Pivoting on the JDY C2 proxy cert hash in https://t.co/C2j3umgWeI shows an IP, 45.76.67.43, that was not listed in Lumen's IOC list. Though it looks like it was only active for 2 days and has since been recycled back into Vultr.
https://t.co/CGKjxVFmPH I am happy to be an advisor, aka Keeper of Secrets to @ThreatHunter_AI and working with @whiskeyhacker. Watch for great things to come.
https://t.co/HYyKDnSiWu the base for a repo for low power tracker research. Expect more to be added. Great research sponsored by @cybraryIT! #flipperzero#ble#airtag
New Research -- "Tainted Love" APT Operation
✴️Targeting Middle East telecom.
✴️ Likely connected to a Chinese groups in the nexus of Gallium and APT41.
Full Report: https://t.co/SWnqTXiAKk
By @milenkowski@juanandres_gs@joeychen@QTrust
Today we’re releasing research on brand new activity cluster we’re calling Hiatus. This actor has an affinity for target routers, to gather pcap and use as covert infrastructure.
Oh and one more thing that caught my eye, when we looked at the embedded config file the malware identified itself as version 1.5. So while this latest campaign goes back to July 2022. This activity cluster almost certainly preceded that date.
Setting up an account on the elephant app, hit me up there [email protected]. Don’t worry I’ll continue to provide the same threat intel, salty comments, and spicy memes as before.