zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - May 14, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - May 14, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Europol Dismantles Fraud Investment Scam Network
  • Scammers Exploit GovDelivery System to Send Fraudulent Messages
  • Geopolitical Focus | Global Conflicts and Counterterrorism Activities

Europol Dismantles Fraud Investment Scam Network

Source: https://www.europol.europa.eu/media-press/newsroom/news/international-crackdown-dismantles-multimillion-euro-investment-scam

What we know: Europol has dismantled a cybercriminal network and arrested a suspect in Cyprus for scamming over 100 victims of more than EUR 3 million (approx. USD 3.3 million) via a fraud online investment platform.

Context: Victims were lured with high returns on their investments and coerced to invest huge sums using fake charts displaying high profits. Criminals used various psychological tactics to manipulate the victims.

Analyst note: The operation almost certainly reveals the presence of scam call centers based in Europe, targeting Europeans. Cybercriminals originating in Europe are likely to be fluent in European languages making them sound more persuasive.

Scammers Exploit GovDelivery System to Send Fraudulent Messages

Source: https://techcrunch.com/2025/05/13/government-email-alert-system-govdelivery-used-to-send-scam-messages/

What we know: Scammers used the GovDelivery email system to send fraudulent messages about unpaid tolls. The emails contained disguised links that redirected to a malicious site mimicking Texas' TxTag toll service.

Context: GovDelivery is widely used by U.S. government agencies to send official alerts to residents. A contractor's compromised account enabled the attack, though no current state systems were confirmed breached.

Analyst note: These scam emails closely mimic official government messages, using familiar formats and domains like govdelivery[.]com to appear legitimate. Victims unknowingly clicking malicious links could likely be exposed to identity theft or fraud.

Geopolitical Focus | Global Conflicts and Counterterrorism Activities

DEEP AND DARK WEB INTELLIGENCE

Xss user proexp: Untested threat actor "proexp" has advertised a fully undetectable (FUD) loader malware targeting SmartScreen, Chrome Alert, and others on xss. There is a roughly even chance that the sale is legitimate. It is likely to be used by financially-motivated cybercriminals or ransomware groups to deliver additional payloads like ransomware or cryptominers.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-4427 and CVE-2025-4428: Ivanti has released updates for Endpoint Manager Mobile (EPMM) to address two security flaws that together enable unauthenticated remote code execution. It can likely lead to full system compromise, data breaches, or unauthorized access to sensitive corporate resources.

Affected products: The affected products are listed in this advisory.

CVE-2025-32756: This vulnerability enables a remote unauthenticated attacker to execute arbitrary code or commands by sending HTTP requests. CVE-2025-32756 has been exploited as a zero day on Fortinet’s FortiVoice phone systems. Threat actors could run any program or action like installing malware, steal data, and take over the entire network. A patch has been released.

Affected products: The affected products are listed in this advisory.

Tags: DIB, tlp:green