Tom's Avatar

Tom

@tom.wicked.design

CEO & founder of wicked.design ✌️, lecturer at Swiss πŸ‡¨πŸ‡­ & Ukraine πŸ‡ΊπŸ‡¦ universities. Cyber guy turned social scientist & system theorist πŸ“š πŸ³οΈβ€πŸŒˆ (he/him) - vegan, cuz friends not food 🌱

244 Followers  |  1,214 Following  |  119 Posts  |  Joined: 16.10.2023  |  2.2615

Latest posts by tom.wicked.design on Bluesky

Post image

Seems like quite some internal systems were infected by InfoStealers.
Quite the irony given the fact that #infostealer like #Lumma, #RedLine, #Raccoon, #Vidar are russion developed and operated #CybercrimeAsaService platforms.

28.07.2025 13:58 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Aeroflot suffers massive outage of their IT systems. | Tom H. Aeroflot suffers massive outage of their IT systems. πŸ›¬πŸš« Two groups, Silent Crow and Cyberpartisans BY, claim responsibility in support of UkraineπŸ‡ΊπŸ‡¦. 🚩 7,000 servers β€” physical and virtual β€” were de...

🚩 Data obtained includes 12TB of databases, 8TB of files from Windows Share, and 2TB of corporate email.

Passengers flight data has also been exfiltrated and is available for researchers for further analysis.

www.linkedin.com/posts/wicked...

28.07.2025 13:48 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image Post image Post image Post image

#Aeroflot airline got hacked by two pro-ukranian groups, #SilentCrow and #Cyberpartisans. πŸ›«πŸš«

🚩 7`000 servers β€” physical & virtual β€” destroyed.
🚩 Compromise of 122 hypervisors, 43 installations of ZVIRT virtualization, ~100 iLO interfaces, & 4 Proxmox clusters.

#Ukraine πŸ‡ΊπŸ‡¦

28.07.2025 13:48 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 1
Post image Post image Post image

PasswΓΆrter im Kanton ZΓΌri, sind sie zu stark bist du zu schwach.

Erst versucht jemand mein Passwort zu reseten, dann sind leider meine PasswΓΆrter zu stark πŸ₯² und dann gibt es als "starke" Authentifizierung nur SMS 🫠

Schon mal was von Passkeys gehΓΆrt?

#KantonZH #Zurich #Government #Passwords

24.06.2025 11:40 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Full panel and blog are still functioning.

The hacker supposedly goes by "kho-kho" from Prague. Let me know who he isβ€”I'll pay real money if the information is genuine." 2/2

08.05.2025 15:25 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Lockbit confirmed:

"On 7 May, someone hacked the light panel with auto registration for all comers, stole the database, but not a single decryptor and not a single company's stolen data were compromised. I'm investigating how they managed to hack it and rebuilding it now. 1/2

08.05.2025 15:25 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image Post image

It reveals the brutal reality of ransomware attacks. They are even attacking #schools: "Dude, we’re #non-profit, educating children,".
Another victim begs: "Dear, $40k is my 6-year salary... Don't spoil my life."

Just remember when #ALPHV / #BlackCat ransomed a breast cancer clinc.

08.05.2025 15:25 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image Post image Post image

#LockBit #ransomware got breached and leaked tonight. A hacker called "kho-kho" (allegedly from Prague πŸ‡¨πŸ‡Ώ) breached their panel & leaked a 30MB SQL dump containing:
πŸ’Ά ~ 60K BTC addresses
πŸ’¬ Negotiation chats with their victims
πŸ› οΈ Build info (dating back to Dec 2024)
πŸ“ˆ Client lists, etc.

08.05.2025 15:25 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 1
Free Automated Malware Analysis Service - powered by Falcon Sandbox - Viewing online file analysis results for 'http://app.go.experian.com/e/er?SP_MID=23065-g&SP_RID=14130344-g&s=2448... Submit malware for free analysis with Falcon Sandbox and Hybrid Analysis technology. Hybrid Analysis develops and licenses analysis tools to fight malware.

- hybrid-analysis.com/sample/1c808...
- www.joesandbox.com/analysis/161...

26.02.2025 11:02 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

After some analysis the campaign appears to use Tycoon2FA Phishing Kit.

The website is loading O365 assets from oktacdn[.]com

This domain has been attributed to Tycoon before.
Any.Run: any.run/cybersecurit...

Others like JoeSandbox or Hybrid Analysis currently label it as clean

26.02.2025 11:02 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Proton Drive Securely store, share, and access your important files and photos. Anytime, anywhere.

For anyone interested, here is the sourcode of the phishing site - heavily obfuscated: drive.proton.me/urls/3Z8SZZN...

26.02.2025 10:38 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Be cautious:
As the QR code is ment to be scanned via smartphone, DNS and firewall blocking might have a limited effect!

IOCs:
▢️ [01] no-reply@nepalpottery[.]com
▢️ [02] https://864b5744a8e3e6f83afff7bd2c6.altedsx[.]com/
▢️ [03] https://w5vv.mdernstyle[.]ru/

26.02.2025 10:24 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Defender apparently picks up on it while other mail filters currently let it pass.

Recommended actions:
▢️ Implement a block filter for the nepalpottery
▢️ Implementation of DNS filtering should be implemented.
▢️ Inform your organisation about the current situation.

26.02.2025 10:24 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

It contains a lure about an updated company handbook and a QR code.

