ZeroFox Daily Intelligence Brief - May 12, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - May 12, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Four Foreign Nationals Charged in Botnet Conspiracy Involving 5socks and AnyProxy
- Germany Shuts Down Crypto Exchange Used for Money Laundering
- New Info-Stealer Malware Disguised as Fake AI Generation Tool
Four Foreign Nationals Charged in Botnet Conspiracy Involving 5socks and AnyProxy
What we know: U.S. authorities have issued a domain seizure warrant and an indictment charging four individuals with conspiracy to maintain, operate, and profit from botnet services known as AnyProxy and 5socks, along with other cyber crimes.
Context: The indictment alleges that the hackers used malware to infect outdated wireless routers worldwide, turning them into proxy servers sold on Anyproxy[.]net and 5socks[.]net without owners' knowledge.
Analyst note: Court documents revealed that 5socks[.]net sold over 7,000 proxies worldwide. This enabled anonymous access to compromised networks by masking identities and locations, leading to widespread cybercrime, fraud, and data breaches.
Germany Shuts Down Crypto Exchange Used for Money Laundering
Source: https://thehackernews.com/2025/05/germany-shuts-down-exch-over-19b.html
What we know: Germany's Federal Criminal Police Office (aka Bundeskriminalamt or BKA) has shut down the eXch cryptocurrency exchange, seizing EUR 34 million (USD 38.25 million) in assets and 8 terabytes of data linked to money laundering and criminal activities.
Context: The exchange had been operating since 2014, offering digital asset swapping services on both the clearnet and the dark web.
Analyst note: The shutdown of eXch[.]cx dismantles a platform used to anonymize criminal proceeds, disrupting a key tool for cybercriminals and reducing the risk of fraud, scams, and other cybercrimes for users.
New Info-Stealer Malware Disguised as Fake AI Generation Tool
What we know: Threat actors are using fake Artificial Intelligence (AI)-powered video making tools and Facebook ads to distribute a new information stealing malware known as Noodlophile.
Context: Noodlophile is being sold on dark web forums, usually along with "Get Cookie+Pass" services, a malware-as-a-service (MaaS) operation linked to Vietnamese-speaking actors. The malware targets data stored on web browsers including crypto wallets and account credentials.
Analyst note: Financially-motivated threat actors are likely to exploit any new AI content trend to deploy malware by claiming to offer free AI tools. This can result in financial losses and account takeover of victims, which can be further misused for social-engineering attacks.
DEEP AND DARK WEB INTELLIGENCE
New BreachForums site: ZeroFox has noted a message on a new BreachForums site, breachforums[.]sx, saying that the administrators are seeking to transfer the ownership of the site. Moreover, various sections on the site like databases, stealer logs, and other leaks have been removed. This site is likely a BreachForums clone site attempting to sell the domain name. This domain is very likely to be used to scam users by claiming to be the original BreachForums site.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-3711: This is a stack-based buffer overflow vulnerability in IP-based CL5708IM LCD KVM Switch. It enables remote attackers to execute arbitrary code on a targeted device. This vulnerability likely enables threat actors to disrupt operations on a device, or steal information. Government, education, transport, and broadcasting and media sectors using this device are likely to be targeted by either financially or politically-motivated threat actors.
Affected products: CL5708IM LCD KVM Switch
Tags: DIB, tlp:green