ZeroFox Daily Intelligence Brief - May 21, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - May 21, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- VanHelsing Ransomware Source Code Published for Free
- Peter Green Chilled Joins Growing List of UK Retail Cyber Victims
- SideWinder Targets South Asian Ministries Using Old Vulnerabilities
VanHelsing Ransomware Source Code Published for Free
What we know: The source code for VanHelsing ransomware-as-a-service’s (RaaS) affiliate panels and data leak site, along with an operating system (OS) encryptor builder has been published on Russian-language dark web forum RAMP, ahead of VanHelsing 2.0’s release.
Context: The RaaS operators published the source code for free after one of their former developers, called “th30c0der” (also “bg1”), tried to sell it for a minimum USD 10,000. However, the free publication reportedly doesn’t feature the Linux builder, which th30c0der says they have.
Analyst note: The data published for free is almost certainly legitimate. There is a roughly even chance that the other features being sold by th30c0der are also true. However, th30c0der’s asking price is likely to take a hit with the publication of the free data set. The data is likely to be used to enhance the ransomware to support other extortion cyberattacks.
Peter Green Chilled Joins Growing List of UK Retail Cyber Victims
Source: https://www.theregister.com/2025/05/20/ransomware_attack_on_food_distributor/
What we know: Peter Green Chilled, a major UK food distributor, has been hit by a ransomware attack, disrupting deliveries to supermarkets and small businesses.
Context: UK retail giants continue to face a wave of cyberattacks, with Peter Green Chilled the latest victim following recent incidents at Marks and Spencer and Co-op.
Analyst note: Retail companies like Peter Green Chilled are lucrative targets since they are connected with other major retailers that could give threat actors access to a large customer database consisting of sensitive data, like payment information, addresses, passwords, and more.
SideWinder Targets South Asian Ministries Using Old Vulnerabilities
Source: https://thehackernews.com/2025/05/south-asian-ministries-hit-by.html
What we know: Threat actor SideWinder has been using spear phishing emails and geofenced malware to infiltrate government institutions in Sri Lanka, Bangladesh, and Pakistan.
Context: The actor deployed malware designed to maintain persistent access within the targeted networks by exploiting known remote code execution flaws (CVE-2017-0199 and CVE-2017-11882).
Analyst note: The threat actor is very likely gathering intelligence for strategic or military gain and could further escalate to deploying destructive malware and manipulating data. Targets are likely to face data breaches, surveillance, and disruption of critical operations.
DEEP AND DARK WEB INTELLIGENCE
Telegram user Holy League: In a recent Telegram post, pro-Russian and pro-Palestinian threat actor collective “Holy League” named the cyber units affiliated with it and have been involved in coordinated cyberattacks against Ukraine and Israel. Dark Storm Team, which was allegedly behind the March 2025 X/Twitter outage, is also among one of the affiliates. Successful hacktivist operations are likely to be a multi-group effort aimed at drawing attention to a particular common ideological or political cause.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-47934: This flaw in OpenPGP.js enables attackers to spoof signed and encrypted messages. Attackers could manipulate and forge messages that appear legitimately signed, leading to data tampering, phishing, and more.
Affected products: OpenPGP.js versions 5.0.1 through 5.11.2; and 6.0.0-alpha.0 through 6.1.0
Tags: DIB, tlp:green