ZeroFox Daily Intelligence Brief - May 5, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - May 5, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- AUR Candidate George Simion Leads Romanian Presidential Elections
- Widespread Subscription Scams Collect Payment Data
- Iranian Group Targets Middle Eastern CNI for Two Years
AUR Candidate George Simion Leads Romanian Presidential Elections
Source: https://www.zerofox.com/advisories/32773/
What we know: Amid the threat of Russian interference, including aggressive social media campaigns, Romania’s first round of presidential polls have a resolute winner in Alliance for Union of Romanians (AUR) candidate George Simion, followed by Bucharest mayor Nicușor Dan.
Context: The original December 2024 poll was annulled and independent candidate Călin Georgescu disqualified over evidence of Russian interference. ZeroFox has found evidence of Georgescu’s alleged social media “network” still active and supporting George Simion.
Analyst note: ZeroFox analyzes that the election outcome will almost certainly have immediate consequences for Black Sea security, and NATO’s eastern defense posture. Despite December 2024 mitigation, Russia-linked social media manipulation remains a likely threat to the elections.
Widespread Subscription Scams Collect Payment Data
Source: https://hackread.com/fake-retail-sites-used-new-wave-subscription-scams/
What we know: More than 200 online shops and mystery box scams have been tricking unknowing users into signing up for subscriptions and recurring payments, while collecting credit card data.
Context: These scammers have been impersonating influencers to promote these scams through sponsored ads, making offers appear trustworthy and increasing their reach and impact.
Analyst note: Threat actors are likely stealing victims’ credit card details and selling them on dark web carding forums. Buyers could use this data for unauthorized purchases in fraud campaigns.
Iranian Group Targets Middle Eastern CNI for Two Years
Source: https://thehackernews.com/2025/05/iranian-hackers-maintain-2-year-access.html
What we know: An Iranian state-sponsored group conducted a nearly two-year cyber intrusion targeting critical national infrastructure (CNI) in the Middle East.
Context: The attack aligns with the tactics of Iranian threat group Lemon Sandstorm, active since at least 2017. It has previously targeted key sectors, like aerospace, energy, and utilities across multiple regions.
Analyst note: The persistent access to critical infrastructure could enable disruption of essential services or covert intelligence gathering, likely leading to targeted attacks, strategic manipulation, or long-term surveillance.
DEEP AND DARK WEB INTELLIGENCE
Exploit user t3tr1s: Untested threat actor "t3tr1s" has advertised an India database containing approximately six million records on Exploit. According to t3tr1s, there are two separate datasets available for purchase. The records are likely to expose sensitive personal information—leading to identity theft, fraud, or targeted cyberattacks against individuals and organizations.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-38475: A vulnerability in Apache HTTP Server mod_rewrite (up to version 2.4.59) enables attackers to access unintended files or execute code via unsafe URL mappings. It was recently exploited on SonicWall SMA 100 devices—a secure remote access device—and reportedly enables unauthorized file access. Threat actors could exploit it to maintain long term persistence, data theft, and operational disruption.
Affected products: Apache Software Foundation Apache HTTP Server versions from 2.4.0 through 2.4.59
Tags: DIB, tlp:green