zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - May 26, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - May 26, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Operation ENDGAME Strikes Again with Ransomware Kill Chain Broken at Its Source
  • FBI Warns of Threat Actor Targeting Law Firms
  • Hackers Steal USD 223 Million from Cetus Protocol on Sui Blockchain

Operation ENDGAME Strikes Again with Ransomware Kill Chain Broken at Its Source

Source: https://www.europol.europa.eu/media-press/newsroom/news/operation-endgame-strikes-again-ransomware-kill-chain-broken-its-source

What we know: A global operation coordinated by Europol and Eurojust has dismantled ransomware infrastructure, taking down 300 servers, neutralizing 650 domains, issuing 20 arrest warrants, and seizing EUR 3.5 million (approx. USD 3.9 million) from May 19 to May 22, 2025.

Context: The operation targeted initial access malware—tools that enable cybercriminals to infiltrate systems undetected. Disrupted malware strains include Bumblebee, Lactrodectus, Qakbot, Hijackloader, DanaBot, Trickbot, and Warmcookie.

Analyst note: By disrupting the entry points of the ransomware kill chain, the operation likely weakened the cybercrime-as-a-service ecosystem. This disruption is likely to make it difficult for cybercriminals to launch ransomware, potentially reducing the risk and damage for businesses and individuals worldwide.

FBI Warns of Threat Actor Targeting Law Firms

Source: https://hackread.com/fbi-silent-ransom-group-law-firms-via-scam-calls/

What we know: The FBI is warning of threat actor Luna Moth targeting law firms using social engineering calls and callback phishing emails, to gain remote access to systems or devices and steal sensitive data to extort the victims.

Context: The actor has developed a publicly available site to post victim data; however, they are inconsistent in their use of the site and do not always follow through on posting victim data.

Analyst note: Luna Moth is likely targeting law firms because they manage sensitive data across multiple industries, involving intellectual property, case details, business strategies, and personal client information.

Hackers Steal USD 223 Million from Cetus Protocol on Sui Blockchain

Source: https://www.bleepingcomputer.com/news/security/hacker-steals-223-million-in-cetus-protocol-cryptocurrency-heist/

What we know: Hackers have stolen USD 223 million in cryptocurrency from decentralized exchange (DEX) Cetus Protocol operating on the Sui and Aptos blockchains.

Context: Cetus Protocol has paused its smart contract and the USD 162 million of the stolen funds. Hackers reportedly exploited a vulnerability in Cetus’s smart contract which led to flash loan-style attacks. The crypto project has also announced a USD 5 million bounty for information on the hackers.

Analyst note: There is a roughly even chance that the hackers will accept the white-hat settlement offered by Cetus Protocol since their transactions are being tracked. In the short term, the DEX’s investors are likely to move to other platforms, causing CETUS to lose its value.

DEEP AND DARK WEB INTELLIGENCE

Adidas data breach: German sportswear maker Adidas reported that an unauthorized external party gained access to certain consumer data through a third-party customer service provider. The company clarified that no passwords or credit card information was compromised. The breached data primarily included contact information of consumers who had previously reached out to its customer service help desk. This breach will likely expose individuals to phishing or other scams.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-20152: This already-patched vulnerability in Cisco’s Identity Services Engine (ISE) affects its RADIUS message processing feature. An attacker is able to exploit the bug by sending a specific authentication request to a network access device (NAD), leading to a denial-of-service (DoS) condition. The vulnerability is likely to be used by threat actors, especially politically motivated actors, to carry out distributed denial-of-service (DDoS) attacks targeting critical infrastructure entities.

Affected products: Cisco ISE configured with RADIUS authentication services

Tags: DIB, tlp:green