May 5, 2025

Monthly Threat Digest APRIL 2025

For a detailed threat digest, download the pdf file here



In April, the cybersecurity arena drew significant attention due to the active exploitation of nine zero-day vulnerabilities. Among them, Apple patched two zero-day vulnerabilities (CVE-2025-31200, CVE-2025-31201) used in targeted attacks. The flaws affect iPhones, Macs, iPads, Apple TVs, and Vision Pro, allowing potential code execution or security bypass.

During this period, ransomware attacks surged, with variants such as Hellcat, PlayBoy Locker, DOGE BIG BALLS, Interlock, CrazyHunter, and Cactus aggressively targeting victims. As ransomware tactics grow more sophisticated, organizations must bolster their defenses by implementing comprehensive backup and disaster recovery strategies. Additionally, training employees to detect and prevent phishing attacks remains essential.

The Lazarus group’s “Operation SyncHole” targets South Korean industries using exploits and watering hole attacks, deploying malware like ThreatNeedle and SIGNBT. The campaign highlights their evolving tactics to infiltrate supply chains and deepen network access.

Concurrently, eleven threat actors have engaged in various campaigns. The China-linked APT group known as Earth Alux is stirring the cyberespionage landscape with nearly undetectable intrusions. This group has set its sights on strategically vital sectors across the Asia-Pacific and Latin American regions. At the same time, the ToddyCat APT exploited CVE-2024-11859 in ESET’s command-line scanner by using DLL proxying and a custom tool (TCESB) to stealthily load malicious code and manipulate kernel structures. As the cybersecurity landscape evolves, organizations must remain vigilant and proactively address emerging threats.



Subscribe to keep up on a weekly basis with our weekly threat digests and newsletters.

Recent Resources

Dive into our library of resources for expert insights, guides, and in-depth analysis on maximizing Uni5 Xposure’s capabilities

Book a demo and find out more about how Hive Pro can double your operational efficiency

Book a Demo