#ESETresearch uncovered a multiplatform supply-chain attack by the 🇰🇵 #ScarCruft APT group targeting the Yanbian region via backdoor-laced Windows and Android games. https://t.co/oNRdiQwpR0 1/6
#BREAKING#ESETresearch provides technical details on #DynoWiper, a data‑wiping malware used in a data‑destruction incident on December 29, 2025, affecting a company in Poland’s 🇵🇱 energy sector.
https://t.co/3S5nF2O27T 1/5
🚨BREAKING: We uncovered LANDFALL — a commercial-grade Android spyware exploiting a now-patched Samsung zero-day (CVE-2025-21042) through weaponized DNG images sent via WhatsApp, enabling zero-click compromise of Samsung Galaxy devices. 1/
https://t.co/hfTFP1MMX2
CNCERT confirms Operation Triangulation attacks on Chinese orgs and connects it to NewDSZ - the implant we discovered and analyzed in 2023 https://t.co/BdilsrMVbn
Zero-Day used by Stealth Falcon APT group in a spear-phishing campaign:
💥 .URL file exploitation (assigned CVE-2025-33053)
🧰 Custom Mythic implants, LOLBins, and custom payloads
🌍 High-profile targets across the Middle East and Africa
https://t.co/OnQmC2GBLJ
#ESETresearch has discovered a zero day exploit abusing #CVE-2025-24983 vulnerability in Windows Kernel to elevate privileges (#LPE). First seen in the wild in March 2023, the exploit was deployed through #PipeMagic backdoor on the compromised machines. 1/4
#PIVOTcon25#CfP is open and you can submit your proposals till 7 FEB 2025
Remember
- one track,30m
- no recording/streaming/tweeting. U should feel comfy to share more
- No TLP:WHITE
- Original content only
Let us guide u through with a little meme-thread
#CTI#ThreatIntel 1/10
#ESETresearch reveals the first Linux UEFI bootkit, Bootkitty. It disables kernel signature verification and preloads two ELFs unknown during our analysis. Also discovered, a possibly related unsigned LKM – both were uploaded to VT early this month. https://t.co/CZW6Mfm6bK 1/5
.@Volexity’s latest blog post describes in detail how a Russian APT used a new attack technique, the “Nearest Neighbor Attack”, to leverage Wi-Fi networks in close proximity to the intended target, while the attacker was halfway around the world.
https://t.co/R3aKyrjVYR
#dfir
#ESETresearch has discovered the Lunar toolset, two previously unknown backdoors (which we named #LunarWeb and #LunarMail) possibly linked to Turla, compromising a European MFA and its diplomatic missions abroad. https://t.co/VnCsGTidwr 1/6
❤️🔥!! CALL FOR PAPERS !! ❤️🔥
Submission Deadline: June 21, 2024
- Talks are 20 minutes long + 5 minutes for Q&A
- Workshops are 90 minutes long.
LABScon is primarily a threat intelligence and vulnerability research conference but we keep an open-mind.
CFP is live: https://t.co/c01fSY2eBr
Thanks to marcan (https://t.co/sDwlE7Wq6T) and @zhuowei (https://t.co/EzBvk4cNBY) now we know the original purpose for this unknown hardware feature. Its MMIO debug registers for GPU L2 cache. I am really excited that we are very close to solving this mystery!
The recording of our (me, @bzvr_, @kucher1n) #37c3 talk “Operation Triangulation: What You Get When Attack iPhones of Researchers” was published! https://t.co/j97J9TiXsC
During routine monitoring of suspicious activities on the systems of high-profile customers, #ESETresearch discovered a sophisticated and previously undocumented #StealthFalcon backdoor that we named #Deadglyph. https://t.co/SYn1Y4MXdd
@greglesnewich@ConnorSecurity@labscon_io Great presentation! It seems one clean file slipped into the IOCs c9cd5c9609e70005926ae5171726a4142ffbcccc771d307efcd195dafc1e6b4b