zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - May 7, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - May 7, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Unsophisticated Cyber Actors Targeting Operational Technology
  • ZeroFox Intelligence Flash Report - Series of Cyberattacks Target UK Retail Organizations
  • India-Pakistan: Cross-Border Strikes and Retaliation

Unsophisticated Cyber Actors Targeting Operational Technology

Source: https://www.cisa.gov/news-events/alerts/2025/05/06/unsophisticated-cyber-actors-targeting-operational-technology

What we know: Unsophisticated threat actors have been targeting Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) systems within U.S. critical infrastructure sectors, specifically in energy and transportation systems.

Context: These activities often rely on basic intrusion techniques, which are especially effective with insecure and exposed assets.

Analyst note: CISA urges critical infrastructure asset owners and operators to implement the mitigations outlined in its advisory. In absence of adequate protections, actors are likely to tamper with operational technology (OT) for defacement, configuration changes, operational disruptions, and physical damage.

ZeroFox Intelligence Flash Report - Series of Cyberattacks Target UK Retail Organizations

Source: https://www.zerofox.com/advisories/32861/

What we know: A series of prominent cyber incidents have targeted UK-based retail organizations in recent days, including Marks & Spencer (M&S) and The Co-operative Group (Co-op).

Context: The cyber incidents reportedly began with social engineering tactics urging retailers’ IT help desks to reset passwords of employee accounts. Ransomware and digital extortion (R&DE) collective DragonForce and another threat collective Scattered Spider are rumored to be behind the cyber incidents.

Analyst note: ZeroFox analyzes that if a ransomware group is responsible and if extortion attempts are unsuccessful, it is very likely that stolen data will be published to the threat group’s leak site. Exposed customers are likely to be targeted in phishing and social engineering campaigns.

India-Pakistan: Cross-Border Strikes and Retaliation

DEEP AND DARK WEB INTELLIGENCE

Telegram user DesertCr0ws: On May 6, 2025, a new pro-Pakistan threat actor group “DesertCr0ws” claimed to have leaked data associated with the Punjab state government in India on their Telegram channel over rising India-Pakistan tensions. It is unlikely that the leaked data is new or concerning. Meanwhile, hacktivist group Indian Cyber Force has claimed to have hacked over 1,000 surveillance cameras in Pakistan.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-7399: Hackers are actively exploiting an unauthenticated remote code execution (RCE) vulnerability in Samsung MagicINFO 9 Server—a centralized content management platform. It enables attackers to upload and execute malicious code to hijack devices and deploy malware. Vulnerable systems could further be used to display unauthorized content, disrupt operations, or serve as entry points into broader corporate networks.

Affected products: Samsung MagicINFO 9 Server version before 21.1050

Tags: DIB, tlp:green