ZeroFox Daily Intelligence Brief - June 2, 2025
|by Alpha Team

ZeroFox Daily Intelligence Brief - June 2, 2025
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - U.S. Property Data Advertised for Sale on Dark Web Forum
- ZeroFox Intelligence Flash Report - Web Page Shares Personally Identifiable Information of CEOs
- International Law Enforcement Seizes AVCheck, Disrupting Malware Testing Service
ZeroFox Intelligence Flash Report - U.S. Property Data Advertised for Sale on Dark Web Forum
Source: https://www.zerofox.com/advisories/33543/
What we know: An actor, using the alias “Sentap,” has advertised 1.02 terabytes of property data on predominantly Russian-speaking dark web forum xss.
Context: Sentap claimed to have obtained "unprecedented" access to this data from the cloud infrastructure of a U.S.-based title company that specializes in property record search services.
Analyst note: Purchasing this information likely poses a physical threat to individuals and organizations linked to the exposed properties. Threat actors could exploit this data to stalk victims, commit burglary, and carry out financial scams for greater financial gains.
ZeroFox Intelligence Flash Report - Web Page Shares Personally Identifiable Information of CEOs
Source: https://www.zerofox.com/advisories/33560/
What we know: ZeroFox has observed a web page theceodatabase[.]com, which hosts a publicly accessible database of personally identifiable information (PII) associated with over 1,000 corporate executives.
Context: A person or group with an affinity for the suspect alleged to have murdered a United Health Care CEO promoted the database. As of this writing, the site is offline—but an archived version remains, which could expose an executive's PII to determined users.
Analyst note: The database consolidates already publicly available contact information in one place—including executive names, job titles, company affiliations, LinkedIn profiles, and in many cases, mobile phone numbers. It is likely to be misused for harassment or targeted intimidation.
International Law Enforcement Seizes AVCheck, Disrupting Malware Testing Service
What we know: An international law enforcement operation has taken down AVCheck, a major cybercriminal tool for testing malware against antivirus software.
Context: AVCheck enabled cybercriminals to fine-tune malware to evade detection before deployment. Its domain was seized as part of Operation Endgame and now displays banners from U.S. and Dutch authorities.
Analyst note: AVCheck provided cybercriminals with an environment to test and improve their malware's ability to evade antivirus detection before deployment—likely helping them carry out stealthier attacks. Its takedown dismantles a behind-the-scenes tool essential to malware development.
DEEP AND DARK WEB INTELLIGENCE
DarkForums user Often9: Untested threat actor “Often9” has advertised databases associated with TikTok on DarkForums. The breached data allegedly contains 428 million records, including user id, username, email, profile url, and avatar url. This will likely put users at risk of identity theft, phishing attacks, and other forms of online fraud.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2025-48827 and CVE-2025-48828: These two critical vulnerabilities in vBulletin could enable attackers to execute arbitrary code remotely, taking full control of affected vBulletin servers, stealing user data, and deploying malware. CVE-2025-48827, confirmed to be actively exploited, enables actors to exploit crafted URLs to invoke protected methods and abuses template conditionals in vBulletin's template engine.
Affected products: vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3
Tags: DIB, tlp:green