Saher's first blog on the scourge that is ClickFix usage in the espionage space!!
Had to sneak in the UNK_RemoteRogue RDP shenanigans as well - a thus far unattributed group we assess to be Russia-aligned, using a pretty fun set of email tactics
@x-hunt3r.bsky.social
Threat Hunting & Research, Network Forensics | Principal Threat Analyst @ Recorded Future | "Undesirable" | Member CuratedIntel | Views and opinions are my own
Saher's first blog on the scourge that is ClickFix usage in the espionage space!!
Had to sneak in the UNK_RemoteRogue RDP shenanigans as well - a thus far unattributed group we assess to be Russia-aligned, using a pretty fun set of email tactics
Attention!
Check your Compromised Website Report for critical events tagged โfortinet-compromisedโ and follow Fortinet's mitigation advice on compromised devices:
fortinet.com/blog/psirt-b...
Data available from 2025-04-11+
shadowserver.org/what-we-do/n...
Snoop, a Romanian investigative journalism outlet, has linked an online advertising company named AdNow to intelligence officials from Russia's FSB and SVR services
snoop.ro/pe-urmele-ba...
๐ชก Our 2024 Malicious Infrastructure Report showcases the results of our detections across hundreds of malware families and threat actors, revealing victims in 200+ countries and highlighting the global scale of cyber threats.
Blog: www.recordedfuture.com/research/202... (1/10)
@volexity.com recently identified multiple Russian threat actors targeting users via #socialengineering + #spearphishing campaigns with Microsoft 365 Device Code authentication (a well-known technique) with alarming success: www.volexity.com/blog/2025/02...
#dfir #threatintel #m365security
New Insikt Report just landed: RedMike AKA Salt Typhoon targeting of Global Telcos.
www.recordedfuture.com/research/red...
๐ฅ Live streams resume this week! Greg Lesnewich joins us to talk about 100 Days of Yara, some Yara rule tips and the current state of email borne threats!
https://buff.ly/4gukMSN
๐๏ธ Thursday at 2pm CST
Ukrainian military officials, lawmakers, and experts are discussing the creation of a separate branch of Ukraine's Armed Forces dedicated to cyberspace operations, according to the General Staff of Ukraine.
kyivindependent.com/ukraine-cons...
New report! Check it out.
This research examines the operations of Crazy Evil โ a Russian-speaking โtraffer teamโ and cryptoscam gang โ which has victimized thousands of people with infostealer malware.
Blog: www.recordedfuture.com/research/cra...
PDF: go.recordedfuture.com/hubfs/report...
New Blog! Tracking Adversaries: Ghostwriter APT Infrastructure ๐ง๐พ
blog.bushidotoken.net/2025/01/trac...
Great work!
14.01.2025 12:56 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0UK domain giant Nominet confirms cybersecurity incident linked to Ivanti VPN hacks
13.01.2025 12:20 โ ๐ 23 ๐ 10 ๐ฌ 1 ๐ 0New report! Check it out.
This research examines the global proliferation of Russian surveillance technologies, their use by repressive governments, and possible data-sharing with Russian intelligence.
Blog: www.recordedfuture.com/research/tra...
PDF: go.recordedfuture.com/hubfs/report...
DOOM-based CAPTCHA system
doom-captcha.vercel.app
Russia's 'Sovereign Runet' initiative aims to isolate its internet from the global web, posing significant challenges to the cybercrime underworld that thrives on international connectivity. #CyberSecurity #Runet
www.cybercrimediaries.com/post/russia-...
New report! Check it out.
This research examines the role of Chinese international communication centers (ICCs) in amplifying propaganda via inauthentic social media activity, foreign influencers, and more.
Blog: www.recordedfuture.com/research/bre...
PDF: go.recordedfuture.com/hubfs/report...
Great to be back at Cyber Threat for a third year. Awesome talks, great networking, and a very fresh and fun CTF. #cyberthreat24
10.12.2024 16:27 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0๐จ New Report Alert: Insikt Group has uncovered #BlueAlpha, a Russian FSB-linked threat group overlapping with #Gamaredon, conducting a cyber-espionage campaign against Ukrainian targets. www.recordedfuture.com/research/blu...
05.12.2024 16:30 โ ๐ 4 ๐ 3 ๐ฌ 0 ๐ 0@milenkowski.bsky.social and I are looking forward to presenting together at #CyberThreat2024 in London next month. Weโll be discussing China-nexus APTs engaging in cybercriminal activities like ransomware.
25.11.2024 16:20 โ ๐ 8 ๐ 4 ๐ฌ 0 ๐ 0Looking for more people to follow on BlueSky? Find the @curatedintel.bsky.social folks here: go.bsky.app/Kfp62Uh
18.11.2024 16:11 โ ๐ 28 ๐ 17 ๐ฌ 3 ๐ 1A new TAG-110 report, including victimology and recent C2 infrastructure, has just landed. #TAG110 #BlueDelta #APT28 www.recordedfuture.com/research/rus...
21.11.2024 15:37 โ ๐ 5 ๐ 0 ๐ฌ 0 ๐ 0Screengrab of search results in Bluesky for the handle "bbcnews". It shows a list of accounts all of which could be the real BBC news, but it's unclear.
As we're in this rapid growth of @bsky.app, not only are we going to see accnts impersonating high profile individuals, but critically, impersonating high reputation news sources.
All it would take is some imaginative "Breaking News" to hit public confidence.
Can the real BBC News please stand up?