ZeroFox Daily Intelligence Brief - May 7, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - May 7, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Unsophisticated Cyber Actors Targeting Operational Technology
- ZeroFox Intelligence Flash Report - Series of Cyberattacks Target UK Retail Organizations
- India-Pakistan: Cross-Border Strikes and Retaliation
Unsophisticated Cyber Actors Targeting Operational Technology
What we know: Unsophisticated threat actors have been targeting Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) systems within U.S. critical infrastructure sectors, specifically in energy and transportation systems.
Context: These activities often rely on basic intrusion techniques, which are especially effective with insecure and exposed assets.
Analyst note: CISA urges critical infrastructure asset owners and operators to implement the mitigations outlined in its advisory. In absence of adequate protections, actors are likely to tamper with operational technology (OT) for defacement, configuration changes, operational disruptions, and physical damage.
ZeroFox Intelligence Flash Report - Series of Cyberattacks Target UK Retail Organizations
Source: https://www.zerofox.com/advisories/32861/
What we know: A series of prominent cyber incidents have targeted UK-based retail organizations in recent days, including Marks & Spencer (M&S) and The Co-operative Group (Co-op).
Context: The cyber incidents reportedly began with social engineering tactics urging retailers’ IT help desks to reset passwords of employee accounts. Ransomware and digital extortion (R&DE) collective DragonForce and another threat collective Scattered Spider are rumored to be behind the cyber incidents.
Analyst note: ZeroFox analyzes that if a ransomware group is responsible and if extortion attempts are unsuccessful, it is very likely that stolen data will be published to the threat group’s leak site. Exposed customers are likely to be targeted in phishing and social engineering campaigns.
India-Pakistan: Cross-Border Strikes and Retaliation
- Details of the nine areas India targeted under “Operation Sindoor” have emerged, of which the Markaz Subhan camp was the deepest target in Pakistan, about 100 km (approx. 63 miles) from the India-Pakistan border.
- Indian news outlets are claiming that the operation targeted key terrorist infrastructure belonging to Lashkar-e-Taiba (LeT), Jaish-e-Mohammed (JeM), and Hizbul Mujahideen. Reportedly, Pakistani terrorist Masood Azhar's family members have also been killed.
- However, according to Pakistani sources, the “precision strikes” claimed the lives of 26 people and left 46 injured in Pakistan.
- Separately, Indian officials reported that at least seven civilians were killed and 30 wounded due to Pakistani firing and shelling across multiple locations along the Line of Control (LoC) in disputed Kashmir.
- An Indian strike also reportedly struck an intake structure on the Noseri Dam on the Neelum River, a part of the Indus water system that is a major water source for Pakistan.
- There has been a lot of unconfirmed chatter about India shooting down a Pakistani JF-17 fighter jet. Meanwhile, Pakistani sources are claiming that Pakistan has shot down five Indian aircraft, but India has yet to confirm this.
DEEP AND DARK WEB INTELLIGENCE
Telegram user DesertCr0ws: On May 6, 2025, a new pro-Pakistan threat actor group “DesertCr0ws” claimed to have leaked data associated with the Punjab state government in India on their Telegram channel over rising India-Pakistan tensions. It is unlikely that the leaked data is new or concerning. Meanwhile, hacktivist group Indian Cyber Force has claimed to have hacked over 1,000 surveillance cameras in Pakistan.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-7399: Hackers are actively exploiting an unauthenticated remote code execution (RCE) vulnerability in Samsung MagicINFO 9 Server—a centralized content management platform. It enables attackers to upload and execute malicious code to hijack devices and deploy malware. Vulnerable systems could further be used to display unauthorized content, disrupt operations, or serve as entry points into broader corporate networks.
Affected products: Samsung MagicINFO 9 Server version before 21.1050
Tags: DIB, tlp:green