ZeroFox Daily Intelligence Brief - April 30, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - April 30, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report: India-Pakistan Tensions Likely to Escalate
- France Accuses Russian Military Hacking Group of Espionage
- Cybersecurity Giant Uncovers Cyber Campaign
ZeroFox Intelligence Flash Report: India-Pakistan Tensions Likely to Escalate
Source: https://www.zerofox.com/advisories/32653/
What we know: A military escalation between India and Pakistan is likely after a terror attack in Kashmir (India). Hacktivist groups on both sides are targeting public and private entities.
Context: On April 22, 2025, gunmen killed at least 26 civilians and injured 17 near Pahalgam in Kashmir. The Resistance Front, an offshoot of Pakistan-based terror group Lashkar-e-Taiba, initially claimed responsibility for the attack but later retracted its claim.
Analyst note: ZeroFox has observed incendiary posts, AI-generated content, fake victim stories, and mis/disinformation being widely circulated on social media that could likely lead to public outrage, retaliatory violence, and communal unrest. Cyberattacks by hacktivists could disrupt critical infrastructure.
France Accuses Russian Military Hacking Group of Espionage
What we know: France has accused Russia’s advanced persistent threat, APT28 (also known as Strontium and Fancy Bear), of targeting and compromising several French entities for “strategic intelligence” gathering since 2021.
Context: The French report states that the infection chain begins with phishing campaigns, exploiting bugs, and brute-force attacks against webmail. The report singled out the zero-day vulnerability CVE-2023-23397 as among the bugs exploited and warned of poorly-supervised edge devices being targeted.
Analyst note: Russian APTs are likely to continue targeted attacks against NATO, North American, and European entities with the aim of maintaining persistent access and stealing login credentials for espionage. Western sanctions are unlikely to disrupt Russia’s hybrid warfare.
Threat Actors Look for Exposed Git Tokens
What we know: Threat actors have been scanning for exposed Git configuration files, aiming to steal credentials and tokens that can be used to breach cloud services and code repositories.
Context: Git is a tool developers use to manage code changes, especially in collaborative projects. Its configuration files store key project details like branches, repository locations, login credentials, and more.
Analyst note: Protecting Git files is important because they can contain sensitive information like passwords and access keys that threat actors could use to breach companies that rely on those repositories for software, infrastructure, or other services.
DEEP AND DARK WEB INTELLIGENCE
BreachForums new domain: On April 29, 2025, ZeroFox observed a new BreachForums domain, "breachforums[.]sx," with a message by “Momondo” claiming to have departed from the team behind the original BreachForums domain due to differences. Momondo is claiming to reinstate BreachForums independently under new management. It is very likely that this new domain is a scam site intending on financial exploitation.
VULNERABILITY AND EXPLOIT INTELLIGENCE
Apple Vulnerabilities: Researchers have disclosed 23 vulnerabilities in Apple’s AirPlay protocol and SDKs, enabling zero-click and wormable remote code execution, affecting both Apple and third-party devices. Apple patched the flaws in March 2025, but unpatched systems remain at risk of device takeover and lateral attacks across local networks. It is likely that these unpatched devices will enable threat actors to chain these vulnerabilities to infiltrate supply chains, takeover accounts, infiltrate networks, and establish persistence for cyber espionage.
Affected Products: Apple devices with AirPlay Protocol and AirPlay Software Development Kit (SDK)
Tags: DIB, tlp:green