Top Tweets for #TA413

@FiligranHQ See how we leverage #OpenCTI (@FiligranHQ), @virustotal & @PeeringDB to map infrastructure used by #TA413 threat actor group for their campaigns, such as domains, IP addresses, file names, and hashes: https://t.co/Jh7oe7aCgw
@DomainTools See how we leverage @DomainTools #Iris and @RecordedFuture to outline the hosting infrastructure and assess risk scores of known #phishing domains run by #TA413 threat actor group: https://t.co/M29nKcgTxU
RT @OpenSpringES: El APT chino ๐จ๐ณ conocido como #TA413 ha expuesto una serie de debilidades de #SophosFirewall y #MicrosoftOffice implementando un troyano nuevo llamado #LOWZERO
#OpenSpring #ciberseguridad @unaaldia
https://t.co/Tq4EgHoqGM
El APT chino ๐จ๐ณ conocido como #TA413 ha expuesto una serie de debilidades de #SophosFirewall y #MicrosoftOffice implementando un troyano nuevo llamado #LOWZERO
#OpenSpring #ciberseguridad @unaaldia
https://t.co/MdbbuEqyjD
#Hacking #TA413 #APT #Intelligence #China #Tibet #Backdoor #Lowzero #Malware #Vulnerability #Cyberespionage #CyberCrime #CyberAttack #CyberSecurity
China-linked TA413 group targets Tibetan entities with new backdoor.
https://t.co/AMr8ZPgL0M

Chinese State-Sponsored Group TA413 Adopts New Capabilities in Pursuit of Tibetan Targets https://t.co/duGWIACmyn #ta413
Chinese State-Sponsored Group #TA413 Adopts New Capabilities in Pursuit of Tibetan Targets https://t.co/zR395SZ1Ck
(9/9) Last but not least, #OpenCTI (@FiligranHQ) in combination with #Maltego's #STIX2 (@OASISopen) Entities lets you query and explore threat intelligence data from any OpenCTI instance. We've used it to investigate #TA413 before: https://t.co/Jh7oe7aCgw
An Actively Exploited Microsoft Zero-Day Flaw Still Has No Patch | Proofpoint's APT threat research is covered by @lilyhnewman for @WIRED. #TA413 #Follina #malware #cybersecurity @threatinsight https://t.co/fOWnxcSMvA
#China-linked #TA413 group actively exploits #Microsoft #Follina #zeroday flaw.
#CyberSecurity #infosec #cybercrime
https://t.co/y9urkCSAiY

Ease of use has some less sophisticated APTs rapidly adopting the technique & pairing with pre-existing tactics. Definitely a case of evasion by obscurity w/ bad URLs, RARs, word templates, 0 days, powershell and PE stagers. But using an email they've had since 2021 SMDH #TA413
๐ก Amazing investigation on #TA413 Threat Actor Group from the @MaltegoHQ team leveraging @OASISopen #STIX and @LuatixHQ #OpenCTI platform. https://t.co/qfTZgc2rUc
In this article, we show you how to utilize #STIX2 (@OASISopen) Entities & query #OpenCTI (@LuatixHQ) #threatintel in #Maltego by investigating the Tactics, Techniques, and Procedures (#TTP) of the attack group #TA413. Learn more: https://t.co/Jh7oe7aCgw
Last Seen Hashtags on Sotwe
momson()*************************
Seen from France
nolimit()filter:native_video
Seen from Turkey
Boicest
Seen from Vietnam
GracieGates
Seen from United States
omegle
CGVId
Seen from United States
pocket pussy
Seen from United States
AuthorLife
Seen from United States
momson filter:videos
Seen from Turkey
ุณูุณ_ุณูุฏุงูู
Most Popular Users

Elon Musk 
@elonmusk
241.1M followers

Barack Obama 
@barackobama
119.1M followers

Cristiano Ronaldo 
@cristiano
112.4M followers

Donald J. Trump 
@realdonaldtrump
111.8M followers

Narendra Modi 
@narendramodi
107.1M followers

Rihanna 
@rihanna
98.1M followers

NASA 
@nasa
92.2M followers

Justin Bieber 
@justinbieber
91.3M followers

KATY PERRY 
@katyperry
88.7M followers

Taylor Swift 
@taylorswift13
82.6M followers

Lady Gaga 
@ladygaga
74.1M followers

Virat Kohli 
@imvkohli
71.5M followers

Kim Kardashian 
@kimkardashian
70.3M followers

YouTube 
@youtube
68.7M followers

Bill Gates 
@billgates
64.5M followers

Neymar Jr 
@neymarjr
64.4M followers

The Ellen Show
@theellenshow
62.4M followers

CNN 
@cnn
61.8M followers

Selena Gomez 
@selenagomez
61.8M followers

X 
@x
60.8M followers



















![threatinsight's tweet photo. TA413 CN APT spotted ITW exploiting the #Follina #0Day using URLs to deliver Zip Archives which contain Word Documents that use the technique. Campaigns impersonate the "Women Empowerments Desk" of the Central Tibetan Administration and use the domain tibet-gov.web[.]app https://t.co/4FA9Vzoqu4](https://pbs.twimg.com/media/FUGmUF5WUAQVtFf.jpg)


![sifbaksh's tweet photo. Phishing emails delivered by the TA413 attackers to their targets' mailboxes redirected them to the attacker-controlled you-tube[.]tv domain that displays a fake Adobe Flash Player Update landing page. #firefox #gmail #malware #ta413 https://t.co/AxcIvQSRZ0 https://t.co/gahAwMZhqz](https://pbs.twimg.com/media/EvKYXm4XAAY4CXu.jpg)