zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - May 6, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - May 6, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • U.S. Sanctions Myanmar Militia Involved in Cyber Scams
  • Darcula PhaaS Steals 884,000 Credit Cards in Global Text Message Scam
  • Luna Moth Continues to Extort Legal and Financial Firms

U.S. Sanctions Myanmar Militia Involved in Cyber Scams

Source: https://home.treasury.gov/news/press-releases/sb0129

What we know: The U.S. Treasury has sanctioned a Myanmar militia group, the Karen National Army (KNA) and associated members, for facilitating cyber scams targeting American citizens.

Context: The group’s leader and two other individuals were also sanctioned. The group is also involved in human trafficking and cross-border smuggling and controls the border area with Thailand.

Analyst note: The sanctions are likely going to disrupt the operations of cybercrime networks prevalent in Southeast Asia, including “pig butchering” scams. Furthermore, the sanctions are likely to dissuade other individuals from engaging with the entities.

Darcula PhaaS Steals 884,000 Credit Cards in Global Text Message Scam

Source: https://www.bleepingcomputer.com/news/security/darcula-phaas-steals-884-000-credit-cards-via-phishing-texts/

What we know: The Darcula phishing-as-a-service (PhaaS) platform stole 884,000 credit cards over a seven-month span through malicious text messages that tricked users into clicking fake links.

Context: Operating globally across more than 100 countries, Darcula used 20,000 spoofed domains mimicking trusted brands to target both Android and iPhone users. The phishing texts often appeared as road toll fines or delivery notifications, containing links to phishing sites.

Analyst note: Attackers are likely to drain bank accounts, commit identity fraud, or sell stolen data of the victims on dark web markets—leading to further attacks.

Luna Moth Continues to Extort Legal and Financial Firms

Source: https://www.bleepingcomputer.com/news/security/luna-moth-extortion-hackers-pose-as-it-help-desks-to-breach-us-firms/

What we know: Data extortion group Luna Moth has been conducting callback phishing attacks on U.S. legal and financial firms. They have been stealing sensitive data and extorting victims with ransom demands up to USD 8 million.

Context: Callback phishing is a social engineering tactic where attackers pose as support staff to trick victims into calling fake numbers and handing over sensitive information or remote access.

Analyst note: This group is likely targeting legal and financial firms to access large databases containing sensitive client data, proprietary information, and business dealings—assets that, if stolen, could threaten them financially and operationally.

DEEP AND DARK WEB INTELLIGENCE

Xss user Skez: ZeroFox has observed negative reputation threat actor "Skez" advertising web panel access with administrator rights to a customer relationship management system of an unnamed French retail company. If the claims are true, any actor who acquires the access could breach the company’s network and run malicious codes, exfiltrate sensitive information, and change network settings to conduct further attacks.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-3248: The already patched vulnerability impacts the open-source Langflow platform and is being actively exploited. It enables remote attackers to take unauthorized control of Langflow servers. The affected countries include the United States, Germany, India, Singapore, and China. The bug is likely to compromise affected servers, enabling data theft or persistent access to systems.

Affected products: Langflow versions prior to 1.3.0

Tags: DIB, tlp:green