π Our latest #TDR report delivers an in-depth analysis of Adversary-in-the-Middle (#AitM) #phishing threats - targeting Microsoft 365 and Google accounts - and their ecosystem.
This report shares actionable intelligence to help analysts detect and investigate AitM phishing.
               
            
            
                11.06.2025 08:32 β π 10    π 7    π¬ 1    π 0                      
            
         
            
        
            
            
            
            
            
    
    
    
    
            The future of security operations depends on tools that reflect a deep understanding of investigative work. Unfortunately, many AI-driven products are being built by folks with neither investigative experience nor insight into the cognitive processes underlying effective analysis
               
            
            
                05.06.2025 16:01 β π 2    π 1    π¬ 1    π 0                      
            
         
            
        
            
            
            
            
            
    
    
    
    
            CTI tip: monitor transactions from the Ethereum address 0x53fd54f55C93f9BCCA471cD0CcbaBC3Acbd3E4AA to identify new PowerShell commands distributed by ClearFake - and block/detect any traffic to malicious domains!
As usual, feedback is greatly appreciated!
               
            
            
                20.03.2025 18:50 β π 2    π 1    π¬ 0    π 0                      
            
         
            
        
            
            
            
            
            
    
    
    
    
            Here is our in-depth analysis of the latest #ClearFake variant using the Binance Smart Chain and two new ClickFix lures.
ClearFake is injected into thousands of compromised sites to distribute the #Emmental Loader, #Lumma, #Rhadamanthys, and #Vidar.
β¬οΈ
bsky.app/profile/seko...
               
            
            
                20.03.2025 18:50 β π 4    π 1    π¬ 1    π 0                      
            
         
            
        
            
            
            
            
            
    
    
            
                        
                Ten Machine Requirements To Satisfy Essentials Of Joint Activity
                
            
        
    
    
            I recently read the paper "Towards Joint Activity Design Heuristics: Essentials for Human-Machine Teaming" which I loved so much I wanted to make it easier to share. To that end, I've excerpted the Ten Heuristics from the paper here: human-machine.team with anchors for each heuristic.
               
            
            
                07.03.2025 02:24 β π 16    π 10    π¬ 0    π 0                      
            
         
            
        
            
            
            
            
            
    
    
    
    
            Thank you, I love these blog posts!
Out of curiosity: do you track EpiBrowser and OneStart as belonging to this BrowserAssistant cluster that you just dropped?
               
            
            
                24.02.2025 17:17 β π 1    π 0    π¬ 1    π 0                      
            
         
            
        
            
            
            
            
            
    
    
    
    
            For those who did not monitor the supply chain attack against Chrome extensions in December 2024, our article provides an overview of:
- the targeted phishing attack against extension developers
- malicious code
- the adversary's infrastructure
β¬οΈ
bsky.app/profile/seko...
               
            
            
                22.01.2025 14:39 β π 3    π 3    π¬ 0    π 0                      
            
         
            
        
            
        
            
            
            
            
                                                
                                                
    
    
    
    
            Around 1,000 malicious domains are hosting webpages impersonating Reddit and WeTransfer, redirecting users to download password-protected archives
These archives contain an AutoIT dropper, we internally named #SelfAU3 Dropper at @sekoia.io, which executes #Lumma Stealer
IoCs β¬οΈ
               
            
            
                20.01.2025 18:13 β π 9    π 6    π¬ 2    π 0                      
            
         
            
        
            
            
            
            
            
    
    
    
    
            25gray3cook[.]com #Mamba2FA
               
            
            
                17.01.2025 15:07 β π 0    π 0    π¬ 0    π 0                      
            
         
            
        
            
            
            
            
            
    
    
    
    
            Our last article exposes the new AiTM phishing kit Sneaky 2FA, sold by the cybercrime service "Sneaky Log"!
We provide an in-depth analysis of the phishing pages, the associated service, detection opportunities and multiple IoCs.
β¬οΈ
bsky.app/profile/seko...
               
            
            
                16.01.2025 16:44 β π 6    π 1    π¬ 1    π 0                      
            
         
            
        
            
            
            
            
            
    
    
            
                            
                        
                Double-Tap Campaign : Russia-nexus APT possibly related to APT28 conducts cyber espionage on Central Asia and Kazakhstan diplomatic relations
                Uncover the details of UAC-0063 cyberespionage campaign in Kazakhstan and its potential connection to APT28
            
        
    
    
            Sekoia investigated a cyber espionage campaign using legitimate Office documents assessed to originate from the Ministry of Foreign Affairs of Kazakhstan, docs weaponized and used to collect strategic intelligence in Central Asia.
Here is the Double Tap campaign > blog.sekoia.io/double-tap-c...
               
            
            
                13.01.2025 09:00 β π 1    π 1    π¬ 0    π 0                      
            
         
            
        
            
            
            
            
            
    
    
    
    
            New Mamba 2FA relay domain:
25black1cook[.]com
#Mamba2FA #AiTM #PhaaS #phishing
               
            
            
                08.01.2025 14:19 β π 0    π 0    π¬ 1    π 0                      
            
         
            
        
    
         
        
            
        
                            
                    
                    
                                            Art and engineering. Random hobbyist
Livre photo "Corneilles, pas corbeaux" : https://ko-fi.com/aweusmeuh
                                     
                            
                    
                    
                                    
                            
                    
                    
                                    
                            
                    
                    
                                            Senior Intelligence Analyst at Red Canary, former DFIR at Mandiant. Psychology and history nerd. When I am not computering, I go outside and play!
                                     
                            
                    
                    
                                    
                            
                            
                    
                    
                                            Journaliste. Ex du Figaro. Co-responsable de la mineure MΓ©dias et Recherche Γ  l'ENS.
Contact : sderavinel(@)hotmail(.)com
                                     
                            
                    
                    
                                    
                            
                    
                    
                                            CEO @ KittyCADInc, π©π»βπ» @ oxidecomputer, π @ ACMQueue
                                     
                            
                    
                    
                                    
                            
                            
                    
                    
                                            Assistant Professor, Stanford Law School. Aussie struggling with Β°F & online speech stuff.
                                     
                            
                    
                    
                                            Influenceur Questions pour un Champion, époux de la merveilleuse Maritro, papa du minuscule Minitro. Petit rigolo de la cathosphère selon La Croix, c'est un peu exagéré selon ma Maman.
                                     
                            
                    
                    
                                            β οΈ MIRROR OF twitter.com/Erdayastronaut
β οΈ If you own the original account and want to claim this, please contact @twttr-mirrors.bsky.social
                                     
                            
                    
                    
                                            Cofounder, @AdaptiveCLabs, βthe NTSB of Techβ bringing Resilience Engineering to industry. he/him. Wonβt speak on all-male panels, and #blacklivesmatter.
                                     
                            
                    
                    
                                            independent writer of citationneeded.news and @web3isgoinggreat.com β’ tech researcher and cryptocurrency industry critic β’ software engineer β’ wikipedian
support my work: citationneeded.news/signup
links: mollywhite.net/linktree
πππ
                                     
                            
                    
                    
                                            CISO of SentinelOne, teaching at Stanford.