Hunting Laundry Bear: Infrastructure Analysis Guide and Findings | Validin
Hunting Laundry Bear: Infrastructure Analysis Guide and Findings
π¨ New blog post π¨
Hunting Laundry Bear: Infrastructure Analysis Guide and Findings
How to enrich previous reporting with Validin to find dozens of indicators not previously reported.
#LaundryBear #VoidBlizzard #APT
www.validin.com/blog/laundry...
25.07.2025 12:13 β π 0 π 0 π¬ 0 π 0
From @re.wtf:
bsky.app/profile/re.w...
20.06.2025 17:24 β π 0 π 0 π¬ 0 π 0
Zooming through BlueNoroff Indicators with Validin | Validin
Pivoting through recently-reported indicators to find BlueNoroff-associated domains
Hot on the heels of the researched published by @huntress.com, hunting for Zoom-themed lures from DPRK's #BlueNoroff
π₯Learn hunting techniques
π₯Leverage new Validin features and data
π₯Full, unredacted indicator list (domains, IPs, hashes)
www.validin.com/blog/zooming...
20.06.2025 17:24 β π 2 π 2 π¬ 1 π 0
At @pivotcon.bsky.social, I'm presenting with @hegel.bsky.social and Sreekar Madabushi on the first public look at the full scope of a stealthy, long-running phishing network.
24.04.2025 14:31 β π 7 π 5 π¬ 0 π 0
Finding Booking.com themed ClickFix domains using Validin | Validin
Finding Booking.com themed ClickFix domains using Validin
From on a report on X, we walk through proactive detection of a #booking #fakecaptcha #clickfix campaign delivering #asyncrat
As always, full indicator list and detailed step-by-step repro included π₯ ‡οΈ
www.validin.com/blog/finding...
17.04.2025 10:54 β π 0 π 0 π¬ 0 π 0
Not Reality: Exploring Meta-themed Phishing with Validin | Validin
Not Reality: Exploring Meta-themed Phishing with Validin
@bushidotoken.net explored a Meta-themed credential phishing campaign (not "Reality"). From those indicators, I pulled the "Threads" & this is far from an isolated campaign. Found great pivots in registration "Meta"data. (I'll see myself out.)
All 762 indicators π₯‡οΈ
www.validin.com/blog/not_rea...
07.04.2025 14:49 β π 2 π 2 π¬ 0 π 0
Lazarus Group Bybit Heist: C2 forensics | Validin
An in-depth hunt for Lazarus APT group infrastructure related to the Bybit hack using Validin's host response and DNS databases.
Found these likely #Lazarus / #TraderTraitor domains w/ #Validin
getcoinprice[.]info
stocksindex[.]org
wfinance[.]org
stockinfo[.]io
Read my how-to on leveraging Validin's exceptional visibility, history, and pivoting features for C2 infrastructure forensics:
www.validin.com/blog/bybit_h...
11.03.2025 18:33 β π 5 π 2 π¬ 0 π 0
Incredibly excited to drop some new research alongside @kennethkinion.bsky.social and Sreekar Madabushi at this years @pivotcon.bsky.social
10.03.2025 13:59 β π 7 π 1 π¬ 0 π 0
π£ Oops!... They did it again!!!
61 Talks submitted and so many too good that, once again, we had to increase a bit the number of accepted talks.π₯
#PIVOTcon25 Agenda is finally here, and the caliber is insane!!! Check it outβ‘οΈ pivotcon.org/agenda-2025/
#CTI #ThreatIntel
Talks and presenters inπ§΅β¬οΈ 1/18
07.03.2025 14:42 β π 20 π 14 π¬ 1 π 5
Really looking forward to my first @pivotcon.bsky.social in May. I'm super excited about doing this talk alongside @hegel.bsky.social and Sreekar!
07.03.2025 18:42 β π 0 π 0 π¬ 0 π 0
Cybersecurity reporter at Bloomberg News in DC. Signal: @howelloneill.01, email: patoneill1@bloomberg.net
We are the Threat Intelligence and Malware Analysis team of
@SentinelOne
https://sentinellabs.com
https://labscon.io
Experienced ignorer of Safe Browsing warnings
Founder @ Phish Report π£
Threat Research | Threat Intelligence | PhD | European Commission Marie Curie Research Fellow 2011-2014 | https://milenkoski.com | Personal Profile
βI understand you want the answer to be easy, but thatβs not the same thing as it being easy.β - Ken White
Managed endpoint protection, detection and response designed to help the 99% fight back against todayβs cybercriminals.
personal website @ cloudcurio.us β¦ researching @ Wiz Security (threats.wiz.io) π maintaining @ cloudvulndb.org ποΈ podcasting @ cryingoutcloud.io πΊοΈ pivoting @ Pivot Atlas (gopivot.ing)
sr detection engineer @ huntress β’ malware enjoyer β’ macOS security
https://alden.io
oh great, now Iβm on bluesky
software engineer | household alphabet teacher | karaoke try-hard
Taking a random walk down the software stack.
Also a dad of two toddlers, currently pursuing a management role in my house.
Founder of The Vertex Project (@vtxproject)
Father of the #APT1 Report @Mandiant.
Inventor of #synapse, #vivisect, UNCs, imphash, ...
DEFCON CTF Champion, Founder of Kenshoto
CYBERWARCON is a one-day conference in Arlington, VA focused on the specter of destruction, disruption, and malicious influence on our society through cyber capabilities.
cyberwarcon.com
#ThreatIntel #ICS #DFIR; ''Learning iOS Forensics'' author;
#BSidesZH #BSidesBE #PIVOTcon org.
@pivotcon.bsky.social
https://pstirparo.ch
twitter.com/pstirparo
Related interests/obsessions:
#ThreatHunting #CTI #YARA #CriticalThinking #Books #Obsidian
Distinguished Threat Researcher, Research Lead @SentinelOne.
Advisor with @ValidinLLC.
https://tomhegel.com/blog.html
You may know me from your server logs.
Malware, Hacks, Internet Scanning, CTI
w00w00, Censys, IST
Executive Director for Intelligence and Security Research @ SentinelOne.
Distinguished Fellow and Adj Professor @ Hopkins SAIS Alperovitch Institute. Three Buddy Problem Co-Host. LABScon Founder, Cyber Paleontologist, Fourth-Party Collector.
Mandiant Intelligence at Google. CYBERWARCON and SLEUTHCON founder. Johns Hopkins professor. Army vet.
Senior Manager, Amazon/AWS Threat Intelligence. @CitizenLab.ca Research Fellow. Former federal agent. Fan of space, books, technology, and Mother NatureπͺοΈ. Personal account. πΊπΈ πΊπ¦ πΉπΌ #ThreatIntel
Storm chasing: https://bsky.app/profile/wxdox.com
Cybersecurity Specialist, Public Speaker, Ex-Hacker.
https://marcushutchins.com
Founder of Granitt, securing journalists and at-risk people around the world.