ZeroFox Daily Intelligence Brief - April 28, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - April 28, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ToyMaker Powers Double Extortion Attacks with LAGTOY Malware
- Phishing Attack Targets WooCommerce Sites with Fake Security Patch
- Geopolitical Focus | Iran Port Blast, Vancouver Festival Tragedy, and More
ToyMaker Powers Double Extortion Attacks with LAGTOY Malware
Source: https://thehackernews.com/2025/04/toymaker-uses-lagtoy-to-sell-access-to.html
What we know: Initial access broker ToyMaker has been reportedly compromising systems using custom malware called LAGTOY (aka HOLERUN) and selling network access to ransomware groups, like CACTUS, for double extortion attacks.
Context: LAGTOY has been linked to threat group UNC961 (aka Gold Melody/Prophet Spider) and exploits known internet-facing vulnerabilities. The malware is deployed soon after reconnaissance and credential theft.
Analyst note: ToyMaker enables ransomware groups to rapidly gain access to vulnerable networks, facilitating the deployment of destructive attacks. Victims are likely to face operational disruption, financial loss, and potential data theft.
Phishing Attack Targets WooCommerce Sites with Fake Security Patch
What we know: An ongoing phishing campaign is tricking WooCommerce users into installing a fake patch that plants hidden admin accounts, web shells, and backdoors on their sites.
Context: WooCommerce is a popular open-source plugin for WordPress that lets users create and manage online stores.
Analyst note: Installing the fake patch gives attackers complete administrative access to the victims’ sites, likely enabling customer data exfiltration, online stores hijacking, malware planting, and business operations disruption.
Geopolitical Focus | Iran Port Blast, Vancouver Festival Tragedy, and More
- Amid a third round of nuclear talks between Iran and the United States, a massive blast was reported at Iran’s Bandar Abbas port city on April 26, 2025, killing at least four people and injuring over 500 others. Meanwhile, unverified social media sources reported a fire near Tehran’s southern bus terminal on the midnight of April 28, 2025.
- A 30-year-old man has been held for ploughing his car into a crowd during a street festival in Vancouver on April 26, 2025, which has killed at least 11 people.
- Indian American diaspora held a silent vigil at Washington, D.C. over the Kashmir terror attack. Meanwhile, cross border gunfire has continued between Indian and Pakistani forces at LoC in Kashmir as tensions soar.
- U.S. President Donald Trump questioned Russian President Vladimir Putin’s commitment to peace after meeting Ukrainian counterpart Volodymyr Zelenskyy. On the other hand, North Korea admitted to sending troops to fight the Russian war in Ukraine.
- China has claimed sovereignty over a tiny reef called Sandy Cay in the South China Sea in an escalation of dispute with the Philippines.
DEEP AND DARK WEB INTELLIGENCE
Ukraine’s electronic payments disrupted: Electronic payment systems in post offices, restaurants, and the metro system in Ukraine were reportedly temporarily disrupted. There has been no immediate indication that the disruptions were caused by any hostile actions. These disruptions could hinder daily transactions, impact businesses, and disrupt public services.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-31324: This is a missing authentication and authorization vulnerability in SAP NetWeaker Visual Composer’s development server part that is used to design business tools without writing code. The bug likely results in full system takeover as it lacks checks to verify if a user has the required permissions.
Affected products: VCFRAMEWORK 7.50
Tags: DIB, tlp:green