Expel's Avatar

Expel

@expelsecurity.bsky.social

The leading MDR provider trusted by some of the worldโ€™s most renowned brands to expel adversaries, minimize risk, and build security resilience. ๐Ÿ”— expel.com

34 Followers  |  2 Following  |  103 Posts  |  Joined: 02.12.2024  |  2.1936

Latest posts by expelsecurity.bsky.social on Bluesky

The pages donโ€™t include a download link and we havenโ€™t been able to answer the question: What does the user see?

If youโ€™re able to find out, let us know in our DMs or comments ๐Ÿ“ฅ

01.08.2025 21:21 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image Post image

Clicking on the โ€œDragons Guideโ€ sent us to Bing instead. From Bing, we were able to view one of the several Link-pits we found. We found other sites by looking for webpages with the same โ€œdodecadragons-guideโ€ in the URL.

01.08.2025 21:21 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

We also found a few hosting the SEO poisoning. Here are some examples: graduatetutor[.]org, theyansweredthecall[.]com, traykin[.]com, and mediagin[.]net.

These websites are โ€œLink-pits.โ€ They hold a large number of pages and keywords to arrive high in search results.

01.08.2025 21:21 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

We did some digging and found a bunch of these JavaScript files. The name is always โ€œFULL DOCUMENT.JSโ€ but they come in a ZIP file with the name from the SEO poisoning. The ZIPs were named like the examples below.

01.08.2025 21:21 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

The JS file contains the following content.

It calls GetObject() with content that decodes to "scriptlet:http[:]//0x3e3cb218/vag"

That hex? Thatโ€™s an IP address ๐Ÿ‘€ 62.60.178[.]24

When the script executes, it downloads a remote payload and starts the malware infection.

01.08.2025 21:21 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

A user attempts to download a sort of guide. Their โ€œguideโ€ arrives high in search results. If they download the file, they receive a .ZIP and inside the ZIP file there is a small JS file. Due to size and obfuscation, this small file can easily bypass the first pass of detections.

01.08.2025 21:21 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

โš ๏ธ Weโ€™ve noticed a campaign leveraging SEO poisoning to drop a small loader. If youโ€™ve seen the lure in the watering hole, weโ€™d love to know. A copy of the malware can be found on VirusTotal as MD5 hash 6af56c606b4ece68b4d38752e7501457.

Hereโ€™s what weโ€™re seeing ๐Ÿงต

01.08.2025 21:21 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
What Fortune 100s are getting wrong about cybersecurity hiring - Help Net Security New research reveals cybersecurity hiring trends for 2025, showing how rigid job requirements and low flexibility are driving talent away.

What Fortune 100s are getting wrong about cybersecurity hiring

๐Ÿ“– Read more: www.helpnetsecurity.com/2025/07/17/c...

#cybersecurity #cybersecuritynews #burnout #certification @expelsecurity.bsky.social

17.07.2025 07:31 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image Post image Post image

Spotted in NYC โŽ๐Ÿ‘€

Took cloud security so seriously we actually ended up in the clouds. โ˜๏ธ Thanks for having us, Nasdaq!

30.06.2025 17:18 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
What we're seeing from Iran (and what it means for you) Here's Expel's take on what the geopolitical issues between the US, Israel, and Iran look like for the cybersecurity community to date.

โš ๏ธ Weโ€™ve been keeping a close eye on the US-Israel-Iran geopolitical situation. Many resources are providing a ton of information and data but not a lot of analysis.

Our take: things are not likely to intensify in the cyber realm.

Here's what to do and what Expel is doing:

26.06.2025 17:50 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Explore Expelโ€™s auto remediations: Delete malicious file In this series, we explore Expel's auto remediations so you understand how they work. Let's explore delete malicious file.

๐Ÿ“‚๐Ÿ’ฅ When a malicious file hits your environment, every second counts.

Expel's โ€œdelete malicious fileโ€ response action enables our SOC to permanently remove a confirmed malicious file directly from an affected host, using the EDRs and security tools you already have. expel.com/blog/explore...

