The Cyber Intelligence and Policy Project is dedicated to examining global cyber conflict through the lens of threat intelligence and legal/policy analysis
[UPDATE] We added improved detection and extraction of OLE Compound File (e.g. MSI) overlays and certificate information. Here's a recent sample as showcased in @VirusTotal @markrussinovich security vuln disclosure: https://t.co/ELtUgLgc6T
Why #WeNeedWHOIS 1:
We use WHOIS data to discover targeted phishing set up by threat actors. Example:
Iranian threat group Charming Kitten used [email protected] as registrant of 12 domains used for phishing against human rights activists.¹
¹https://t.co/m2a730fiMQ
#Unit42 examines the Reaper Group’s updated mobile arsenal, including a Bitcoin Ticker Widget and a PyeongChang Winter Games application https://t.co/QrosqH0GRr
Here the full analysis of the #MuddyWater attack.
Contains heavy anti-evasion features, also requires OS reboot.
https://t.co/Ym2KjU5Ru5
Source: https://t.co/eFvaLsmhqs
At Cyber Command, they are angry & ready, moving from the Billy Mitchell phase of development, to the Curtis Lemay. Getting in close to grapple w/ adversary cyber forces is almost certainly the right move, but incredibly risky... https://t.co/AcS9YKW42w
If it’s Sandworm, as suggested here, they were swinging for the fences just as they were being publicly blamed for the most economically damaging cyberattack in history. https://t.co/Ln2h131F9w