ZeroFox Daily Intelligence Brief - May 22, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - May 22, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Justice Department Seizes Domains Behind Major Information-Stealing Malware Operation
- Russian Cyber Espionage Campaign Exploits IP Cameras to Track Aid Routes to Ukraine
- Geopolitical Focus | Israel-Palestine Developments
Justice Department Seizes Domains Behind Major Information-Stealing Malware Operation
What we know: The Justice Department has unsealed two warrants to seize five internet domains used in operations associated with LummaC2 information-stealing malware service. Meanwhile, Microsoft's Digital Crimes Unit (DCU) filed a legal action against Lumma Stealer after finding 400,000 Windows computers infected by the malware globally.
Context: Malware like LummaC2 is used to steal sensitive data, including login credentials, from victims to enable cybercrimes. The seized websites were used by LummaC2’s operators to distribute the malware to affiliates and other cybercriminals.
Analyst note: Cybercriminals used LummaC2 to harvest victims' personal data, likely for sale on dark web forums or for financial fraud and identity theft. Shutting down these websites likely disrupted the distribution network of malware service preventing widespread exploitation of stolen information.
Russian Cyber Espionage Campaign Exploits IP Cameras to Track Aid Routes to Ukraine
Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-141a
What we know: Authorities have uncovered a Russia-backed cyber espionage campaign by APT28 (aka Fancy Bear or Forest Blizzard) targeting foreign aid routes into Ukraine.
Context: Private internet protocol (IP) cameras in strategic locations, such as military areas, border crossings, and rail stations, were compromised to track movement of materials. Techniques like credential guessing, spear phishing, and vulnerability exploitation were used to gain initial access. The targeted entities were located in the United States and Europe.
Analyst note: APT28 is very likely to continue its cyber espionage campaign using the known tactics, techniques, and procedures (TTPs). Similar TTPs are likely to be used by other adversaries in separate conflict regions as well.
Geopolitical Focus | Israel-Palestine Developments
- Authorities apprehended a suspect behind the fatal shooting of two Israeli embassy staff near a museum in Washington, DC, on May 21. The suspect reportedly committed the crime as a show of support for the Palestinian cause. FBI investigations are exploring any ties to potential terrorism.
- On May 21, Israeli troops fired warning shots near a group of 25 diplomats visiting Jenin in the occupied West Bank. The Israeli military said the approved visit “deviated” from its planned route, while international leaders have called for an investigation.
DEEP AND DARK WEB INTELLIGENCE
DarkForums user Jack_back: Untested threat actor "Jack_back" has advertised a database associated with the U.S. Social Security Administration on DarkForums. The database reportedly comprises 21 million records, including financial and other personal information. It is likely that impacted individuals face additional attacks like phishing, extortion, and identity theft.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-47949: This critical authentication bypass vulnerability in SAML implementations, enables attackers to impersonate administrative users by injecting unsigned malicious assertions into otherwise legitimately signed SAML responses. It can lead to unauthorized access to sensitive systems, data breaches, and complete compromise of affected applications.
Affected products: All versions of Samlify before 2.10.0
CVE-2025-36535: This missing authentication vulnerability in AutomationDirect’s Modbus (MB) Gateway devices enables possible remote attacks and configuration changes directly through the internet. A hacker is likely to gain unrestricted remote access to devices and move laterally across a network through this bug. Critical infrastructure entities are likely to be targeted through this vulnerability.
Affected products: All versions of MB-Gateway
Tags: DIB, tlp:green