@nas_bench@cyb3rops@SecurityAura Code as screenshots sometimes makes sense to avoid your report triggering overzealous AVs. The rest is true. IPs should always half first seen/last seen.
@iblametom Red teams using it and criminals using it is not mutually exclusive (and Crowdstrike never said it was criminal here, a RT is a threat actor). There are well documented cases of known APT and criminal groups using Brute Ratel C4.
@godslittlemacro@ImposeCost What came to mind for me was things like malware/infrastructure/exploit supply chains that are not necessarily part of the direct operational team.
@ImposeCost Not directly related to intelligence (but touches on it at times), but "Once Upon a Time in Northern Ireland" docuseries by the BBC is fantastic and the best if you're looking to learn about the history of The Troubles more.
@lordx64 This is my last reply as this is going in circles and you're constantly changing your argument. They're claiming it's likely a CN APT. They're not claiming that due to observed minimal overlap with Violet Typhoon as you keep saying. You're misunderstanding that part of the report
@lordx64 It could mean they use shared infrastructure procurement anonymization networks but are distinct groups (something extremely common among CN APTs). Distinct groups can still have overlap for this reason. They should have been more specific in what the observed overlap was. (2/2)
@lordx64 They're quite clearly not claiming that because of observed minimal overlap with Violet Typhoon therefore STORM-0558 is Chinese APT like you're suggesting. "Minimal overlap" can mean lots of things. (1/2)
@lordx64 Yes, rereading your other reply to another user in this thread I think you're misunderstanding what they are saying regarding this minimal overlap part.
@lordx64 It's just saying it's likely a distinct activity group to Violet Typhoon but acknowledging some minimal degree of overlap (which is very common among Chinese APTs due to shared infrastructure and other procurement chains). Really struggling to understand your point around that.
@lordx64 The piece is clearly not intended to lay out all of their country attribution evidence as you seem to be insinuating. You've also left out the historical targeting of Uyghur and Taiwan-linked entities specified in the blog.
@SecuritySphynx@sherrod_im @d4vesgrill I like the multilayer categorisation but I think names still need to be easy to say out loud for internal/external oral briefings (and just general conversation with coworkers).
@cisonaut@ImposeCost Actor says ok well I'll just not use malware then and then industry doesn't report on them because they only know how to look for malware. Actor happy. (2/2)
@cisonaut@ImposeCost Industry prioritizes looking for new shiny malware families that actors take ages developing to the detriment of other collection methods and report on them constantly. Actor sad. (1/2)