Lets use this pivot point on @ValidinLLC
Title: Zoom Client Update
Reported to @abuse_ch
Telegram info
'bot_url' "6366434554:AAFV0fUvPM4BdKKUvMt9aQwg1nQ8MsxCpXE"
'chat_id' "588250349"
Validin's threat intelligence platform requires unfettered access to data, with affordable, high-performance storage, bandwidth, and scaling.
They’ve found that with Vultr Bare Metal, Cloud Compute, and File System.
See how @ValidinLLC wins with Vultr: https://t.co/DDnZPOxB9t
Six months after @DJSnM and @_JohnHammond were targeted with a fake "DMCA takedown" campaign, we revisit old pivots and find some new connections.
https://t.co/kOBltqUbKX
New report revisiting Gamaredon, this time focusing on their phishing emails and first stage downloaders - GammaDrop and GammaLoad. Despite years of active campaigns, detailed public analysis of either has been lacking. So we fixed that. 1/5
Ok, real question: how many of you have mistyped regsvr32.exe too?
New blog is out! Got a chance to take a peek at CastleLoader 🏰 and a .NET stealer we are calling CastleStealer (duh)
Their launch_method 4 calls regsrv32.exe. Yes, regsrv32.exe. The devs typo'd a binary that's been shipping since the 90s and never noticed :C
I also didn't forget to give @ValidinLLC a shoutout this time.
Would you check out the blog, pretty please? https://t.co/QklbaYitoQ
In this guest post, researchers @lontze7 and @cfotopoulos2000 analyze UNC1069 sample behavior and track related infrastructure with Validin. They provide IOCs and show great detail. Check out out! ⤵️
Raw IP data in Device ID reporting, with device_vendor set to Progress & device_model to ShareFile: https://t.co/1uPaaDBQcc
Thank you to @ValidinLLC for the collaboration!
Dashboard World Map view: https://t.co/MT2auFb71P
Dashboard Tree Map view:
https://t.co/FZnoeSIuWH
@andrewdanis@500mk500@andrewdanis we do not have pivots that require a premium account (except for registration, which this is not). It appears that the data aged out of the community platform.
657 instances shared for 2026-03-14. We expect to increase the volume of the feed in the future!
We would like to thank our Alliance partners and @ValidinLLC for the collaboration making this possible!
Background on investigating ClickFix/ClearFake: https://t.co/UY8NFEKr1C
📣#PIVOTcon26 Agenda is here 🤟 We are thrilled to announce the lineup for this year's speaker lineup.
2⃣days and 19 talks from leading #ThreatResearch experts.
The agenda link is in the first comment👇, and the talks and speakers are in the thread.🧵
#CTI#ThreatResearch
1/15
We're tracking the rapid proliferation of this exploit chain. Read our analysis of the C2 domains and the discovery of many recent dropper pages.
Tracing the iOS Exploit Kit from Ukraine to Iran War Lures:
https://t.co/fVLUFYDXxs
5 exploit chains, 23 exploits, nation-state grade malware has leaked with the capability to mass exploit iPhones. IOCs and technical overview on our blog:
https://t.co/LkpnXbjGau
#iOS#malware#mobilesecurity#cybersecurity#cyberattack