ZeroFox Daily Intelligence Brief - May 14, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - May 14, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Europol Dismantles Fraud Investment Scam Network
- Scammers Exploit GovDelivery System to Send Fraudulent Messages
- Geopolitical Focus | Global Conflicts and Counterterrorism Activities
Europol Dismantles Fraud Investment Scam Network
What we know: Europol has dismantled a cybercriminal network and arrested a suspect in Cyprus for scamming over 100 victims of more than EUR 3 million (approx. USD 3.3 million) via a fraud online investment platform.
Context: Victims were lured with high returns on their investments and coerced to invest huge sums using fake charts displaying high profits. Criminals used various psychological tactics to manipulate the victims.
Analyst note: The operation almost certainly reveals the presence of scam call centers based in Europe, targeting Europeans. Cybercriminals originating in Europe are likely to be fluent in European languages making them sound more persuasive.
Scammers Exploit GovDelivery System to Send Fraudulent Messages
What we know: Scammers used the GovDelivery email system to send fraudulent messages about unpaid tolls. The emails contained disguised links that redirected to a malicious site mimicking Texas' TxTag toll service.
Context: GovDelivery is widely used by U.S. government agencies to send official alerts to residents. A contractor's compromised account enabled the attack, though no current state systems were confirmed breached.
Analyst note: These scam emails closely mimic official government messages, using familiar formats and domains like govdelivery[.]com to appear legitimate. Victims unknowingly clicking malicious links could likely be exposed to identity theft or fraud.
Geopolitical Focus | Global Conflicts and Counterterrorism Activities
- On May 13, 2025, the Indian Army neutralized three Pakistan-linked Lashkar-e-Taiba terrorists in a counterterrorism operation in Shopian, south Kashmir.
- On May 14, 2025, an Israeli airstrike on the European Hospital in Khan Younis reportedly killed 28 people and injured dozens. Additionally, on May 13, the Israeli military intercepted a hypersonic ballistic missile fired by the Houthi group toward Ben Gurion Airport, close to Tel Aviv.
- The Department of the Treasury’s Office of Foreign Assets Control (OFAC), on May 13, 2025, sanctioned nearly two dozen firms connected with Iran’s illicit international oil trade.
DEEP AND DARK WEB INTELLIGENCE
Xss user proexp: Untested threat actor "proexp" has advertised a fully undetectable (FUD) loader malware targeting SmartScreen, Chrome Alert, and others on xss. There is a roughly even chance that the sale is legitimate. It is likely to be used by financially-motivated cybercriminals or ransomware groups to deliver additional payloads like ransomware or cryptominers.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-4427 and CVE-2025-4428: Ivanti has released updates for Endpoint Manager Mobile (EPMM) to address two security flaws that together enable unauthenticated remote code execution. It can likely lead to full system compromise, data breaches, or unauthorized access to sensitive corporate resources.
Affected products: The affected products are listed in this advisory.
CVE-2025-32756: This vulnerability enables a remote unauthenticated attacker to execute arbitrary code or commands by sending HTTP requests. CVE-2025-32756 has been exploited as a zero day on Fortinet’s FortiVoice phone systems. Threat actors could run any program or action like installing malware, steal data, and take over the entire network. A patch has been released.
Affected products: The affected products are listed in this advisory.
Tags: DIB, tlp:green