🚨 South Korean industrial motor manufacturer HIGEN RNM(https://t.co/FA2CM0PhT0) was listed as a new victim by the ransomware group Qilin on August 10. — Reported by #TEAM_D4rkn3ttz@wntidled
Qilin claims to have exfiltrated approximately 400GB of “Critical Data.” However, no details regarding the allegedly stolen data or supporting samples have been published at the time of reporting.
The domain listed by Qilin, https://t.co/UkCYrkaAUE, does not appear to be currently active. While the preview image published by the group displays HIGEN branding, it also contains the name HOANG LONG PHU COMPANY LIMITED, which appears to be a Vietnam-based distributor of HIGEN products.
This introduces uncertainty regarding the actual source of the alleged compromise. The available material may be related to HIGEN RNM, but it does not establish that the claimed 400GB of data was obtained directly from the company’s systems. The possibility that the material originates from, or is associated with, a distributor or other related third party cannot currently be ruled out.
As no data samples have been released, the alleged compromise of HIGEN RNM remains unverified. Further assessment will be possible if Qilin publishes additional evidence or samples.
#CyberThreatIntelligence #ThreatIntel #Ransomware #Qilin #HIGENRNM
OGhidra
It bridges Large Language Models with Ghidra's reverse engineering platform, enabling AI-driven binary analysis through natural language. Analyze binaries conversationally, automate complex workflows, and maintain complete privacy with local AI models.
Resource/Source: https://t.co/K7bADQyxXt
🚩 UNC6671 Targets Hedge Funds in Vishing-Led Extortion Campaigns
https://t.co/rEIJ5OS9vD
UNC6671 is targeting hedge funds and private-equity firms with helpdesk vishing attacks that lead to cloud account takeovers and data theft.
The group, linked to BlackFile, has operated under names including Redact, Pink, Helix, and Falcon.
Attackers spoof corporate helpdesks, direct victims to fake passkey or MFA pages, steal credentials and session cookies, then access Microsoft 365, Okta, and other connected platforms.
#ThreatIntel #UNC6671 #Vishing #CyberSecurity
#TEAM_D4rkn3ttz is now on GitHub.
We’re publishing open resources for the cybersecurity community:
• reusable Codex skills
• threat intelligence reports
• defensive monitoring playbooks
Explore: https://t.co/QgxQJWRNob
#ThreatIntelligence#OSINT#CyberSecurity
🚨 Threat Intelligence Alert – Active Multi-Bank Phishing Campaign
We have identified a recent phishing campaign targeting multiple Brazilian banks, with a focus on corporate (Pessoa Jurídica) self-service portals and financial management platforms. The infrastructure uses the canonical path /appcx/index.html as a common fingerprint across multiple impersonating domains.
Key indicators observed:
• Lookalike domains identified: https://t.co/j1kAob1SB4 https://t.co/HDAO4Lk8MS https://t.co/wNVVwOVSDO https://t.co/WGCsXZveNS
• Pages under /appcx/ employ aggressive SEO content (keyword stuffing + https://t.co/bRbY8z5OkV) impersonating official portals of different Brazilian financial institutions, particularly Caixa Econômica Federal and Banco do Brasil, with deliberate mixing of brand terminology to expand reach.
• Infrastructure: – Primary IP: 5.230.54.41 (AS12586 – GHOSTnet GmbH, Frankfurt) – Some hosts protected by Cloudflare – nginx + PHP server (sessions via PHPSESSID) – Forced redirection from root to /appcx/index.html
At the time of analysis, the classic credential collection form was not exposed on common paths. The campaign is currently operating in the traffic acquisition and legitimacy-building stage, with potential for expansion to additional banks.
#Phishing #CyberSecurity #ThreatIntelligence #InfoSec #BankingPhishing #Caixa #BancoDoBrasil #BrazilCyber #CTI #FinancialFraud
⚠️ UPDATE: Further review of the data directory listing GUNRA claims to have stolen from South Korean manufacturer World Tube identified
a directory structure suggesting a possible connection to the company’s internal operations — Reported by
#TEAM_D4rkn3ttz@mingming0l@kwisejh@k_anrms
🔎 Directory and filename information published by GUNRA revealed references to:
• Employee names and apparent roles
• Customers, business partners, and subjects of exchanged materials
• World Tube product or part identifiers
• Factory, production, logistics, and quality-management operations
If GUNRA possesses the underlying files, sensitive corporate, technical, and supply-chain information may have been
exposed.
