zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - May 19, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - May 19, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report: Rise of Hacktivism Incidents amid India-Pakistan Hostilities
  • New HTTPBot Botnet Targets Major Industries in China with DDoS Attacks
  • Russian Developers Hit with Fake Python Package

ZeroFox Intelligence Flash Report: Rise of Hacktivism Incidents amid India-Pakistan Hostilities

Source: https://www.zerofox.com/advisories/33167/

What we know: ZeroFox has observed an increase in hacktivist incidents during the recent India-Pakistan hostilities, with new and old groups targeting entities on both sides of the border.

Context: Some collectives originally known to support a different cause have also been involved in India-Pakistan hacktivist incidents. Their alleged tactics, techniques, and procedures (TTPs) include distributed-denial-of-service (DDoS), website defacement, and data breaches.

Analyst note: These cyberattacks by hacktivists likely took place, given the provision of checkhost links. However, targeted organizations are unlikely to have been significantly affected. As tensions reduce, hacktivist activities are very likely to reduce in intensity and tempo.

New HTTPBot Botnet Targets Major Industries in China with DDoS Attacks

Source: https://thehackernews.com/2025/05/new-httpbot-botnet-launches-200.html

What we know: A new botnet malware strain, called HTTPBot, has been primarily targeting the gaming industry, technology companies, and educational institutions in China. It is used in advanced HTTP-based distributed denial-of-service (DDoS) attacks.

Context: HTTPBot emerged in August 2024 and has issued over 200 attack commands since April 2025. It is written in Golang.

Analyst note: HTTPBot evades detection by mimicking HTTP traffic, making it harder to block and analyze. Victims are likely to face service disruptions, potential financial losses, and more.

Russian Developers Hit with Fake Python Package

Source: http://hackread.com/ukraine-group-russian-developers-python-backdoor/

What we know: Dbgpkg is a malicious Python package that was discovered on the Python Package Index (PyPI) and was observed to target Russian developers.

Context: Dbgpkg masquerades as a legitimate debugging tool and is suspected to be linked to pro-Ukraine threat actors. It secretly installs a backdoor on the systems of developers.

Analyst note: Threat actors could use this package to install a backdoor, enabling remote access to infected development environments to steal source code, establish long term persistence, and infect larger networks.

DEEP AND DARK WEB INTELLIGENCE

Xss user USA_Straday: Untested threat actor "USA_Straday" has advertised an auction for remote monitoring and management (RMM) access with local administrator rights to an unnamed U.S.-based bank on xss. If the threat actor’s claims for possessing this access are true, they could gain unauthorized access to compromised devices and deploy backdoors, enabling them to establish long-term persistence, introduce malware, exfiltrate data, transfer funds, and more.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2024-45332, CVE-2024-28956, and CVE-2025-24495: These microcode patched vulnerabilities, clubbed together as “Spectre,” can leak sensitive information from memory from modern Intel CPUs. They are likely to enable an authenticated user to disclose information via local access and access confidential information through a privileged process.

Affected products: The affected products are listed in this advisory.

Tags: DIB, tlp:green