Persistence without malware?
Here's how attackers abuse T1547.001 using only built-in Windows tools - and how to catch them. 🕵️
🔍 https://t.co/1jrmvtDwrh
The Silent Push team investigates SocGholish and its TA569 operator. SocGholish functions as a MaaS vendor, uses "fake browser update" as lures, and leverages TDSs like Parrot TDS & Keitaro TDS. TA569 acts as an IAB enabling other notorious groups. https://t.co/rnJuGZ5V0y
ANSSI has published details about the Houken intrusion campaign, which seeks initial access to the networks of French entities through the exploitation of several zero-day vulnerabilities on Ivanti Cloud Service Appliance devices. https://t.co/6KwHGr5mCt
Sharing my slides from BotConf 2025: "Elephant in the Sandbox: An Analysis of DBatLoader’s Unique Evasion Techniques". If you want to learn about weird and stupid evasion techniques, then look no further.
Ps. The URL title doesn't match, I know. 😄
https://t.co/o3CiuZh55A
Sophos researchers analyse a Lumma Stealer campaign using fake CAPTCHA sites that instructed victims to paste a (malicious) PowerShell-encoded command into Windows’ command-line interface. https://t.co/llVsnysDzM
Been looking at AI recently and added some Velociraptor AI capabilities:
1. Ollama and refactored Open AI enrichment artefacts . Learn more:
- Ollama: https://t.co/3soqwm7Ulu
- Open AI Enrichment: https://t.co/GEWaHYulHn
2. Proof of Concept (POC) Velociraptor MCP server.
Works fairly well in my testing but needs some finesse on context windows. Check it out here:
https://t.co/EcP6ABdVCf
@velocidex
GitHub - DarkSpaceSecurity/SpyAI: Intelligent Malware that takes screenshots for entire monitors and exfiltrate them through Trusted Channel Slack to the C2 server that's using GPT-4 Vision to analyze them and construct daily activit https://t.co/oGQtoK8zC8
Using Windows Sandbox - Course
This is another FREE course to learn howto setup and use Windows Sandbox for #malware analysis or anything you want. #DFIR#infosec#CyberSecurity
Check it out:
https://t.co/NZCNVPvXg9
Just friday network tweet 👾
I decided to show you #Stealer#EncryptHub (aka #Fickle) C2 communication in network traffic in more details ⬇️
(from https://t.co/eoSvZHz3He)
Sandbox examples:
https://t.co/GeB4AAFEfn
https://t.co/IoGKt8ackQ
Detecting Palo Alto Firewall Exploits
Palo Alto Networks has found a new firewall bug that attackers are actively using. This, along with two earlier flaws, targets unpatched PAN-OS firewalls. GreyNoise reports a rise in attack attempts, with 25 IP addresses involved.
Google dork to find #LummaStealer disguised as cracked software (games, applications and security tools)
site:https://t.co/vWHbNu0wmb intitle:Crack AND intitle:Download AND intext:"you have come to the right place"
payload servers were subdomains of saferedirect.]top