🚨 New Blog: *Kimsuky: A Gift That Keeps on Giving* 🎁
Explore Kimsuky APT's multi-stage infection chain using LNK files, VBS scripts, and C2 communication. See how this DPRK threat actor evolves.
🔗 https://t.co/RshpYDK1RR
#Kimsuky#APT#Malware#DPRK
New supply chain threat uncovered
CloudSEK TRIAD found an npm campaign using crypto-javascri, a typosquatted package impersonating crypto-js.
It steals npm/GitHub credentials, hijacks maintainer accounts, and uses Tor-based C2 to stay harder to disrupt.
https://t.co/akr2RpJeDg
🚨 New Research Alert: Inside the RedSun Windows 0day
A closer look at why this vulnerability exists and how Defender’s own logic enables the system compromise.
Read more:
https://t.co/3P4XWbGueJ
h/t @WeirdQuadratic 🐐
#Windows#RedSun#0Day
🚨 New Research Alert: Inside the RedSun Windows 0day
A closer look at why this vulnerability exists and how Defender’s own logic enables the system compromise.
Read more:
https://t.co/3P4XWbGueJ
h/t @WeirdQuadratic 🐐
#Windows#RedSun#0Day
Here's the exploit in action, using the RedSun PoC
(note this is demostrated in virtual machines and this is purely for educational purposes, please don't repilcate the exploit on any systems you are not permited to do so)
CloudSEK Triad has published a detailed investigation into the RAMP cybercrime forum, covering its operations and working from 2021 through its seizure by the FBI in January 2026.
Read the full report: https://t.co/8SXZDf4K8n
Sergey Mineev was the greatest APT hunter of all time. He sought no glory, he just loved the hunt. And his discoveries repeatedly redefined our collective knowledge of global cyberespionage.
🚨Recent MuddyWater APT campaign, linked to Iranian intelligence, exposed by Ctrl-Alt-Intel 😬
- 10+ CVEs used
- Custom-developed C2s
- EtherHiding malware
- Sensitive data stolen
https://t.co/T7ppLU9M8C
Super fun collab-ing with @ice_wzl_cyber to get this published 🔥
Excited to share my latest research on APT37 (aka ScarCruft) and their evolving campaign targeting so-called "isolated" networks through a carefully orchestrated multi-stage infection chain.
Key findings:
▶️Ruby-based loader: APT37 is deploying full Ruby runtimes with trojanized script to blend execution within legitimate environments.
▶️USB dead-drop technique: A refined removable media workflow bridges air-gapped segments, leveraging hidden directories to stage tasking and exfiltrate data.
▶️Cloud C2 evolution: The group has expanded its cloud abuse playbook, incorporating Zoho WorkDrive as an operational command-and-control channel.
In this research, I detail the full intrusion lifecycle from the initial LNK lure to the deployment of the surveillance backdoors with technical breakdowns.
Blog: https://t.co/usDMqBmQRn
Chinese SEO's are apparently also scared of "Silver Fox", which is supposed to be a Chinese APT: 防止银狐等病毒群发诈骗领导和同事 ( "Prevent silver fox and other viruses from sending out mass fraud to defraud leaders and colleagues" ).