The 8th edition of the Proton Lifetime Charity Fundraiser is here!
🎟️ Enter the raffle for a chance to win 1 of 10 Lifetime plans
💜 Help us support 10 community-nominated organizations
🎁 NEW: We’re giving away an additional Lifetime plan through a social contest.
⬇️1/6
It’s been a busy couple of days at @Trellix, with many of our teams working through the weekend to help customers: recover from the outage, understand what went wrong at CrowdStrike, and update them on the latest adversarial intelligence.
Very difficult situation for many customers across the world. CrowdStrike support is overwhelmed. I have mobilized our Trellix Customer Support team to assist any CrowdStrike customers who need assistance with restoring their endpoints. #TrellixThrive#StandTogether
Over two years, our team analyzed & enhanced threat intelligence for Operation Morpheus. Learn about the data we shared with law enforcement to assist in the dismantling of Cobalt Strike's infrastructure from @John_Fokker, @JMarques15, & @LeandroNVelasco. https://t.co/34F2IsbZDY
In June, we debuted Ghidra scripts for analyzing Go-based malware. @Libranalysis, in collaboration with @pad0rka, updated the scripts to now include:
➡️ Support for Golang 1.20
➡️Support for MachO files
➡️Resolved to-do segments
Find the scripts here: https://t.co/vnnFNH8UP1
Despite takedown attempts in 2021, Emotet resurfaced, and threat actors continue to use it today. @TrellixARC’s @Adi_Cha_, @JCMarques15, and Raghav Kapoor explore its evolution and current TTPs. Read to learn more. https://t.co/VE5rMMqSuv
Head of Threat Intelligence @John_Fokker shares our observations on cybercriminal behavior from over a year virtually staked out in the Genesis Marketplace — these insights ultimately assisted law enforcement in the market’s takedown. Hear more. https://t.co/dh2rqYzYjl
Malware Analyst @Libranalysis provides a technical look at the “Read The Manual” (RTM) Locker gang, including a deep dive into their Windows ransomware executable, on the blog. https://t.co/DVGMazzeKx
Threat actors’ use of Microsoft OneNote to spread Qakbot marks a novel malware distribution strategy. Our researchers detail how they deobfuscated and unpacked it, and extracted its configurations. Read more. https://t.co/IpsCRI2MqK
Check out our newest blog post on linking and tracking UAC-0056 tooling through code reuse analysis.
https://t.co/SvtJBM4GEa
#threatintel#malware#graphiron
This week VMware observed ransomware actors targeting CVE-2021-21974, a remote code execution vuln allowing an attacker to exploit the OpenSLP protocol. More on the global ESXiArgs ransomware campaign on the blog. https://t.co/J14wFUMWlp
“Don’t focus on flashy visualization - choose the way that fits. We are not in a casino - sometimes a simple spreadsheet may be the best visualization of data. It needs to make sense for the user.” A reality check by @John_Fokker - @TrellixARC during #cyberconf22
Finished my presentation at @BlackHatEvents@ToolsWatch's Arsenal! Had an absolutrle blast presenting! DotDumper is now live, find it here: https://t.co/hVdrkyQQ84
We made the unfortunate decision to let go of 20% of our team. They are extremely talented, please do not hesitate to hire them. Here's a spreadsheet with their names: C:/MyDocuments/Accenture2022/bottom_20_underperformers_v6_FINAL.xlsx
Good news for the @MISPProject's user community! Now you can export your VT Graph into a MISP event (Download as>MISP Event) including all relationships and (optionally) the VT report for all the indicators.