Genuinely curious why so-called researchers would rather talk behind my back and push allegations than reach out and confirm anything with me directly.
Spreading rumors isn't normal practice. You can just ask, you know. Disinformation, harassment and misattribution were never part of TI.
🔥 We “hired” Lazarus APT remote workers — and uncovered their toolkit.
@BirminghamCyber & @north_scan used #ANYRUN Sandbox to capture weeks of Famous Chollima activity inside a fake startup.
👀 How not to let a spy in? See full story and videos: https://t.co/IOUZmZEjJQ
🇰🇵 We built a fake company. We recruited DPRK IT workers. We recorded everything.
📹 The full story is finally out: hours of footage, IOCs, things we never showed at DEF CON and even a familiar face from Season 1.
Smile, You’re on Camera: Episode 2.
If you have a malicious sample in front of you during an active intrusion, spend 20-30 minutes on it.
I know the pull to dodge it - the timeline is on fire, EDR is throwing process trees at you, and grabbing the hash and outbound connections feels like enough.
But even where it recorded cleanly, process data only shows what ran on that host, at that moment, under those conditions.
The binary tells you what to go look for on disk, and half the time it's still sitting there (trust).
Thirty minutes of triage and the pieces start fitting together:
- Backup C2s that were never contacted because the primary was still up
- Drop paths and artifacts the sample writes that never generated an alert, but are still on the host if you know the filename
- Config strings and beacon patterns that tie this intrusion to prior activity
- Sandbox checks that explain why your detonation came back clean
- Conditional persistence
The US military cannot be beaten in open combat. So they convince a young gullible generation online we are evil. I’m not mad it’s happening I’m mad it’s working. But I respect the game
🚨 Pressure is mounting behind the scenes.
The ShinyHunters group has updated its darknet leak site with a warning directed at an unnamed victim, claiming the compromise includes:
• 11.5M+ records from Salesforce, ServiceNow, and Microsoft Entra containing customer and employee PII.
• More than 3.1TB of internal corporate data.
The group has set a deadline of August 10, 2026, threatening to publish the data and cause additional "digital problems" if the victim does not make contact.
While the victim remains undisclosed, this type of public countdown is often used as additional leverage during ongoing ransom negotiations.
👀 Track ransomware negotiations, darknet activity, and emerging threats in real time with DarkFeed.
🌐 https://t.co/3e2zfCtlvp
#CyberSecurity #Ransomware #ThreatIntelligence #DarkWeb #CTI #DarkFeed
Kathy Hochul and Letitia James have the combined IQ of a fine plate of spaghetti with some freshly made meatballs.
Soon New York state will implement the SAFE for Kids Act.
Basically, you need to verify your identity to Instagram, TikTok, or any social media platform which is algorithmic (???).
They're doing this to protect children. They ARE NOT doing it to allow social media companies to aggregate your data and sell it to third parties (or worse).
You trust Instagram, TikTok, Facebook, X, SnapChat, YouTube, Reddit, LinkedIn, and Pinterest with your driver's license, right? Because to even view these websites you need to give them your driver's license. It is to protect children from algorithms.
Just give them your driver's license, bro. They said they'll delete it and they said they won't track you. Why would multi-billion dollar companies do something potentially unethical? You trust them, right? It's to protect kids, bro, you care about kids, right?
It's a well established fact parents are incapable of parenting and we must make tech companies and the government parent our children. Right?
Lots of discussion lately about cyber security job titles and functions, simplified it for you all
Threat hunter = proactively find bad
Incident responder = reactively find bad
Threat intelligence analyst = attribute bad
SOC analyst = catch your own staff doing bad
Red teamer = be bad
Malware developer = build bad software
Malware analyst = understand bad software
Security architect = draw pictures about theoretical bad
Risk analyst = write words about theoretical bad
Compliance analyst = stop companies being fined when bad happens
Data governance analyst = stop companies being fined when bad happens in Europe
CISO = pray they don't get fired when bad happens
After 20 years chasing ransomware gangs for other people and organizations, I'm finally doing it doing it under my own company.
Launching Arkem Cyber today. Not another IOC feed, not another framework, original research on the adversary, built for the humans who have to make the call.
Also, I don't have a graphic designer, so forgive the logo. I made it myself, between getting this thing off the ground.
If you're a security leader who's tired of dashboards that can't answer "so what do we do about it?", let's talk: https://t.co/isJZYiCnBa
#ThreatIntelligence #Ransomware #CyberSecurity
I've praised a few malwares for various reasons. However, this particular malware is very interesting.
- Initially masquerading malware, designed to target very specific audience
- Written in multiple programming languages. However, the first stage is written in an uncommon programming language (Delphi) and compiled using an uncommon compiler (Embarcadero), specifically Delphi GUI TForm from Embarcadero (Vcl?)
- Obfuscated, in a very natural way. The binary at first glance appears semi-legitimate, it hides itself well
- The first stage (stager, or packer) contains multiple layers of decoy data. It makes reverse engineering challenging, not due to difficulty but time exhaustion
- Secondary stage (where I'm currently at) is loaded into memory discretely, it flows naturally with the GUI application. When decompiled, the stager has over 15,000 functions. It makes finding the in-memory loaded secondary stage tricky
- The secondary stage has some form of interprocess communication, it relies on the first stage to load it. If the first stage is not present, it does not work.
- The second stage works (in a currently unknown capacity) to load a third stage payload. However, the secondary stage with the first stage work (in a currently unknown way) to decrypt the third (and potentially final) stage a/k/a the actual payload
- The second stage uses deterministic probability to alert the first stage if the machine executing the first stage is a virtual machine and/or anti malware environment.
- The second stage has multiple integrity checks, it ensures it has not been tampered with to force the binary to pull the third and final stage.
This malware is pretty tricky. It definitely hasn't been written by a noob. This is definitely a very skilled Threat Actor who is using AI to supercharge their code base. Based on my conversations with my colleague, and information he can share, this code base has been rapidly evolving over the past couple of months in a uncharacteristic manner. While this Threat Actor has always shown evolution and improvement, it is now much faster, precise, and flexible.
Overall, based on what I've seen so far, they've put in a lot of work to make this as painful as possible. In order to successfully reverse engineer this binary, it require outside the box thinking and/or building a custom solution to successfully trick the secondary stager to give up the goop (the third stage)... or a custom extractor to pull the third stage statically.
No solution is ideal. This is good malware. If it's not state-sponsored, it's someone who has been doing this a long time and knows ball.
Update: We are working on a follow-up to the LG story and have some disturbing findings re: LG's products. It will take us a while to parse everything and we have involved multiple security researchers, lawyers (working on reading around 40,000 words of LG agreements that are, generally, terrifying in scope), and network experts, but will have an update for you all as soon as we can finalize collecting all of the information and parsing. There is a lot for us to crawl through (and I'm also already up to thousands of dollars in LG product purchases, but each one peels back another layer of the enshittified onion). This will be a fairly large research piece and will take time, but is also the worst I've seen so far in this 'genre' of product and agreements.