Your cyber threat intel is part of the North Korean strategy: DPRK operators are abusing CTI platforms to see if theyβve been seenβand moving faster because of it. π
04.09.2025 13:57 β π 7 π 8 π¬ 1 π 0
Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms
DPRK-aligned threat actors abuse CTI platforms to detect infrastructure exposure and scout for new assets.
New research from @milenkowski.bsky.social (S1) and @kennethkinion.bsky.social (Validin):
π°π΅ Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms
Research: www.sentinelone.com/labs/contagi...
Reuters story: www.reuters.com/world/asia-p...
04.09.2025 14:45 β π 7 π 5 π¬ 0 π 0
Hunting Laundry Bear: Infrastructure Analysis Guide and Findings | Validin
Hunting Laundry Bear: Infrastructure Analysis Guide and Findings
π¨ New blog post π¨
Hunting Laundry Bear: Infrastructure Analysis Guide and Findings
How to enrich previous reporting with Validin to find dozens of indicators not previously reported.
#LaundryBear #VoidBlizzard #APT
www.validin.com/blog/laundry...
25.07.2025 12:13 β π 0 π 0 π¬ 0 π 0
From @re.wtf:
bsky.app/profile/re.w...
20.06.2025 17:24 β π 0 π 0 π¬ 0 π 0
Zooming through BlueNoroff Indicators with Validin | Validin
Pivoting through recently-reported indicators to find BlueNoroff-associated domains
Hot on the heels of the researched published by @huntress.com, hunting for Zoom-themed lures from DPRK's #BlueNoroff
π₯Learn hunting techniques
π₯Leverage new Validin features and data
π₯Full, unredacted indicator list (domains, IPs, hashes)
www.validin.com/blog/zooming...
20.06.2025 17:24 β π 2 π 2 π¬ 1 π 0
At @pivotcon.bsky.social, I'm presenting with @hegel.bsky.social and Sreekar Madabushi on the first public look at the full scope of a stealthy, long-running phishing network.
24.04.2025 14:31 β π 7 π 5 π¬ 0 π 0
Finding Booking.com themed ClickFix domains using Validin | Validin
Finding Booking.com themed ClickFix domains using Validin
From on a report on X, we walk through proactive detection of a #booking #fakecaptcha #clickfix campaign delivering #asyncrat
As always, full indicator list and detailed step-by-step repro included π₯ ‡οΈ
www.validin.com/blog/finding...
17.04.2025 10:54 β π 0 π 0 π¬ 0 π 0
Not Reality: Exploring Meta-themed Phishing with Validin | Validin
Not Reality: Exploring Meta-themed Phishing with Validin
@bushidotoken.net explored a Meta-themed credential phishing campaign (not "Reality"). From those indicators, I pulled the "Threads" & this is far from an isolated campaign. Found great pivots in registration "Meta"data. (I'll see myself out.)
All 762 indicators π₯‡οΈ
www.validin.com/blog/not_rea...
07.04.2025 14:49 β π 2 π 2 π¬ 0 π 0
Lazarus Group Bybit Heist: C2 forensics | Validin
An in-depth hunt for Lazarus APT group infrastructure related to the Bybit hack using Validin's host response and DNS databases.
Found these likely #Lazarus / #TraderTraitor domains w/ #Validin
getcoinprice[.]info
stocksindex[.]org
wfinance[.]org
stockinfo[.]io
Read my how-to on leveraging Validin's exceptional visibility, history, and pivoting features for C2 infrastructure forensics:
www.validin.com/blog/bybit_h...
11.03.2025 18:33 β π 5 π 2 π¬ 0 π 0
Incredibly excited to drop some new research alongside @kennethkinion.bsky.social and Sreekar Madabushi at this years @pivotcon.bsky.social
10.03.2025 13:59 β π 7 π 1 π¬ 0 π 0
π£ Oops!... They did it again!!!
