zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - May 9, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - May 9, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Threat Actors Join Targeting of India and Pakistan
  • FBI Warns of End-of-Life Routers Abused for Cybercrime
  • Data Breach at Pearson

Threat Actors Join Targeting of India and Pakistan

Source: https://www.zerofox.com/advisories/32941/

What we know: ZeroFox has observed several cyber threat actors targeting the defense sectors on both sides of the conflict. Meanwhile, reports circulating on X are warning the public about malware-laced files like “Dance of Hillary[.]exe,” which could allow espionage or cause widespread system breaches.

Context: On May 7, 2025, India struck at least nine sites in Pakistan in retaliation for an April 22 terrorist attack that killed over two dozen Indian civilians in the disputed territory of Kashmir.

Analyst note: Cybercriminals are increasingly engaging in cyber warfare alongside the physical conflict between India and Pakistan. Threat groups from both sides are likely to continue targeting each other’s critical infrastructure—to disrupt operations, steal sensitive data, and exert strategic pressure during escalating tensions.

FBI Warns of End-of-Life Routers Abused for Cybercrime

Source: https://www.ic3.gov/PSA/2025/PSA250507

What we know: The FBI has been warning of threat actors exploiting outdated routers with known vulnerabilities to install malware and convert them into proxies.

Context: These compromised devices, often infected with variants of TheMoon malware, are used to obfuscate cybercriminal activity, including espionage and crypto theft.

Analyst note: Threat actors are likely to exploit these functioning and unsecured end-of-life routers to launch large-scale attacks while evading detection through proxy networks. These attacks could include network infiltration, account hijacking, distributed denial-of-service attacks, and remote code execution.

Data Breach at Pearson

Source: https://www.bleepingcomputer.com/news/security/education-giant-pearson-hit-by-cyberattack-exposing-customer-data/

What we know: Major UK-based publication company Pearson has confirmed a cyberattack that has resulted in the theft of customer and corporate data. According to the company, the affected data was mostly legacy data.

Context: The threat actors reportedly exploited an exposed GitLab access token, enabling them to steal terabytes of internal data.

Analyst note: Threat actors could exploit legacy data to analyze past systems, access points, and security weaknesses, identifying outdated protocols or unpatched vulnerabilities for future attacks.

DEEP AND DARK WEB INTELLIGENCE

Exploit user el_farado: Untested threat actor "el_farado" has advertised for sale a data breach package affecting U.S.-based business intelligence software company Scope Technologies on Exploit. The data allegedly includes emails, phone numbers, billing, project addresses, and other users' information. The exposure of such sensitive data is likely to lead to identity theft, financial fraud, and more targeted attacks.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-47733: A server-side request forgery (SSRF) vulnerability in Microsoft Power Apps could enable an unauthorized attacker to access and disclose internal network information. Actors are likely to exploit it to access sensitive data, internal services, or for further attacks within the network.

Affected products: Microsoft Power Apps

Tags: DIB, tlp:green