@GossiTheDog I am in Microsoft from past 3 years and have worked in Accenture McAfee and intel but I can tell for sure the growth and culture I have seen here is awesome and the exposure we get here has no limits. I hope we. Kyle have worked together more and learned from each other
Today we are releasing a new blog and technical information regarding TTPs & new malware families observed during previously disclosed #NOBELIUM phishing campaigns we have observed/tracked since as early as Jan 2021.
https://t.co/Cd7DEdGIwl
Thread on the new families & TTPs ⬇️
@DebugPrivilege Hi i am on the same team aka Microsoft Threat Experts with @BakedSec Austin and I am happy to help in case of any questions regarding service ☺️
We're sharing the CodeQL queries that we used to analyze our source code at scale and rule out the presence of the code-level IoCs and coding patterns associated with Solorigate https://t.co/x8G4naSPhC
Here's our analysis of the compromised DLL that led to the Solorigate attack. While the extent of the compromise is being investigated, we want to continue providing the defender community with intel, remediation guidance, and protections we have built: https://t.co/hBCXKydwdI
MSTIC has observed activity by the nation-state actor MERCURY using the CVE-2020-1472 exploit (ZeroLogon) in active campaigns over the last 2 weeks. We strongly recommend patching. Microsoft 365 Defender customers can also refer to these detections: https://t.co/ieBj2dox78
We found a piece of a particularly sophisticated Android ransomware with novel techniques and behavior that exemplify the rapid evolution of mobile threats, surfacing its ransom note using methods we haven’t seen leveraged by malware before: https://t.co/d7GdEKZG7b
Microsoft took action against the Trickbot botnet, disrupting one of the world’s most persistent malware operations. In this blog, we detail the evolution of Trickbot, associated tactics, recent campaigns, and dive into the anatomy of a specific attack. https://t.co/AWhEIZHxgK
India was among the countries with the highest cryptocurrency mining encounters and drive-by download attacks in 2019, according to Microsoft's Security Endpoint Threat Report. https://t.co/8sDfO1O5wd #Cybersecurity https://t.co/Hj6xoefNK8
Our researchers are tracking a phishing infrastructure that’s being used to launch phishing attacks targeting enterprises. The campaign is notable for its use of HTML attachments that pose as Excel files and contain encoded information about targets, indicating prior recon.