ZeroFox Daily Intelligence Brief - May 29, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - May 29, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - Comprehensive Ponzi Scheme Platform Advertised for Sale
- Czech Accuses China of Cyber Espionage Targeting its Foreign Affairs Ministry
- Hacker Gains Access to LexisNexis Data via Third-Party Platform
ZeroFox Intelligence Flash Report - Comprehensive Ponzi Scheme Platform Advertised for Sale
Source: https://www.zerofox.com/advisories/33457/
What we know: Actor “d3fn0d3” has advertised the sale of a “complete investment platform” designed to facilitate a Ponzi scheme on predominantly Russian-speaking deep and dark web (DDW) forum Exploit.
Context: The platform reportedly includes features and services, such as access to a dashboard feature, verified logins for numerous payment platforms, and established know-your-customer (KYC) protocols.
Analyst note: ZeroFox has observed that the platform offers comprehensive features that could allow even low-skilled buyers to launch fraudulent schemes with minimal effort. Buyers could also customize the platform to fit their specific goals, such as adjusting the branding, language, and payment systems.
Czech Accuses China of Cyber Espionage Targeting its Foreign Affairs Ministry
What we know: The Czech Republic has blamed China-sponsored cyber espionage advanced persistent threat group APT31 for targeting a network at its Foreign Affairs ministry.
Context: The “malicious cyber campaign” was ongoing since 2022. APT31 has also been linked to cyberattacks on the Finnish parliament and Joe Biden’s U.S. presidential campaign. The United States has sanctioned two operatives of APT31.
Analyst note: The Czech Republic’s diplomatic reproach is unlikely to curtail the activities of APT31. However, NATO cooperation over APT31 is likely to make it difficult for the group’s operatives to travel to these countries.
Hacker Gains Access to LexisNexis Data via Third-Party Platform
What we know: LexisNexis Risk Solutions has disclosed a data breach affecting over 364,000 individuals, in which a hacker accessed sensitive personal data through a third-party software development platform.
Context: LexisNexis is a data broker that collects and uses personal consumer data to help corporate clients assess risks and detect fraud. The breach has occurred via an intrusion into the company's GitHub account.
Analyst note: The breach exposed sensitive information, including Social Security numbers (SSNs) and driver’s license details, putting customers at risk of identity theft and fraud. The compromised data could also be sold in dark web forums.
DEEP AND DARK WEB INTELLIGENCE
Victoria’s Secret cybersecurity incident: American retailer Victoria’s Secret has revealed that it suspended its website functionality and some in-store services over an undisclosed security incident. A ransomware attack is likely behind the incident. The incident follows a series of ransomware attacks targeting multiple retail and luxury outlets across the United Kingdom.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-32432: This previously patched remote code execution vulnerability in Craft content management system (CMS) enables attackers to execute arbitrary commands on affected systems. It has been exploited to deploy multiple payloads and proxyware, while establishing persistence on affected devices. Establishing persistence on these devices could enable threat actors to mine for cryptocurrencies, harvest sensitive information, and more.
Affected products: Craft CMS
Tags: DIB, tlp:green