational and internet technology convergence and cyber threat entities.

Context: The findings of the analysis aims to identify inadequately addressed security controls and outline future requirements that fill these gaps.

Analyst note: Adversaries are likely to target operational and internet-facing devices, like smart controllers and intelligent embedded devices, due to their usage in critical infrastructure. Inadequate security measures could expose sensitive information and control systems, threatening national security and causing financial harm.

DEEP AND DARK WEB INTELLIGENCE

Xss user Machine1337: Untested threat actor "Machine1337" advertised a breached data set of Indian payments platform Razorpay on xss, which allegedly includes transaction records with destination address and delivery time. There is a roughly even chance of the data being used in phishing and social engineering attacks to carry out financial theft.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-27495: This vulnerability in Siemens TeleControl Server Basic system enables SQL injection leading to remote code execution to enable network access permissions and denial-of-service conditions. There is a roughly even chance of this vulnerability being used by politically-motivated threat actors to target critical infrastructure of perceived adversarial nations.

Affected products: TeleControl Server Basic versions prior to V3.1.2.2

Tags: DIB, tlp:green