zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - May 8, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - May 8, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • DDoS-for-Hire Empire Brought Down: Administrators Arrested, Domains Seized
  • LockBit Ransomware’s Leak Site Hacked, Passwords Leaked
  • CoGUI Strikes Japan; Targets Specific Victims

DDoS-for-Hire Empire Brought Down: Administrators Arrested, Domains Seized

Source: https://www.europol.europa.eu/media-press/newsroom/news/ddos-for-hire-empire-brought-down-poland-arrests-4-administrators-us-seizes-9-domains

What we know: Polish authorities have arrested four alleged operators of platforms used to launch thousands of cyberattacks worldwide. Meanwhile, the United States has seized nine domains associated with booter services

Context: The suspects allegedly ran six stresser/booter sites offering distributed denial-of-service services for EUR 10 (approx. USD 11). These now-defunct platforms enabled widespread attacks on schools, governments, businesses, and gaming sites from 2022 to 2025.

Analyst note: Stresser and booter services offer on-demand cyberattacks, often disguised as tools for legitimate testing—widely used to cause deliberate disruption, likely leaving victims with service outages, financial losses, and more.

LockBit Ransomware’s Leak Site Hacked, Passwords Leaked

Source: https://www.bleepingcomputer.com/news/security/lockbit-ransomware-gang-hacked-victim-negotiations-exposed/

What we know: LockBit ransomware’s leak site has allegedly been hacked and its panels now display the message “Don’t do crime CRIME IS BAD xoxo from Prague,” along with a link to a MySQL database dump.

Context: The message on the leak site is similar to the one used in the recent Everest ransomware leak site hack. The MySQL database allegedly includes targeted company names, messages exchanged between the group and victims, passwords of admins and affiliate users, and more. However, source code or stolen data has reportedly not been compromised.

Analyst note: The hack likely indicates that threat actors lack cybersecurity hygiene, as LockBit’s server was operating PHP 8.1.2, affected by a critical and actively exploited vulnerability, CVE-2024-4577.

CoGUI Strikes Japan; Targets Specific Victims

Source: https://www.darkreading.com/threat-intelligence/cogui-phishing-kit-chinese-hackers-japan

What we know: Threat actors are deploying the CoGUI phishing kit to primarily target victims in Japan, sending over 500 million phishing emails this year, while impersonating major e-commerce platforms, tax agencies, and financial institutions.

Context: The phishing emails to lure specific targets to fake login pages hosted on the CoGUI platform. Only users meeting predefined criteria—like location or device type—are taken to the phishing site, while others are redirected to the real brand site to avoid detection.

Analyst note: The threat actors are likely selecting victims who meet specific criteria to enable further targeted attacks. These attacks could include business email compromise and establishing long-term access to corporate networks, leading to espionage and extortion against high-value targets.

DEEP AND DARK WEB INTELLIGENCE

Telegram user Mr Hamza: Pro-Palestine threat group “Mr. Hamza” has claimed to carry out a series of cyberattacks against India under #Op_India, in response to the recent airstrikes. Pro-Pakistan and pro-India hacktivist groups will likely continue targeting each other’s countries amid escalating geopolitical tensions.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-29824: The now-patched vulnerability affecting Windows Common Log File System (CLFS) was exploited by unknown threat actors linked to Play ransomware in addition to the RansomEXX ransomware group. Threat actors used the vulnerability to escalate privileges after breaching a U.S. organization's network. Unpatched or already compromised systems are likely to be targets of active exploits.

Affected products: Windows Server up to 2025, Windows 10 and Windows 11. Windows 10 remains unpatched.

Tags: DIB, tlp:green