🚨📝 New #FIN7 threat research blog, "Power Hour", published today by @Mandiant. Please enjoy 🌶🌶
https://t.co/HZlyGg2q3M
Blog includes:
- FIN7 archaeology & evolution ⛏
- #POWERPLANT deep dive
- BIRDWATCH (~#JssLoader)
- Supply chain (😱)
neat stuff in thread 🧵⤵️
SilkETW is now available ✍️🧐💡! Check out my short introduction post here => https://t.co/XJLrC6CPi5, you can find the code on the @FireEye GitHub => https://t.co/d9qyZlkzn3
Well covered that Ryuk ❌ NK in blogs by @kryptoslogic@McAfee_Labs@Malwarebytes@CrowdStrike. Here we share an example of an initial infection vector, more details on how Ryuk has been deployed, and some info on the observed TrickBot gtags https://t.co/ki8sDMpDPK
New post is up! We pick apart the latest probable #APT29 phishing campaign and the nuance involved in dealing with, and attributing to, deceptive attackers. Written with @QW5kcmV3, @itsreallynick, @matonis, @jonleathery. Credit to @barryv for the title. https://t.co/eX5D28x1ds
HOT OFF THE PRESS: Read our @FireEye_Intel#TRITON attribution blogpost tying TRITON actors to CNIIHM, a Russian Government-Owned research institute.
https://t.co/Ezl0FS0ntb
In our new @FireEye blog post we analyze some of the most frequent ICS security risks observed in the field during @Mandiant ICS Healthcheck assessments. It is good to have some on-the-ground data to test commonly cited areas of ICS risk. https://t.co/wYWkxrMO0M
The TRITON origin story is a still mystery with lots of missing pieces. @reesespcres and I did some poking and found some overlaps with legit Triconex DLLs. Nothing mind blowing, but still cool: https://t.co/yzWup76fjg #tristation#triton#tubular
Check out my blog post and tool release on OAuth Abuse! OAuth abuse is a social engineering technique that's managed to stay relatively under the radar until now. https://t.co/iaUmEyCahJ
After 9 months Invoke-DOSfuscation is finally released!! There is a lot of information for detection in the white paper, and the Invoke-DosTestHarness function is exactly what I used for detection dev & tuning.
Code: https://t.co/ARK97aDnHg
White paper: https://t.co/i3qz7jn2rs