zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - May 30, 2025

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - May 30, 2025

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • U.S. Sanctions Philippines Tech Company Over Pig Butchering Scams
  • 1.8 Million Individuals Affected by 2024 Data Breach
  • Chinese APT41 Compromises Government Networks Using Cloud-Based Malware

U.S. Sanctions Philippines Tech Company Over Pig Butchering Scams

Source: https://home.treasury.gov/news/press-releases/sb0149

What we know: The United States has sanctioned a Philippines-based company, Funnull Technology Inc., for facilitating virtual currency investment scams, also known as “pig butchering” or “romance baiting” resulting in over USD 200 million in losses for the victims.

Context: Funnull Technology Inc. provided computer infrastructure to cybercrime websites, largely based out of Southeast Asia. The company is also linked to Chinese money laundering operations.

Analyst note: The sanctions will likely curtail the organization and its associates’ ability to acquire internet infrastructure and IP addresses from U.S. providers directly, like they did in the past.

1.8 Million Individuals Affected by 2024 Data Breach

Source: https://www.hipaajournal.com/aln-medical-management-data-breach/

What we know: ALN Medical Management has confirmed a March 2024 data breach that compromised the protected health information of over 1.8 million individuals via a third-party service provider.

Context: Sensitive data including Social security numbers (SSNs) and financial and medical details was exposed.

Analyst note: The compromised data could be used for identity theft, insurance fraud, financial scams, and unauthorized access to medical services and devices.

Chinese APT41 Compromises Government Networks Using Cloud-Based Malware

Source: https://thehackernews.com/2025/05/chinese-apt41-exploits-google-calendar.html

What we know: Chinese state-sponsored APT41 has deployed a malware strain, called TOUGHPROGRESS, using a compromised government site to target other government entities. The malware used a popular online calendar app for stealthy command-and-control (C2) operations.

Context: Each stage of the operation from decryption to payload injection deployed different malware strains. The final stage abused a popular online calendar app to exfiltrate data via event descriptions.

Analyst note: State-sponsored actors have been misusing legitimate cloud services to likely blend in with normal activity, evade detection, covertly steal data and compromise systems within trusted government networks.

DEEP AND DARK WEB INTELLIGENCE

DarkForums user elpatron85: A threat actor, named “elpatron85,” has advertised to sell data associated with Russia’s Ministry of Internal Affairs and Roskomnadzor (a federal agency for media monitoring and censorship), on DarkForums. The actor is selling the data for USD 500 each. There is a roughly even chance that the data is legitimate. If it’s legitimate, the data is likely to be used by adversarial nations for informatized warfare.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2025-22252: A missing authentication vulnerability in affected devices could enable an attacker to bypass authentication and gain full administrative access. This could lead to unauthorized modifications of configurations, data exfiltration, malware deployment, or service disruptions.

Affected products: FortiOS 7.6.0 from 7.4.4 through 7.4.6; FortiProxy from 7.6.0 through 7.6.1; and FortiSwitchManager 7.2.5

Tags: DIB, tlp:green