The QR code leads to Cloudflare protected website [02]. It then forwards to a Microsoft Microsoft 365 themed phishing website [03].

26.02.2025 10:24 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

The sender is the compromised mail account Nepal pottery [01].

The subject follows a certain pattern:
<ORG-NAME>-2025 Q1 Staff Pay Adjustment Handbook-<NUMBER>

26.02.2025 10:24 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

We currently see an uprising in Adobe QR code based phishing for MS O365 creds 🎣

Recipiens are named, TA apparently did some intel:
▢️ Company name
▢️ Employee names (First and Last)

#Phishing #Adobe #O365 #Microsoft #Cybersecurity #Awareness

26.02.2025 10:24 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 2
Preview
mSpy-Leak: So stoppt man Spionage-Apps Mit Überwachungs-Programmen wie mSpy kânnen Privatpersonen einander ausspionieren. Wir erklÀren, wie man solche Angriffe aufdecken und abwehren kann.

Mit Überwachungs-Programmen wie mSpy kânnen Privatpersonen einander ausspionieren. Wir erklÀren, wie man solche Angriffe aufdecken und abwehren kann.

netzpolitik.org/2025/mspy-le...

Alle BeitrΓ€ge zum #mSpyLeak: netzpolitik.org/mspy-leak/

27.01.2025 06:48 β€” πŸ‘ 85    πŸ” 33    πŸ’¬ 3    πŸ“Œ 4

What is the problem of people and companies with the concept β€ža better place for all of us - no matter who you areβ€œ.
It doesnβ€˜t hurt anyone, but it helps people who are already marginalized.

26.01.2025 11:06 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

DHS has terminated the memberships of everyone on its advisory committees.

This includes several cyber committees, like CISA's advisory panel and the Cyber Safety Review Board, which was investigating Salt Typhoon.

That review is "dead," person familiar says.

www.documentcloud.org/documents/25...

21.01.2025 20:43 β€” πŸ‘ 1084    πŸ” 614    πŸ’¬ 54    πŸ“Œ 186

US president pardons drug market founder and operator to β€œ honor of her [mother] and the Libertarian Movement, which supported me so strongly”.

What a singal to law enforcement, law abiding citizens and everyone who works to make our society a safer and healthier place. #SilkRoad

22.01.2025 07:40 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Ich war in BuchaπŸ‡ΊπŸ‡¦, habe mit den Menschen dort gesprochen, gesehen was die Russen verbrochen haben. Menschen haben mir von den Verbrechen erzΓ€hlt. Und in der sicheren πŸ‡¨πŸ‡­sitzen Handlanger der Kriegsverbrecher wie KΓΆppel.

#SlavaUkraini #Ukraine

19.01.2025 12:18 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Genau das!
Traurigstes Beispiel ist der institutionelle Rassismus in CH.

www.edi.admin.ch/edi/de/home/...

18.01.2025 18:52 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

The inspiration for the domain apparently came from agricamex[.]cl - a Chile food company.
Might be a south american TA.

18.01.2025 18:36 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
crt.sh | agricamex.com Free CT Log Certificate Search Tool from Sectigo (formerly Comodo CA)

Right now the website simply redirects to #Google

#ThreatIntel #CyberSecurity #SocialEngineering #Phishing

crt.sh?q=agricamex....

18.01.2025 18:14 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

Apparent threat actor: agricamex[.]com 🎣
We observed this domain cloning #MS #Azure #Entra ID websites of our clients.
Domain fronted by #Cloudflare, registered by #GoDaddy.
Cert transparency logs shows activiy since around 2025-01-12. Inc. #Okta, #ADFS, #SCP, #outlook and #O365

18.01.2025 18:14 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
β€˜We’re Fine’: Lying to Ourselves About a Climate Disaster The dystopia of Los Angeles' fires are horrifying, mundane, and everything in between.

We had to evacuate Los Angeles. Most people I know there have also had to leave. We are safe in San Diego and our apartment is unlikely to burn down. We are very lucky. But alongside the visceral horror of the wildfires there is also the mundanity of dystopia

www.404media.co/were-fine-lo...

09.01.2025 16:55 β€” πŸ‘ 634    πŸ” 143    πŸ’¬ 23    πŸ“Œ 9

#VW

05.01.2025 12:41 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Wir wissen wo dein Auto steht - Volksdaten von Volkswagen has been released on media.ccc.de https://media.ccc.de/v/38c3-wir-wissen-wo-dein-auto-steht-volksdaten-von-volkswagen https://events.ccc.de/congress/2024/hub/event/wir-wissen-wo-dein-auto-steht-volksdaten-von-volkswagen/

29.12.2024 19:46 β€” πŸ‘ 2    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Post image

I love that Apple is trying to do privacy-related services, but this just appeared at the bottom of my Settings screen over the holiday break when I wasn’t paying attention. It sends data about my private photos to Apple.

29.12.2024 02:46 β€” πŸ‘ 352    πŸ” 169    πŸ’¬ 40    πŸ“Œ 26
Orange cat cuddling on their bed.

Orange cat cuddling on their bed.

cat.exe stopped working.
Resource exhaustion.

Chilling after Christmas πŸŽ„ 🐈 #cat #catsofbsky #christmas #AdoptDontShop #AnimalRescue #tierschutz

29.12.2024 19:12 β€” πŸ‘ 6    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@tom.wicked.design is following 20 prominent accounts