Hacktivism and War -- always worth listening to Jim π
www.youtube.com/watch?v=sNaO...
@hegel.bsky.social
Distinguished Threat Researcher, Research Lead @SentinelOne. Advisor with @ValidinLLC. Research Archive: https://tomhegel.com/blog.html
Hacktivism and War -- always worth listening to Jim π
www.youtube.com/watch?v=sNaO...
π₯ The lineup this year is incredible, thanks to everyone who submitted!
Attendees are in for something special⦠and for everyone else, expect some major FOMO.
events.sentinelone.com/event/LABSco...
π₯ The lineup this year is incredible, thanks to everyone who submitted!
Attendees are in for something special⦠and for everyone else, expect some major FOMO.
events.sentinelone.com/event/LABSco...
New research from @milenkowski.bsky.social (S1) and @kennethkinion.bsky.social (Validin):
π°π΅ Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms
Research: www.sentinelone.com/labs/contagi...
Reuters story: www.reuters.com/world/asia-p...
The US, AU, and NZ have tested a prototype for a new cyber defense kit designed to connect and help secure any network.
The kits are operated by a nine-person team and are intended to be portable and moved to any location in the world.
www.defence.gov.au/news-events/...
π₯ The hunt is on for the worldβs ultimate threat hunter? π
π‘οΈIntroducing Sentinels League: The Threat Hunting World Championships π‘οΈ 3 Rounds. 3 Regions. 3 Finalists. Only One World Champion.
Screenshot from Predatory Swallow's Telegram channel, showing folders purporting to hold IranCell data
Someone claiming to be Gonjeshke Darande (Predatory Sparrow) has posted ~2GB of what *appears to be* IranCell subscriber data, covering the 935-939 prefixes.
#privacy #breach #mobile #iran
Hefty new drop w/ @milenkowski.bsky.social
China-nexus Threat Actors Hammer At the Doors of Top Tier Targets
www.sentinelone.com/labs/follow-...
Dutch intelligence discover a new Russian APTβLAUNDRY BEAR
www.aivd.nl/documenten/p...
Microsoft calls it Void Blizzard. Their report is here: www.microsoft.com/en-us/securi...
Is the era of the βnamed actorβ done?
As the OG adversary sets diverge, get promoted, or move on
actors dispersing across the kill chain based on specialized skills increases (ORBs, criminal underground)
AND the CTI models maturingβ¦
APTs β¬οΈβ¬οΈ
UNCs β¬οΈβ¬οΈ
NEW π FreeDrain Unmasked | Uncovering an Industrial-Scale Crypto Theft Network
Months-long research project with Validin we just dropped @pivotcon.bsky.social
π€~40k IOCs: github.com/Validin/indi...
π SentinelLabs: s1.ai/freedrain
π Validin: www.validin.com/blog/freedra...
Enjoy!
NEW π FreeDrain Unmasked | Uncovering an Industrial-Scale Crypto Theft Network
Months-long research project with Validin we just dropped @pivotcon.bsky.social
π€~40k IOCs: github.com/Validin/indi...
π SentinelLabs: s1.ai/freedrain
π Validin: www.validin.com/blog/freedra...
Enjoy!
An absolutely stunning look inside @sentinelone.com 's use of #synapse to provide intelligence context to inter-disciplinary intelligence stakeholders in defense of their own org. Truly on the leading edge of the intel driven fusion, collaboration, and impact. π€©
www.sentinelone.com/labs/top-tie...
At @pivotcon.bsky.social, I'm presenting with @hegel.bsky.social and Sreekar Madabushi on the first public look at the full scope of a stealthy, long-running phishing network.
24.04.2025 14:31 β π 7 π 5 π¬ 0 π 0Text from https://www.politico.eu/article/european-parliament-iran-delegation-chair-victim-tehran-linked-hacking-hannah-neumann/
Text from https://www.politico.eu/article/european-parliament-iran-delegation-chair-victim-tehran-linked-hacking-hannah-neumann/
Text from https://www.politico.eu/article/european-parliament-iran-delegation-chair-victim-tehran-linked-hacking-hannah-neumann/
NEW: Iranian gov hackers targeted #EU Parliament's #Iran delegation chair @hneumannmep.bsky.social
Elaborate operation impersonated former #FBI official to seed spyware.
Good to see a MEP speaking out & sharing this insidious threat to EU institutions 1/
www.politico.eu/article/euro...
#apt #sidewinder "54th CISM World Military Naval Pentathlon Championship 2025.docx"
40712a087a8280425f1b317e34e265c0329ffb0057be298d519fc5e0af6cb58f
-> dirsports.milqq[.]info
blank doc decoy
@bushidotoken.net explored a Meta-themed credential phishing campaign (not "Reality"). From those indicators, I pulled the "Threads" & this is far from an isolated campaign. Found great pivots in registration "Meta"data. (I'll see myself out.)
All 762 indicators π₯‡οΈ
www.validin.com/blog/not_rea...
Here's the Lab Dookhtegan segment
www.youtube.com/watch?v=g-zj...
Really great episode this week. The Signal ID management mess, and the lab dookhtegan topics.. simply delicious π€
30.03.2025 21:10 β π 9 π 2 π¬ 0 π 1Atomic indicators have value beyond just the day theyβre observed - Age alone doesnβt always diminish their usefulness.
Attribution challenges aside, this is a common occurrence in both cybercrime and APT campaigns. Looking at you, South Asia!
Kryptina RaaS: From Unsellable Cast-off to Enterprise Ransomware
www.sentinelone.com/labs/labscon...
Incredibly excited to drop some new research alongside @kennethkinion.bsky.social and Sreekar Madabushi at this years @pivotcon.bsky.social
10.03.2025 13:59 β π 7 π 1 π¬ 0 π 0Great refresher / inside-scoop on the Lamberts -- #WhereAreTheyNow
08.03.2025 22:19 β π 1 π 1 π¬ 0 π 0#dprk #apt 2024λ
κ·μ μ°λ§μ μ° μλ΄λ¬Έ_μΈν.docx.lnk
b81513f0f8d3db382bb8f931bf2b7a0d4f26f74cfcf60b5d889de87ef2f1d543 -> www.roofcolor[.]com/wp-includes/js/src/list.php , www.acschoolcatering[.]com/libraries/src/inc/ decoy:
Look man, I'm not saying anything but I'm also not NOT saying anything
23.02.2025 01:43 β π 21 π 5 π¬ 2 π 0π¨ New analysis of Ghostwriter activity targeting Ukrainian government & Belarusian opposition
s1.ai/ghost-xl
Spicy new drop from the team. H/T to @milenkowski.bsky.social, @dakotaindc.bsky.social, Alex Delamotte
s1.ai/topsec
Today, Google Threat Intelligence is alerting the community to increasing efforts from several Russia state-aligned threat actors (GRU, FSB, etc.) to compromise Signal Messenger accounts.
cloud.google.com/blog/topics/...
If I had a dollar for every single time something is attributed vaguely to ββMustang Pandaββ I could buy a flat in London
14.02.2025 12:39 β π 22 π 4 π¬ 4 π 1