Russia want's its own messanger app, independend and stuff.
Relies on Salesforce π€£
@ilitschko.bsky.social
Russian cyber espionage and cybercrime| Carleton University and MGIMO | GTA Khachipuri
Russia want's its own messanger app, independend and stuff.
Relies on Salesforce π€£
Donβt let anyone tell you that the Russians never arrest cybercriminals. Criminals who cause harm to Russians are regularly arrested, and as this instance shows, often dealt with harshly. See my timeline for a modest sampling of other arrests of hackers, fraudsters, and other Russian cybercriminals.
09.10.2025 11:48 β π 1 π 1 π¬ 0 π 0What we report publicly and attribute vs what they report publicly and attribute are wildly different beasts. Wish Bi Zone gave some geographic attribution but will take what I can get right now.
08.10.2025 22:13 β π 0 π 0 π¬ 1 π 0I think super important to track what they're saying about what they fear, what they think war looks like, & what they think adversaries will do, as well as what they themselves hope to do & what they actually do. Also crucial to track the disconnects between these & whether & when they narrow. 7/7
08.10.2025 15:30 β π 7 π 2 π¬ 1 π 0Most interesting to me is that the cooperation between Gamaredon and Turlais distinct from the Gamaredon cooperation with Invisimole. They are really solidifying themselves as an initial access team within the FSB.
www.welivesecurity.com/en/eset-rese...
APT or Another Phishing Training?
Seqrite reported an attack on the Kazakhstani oil company KazMunayGas attributed to a new group NoisyBear www.seqrite.com/blog/operati...
Yet the company later argued that this was a simulated attack orda.kz/planovoe-mer...
This looks plausible:
1/2
Russia is considering forbidding dissemination of information on how cyber attacks are conducted. Could be a big problem for CTI practitioners or incident responders sharing TTPs, because those include that kind of information.
www.kommersant.ru/doc/7991253
Most notable thing in this (apart from new publicly available info on Energetic Bear), is the assertion that Static Tundra is a subgroup of Energetic Bear. Been happening a lot with GRU groups, now FSB 16th Centre.
blog.talosintelligence.com/static-tundra/
And there goes the rest of my day.
11.08.2025 18:19 β π 3 π 0 π¬ 0 π 0Not a fan, just tastes like a hop bomb.
10.08.2025 02:20 β π 0 π 0 π¬ 0 π 0Very different from what I was expecting but very good. One of those super limited run things at the LCBO so had to get one.
07.08.2025 23:04 β π 1 π 0 π¬ 1 π 0First Japanese wheat beer.
07.08.2025 22:24 β π 3 π 1 π¬ 1 π 0SORM in action. Next, someone will tell me the guys cop boxes outside of embassy gates in Moscow who just want to take a look at your passport aren't taking note. Even when you're just going to the basement bar for cheap Moosehead on a Friday evening.
www.microsoft.com/en-us/securi...
Overall they're decent, but IMO they used to be better. Currently best ones from Chatham-Kent are Red Barn and Glasstown. If Sons of Kent bring back the Fergie Jenkins pilsner, they will be back to the top.
29.07.2025 00:51 β π 1 π 0 π¬ 1 π 0Normally a big fan of my hometown brewery but that particular one is definitely not my favourite.
28.07.2025 19:24 β π 1 π 0 π¬ 1 π 0A major cyber incident in Russia: two groups, Cyber Partisans & Silent Crow, took credit for a cyber attack on Aeroflot, claiming they destroyed its internal IT systems. Aeroflot didn't acknowledge the attack but canceled nearly 100 flights & delayed some more due to an 'outage'
28.07.2025 12:51 β π 198 π 55 π¬ 6 π 6What is interesting is that it looks like more disruption to flights was caused in this attack than by the multiple airlines breached by Scattered Spider.
28.07.2025 10:50 β π 1 π 0 π¬ 0 π 0while youβre at it, just go ahead and burn this collection on SVR cyber operations. who cares. not like it helps SVRβs CI analyses. fuck do I know. (Pg 16)
24.07.2025 23:41 β π 11 π 4 π¬ 1 π 0Regionality has become a recurring theme in reporting on Russian cyber.
20.07.2025 18:45 β π 4 π 1 π¬ 0 π 0Decoding Secrets Through Symbols: How Military Insignia Revealed Russiaβs Hidden SIGINT Network by @checkfirst.network
βοΈ
checkfirst.network/decoding-sec...
some other highlights:
- this cluster tried to re-establish relationships after we disabled their accounts by creating new, similarly named accounts. very persistent!
- if you thought their device linking phase was over, think again! susp apt29 groups looove this & want to make it seem more legit
If there were any American or French lords of war currently imprisoned in Russia, it would make for sweet poetry to get them in a prisoner swap for Russian basketball player Daniil Kasatkin, who was just jailed in Paris on charges of aiding a ransomware conspiracy. meduza.io/en/news/2025...
09.07.2025 21:49 β π 19 π 5 π¬ 0 π 0Probably the best thing from Innis and Gunn I have had.
29.06.2025 02:14 β π 0 π 0 π¬ 0 π 0Reupping my piece on Cyber Espionage Among Friends following @meghara.bsky.social NYT story on Chinese cyber operations targeting Russia
I dig into Russian reports about Chinese APTs & vice versa & provide context on why there's no political backlash
fromcyberia.substack.com/p/cyber-espi...
π¨NEW REPORT: exposing clever new hacking tactic.
π·πΊRussian state-backed hackers used an App-Specific Password attack against prominent Russia expert @keirgiles.bsky.social
It's like they knew what we all expect from π·πΊ...and then did the opposite 1/
By us @citizenlab.ca & Google's GTIG
Keir Giles has been targeted *again* by allegedly Russian hackers β this time using a clever new trick intended to bypass 2-factor authentication.
Over the years Iβve written about Giles an unusual amount, and I have an idea about why.
First, the coverage:
www.reuters.com/technology/s...
The SVR doing something novel with app specific passwords, and having the patience to go back and forth enough times to pull it off through an email conversation.
18.06.2025 18:46 β π 0 π 0 π¬ 0 π 0It's a great wine, though not my preferred choice from Abkhazia. Very difficult to get though, so will enjoy it regardless.
18.06.2025 01:14 β π 1 π 0 π¬ 1 π 0Abkhazian wine tonight.
18.06.2025 00:26 β π 4 π 0 π¬ 1 π 0To avoid βturning even the smallest incidents into scandals and points of conflict,β NATO is now limiting public disclosures of its activities and aid to Ukraine. Sharing less information is supposed to counter Russian disinformation. www.themoscowtimes.com/2025/06/17/t...
17.06.2025 16:01 β π 17 π 2 π¬ 2 π 0