ZeroFox Daily Intelligence Brief - May 27, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - May 27, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- SilverRat Source Code Briefly Exposed on GitHub
- Second LVMH Brand, Tiffany & Co., Confirms Data Breach
- Geopolitical Focus | Global Incidents Roundup
SilverRat Source Code Briefly Exposed on GitHub
Source: https://hackread.com/silverrat-source-code-leaked-online-you-need-to-know/
What we know: The full source code of SilverRAT, a remote access trojan (RAT), was briefly leaked on GitHub before being taken down. The leaked SilverRAT repository included its full source code, build instructions, weaponized features, and more.
Context: SilverRAT is a Middle East-linked remote access trojan sold as malware-as-a-service (maas), enabling cybercriminals with stealthy system control, cryptocurrency monitoring, and data exfiltration capabilities.
Analyst note: Cybercriminals, including low-skilled actors, could use the briefly exposed SilverRAT’s source code to create similar malware for espionage and data theft. A new variant could be created to target specific entities like governments and financial institutions, depending on the actor’s motivation.
Second LVMH Brand, Tiffany & Co., Confirms Data Breach
Source: https://www.chosun.com/english/industry-en/2025/05/26/ORM5MULB7NEM7EBUFVXHVLSB4A/
What we know: Luxury jewelry house Tiffany & Co. has informed its customers in South Korea of a data breach, becoming the second brand under Louis Vuitton Moët Hennessy’s (LVMH), after Dior, to be affected by a data breach.
Context: The breach at Tiffany & Co. reportedly occurred on April 8, 2025. The breach has exposed customer names, addresses, phone numbers, email addresses, purchase history, and internal customer ID numbers.
Analyst note: There is a roughly even chance that LVMH has been struck by a ransomware attack, or one of its vendors in the supply chain has been compromised. More LVMH brands are likely to report similar incidents in the coming days. Targeted customers are likely to be targeted by phishing and social engineering attacks by financially-motivated threat actors.
Geopolitical Focus | Global Incidents Roundup
- On May 26, a vehicle struck a crowd in the City Centre during Liverpool FC’s Premier League victory parade injuring nearly 50 people.
- At least 54 Palestinians were reportedly killed in an Israeli airstrike on Gaza.
- On May 26, the Indian state of Kerala advised fishermen to avoid the site where a container ship carrying hazardous cargo sank in the Arabian Sea and issued a high alert along its coast.
- A complaint was unsealed at the federal courthouse in Brooklyn, charging an individual with attempting to destroy the Branch Office of the U.S. Embassy in Tel Aviv, Israel, using fire or explosives.
DEEP AND DARK WEB INTELLIGENCE
DarkForums user l33tfg: On May 26, 2025, ZeroFox observed untested threat actor “l33tfg” claiming to have leaked Apple App Store’s source code on DarkForums. The source code, in Objective C, can be reportedly accessed through decompiler software known as “Binary Ninja.” There is a roughly even chance of the claim being a scam intended to distribute malicious code via the links pasted on the post.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-5224: A vulnerability in Campcodes Online Hospital Management System involves an unknown function, where the manipulation of an argument leads to SQL injection. The exploit has been disclosed to the public. This vulnerability could enable threat actors to inject malicious SQL queries that manipulate the database and potentially expose sensitive user information, such as credentials and financial data.
Affected products: Campcodes Online Hospital Management System version 1.0
Tags: DIB, tlp:green