zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - May 1, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - May 1, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report: Australian Elections
  • ZeroFox Intelligence Flash Report: Marks & Spencer Cyber Incident
  • FBI Releases Advisory on 42,000 Phishing Domains Linked to LabHost PhaaS Platform

ZeroFox Intelligence Flash Report: Australian Elections

Source: https://www.zerofox.com/advisories/32687/

What we know: ZeroFox has analyzed the threat landscape of the upcoming Australian general elections, scheduled for May 3, 2025. The biggest election cyber risks likely come from financially motivated deep and dark web (DDW) actors selling compromised voter credentials and online election infrastructure.

Context: On March 28, 2025, Australian Prime Minister Anthony Albanese of the Labor Party called general elections. Labor holds 77 of 151 House seats, with 19 held by cross-benchers. Albanese is seeking re-election, facing main opposition from Coalition leader Peter Dutton.

Analyst note: The Australian election faces risks from foreign interference, compromised login credentials for key election portals, and more. The leaked data identified by ZeroFox poses a significant threat to the affected entities, as malicious actors could use it for credential stuffing attacks, account takeovers, social engineering schemes, and targeted phishing or spamming campaigns.

ZeroFox Intelligence Flash Report: Marks & Spencer Cyber Incident

Source: https://www.zerofox.com/advisories/32697/

What we know: The Marks and Spencer (M&S) cyber incident highlights the growing cybersecurity risks faced by the United Kingdom (UK) retail sector, which has immediate impact on reputation and customer trust.

Context: On April 22, 2025, UK’s M&S publicly confirmed a cyber incident, but did not reveal any details. M&S shares dropped an approximate 5 percent after the announcement as customer complaints grew.

Analyst note: Characteristics observed in this incident indicate a likely ransomware attack on M&S, with reports suspecting the Scattered Spider group. As retailers expand their digital operations, they will likely become appealing to threat actors seeking similar benefits, leading to disruptions.

FBI Releases Advisory on 42,000 Phishing Domains Linked to LabHost PhaaS Platform

Source: https://www.ic3.gov/CSA/2025/250429.pdf

What we know: The Federal Bureau of Investigation (FBI) has released an advisory to disseminate 42,000 phishing domains linked to the LabHost phishing-as-a-service (PhaaS) platform between November 2021 and April 2024.

Context: Before the platform was shut down by law enforcement in April 2024, LabHost was a major PhaaS provider, offering a range of illicit services for approximately 10,000 users. It allowed cybercriminals to impersonate over 200 organizations, including banks and government bodies, to steal personal and banking information from victims worldwide.

Analyst note: The FBI encourages recipients of this document to report information concerning suspicious or criminal activity to their local FBI field office. Meanwhile, the FBI San Francisco Field Office has stressed the importance of strong collaboration and timely reporting to protect U.S. networks from evolving ransomware threats.

DEEP AND DARK WEB INTELLIGENCE

RansomHub affiliates’ whereabouts: The ransomware-as-a-service (RaaS) group Qilin’s recent activity and disclosures on its leak site suggest that cybercriminals affiliated with RansomHub have likely migrated to the Russian-speaking collective (Qilin) after RansomHub’s infrastructure went down sometime around April 1, 2025. RansomHub’s affiliates are likely to bring the strategies of their group’s administrators to other RaaS groups like Qilin.

DATA BREACHES

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-30390: Microsoft revealed it has mitigated an improper authorization vulnerability in Azure; such vulnerabilities can allow an authorized attacker to elevate privileges over a network. This requires no customer action to resolve.

Affected products: Azure Machine Learning

Tags: DIB, tlp:green