zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - May 2, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - May 2, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - Hacktivists Claim Responsibility for Recent Power Outages
  • Another UK Retailer Targeted in Cyberattack
  • Threat Group Billbug Targets Southeast Asian Entities

ZeroFox Intelligence Flash Report - Hacktivists Claim Responsibility for Recent Power Outages

Source: https://www.zerofox.com/advisories/32731/

What we know: Hacktivist group “Dark Storm,” alongside “NoName057(16),” claimed responsibility on X (formerly Twitter) for a recent power outage impacting Spain, Portugal, and parts of Southern France.

Context: The Spanish government reported major power outages affecting 55 million people across Europe. The blackout disrupted mobile networks, internet, transport, and payment systems, causing widespread confusion.

Analyst note: At the time of reporting, the Spanish government has denied the outages were caused by a cyberattack and continues to investigate, despite Dark Storm’s claims. ZeroFox has observed on numerous occasions that Dark Storm often makes exaggerated or likely false attributions.

Another UK Retailer Targeted in Cyberattack

Source: https://www.bleepingcomputer.com/news/security/harrods-the-next-uk-retailer-targeted-in-a-cyberattack/

What we know: Another retailer in the United Kingdom, has disclosed an attempted cyberattack, with hackers attempting to gain unauthorized access to some of its systems.

Context: The retailer said that it has taken action and restricted internet access at its sites, and assured customers their experience will not be affected. It is the third UK retailer targeted by a cyberattack after Marks and Spencer and Co-op in the recent week.

Analyst note: A spate of cyberattacks targeting more UK retailers in the coming weeks is likely. A ransomware group or multiple groups are likely behind the cyberattacks. There is a roughly even chance of social engineering tactics being used in future targeting.

Threat Group Billbug Targets Southeast Asian Entities

Source: https://www.darkreading.com/threat-intelligence/billbug-cyber-espionage-campaign-southeast-asia

What we know: A China-linked threat group dubbed Billbug has been observed to target Southeast Asian targets, since late 2024 and early 2025.

Context: In its campaigns, the group has reportedly used outdated, legitimate security software to deploy custom malware across sectors like manufacturing, telecom, and media.

Analyst note: This group is likely stealing sensitive critical infrastructure data, conducting cyber espionage, and maintaining long-term access for strategic intelligence gathering and influence operations to benefit its home country’s geopolitical agenda.

DEEP AND DARK WEB INTELLIGENCE

BreachForums’s moderator armadyl: ZeroFox has observed BreachedForums’s (breachforums[.]sx) moderator "Armadyl" claiming to have leaked DarkForums’ backend infrastructure. The moderator claimed to have observed an active breach attempt originating from DarkForums (darkforums[.]st) and that the leak acts as a countermeasure. DarkForums’ backend infrastructure leak, if legitimate, is likely to involve user data, admin tools, private messages, and operational data, exposing sensitive information, vulnerabilities, and user identities.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-46337: ADOdb is a hypertext preprocessor (PHP) database abstraction library used for executing queries and managing databases. In versions prior to 5.22.9 (patched version), there was a vulnerability where improper escaping of a query parameter could enable an attacker to execute arbitrary structured query language (SQL) commands. This flaw could enable attackers to manipulate SQL queries, potentially leading to unauthorized data access, data modification, or even full compromise of the database.

Affected products: ADOdb's PostgreSQL database versions prior to 5.22.9

Tags: DIB, tlp:green