Malware researcher exploring malware, APT groups, and their campaigns across the wild. | Threat Researcher @dexpose_io | GREM | Blog Author @anyrun_app
Hola
مساء الخير
ME & @M4lcode published Part 2 of our investigation into Lawxsz, the Argentinian threat actor behind the Valkyrie and Prysmax stealers.
What initially appeared to be fragmented online identities across Telegram, GitHub, Discord, forums, and other platforms ultimately revealed a much larger operational footprint through deep infrastructure correlation, alias analysis, breach intelligence, and OPSEC failures.
In this part of the investigation, we focused on:
* Mapping interconnected aliases and personas
* Tracking reused identifiers
* Correlating breach data and underground activity
* Analyzing attribution-relevant operational mistakes
* Linking historical and current identities tied to the actor
This research demonstrates how seemingly disconnected artifacts can be combined into a coherent attribution picture when viewed through multi-vector intelligence analysis.
In Arabic :
فريق dexpose باستخدام Investigation Portal الخاص بـ Dexpose و ال osint قدرنا نكشف واحد من أنشط مطوري الـ Stealers حالياً.Lawxsz هو المطور الرئيسي لي Valkyrie Stealer
Prysmax Stealer
تم تتبعه بشكل كامل بعد تحقيق OSINT طويل شوية ووضحنا بالتفصيل إزاي وصلنا للداتا دي خطوة بخطوة.في التقرير هتلاقوا:هويته الحقيقية
أخطاء OPSEC اللي وقع فيها
Read the full research here::
https://t.co/Q6Z6kXdnLB
🚨 #Lazarus APT has weaponized new malware to hunt C-level credentials
This campaign poses a direct financial and business risk, bypassing detection to steal executive data via fake meeting invites ❗️
Check @MauroEldritch's breakdown for defense steps 👇
https://t.co/HA8BcX0i5M
❗ macOS VM is now live ❗
25K+ U.S. businesses already run on macOS. Yet #macOS threats remain a blind spot for many SOC teams.
👇 Close this gap now with a broader cross-platform threat visibility for faster and confident response!
https://t.co/dyM8gqVYQ0
⚠️ New ransomware #BQTLock & #GREENBLOOD are actively targeting businesses.
Stealth, rapid encryption, and leak-site pressure leave SOC teams little time to react.
Check out detailed analysis and an actionable plan to detect them before downtime ⬇️
https://t.co/FSrvaHo170
🚨 #Phishing on Trusted Cloud Infrastructure: Google, Microsoft, Cloudflare.
We��re tracking a growing trend where phishing kit infrastructure is hosted on legitimate cloud and CDN platforms, not newly registered domains. In some cases, these campaigns specifically target enterprise users. This creates serious visibility challenges for security teams.
We’ve observed this pattern across multiple #phishkits:
🔹 #Tycoon hosted on alencure[.]blob[.]core[.]windows[.]net (Microsoft Azure Blob Storage): https://t.co/7jZBu2c14l
⚠️ #Sneaky2FA hosted on legitimate cloud platforms, filtering out free email domains via a fake Microsoft 365 login to target corporate accounts:
firebasestorage[.]googleapis[.]com (Cloud Storage for Firebase): https://t.co/TP06kgZ6Im
cloudfront[.]net (AWS CloudFront): https://t.co/4YtSW0eMr8
🔹 #EvilProxy hosted on sites[.]google[.]com (Google Sites): https://t.co/SWveDgJXXS
Victims see a “trusted” provider domain, while the network only sees normal HTML being loaded from cloud infrastructure. What looks clean at first glance is exposed by #ANYRUN Sandbox in under 60 seconds, directly reducing MTTD and MTTR.
🔍 Hunt for related activity and pivot from #IOCs using these search queries in TI Lookup:
🔹 Microsoft Azure Blob Storage abuse: https://t.co/l0dlau3eos
🔹 Firebase Cloud Storage abuse: https://t.co/7ju1Ap0bpN
🔹 Google Sites abuse: https://t.co/O3hZPUB3gk
Many security vendors will flag these domains as legitimate. Technically, they are. That’s why security teams need behavioral analysis and network-level signals to reliably uncover phishing before impact.
🚀 Speed up detection and gain full visibility into complex threats with #ANYRUN. Sign up: https://t.co/b0Bq82LxYI
#ExploreWithANYRUN
#IOCs:
mphdvh[.]icu
kamitore[.]com
aircosspascual[.]com
Lustefea[.]my[.]id
🔴 LIVE from inside #Lazarus APT's IT workers scheme.
For weeks, @BirminghamCyber & @north_scan kept #hackers believing they controlled a US dev's laptop. In reality, it was our sandbox recording everything.
See full story and videos ⬇️
https://t.co/gRb7GKIERQ
👀 OpenSource Malware an open database for tracking malicious open-source packages from npm, PyPI, GitHub repos!
Great source of intel feed for supply-chain attacks! 👇
https://t.co/y6ELpxxX1S
The report covers:
Motivations & Objectives
Targeted Regions & Sectors
Malware & Toolset
Attack Techniques
Recent Activity
Critical Vulnerabilities Exploited
Law Enforcement Actions and Indictments
Suspected Ransomware Activity
False-Flag Identity on Twitter/X
MITRE ATT&CK®
IOCs
Just published a deep dive into APT27 (Emissary Panda/Iron Tiger/Lucky Mouse), a Chinese state-sponsored cyber-espionage group active since 2010, known for spear-phishing, watering-hole attacks and exploitation of internet-facing applications.
https://t.co/xNurajdGrq
As-salamu Alaykum
I wrote 3 #yara rules about #RedLine stealer , #ArrowRAT, and #MilleniumRat.
RedLine:https://t.co/4WhbAL84zn
ArrowRAT:https://t.co/MvhsQ3JXJ3
MilleniumRat:https://t.co/ThLEmKlTto