ZeroFox Weekly Intelligence Brief – December 27, 2025
|by Alpha Team

ZeroFox Weekly Intelligence Brief – December 27, 2025
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the threat landscape, including digital, cyber, and physical threats. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 6:00 AM (EDT) on December 25, 2025; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
Major Ransomware Attack on Romanian Water Management Authority
What we know:
- Romania’s cybersecurity agency has confirmed a ransomware attack targeting approximately 1,000 IT systems in regional water administrative units.
- While the ransomware attack affected the Geographic Information System (GIS) server, databases, email, web services, Windows workstations, and other systems, services remained unaffected.
United States Charges 54 Individuals for ATM Jackpotting Using Ploutus Malware
What we know:
- The U.S. government has accused 54 individuals of stealing millions of dollars through Automated Teller Machine (ATM) jackpotting, a type of cyber and physical attack, in the United States.
- The accused individuals are allegedly linked to Venezuelan terrorist organization Tren de Aragua (TdA).
Malicious Npm Package Snoops on WhatsApp Chats, Steals Credentials
What we know:
- A malicious npm package called “lotusbail”, designed as a fully functional WhatsApp Application Programming Interface (API), has been found capable of stealing WhatsApp credentials, intercepting messages, harvesting contacts, and ensuring persistent access.
Tags: tlp:green