@Dragonkin37@BojackTrojan @OhadMZ @Dragonkin37 is correct. At Cyberwarcon I noted that the only links between 33 and DEADWOOD were timing and targeting - which in and of themselves are low-confidence. We track DEADWOOD separately from 33.
I’m hesitant to do this because everyone says how the SolarWinds hack confirms all their priors, but here goes.
My PhD and first book argues the blurred lines between espionage and preparations to attack in cyber make interpretation hard. A short thread on what that means here.
While MuddyWater's link to ransomware remains tenuous and unproven, the group is heavily invested in custom tool development. From PowerShell to .NET to C++ malware, Muddy is fast approaching other groups' capabilities. @snlyngaas reports w/ lines from me https://t.co/Zr2Sn4ZVyp
It's almost as if there are companies providing/selling capabilities whether its Implants, Exploits, or all of the above and what you may see here are downstream customers. @moranned and I covered this a little bit in https://t.co/O1Unl2tMtr from 2015.
There are a number of these kinds of examples where this kind of sharing can be inferred too in the infrastructure side of things, but.. this is Twitter and they probably also read the same tweets the defenders do.
Thanks for your patience, class! Took a little hiatus for a month. But we're back! In week 5 of “Lies & Disinformation” @Georgetown, we pivoted from Russian influence activities to Chinese and Iranian IO state actors.
@9bplus @Mao_Ware@TheCollierJam Im still traumatized by years of 2k erg tests in college, but I will throw down on intervals (500m w/ 1min rest * 8) or a straight 5k.
@RidT@BuchananBen i think its important that you measure effects across intrusion sets - even those that arent targeted via doxxing, indictments, etc. others can watch and learn and not repeat the mistakes their peers may have made.