zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - April 29, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - April 29, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Original BreachForums Domain Releases Update on Forum’s Fate
  • Earth Kurma Observed Targeting Southeast Asian Critical Infrastructure
  • International Operation Dismantles JokerOTP Phishing Tool; Two Arrested

Original BreachForums Domain Releases Update on Forum’s Fate

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/85292

What we know: On April 28, 2025, ZeroFox noticed an update on the original BreachForums domain breachforums[.]st, with an admin message claiming that they had shut down the infrastructure due to the presence of a MyBB zero day exploit.

Context: The admin assured that the domain was not compromised and none of its team members were arrested. Currently, a rewrite of the forum’s backend is allegedly underway. After the domain’s shut down, speculations were rife that it was taken down by law enforcement.

Analyst note: The message on the domain is likely legitimate. Numerous other clone domains of BreachForums are very likely to be scam sites.

Earth Kurma Observed Targeting Southeast Asian Critical Infrastructure

Source: https://thehackernews.com/2025/04/earth-kurma-targets-southeast-asia-with.html

What we know: APT group Earth Kurma has been targeting government and telecom sectors in Southeast Asia with custom malware and rootkits, while exfiltrating data, since June 2024.

Context: The campaign largely targets Philippines, Vietnam, Thailand, and Malaysia and focuses on espionage, credential theft, and maintaining stealthy, persistent access on victim networks.

Analyst note: The group is likely conducting politically motivated espionage operations targeting Southeast Asian critical infrastructure, exfiltrating government data and monitoring telecommunications activity to advance their home country’s geopolitical objectives.

International Operation Dismantles JokerOTP Phishing Tool; Two Arrested

Source: https://hackread.com/jokerotp-dismantled-28000-phishing-attacks-2-arrested/

What we know: An international operation dismantling JokerOTP, a phishing tool used to intercept 2FA codes, resulted in two arrests. The tool enabled cybercriminals to steal over GBP 7.5 million (approx. USD 9 million).

Context: The arrests followed a three-year investigation led by Cleveland Police’s Cyber Crime Unit. JokerOTP was used in over 28,000 attacks across 13 countries, targeting victims via phone scams.

Analyst note: Fraudsters used JokerOTP to impersonate trusted organizations and trick victims into revealing 2FA codes, which gave them access to accounts—likely leading to financial loss, identity theft, and more targeted cyberattacks.

DEEP AND DARK WEB INTELLIGENCE

Cybercriminal Collaboration: Pro-Palestine threat actor “Mr Hamza” has claimed to have formed a tripartite alliance with “Vortex” and “Arab Ghosts Hackers.” The alliance will reportedly lead a major cyber operation targeting U.S entities, like ministries and military sites. These hacktivists could conduct distributed denial-of-service (DDoS) to disrupt websites and operations to call further attention to their cause.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-46661: IPW Systems Metazo versions up to 8.1.3 are vulnerable to unauthenticated remote code execution due to a flaw in smartyValidator[.]php. Users are advised to update to the patched version, if left unpatched, this vulnerability could enable attackers to gain unauthorized control over the server, exfiltrate sensitive data, disrupt services, or use the compromised system as a foothold to launch further attacks within the network.

Affected products: IPW Systems Metazo versions up to 8.1.3

Tags: DIB, tlp:green