GUNRA has publicly exposed the directory structure and filenames associated with the alleged dataset. The contents of
the underlying files have not been independently examined.
No official confirmation from the affected organization has been identified. Gunra’s alleged breach and data claims
therefore remain unconfirmed.
#Ransomware #CyberSecurity #ThreatIntel #CyberThreatIntelligence #SouthKorea
🚨 A CSV allegedly containing South Korean telecom customer data was identified on FEX[.]NET. — Reported by #TEAM_D4rkn3ttz@d0ub13_3@kkalelek@sunah64h@jwahn183@nafi88155632
⚠️ The provided sample contains multiple indicators of syntheic or fabricated data.
• Repeated legacy 01X mobile number prefixes (011, 016, 017, 018, 019) that predate Korea's 010 number unification and post-date its 2021 number-portability cutoff.
• Geographic mismatches between City and Street Address fields, with combinations that do not correspond to real addressable locations.
• Repetitive name-plus-number email address patterns(e.g., [email protected]) using otherwise legitimate domains.
• Highly structured Credit_Limit values confined to just five fixed tiers (0 / 500,000 / 1,000,000 / 2,000,000 / 3,000,000).
• No exceptions in Credit_Limit assignment based on Payment_Method — Prepaid Card and Mobile Payment are fixed at 0 with zero deviation.
The post claims affiliation with a Korean telecom operator, but the displayed sample itself does not provide evidence linking the records to any specific carrier. The claim should be treated as unverified. Based on the exposed sample, the data appears consistent with a fabricated telecom-themed dataset rather than a validated subscriber database.
#CyberThreatIntelligence #ThreatIntel #DataBreach
🚨 #ClickFix
Investigating 31.76.87[.]37 revealed a multi-stage malware delivery chain
- Port 80 hosts a fake Cloudflare verification page instructing users to execute a PowerShell command.
- Port 8443 hosts the second-stage PowerShell loader.'
- The loader downloads LogBri12.msi from a Cloudflare R2 bucket and falls back to 31.76.87[.]37 if the primary download fails.
- The downloaded MSI contains multiple embedded files, including a renamed executable whose original filename is SmartAIP.exe.
IOCs
SHA-256:
Filename: LogBri12.msi
447adde94a1f14ba36c831b1009bd35992e66404aa3a4114b4bca921edab3969
Filename: SmartAIP.exe
ceb70e58e63eac81b8193e7b0dabd42168feb7929a0005c883967b99e1759732
Infrastructure:
31.76.87[.]37
31.76.87[.]37:8443
pub-32e2f642271c45008a1601bacbdfd3f1[.]r2[.]dev
#ThreatIntel #ClickFix #Malware #PowerShell
@malwrhunterteam@500mk500@skocherhan@OpcodeIntel@JAMESWT_WT@smica83@_ChezDaniela
🚨 GUNRA, a ransomware group, has threatened to publish 100 GB of data allegedly stolen from Worldtube, a South Korean automotive parts manufacturer — Reported by #TEAM_D4rkn3ttz@mingming0l@kwisejh@k_anrms
The group’s dark web leak site currently displays an active countdown indicating that the alleged data is scheduled for publication in approximately 10 hours.
⚠️ Details listed by GUNRA:
Target: Worldtube
Website: https://t.co/nloydmNKXx
Location: South Korea
Industry: Automotive parts manufacturing
Claimed revenue: US$20 million
Claimed data volume: 100 GB
Status: Publication pending
🔍 This information is based solely on GUNRA’s claims. No leaked files have been independently examined, and the authenticity, scope, and validity of the alleged compromise remain unverified pending further evidence or official confirmation.
#ransomware #cybersecurity #threatintel #cyberthreatintelligence
No C2 in the binary. This RedLine reads its live C2 off BNB Smart Chain. The ledger is public, so we decrypted a year of rotations. https://t.co/KVfBOe1ohr
يجمع أحدث أكواد الاستغلال (PoCs) وربطها ب CVEs من عدة مصادر.
https://t.co/jMyxvpJvFF
قاعدة بيانات شاملة للثغرات مع PoCs وMetasploit وCISA KEV.
https://t.co/0ZUsHFcAoh
يربط كل CVE مع PoCs وNuclei وSigma وEPSS في صفحة واحدة.
https://t.co/VbeNr9eggH
Unit 42 analyzed XCSSET v40, revealing macOS malware targeting developers via Xcode, with advanced pattern matching and AI decoding its logic. https://t.co/6X68Th30xy