ZeroFox Daily Intelligence Brief - May 16, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - May 16, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Machine1337 Likely Hints at Coinbase Breach in Telegram Post
- Senior U.S. Officials Impersonated in Malicious Messaging Campaign
- Flaws in Webmail Products Exploited in Cyberespionage Campaign
Machine1337 Likely Hints at Coinbase Breach in Telegram Post
Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/86121
What we know: Threat actor “Machine1337” (aka EnergyWeaponUser on BreachForums) has posted “Coinbase: Coming soon” on their Telegram channel. Meanwhile, an X user reported that scammers are leveraging leaked Coinbase customer data to send fake SMS messages to users.
Context: Coinbase has disclosed a major breach involving bribed overseas support agents who stole customer data. The attackers demanded USD 20M, which Coinbase refused—offering a USD 20M reward for leads on the attackers.
Analyst note: If the threat actor’s claims are true and linked to the attack, it could lead to a surge in phishing campaigns exploiting the leaked Coinbase data. The scammers sending fake SMS messages are also likely to conduct further malicious operations for financial gain.
Senior U.S. Officials Impersonated in Malicious Messaging Campaign
Source: https://www.ic3.gov/PSA/2025/PSA250515
What we know: In an ongoing malicious text and voice messaging campaign, threat actors impersonate U.S. officials to target individuals, including current or former senior U.S. federal or state government officials and their contacts.
Context: The threat actors have been smishing and vishing targets in an effort to establish rapport before gaining access to personal accounts.
Analyst note: The campaign could expose information about other key officials, who can further face spear phishing attacks. Threat actors could also impersonate these officials to access sensitive government data, which they could exfiltrate and use in future malicious operations.
Flaws in Webmail Products Exploited in Cyberespionage Campaign
What we know: State-sponsored hackers are running a cyberespionage campaign dubbed “RoundPress,” exploiting zero-day vulnerabilities in multiple webmail products like Zimbra, RoundCube, and MDaemon, to target high-value government entities.
Context: Russia-backed hackers are suspected to be behind the campaign targeting various European countries, including Ukraine, Romania, and Greece, since at least 2023. The attack chain starts with spear phishing that leads to theft of email content, passwords, and more.
Analyst note: The highly targeted nature of spear phishing likely indicates hackers have access to email addresses of victims. Government employees’ publicly available email addresses or those used for third-party websites are likely to be more susceptible to targeting.
DEEP AND DARK WEB INTELLIGENCE
Xss user Machine1337: Machine1337 has claimed to have leaked data associated with a number of prominent tech giant companies based in the United States and China, including Snapchat, Apple, and more. It is very likely the threat actor will continue targeting industry giants for financial gain by exploiting sensitive information.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-4664: This is an actively-exploited insufficient policy enforcement vulnerability in a component called Loader in Google Chrome, that enables a remote attacker to leak cross-origin data via a maliciously crafted HTML page. The vulnerability is likely to enable a full account takeover by an attacker.
Affected products: Google Chrome versions before 136.0.7103.113
Tags: DIB, tlp:green