23.06.2025 18:04 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Emerging threat: Scattered Spiderโ€™s heightened activityโ€”hereโ€™s the 411 Threat group Scattered Spider is making headlines again as they increase targeting for financial services and insurance orgs.

โš ๏ธ๐Ÿ•ท๏ธ Scattered Spider is acting with a heightened amount of activity. We're seeing them pivot from credential harvesting to directly targeting IT help desks, using social engineering to reset passwords and bypass MFA.

Get the full 411 on Scattered Spider's heightened activity:

20.06.2025 18:50 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Patch Tuesday: June 2025 (Expel's version) The June 2025 edition of Patch Tuesday is live, and this month we're highlighting a handful of Ivanti critical vulnerabilities.

Itโ€™s Patch Tuesday! ๐Ÿฉน This month, Microsoft released 66 CVEs including CVE-2025-33053 and CVE-2025-33070.

Of the vulnerabilities, here are the three that caught our eye as the highest priority due to the vulnerability exploitation risk factors ๐Ÿ‘€๐Ÿšจ expel.com/blog/patch-t...

10.06.2025 19:44 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
More SIEM flexibility: Expel MDR adds support for XSIAM Expel expands its SIEM coverage by launching advanced support for Palo Alto Networks Cortexยฎ XSIAM. Welcome XSIAM users!

Learn more about how Expel MDR can work with your XSIAM deployment: expel.com/blog/more-si...

10.06.2025 17:58 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

What this means for your security team:
๐Ÿคธ Choose the best security tools for you knowing Expel can integrate with them
๐Ÿ”Ž Combine the strengths of your SIEM data & detections with Expelโ€™s expert analysis & response capabilities
๐ŸŸฐ Receive the same high-quality Expel MDR experience

10.06.2025 17:58 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Youโ€™ve invested in your SIEM, now our goal is to make that investment ๐˜ธ๐˜ฐ๐˜ณ๐˜ฌ.

Weโ€™re doubling down on our position as a leader in MDR flexibility by announcing the expansion of our SIEM coverage. Weโ€™ve launched advanced support for Palo Alto Networks Cortex XSIAM this month. ๐Ÿ‘

10.06.2025 17:58 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
5 questions to ask when your security vendor gets acquired Whether your MDR provider is going through a merger or acquisition, here are five questions you'll want to ask your new point of contact.

Acquisitions happen. But when your security vendor gets bought out, it's not just business as usual. Are you ready to ask the hard questions? Because you need to.

Our CSO Greg Notch lays out the 5 questions you need to ask when your security vendor gets acquired: expel.com/blog/5-quest...

09.06.2025 16:16 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
How to onboard with Expel in 7 minutes (No, really. We'll show you.) See with your own eyes how Expel MDR is up and running in less than seven minutes, from API connection to immeidate protection.

In 7 minutes you can...

๐Ÿƒ run a darn good mile
๐Ÿคณ doom scroll before your next meeting
๐Ÿ–ฅ๏ธ or onboard Expel

That's right. The onboarding even includes time to validate the connection within Expel Workbenchโ„ข and to test the connection. Watch the full demo and follow along! expel.com/blog/how-to-...

06.06.2025 19:47 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Identity: Your new financial fortress (and who's trying to log in?) Identity is the new perimeter in cybersecurity, and bad attackers aren't breaking inโ€”they're logging in, and targeting FinServ.

This is where Expel MDR can partner with financial organizations to protect against bad actors attempting to look like the real deal. Learn more ๐Ÿ‘‡ expel.com/blog/identit...

03.06.2025 15:53 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

The numbers paint a clear picture:

๐Ÿง‘โ€๐Ÿ’ป Stolen credentials were used in 22% of breaches
๐Ÿ’ธ ATO incidents jumped 13% in 2024, with global losses projected to hit $17 billion by 2025
๐Ÿ™… 80% of consumers would ditch a platform after an account takeover

03.06.2025 15:53 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

๐Ÿฆน While the convenience is great, cybercriminals are all over thisโ€”targeting credentials via phishing and social engineering to simply walk into your systems.

