Fun crossover blog about TA829 (RomCom) & TransferLoader with my ecrime pals it’s got everything:
🛰️ Popped routers for sending phish
📊 ACH on attribution
👾 custom protocols
👽 cool malware
🕵️ crime
🎯 espionage
❔many unanswered questions
https://t.co/f0AzNT1pE3
Fun blog from @greglesnewich and team. Come for the great title, stay for the excellent analysis highlighting some strange overlaps and unanswered questions.
@greglesnewich Been looking forward to this for a long time! What a crew to join, getting to learn from and work with some of the best 💪🏼
Time to run it up 😮💨🙏🏻
This was the most important tough love keynote CTI has needed to hear and desperately needs to digest, otherwise “…reorgs will continue until perception of value improves” (h/t @invisig0th) #PIVOTcon24#TheFanciestBear
Officially looking for work in the CTI space. Happy to have a chat about roles!
I’ve been a power user of Synapse from @vtxproject for over a year in an enterprise setting as well.
Here is my demo of the VM escape exploit on the latest version of VMware Fusion along with ESXi and Workstation. It was used to participate in GeekPwn 2022 and won the championship.
BREAKING - Dutch intelligence services say they prevented a Russian spy from accessing the International Criminal Court in the Hague as an intern. The man was working under a Brazilian identity but actually belonged to the GRU - @AFP
#threatintel 🧵: In scenarios where cyber threat activity that is relevant to your org overlaps with geo-political tensions, it is important to clearly distinguish the parts of your assessment that are uniquely yours, and those you derive from other sources (1/x)
There are several Twitter search operators one can use, such as these two:
1. within_time:3h
2. filter:news
e.g. "Merkel" within_time:3h filter:news -> will give you Tweets with "Merkel" from the last 3 hours & a link to a news article. Give it a try.
#OSINT#research#news
New TAG post on Countering Threats from Iran https://t.co/ZIVSArh5P1
Aim is to provide some new details on what Ajax and the team discovered and blocked from APT35 (also known as Rocket Kitten and some other names)