ZeroFox Weekly Intelligence Brief – May 24, 2025
|by Alpha Team

ZeroFox Weekly Intelligence Brief – May 24, 2025
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the threat landscape, including digital, cyber, and physical threats. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 6:00 AM (EDT) on May 22, 2025; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
Flaws in Webmail Products Exploited in Cyber Espionage Campaign
What we know:
- State-sponsored hackers are running a cyber espionage campaign dubbed “RoundPress,” exploiting zero-day vulnerabilities in multiple webmail products like Zimbra, RoundCube, Horde, and MDaemon to target high-value government entities.
- Russian state-sponsored threat group “APT28” (also known as "Fancy Bear" or "Sednit") is suspected to be behind the campaign.
- Government, military units, and critical infrastructure in Ukraine, Romania, Greece, Serbia, Ecuador, Bulgaria, and Cameroon have been targeted since at least 2023.
U.S. Justice Department Seizes Domains Behind Major Information-Stealing Malware Operation
What we know:
- The Justice Department has unsealed two warrants to seize five internet domains used in operations associated with the LummaC2 information-stealing malware service. Meanwhile, Microsoft's Digital Crimes Unit (DCU) filed a legal action against Lumma Stealer after finding 400,000 Windows computers infected by the malware globally.
Peter Green Chilled Joins Growing List of UK Retail Cyber Victims
What we know:
- Peter Green Chilled, a major UK food distributor, has been hit by a ransomware attack, disrupting deliveries to supermarkets and small businesses.
Tags: tlp:green