03.06.2025 15:53 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

๐ŸŽญ Identity is your new perimeter in cybersecurity. Today, hackers arenโ€™t just breaking in, theyโ€™re logging in.

In financial services, trust is everything. Your customers and employees need to securely access your services from anywhere.

03.06.2025 15:53 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Explore Expelโ€™s auto remediations: Contain host In this series, we explore Expel's auto remediations so you understand how they work, and the benefits of each. Let's explore contain host.

Expel's contain host auto remediation allows our SOC analystsโ€”with your pre-approvalโ€”to automatically isolate a compromised or suspicious endpoint from your network.

Learn:
โš™๏ธhow our contain host auto remediation works
๐Ÿ‘Ÿhow our analysts kick off this action
๐Ÿ–ฅ๏ธhow to set it up

28.05.2025 15:55 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

In media (and cloud) we trust ๐Ÿซก

Join Pierre Noel on 3rd June at #Infosec2025 for insights on overcoming common cloud transformation challenges in a changing digital media ecosystem. And don't forget to come see us at stand C85 for custom AI portraits and swag. expel.com/infosecurity...

27.05.2025 18:46 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿ•ท๏ธOperation Endgame just announced disruption of the infrastructure behind Lactrodectus malware, a malware used by ransomware actors to gain access to enterprise networks. But the devs are persistent so we expect them to return.

Here are the most recent tactics we've seen: expel.com/blog/followi...

23.05.2025 16:38 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
How to protect M&A in FinServ with Visa and Expel | Expel

Mergers and acquisitions can fuel growth but they also create opportunities for cyber threats. Join Expel's experts along with Visa's Ilaiy Elangovan on June 5 for a discussion on expanding your orgโ€”without slowing down the deal. ๐Ÿฆ๐Ÿ›ก๏ธ

Register now: expel.com/webinars/ma-...

19.05.2025 16:43 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Explore Expelโ€™s auto remediations: Kill process In this series, we explore Expel's auto remediations so you understand how they work, and the benefits of each. Let's explore kill process.

New blog series alert! ๐Ÿ”ฆ Follow along as we explore all of Expelโ€™s auto remediations.

In this post, we'll focus on the kill process auto remediation, which enables Expel's SOC to immediately terminate malicious processes across endpoints.

Here's how it works and how to set it up:

15.05.2025 20:00 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Recapping RSAC 2025: How AI, ethics, and geopolitical events combine in cybersecurity scenarios Here's a recap of the Expel team's experience at RSAC 2025. We pet puppies and goats, played games, connected, and highlight trending topics.

Now that we're (a bit more) recovered from #RSAC, we wanted to take a minute to highlight the key themes we saw this year.

๐Ÿง AIโ€”whoโ€™s using it & how
๐Ÿ—บ๏ธGeopolitical shifts & its impact on cybersecurity
๐Ÿ’ญChanges in corporate expectations
๐Ÿ’กHow all of this is shaping new tech

expel.com/blog/recappi...

08.05.2025 18:34 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Why Identity Is the New Battleground in Cyber Defense Credential theft is eclipsing ransomware as one of the top threat vectors targeting victims around the world, according to Expel's Dave Merkel, who explains how

Identity has become the new frontline in cybersecurity. ๐Ÿชช

๐ŸŽฅ In this interview with ISMG at #RSAC 2025, our CEO Dave Merkel shares why threat actors are prioritizing identity-based attacks and what security leaders should ask when evaluating AI-enabled tools. www.databreachtoday.com/identity-new...

08.05.2025 16:43 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Simplifying Microsoft security with Expel MDR Expel MDR seamlessly integrates with all the Microsoft security tools in your tech stack, from Microsoft Azure to Microsoft 365 and more.

If you're one of the many orgs that consolidated their security tools around @microsoft.com to keep costs down and now need an MDR provider to protect these new investments, you're in the right place. ๐Ÿ€

Learn how Expel MDR works seamlessly with your Microsoft environment: expel.com/blog/simplif...

07.05.2025 22:07 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@expelsecurity is following 2 prominent accounts