zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief – April 26, 2025

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief – April 26, 2025

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the threat landscape, including digital, cyber, and physical threats. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 6:00 AM (EDT) on April 24, 2025; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

Hotel Staff Tricked by Fake Booking[.]com Emails to Install Malware

What we know:

  • A phishing campaign impersonating Booking[.]com is targeting hotel staff to deploy AsyncRAT, a powerful remote access trojan.
  • Victims are tricked into running malicious code via clipboard injection after interacting with a fake CAPTCHA page. The malware grants attackers remote access to infected systems, including keylogging, data theft, and persistent control.

UK Veteran Retailer M&S Reports Cyber Incident as Customer Complaints Mount

What we know:

  • UK-based retail giant Marks and Spencer (M&S) has informed customers of possible delays with their click and collect orders owing to an unspecified “cyber incident.”

North Korean Hackers Are Using Zoom Remote Control Feature to Steal Crypto

What we know:

  • North Korean hackers are reportedly repurposing Zoom’s remote-control feature and social-engineering tactics to steal cryptocurrency from targets over video calls in an ongoing campaign named “Elusive Comet.”

Tags: tlp:green