ZeroFox Daily Intelligence Brief - April 25, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - April 25, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- North America Disproportionately Targeted in Ransomware Attacks in Q1 2025
- ZeroFox Observes New BreachForums Developments
- Geopolitical Focus | Global Tensions Rise amid Attacks and Retaliations
North America Disproportionately Targeted in Ransomware Attacks in Q1 2025
Source: https://www.zerofox.com/advisories/32542/
What we know: Zerofox observed at least 1,961 ransomware and digital extortion (R&DE) incidents in the first quarter of 2025, with North America-based entities being the most targeted.
Context: The incidents observed are higher in total than those recorded in any previous three-month period. The manufacturing industry continues being the most targeted by R&DE attacks. Cl0p, RansomHub, Akira, Lynx, and Qilin were the most active ransomware groups.
Analyst note: The disproportionate targeting of North America likely stems from geopolitical motivations, low risk of extradition from countries like Russia, and the accessibility of assets through widespread adoption of technology. Countermeasures in North America and Europe almost certainly indicate the serious impact of ransomware threats.
ZeroFox Observes New BreachForums Developments
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/85134
What we know: A message on the breached[.]fi website, the supposed new Breach Forums domain, reportedly states that the FBI has seized the older BreachForums domain, BreachForums[.]st, and that members “IntelBroker” and “Shiny” have been arrested.
Context: According to reports, a threat actor claims to have breached breachfed[.]fi, a domain linked to the now defunct breachforums[.]st. ZeroFox has observed that Anastasia was the self-proclaimed admin of breachfed[.]fi.
Analyst note: It is likely that information obtained through IntelBroker and Shiny’s arrests could provide law enforcement with information to track down other members of the criminal network. Other forum members are likely to halt activities to avoid further investigations.
Geopolitical Focus | Global Tensions Rise amid Attacks and Retaliations
- President Donald Trump has condemned a Russian airstrike that killed 12 people in Kyiv. Taking to social media, Trump urged President Vladimir Putin to "STOP." Ukrainian President Volodymyr Zelenskiy has confirmed that the Russian missile that struck a residential building in Kyiv was supplied by North Korea.
- Firing was reported from Pakistani posts along the Line of Control (LoC), a military control line running through Kashmir, India. Overnight, the homes of two Lashkar terrorists involved in the attack were destroyed.
- An Israeli airstrike on a police station in Jabalia, northern Gaza, reportedly killed at least 10 people. Israel's military stated it targeted a Hamas and Islamic Jihad command center. Additional airstrikes across Gaza killed 34 more, raising the death toll to 44.
DEEP AND DARK WEB INTELLIGENCE
Lazarus targets six companies: North Korean threat group “Lazarus” has targeted South Korean organizations in sectors like finance and IT, using watering hole attacks. This campaign has likely enabled Lazarus to gather intelligence from high-value targets, aiding North Korea's geopolitical and military interests.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-34028: The vulnerability in Commvault Command Center enables arbitrary code execution on affected systems, leading to complete compromise of the Command Center environment. The bug has been patched in versions 11.38.20 and 11.38.25. It is likely to be exploited in attacks against the Information Technology (IT) industry and IT departments within other organizations as the vulnerable systems are mostly used for data protection and backups.
Affected products: Innovation Release versions from 11.38.0 through 11.38.19
Tags: DIB, tlp:green