ZeroFox Daily Intelligence Brief - May 13, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - May 13, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- DoppelPaymer Ransomware Suspect Arrested in Moldova for Targeting Dutch Organizations
- ASUS Patches Critical DriverHub Flaws Enabling Remote Code Execution
- APT36 Uses ClickFix in Recent Campaign
DoppelPaymer Ransomware Suspect Arrested in Moldova for Targeting Dutch Organizations
What we know: A joint operation by Moldova and the Netherlands has resulted in the arrest of a suspect associated with DoppelPaymer ransomware attacks that targeted Dutch organizations in 2021.
Context: The 2021 ransomware attack against the Dutch Research Council (NWO) cost nearly EUR 4.5 million (approx. USD 4.9 million) in damages. Authorities have seized an electronic wallet, a mobile phone, several laptops, and memory cards among other evidence.
Analyst note: The operation is likely to expose other cybercrime network/s associated with the suspect. The increasing government scrutiny is likely to add to the waning profitability of ransomware operations.
ASUS Patches Critical DriverHub Flaws Enabling Remote Code Execution
Source: https://thehackernews.com/2025/05/asus-patches-driverhub-rce-flaws.html
What we know: ASUS has fixed two security flaws (CVE-2025-3462 and CVE-2025-3463) in its DriverHub software, which could enable attackers to remotely execute code on a victim’s system.
Context: DriverHub is a tool that automatically identifies a computer's motherboard model and fetches relevant driver updates by connecting to ASUS's dedicated site at “driverhub.asus[.]com.”
Analyst note: Attackers could trick users into visiting malicious subdomains and exploit the flaws to run arbitrary code using a trusted ASUS executable. This could lead to full system compromise, installation of malware, data theft, or persistent backdoor access.
APT36 Uses ClickFix in Recent Campaign
What we know: A new ClickFix campaign by APT36 has targeted popular operating systems’ users, tricking them into running operating-system-specific malware commands via fake error or verification prompts.
Context: ClickFix is a social engineering tactic that tricks users into manually executing malicious commands by mimicking system errors or verification prompts.
Analyst note: This ClickFix campaign bypasses traditional security defenses through social engineering, likely leading to successful malware infections, data theft, and ransomware, as users are tricked into downloading malware themselves.
DEEP AND DARK WEB INTELLIGENCE
Telegram user DieNet: ZeroFox has observed pro-Palestine threat actor group “DieNet” claiming to launch its new ransomware service “LockNet” soon. The group claims that it already has access to several companies, including some operating in the cybersecurity sector. If DieNet’s claim of accessing multiple organizations is true, the new service could provide insights into victims’ defensive tools, incident response procedures, and other cybersecurity measures.
VULNERABILITY AND EXPLOIT INTELLIGENCE
Apple vulnerabilities: Apple has released a series of security updates for its multiple software versions to address various security vulnerabilities.
Affected products: The affected products are listed in this advisory.
CVE-2025-27920: A Turkey-based cyberespionage group, also known as Sea Turtle, is known to have exploited this directory traversal bug to target the Kurdish military in Iraq. It enables attackers to access sensitive files, source code, deploy malware, and potentially lead to remote code execution. Other cyberespionage and financially-motivated threat actors are likely to exploit the vulnerability in unpatched versions targeting critical infrastructure entities.
Affected products: Output Messenger before 2.0.63
Tags: DIB, tlp:green