ZeroFox Daily Intelligence Brief - May 1, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - May 1, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report: Australian Elections
- ZeroFox Intelligence Flash Report: Marks & Spencer Cyber Incident
- FBI Releases Advisory on 42,000 Phishing Domains Linked to LabHost PhaaS Platform
ZeroFox Intelligence Flash Report: Australian Elections
Source: https://www.zerofox.com/advisories/32687/
What we know: ZeroFox has analyzed the threat landscape of the upcoming Australian general elections, scheduled for May 3, 2025. The biggest election cyber risks likely come from financially motivated deep and dark web (DDW) actors selling compromised voter credentials and online election infrastructure.
Context: On March 28, 2025, Australian Prime Minister Anthony Albanese of the Labor Party called general elections. Labor holds 77 of 151 House seats, with 19 held by cross-benchers. Albanese is seeking re-election, facing main opposition from Coalition leader Peter Dutton.
Analyst note: The Australian election faces risks from foreign interference, compromised login credentials for key election portals, and more. The leaked data identified by ZeroFox poses a significant threat to the affected entities, as malicious actors could use it for credential stuffing attacks, account takeovers, social engineering schemes, and targeted phishing or spamming campaigns.
ZeroFox Intelligence Flash Report: Marks & Spencer Cyber Incident
Source: https://www.zerofox.com/advisories/32697/
What we know: The Marks and Spencer (M&S) cyber incident highlights the growing cybersecurity risks faced by the United Kingdom (UK) retail sector, which has immediate impact on reputation and customer trust.
Context: On April 22, 2025, UK’s M&S publicly confirmed a cyber incident, but did not reveal any details. M&S shares dropped an approximate 5 percent after the announcement as customer complaints grew.
Analyst note: Characteristics observed in this incident indicate a likely ransomware attack on M&S, with reports suspecting the Scattered Spider group. As retailers expand their digital operations, they will likely become appealing to threat actors seeking similar benefits, leading to disruptions.
FBI Releases Advisory on 42,000 Phishing Domains Linked to LabHost PhaaS Platform
Source: https://www.ic3.gov/CSA/2025/250429.pdf
What we know: The Federal Bureau of Investigation (FBI) has released an advisory to disseminate 42,000 phishing domains linked to the LabHost phishing-as-a-service (PhaaS) platform between November 2021 and April 2024.
Context: Before the platform was shut down by law enforcement in April 2024, LabHost was a major PhaaS provider, offering a range of illicit services for approximately 10,000 users. It allowed cybercriminals to impersonate over 200 organizations, including banks and government bodies, to steal personal and banking information from victims worldwide.
Analyst note: The FBI encourages recipients of this document to report information concerning suspicious or criminal activity to their local FBI field office. Meanwhile, the FBI San Francisco Field Office has stressed the importance of strong collaboration and timely reporting to protect U.S. networks from evolving ransomware threats.
DEEP AND DARK WEB INTELLIGENCE
RansomHub affiliates’ whereabouts: The ransomware-as-a-service (RaaS) group Qilin’s recent activity and disclosures on its leak site suggest that cybercriminals affiliated with RansomHub have likely migrated to the Russian-speaking collective (Qilin) after RansomHub’s infrastructure went down sometime around April 1, 2025. RansomHub’s affiliates are likely to bring the strategies of their group’s administrators to other RaaS groups like Qilin.
DATA BREACHES
- British supermarket chain Co-op shut down certain sections of its IT systems after detecting an attempted breach of its network, leading to disruptions in back-office operations and call center services.
- Ascension is informing its patients that their personal and medical information was compromised in a data breach that occurred in December 2024.
- Commvault (provider of data protection solutions) has reported that although a nation-state threat actor breached its Azure environment, no customer backup data was accessed during the incident.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-30390: Microsoft revealed it has mitigated an improper authorization vulnerability in Azure; such vulnerabilities can allow an authorized attacker to elevate privileges over a network. This requires no customer action to resolve.
Affected products: Azure Machine Learning
Tags: DIB, tlp:green