FYI we got some IOCs from @rapid7.com
x.com/cyb3rops/sta...
FYI we got some IOCs from @rapid7.com
x.com/cyb3rops/sta...
Write-up says update traffic was selectively redirected to attacker-controlled servers & hints at a CN state group
If thatβs the case, there must be at least some infra IOCs: IPs/FQDNs, redirect URL
Even if you donβt have package hashes, can you share infra IOCs so people can check proxy/DNS logs?
Never give up! We got your back
21.11.2024 07:26 β π 1 π 0 π¬ 0 π 0π«ΆπΉ
20.11.2024 21:02 β π 0 π 0 π¬ 0 π 0