Unit 42 has observed #StatelyTaurus (aka #MustangPanda) used the following domains in various campaigns to enable its globally spanning espionage operations in the last 90 days: https://t.co/vFtuwuyPyj
New research from @milenkowski and @ValidinLLC
🇰🇵 Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms
Research: https://t.co/WknGevy514
Reuters story: https://t.co/hTP4qLb3PS
Here's a quick hunting query you can use to find #Clickfix fake booking sites with a tiny bit of regex in our Community Edition.
Shoutout to @JAMESWT_WT for sharing the initial domains 🔥
⚡️ New report out today from our team at @RecordedFuture: “Russian Influence Assets Converge on Moldovan Elections”
Ahead of the upcoming parliamentary elections, we touch on multiple Russia-based/linked influence operations we assess are attempting to destabilize Moldova, including:
🪆 Matryoshka (Operation Overload),
✂️ Operation Undercut,
🌩️ Foundation to Battle Injustice (CopyCop/Storm-1516),
📺 Ilan Shor-sponsored Moldova24 television network and covertly sponsored Facebook pages, and finally
🤺 Portal Kombat’s “Pravda Moldova”
https://t.co/AdLAFzq6T1
This report on Stark Industries is a fantastic case study in the cat-and-mouse game between hosting providers and law enforcement. The new "Threat Activity Enabler" (TAE) terminology is spot-on and highlights the critical role these providers play in the cybercrime ecosystem.
Anthropic says a hacker used its Claude chatbot "to an unprecedented degree": Claude identified vulnerable companies, wrote infostealer malware, analyzed stolen files for extortion purposes, calculated extortion amounts, and wrote extortion messages. https://t.co/gVyu3b7YG0
Highly recommend this report on TAG-144. It breaks down the group's operations into five distinct clusters and reveals some serious tradecraft! From using compromised government emails to hiding payloads in JPGs. A deep dive into a very sophisticated threat.
Great deep dive into Stark Industries by my colleagues @Lawrence_Sec and @_whoisnt, covering its role as a TAE, how it preempted and evaded EU sanctions, and broader issues with the hosting ecosystem. Definitely underreported topic and highly recommended read.
We recently announced the GA launch of our urlscan Observe feature. With urlscan Observe you can set up hunting rules for new domains and websites, trigger notifications and additional monitoring. Observe now allows you to control the monitoring process: https://t.co/hNmk63URfA
Former @CISAgov director Jen Easterly helped put together a site that matches laid-off CISA employees with companies that want to hire them. https://t.co/YHlXWko0lW
🚨New Research Blog 🚨Sensitive VPN Information Discovered in #Lazarus Group Infrastructure
Silent Push analysts have conducted in-depth research into the latest #bybit Crypto Heist by the Lazarus #APT group.
Read on for our findings below 👇
https://t.co/IafUBCkjmY
@ArmandDoma This is *beyond* evil. In addition to being cruel, it breaks a solemn promise we made to people who risked their lives for us and it ultimately undermines our standing with allies.
🧵Thread of reports on 🇷🇺/🇺🇦 cyber activity in January 2025:
1. FANCY BEAR targets Central Asia with HATVIBE and CHERRYSPY malware (https://t.co/b6uwcCxAva)
2. Star Blizzard impersonates a US government officials in WhatsApp account takeover phish (https://t.co/vvqHoyHm07)
Symantec's Threat Hunter Team look into an espionage campaign, linked to China-based APT groups, targeting high-profile organizations in Southeast Asia. https://t.co/VrZEhFtFIJ