61 Talks submitted and so many too good that, once again, we had to increase a bit the number of accepted talks.π₯
#PIVOTcon25 Agenda is finally here, and the caliber is insane!!! Check it outβ‘οΈ pivotcon.org/agenda-2025/
#CTI #ThreatIntel
Talks and presenters inπ§΅β¬οΈ 1/18
07.03.2025 14:42 β π 20 π 14 π¬ 1 π 5
Really looking forward to my first @pivotcon.bsky.social in May. I'm super excited about doing this talk alongside @hegel.bsky.social and Sreekar!
07.03.2025 18:42 β π 0 π 0 π¬ 0 π 0
π°π΅ #BSidesPyongyang2025 : Nov 18 2025 (Missile Industry Day) @ Lazarus HQ Pyongyang
https://bsidespyongyang.com/
Official Computer Emergency Response Team (CERT) for the Democratic People's Republic of Korea
#NorthSide #NorthKoreaBestKorea
Journalist at Bloomberg News in DC. Signal: @howelloneill.01, email: patoneill1@bloomberg.net https://www.bloomberg.com/authors/AXb8dLPHBFc/patrick-howell-oneill
We are the Threat Intelligence and Malware Analysis team of
@sentinelone.com
https://sentinellabs.com
https://labscon.io
Experienced ignorer of Safe Browsing warnings
Founder @ Phish Report π£
Threat Research | Threat Intelligence | PhD | European Commission Marie Curie Research Fellow 2011-2014 | https://milenkoski.com | Personal Profile
Republics are systems that require people to compromise with each-other. Radicalism is the path to authoritarianism.
Managed endpoint protection, detection and response designed to help the 99% fight back against todayβs cybercriminals.
personal website @ cloudcurio.us β¦ researching @ Wiz Security (threats.wiz.io) π maintaining @ cloudvulndb.org ποΈ podcasting @ cryingoutcloud.io πΊοΈ pivoting @ Pivot Atlas (gopivot.ing)
sr detection engineer @ huntress β’ malware enjoyer β’ macOS security
https://alden.io
oh great, now Iβm on bluesky
software engineer | household alphabet teacher | karaoke try-hard
Taking a random walk down the software stack.
Also a dad of two toddlers, currently pursuing a management role in my house.
Founder of The Vertex Project (@vtxproject)
Father of the #APT1 Report @Mandiant.
Inventor of #synapse, #vivisect, UNCs, imphash, ...
DEFCON CTF Champion, Founder of Kenshoto
CYBERWARCON is a one-day conference in Arlington, VA focused on the specter of destruction, disruption, and malicious influence on our society through cyber capabilities.
cyberwarcon.com
Founder @ RationalEdge
#ThreatIntel #ICS #DFIR; ''Learning iOS Forensics'' author;
#BSidesZH #PIVOTcon org.
@pivotcon.bsky.social
https://pstirparo.ch
https://rationaledge.io
Related interests/obsessions:
#ThreatHunting #CTI #YARA #CriticalThinking #Books
Distinguished Threat Researcher, Research Lead @SentinelOne.
Advisor with @ValidinLLC.
https://tomhegel.com/blog.html
You may know me from your server logs.
#Malware, Hacks, Internet Scanning, #CTI
Executive Director for Intelligence and Security Research @ SentinelOne.
Distinguished Fellow and Adj Professor @ Hopkins SAIS Alperovitch Institute. Three Buddy Problem Co-Host. LABScon Founder, Cyber Paleontologist, Fourth-Party Collector.
Mandiant Intelligence at Google. CYBERWARCON and SLEUTHCON founder. Johns Hopkins professor. Army vet.
Senior leader for Cyber Threat Intelligence analysis at Amazon. @CitizenLab.ca Research Fellow. Former federal agent. Fan of space, books, tech, and Mother NatureπͺοΈ. Personal account. πΊπΈ πΊπ¦ πΉπΌ #ThreatIntel
Storm chasing: https://bsky.app/profile/wxdox.com