Tommy Madjar's Avatar

Tommy Madjar

@ffforward.bsky.social

Threat Researcher @ Proofpoint. Opinions are my own etc

414 Followers  |  64 Following  |  5 Posts  |  Joined: 16.11.2024  |  1.5548

Latest posts by ffforward.bsky.social on Bluesky

New ecrime insights:

TA4557, known for distributing More_eggs malware, notably expanded to an international audience in recent campaigns.

Per our data, the recruiter-focused TA was seen targeting orgs in France, England & Ireland, in addition to typical North America-targeted threats.

16.06.2025 15:08 β€” πŸ‘ 2    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0

There is however at least two separate current malvertising/SEO campaigns, one leading to Bumblebee and one leading to SMOKEDHAM/Thundershell, but it's not from the official website.
2/2

19.05.2025 15:47 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

This article that starts getting traction claims that the official RVTools website was distributing a malicious installer leading to Bumblebee. I see zero evidence of this actually being the case.
1/2

19.05.2025 15:47 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

Proofpoint also recently observed this activity delivering GootLoader. Google Ads for a fake document creation app (lawliner[.]com) led to a malicious document creation website, on which users are directed to enter their email address.

31.03.2025 16:43 β€” πŸ‘ 4    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0

Great research on that #GootLoader is now including email in their delivery chain. Please don't download NDAs and other contract templates from free sites without any history.

31.03.2025 14:42 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

New blog drop with @selenalarson.bsky.social and the rest of the team. This one covers a lot of threats using the #ClickFix technique to lure targets to infect themselves by pasting malicious CMD/PS code. My "fave" is the chumbox #malvertising on major tech sites.
www.proofpoint.com/us/blog/thre...

18.11.2024 12:44 β€” πŸ‘ 11    πŸ” 5    πŸ’¬ 0    πŸ“Œ 1

Well I guess it's time to try this platform too πŸ˜…

16.11.2024 13:53 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

@ffforward is following 19 prominent accounts