DTI finds an actor using the Google Play Store to install malware delivery sites disguised as legitimate payment and government identity applications for users in Southeast Asia. Read the post at the link below ⬇️
https://t.co/d9B7TtkDMn
#Cybersecurity#ThreatIntel#Cybercrime
New research raises questions about PoisonSeed using TTPs similar to SCATTERED SPIDER. The DTI team identified 21 new malicious domains spoofing SendGrid & using fake Cloudflare CAPTCHAs to harvest credentials:
https://t.co/FxAxbaLp8D
#ThreatIntel#PoisonSeed#SCATTEREDSPIDER
🚨 Threat intel goldmine 🚨
The "Kim" leak exposes a DPRK APT expanding operations into Taiwan and targeting identity systems. Our analysis provides IOCs and defensive guidance for nation-state analysts and SOC teams: https://t.co/XrmALkyNkl
#ThreatIntelligence#Kimsuky
A new #SpyNote report is out! 🚨 Dive into the tactics of this Android RAT campaign, from dynamic payload decryption to new obfuscation methods. Learn how threat actors are using deceptive Google Play Store clones to target users:
https://t.co/sPujkpc524
Recent DTI research tracked a trojan using hosted PowerShell scripts, uncovering bulletproof hosting services and how #LummaStealer remains a threat.
Read the full report: https://t.co/3gmdfaxRNz
#Cybersecurity#ThreatIntel#Malware#BlueTeam
DPRK IT workers infiltrate global remote companies via forged identities, siphoning millions to fund North Korea's weapons. A critical insider threat risking IP theft & espionage. Get essential intel:
https://t.co/PKq5X3XwVm
#threatintelligence#cybersecurity#infosec
ICYMI: Skeleton Spider (FIN6) is using trusted cloud services like AWS to deliver malware via fake resumes & job lures. Social engineering meets stealthy infrastructure. Learn more here: https://t.co/u9nFaGxAAM
"In a twist on typical hiring-related social engineering attacks, the FIN6 hacking group impersonates job seekers to target recruiters, using convincing resumes and phishing sites to deliver malware." Read more from @BleepinComputer here: https://t.co/EjS0q5GuKF
"The financially motivated threat actor known as FIN6 has been observed leveraging fake resumes hosted on Amazon Web Services (AWS) infrastructure to deliver a malware family called More_eggs." Read more from @TheHackersNews here: https://t.co/I4QAEA9qlN
FIN6 (Skeleton Spider) is using AWS & fake resumes to deliver malware via trusted job platforms.
⚠️ Realistic lures
🕵️♂️ Cloud-hosted phishing
🥚 More_eggs backdoor
Read the full analysis here: https://t.co/e3ga3XMKfQ
🚨 Watch your clipboard!
A fake DocuSign site tricks users into running malware with a sneaky PowerShell script—copied via CAPTCHA.
✔️ Clipboard poisoning
✔️ Fake Gitcode & DocuSign sites
✔️ NetSupport RAT deployed
👀 Learn how it works → https://t.co/Cb3KjDHjPm
Key tactics include:
🔹 Clipboard poisoning via fake CAPTCHA pages
🔹Multi-stage PowerShell downloaders
🔹Spoofed Gitcodes and Docusign domains
🔹Infrastructure overlap with known threat groups like SocGholish, FIN7 and STORM-0408
DomainTools Investigations’ (DTI) latest analysis uncovers a technically sophisticated malware campaign that uses fake CAPTCHAs and spoofed document verification pages to trick users into self-infecting their machines with the NetSupport RAT.
https://t.co/CEYlv5bKtf
🎵 Newsletter No. 5 is here!
Daniel Schwalbe, CISO @DomainTools, shares the latest on:
🔹 VenomRAT via fake sites
🔹 Malicious Chrome extensions
🔹 Exploiting viral media events
Read the full scoop 👉 https://t.co/PdvEv74DYW
What do cats have to do with Lumma C2 malware?
Some domains linked to the infostealer use a landing page titled “About Cats” 🐱
How many domains? Avg risk score? IOC overlaps?
🔗 Read more: https://t.co/VTdpLvUVK2
ICYMI!
Ian Campbell's latest Recommended Reading list is out. This edition features @MaltegoHQ's Human Element Podcast hosted by @bapril!
Learn more and see Ian's other Recommended picks here: https://t.co/NZPLSwyul7
"The attackers used websites that mimicked popular brands to trick users into installing the apps that had been laced with malware designed to steal passwords and digital wallets." Read more from @Forbes here: https://t.co/1bs7Qot5Ua
🚨 Hackers built a fake Bitdefender site to push Venom RAT—stealing passwords, crypto, and control.
Behind it? A stealthy combo of open-source tools, MFA bypass tricks, and real-time phishing tactics. You won’t believe what they’re exploiting now.
Read: https://t.co/hodaZnky4Z