ZeroFox Daily Intelligence Brief - May 15, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - May 15, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- U.S. Steel Producer Nucor Corporation Discloses Cyber Incident
- New Malware Threat Spreads Across Latin America via Phishing
- Scammers Target Job Seekers on Popular Messaging Application
U.S. Steel Producer Nucor Corporation Discloses Cyber Incident
What we know: American steel producer Nucor Corporation recently disclosed a cyber incident that forced it to halt operations at certain locations and take some of its networks offline.
Context: Reportedly, the cybersecurity incident involved unauthorized access to certain information technology (IT) systems. Nucor Corporation is a major supplier of reinforcing bars for the construction sector in North America.
Analyst note: It is likely that Nucor Corporation is facing a ransomware attack. ZeroFox has observed manufacturing and construction industries being the most targeted by ransomware groups. The disruption in operations is likely to add to the cost of damages incurred from the incident.
New Malware Threat Spreads Across Latin America via Phishing
Source: https://thehackernews.com/2025/05/horabot-malware-targets-6-latin.html
What we know: A new phishing campaign is distributing Horabot malware by mimicking legitimate invoices or financial emails in Latin America. The campaign hijacks email accounts to spread the malware strain and installs banking trojans on compromised systems.
Context: The campaign primarily targets Spanish-speaking users and uses Outlook COM automation for lateral spread.
Analyst note: Cybercriminals are using social engineering tactics to spread malware and deceive victims into revealing sensitive information—likely resulting in data theft, financial loss, and widespread malware infections across networks.
Scammers Target Job Seekers on Popular Messaging Application
Source: https://hackread.com/job-seekers-targeted-scammers-government-whatsapp/
What we know: Scammers have been targeting job seekers through a popular messaging app with fake job offers, tricking them into submitting personal information or depositing cryptocurrency under the pretext of task-based earnings.
Context: These scams involve impersonating government and corporate recruiters, using phishing sites and social engineering to commit fraud and identity theft.
Analyst note: These scammers could gather personal information, like identification numbers and other personally identifiable information, to open fraudulent accounts, impersonate victims to scam others, and use the data for extortion.
DEEP AND DARK WEB INTELLIGENCE
DarkForums user INDOHAXSEC: Well reputed pro-Pakistan threat group “INDOHAXSEC” has claimed to have leaked data associated with the Election Commission of India on DarkForums. The information allegedly includes name, physical address, passport number, and more. Threat actors are likely to misuse this kind of data in identity theft and potential electoral interference.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-4632: This improper limitation of a pathname to a restricted directory vulnerability that enables attackers to write arbitrary files as system authority has been exploited in the wild. Samsung has released updates for it. If devices are not updated, threat actors could bypass device security by rewriting arbitrary files to install malware, lock systems, and cause operational disruptions.
Affected products: Samsung Electronics MagicINFO 9 Server versions affected from 0 to 21.1052
Tags: DIB, tlp:green