Saher's Avatar

Saher

@saffronsec.bsky.social

Threat Research @ Proofpoint. Former @virtualroutes.bsky.social fellow. @warstudieskcl.bsky.social alum. She/her

154 Followers  |  95 Following  |  13 Posts  |  Joined: 07.03.2025  |  1.6737

Latest posts by saffronsec.bsky.social on Bluesky

There’s always tomorrow

05.11.2025 19:17 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Elusive Iranian APT Phishes Influential US Policy Wonks Iran is spying on American foreign policy influencers. But exactly which of its government's APTs is responsible remains a mystery.

Thanks to Nate Nelson at @darkreading.bsky.social for covering my report! www.darkreading.com/cyberattacks...

05.11.2025 16:53 β€” πŸ‘ 5    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Crossed wires: a case study of Iranian espionage and attribution | Proofpoint US Proofpoint would like to thank Josh Miller for his initial research on UNK_SmudgedSerpent and contribution to this report.Β  Key findingsΒ  Between June and August 2025,

New Iran drop from me tracking an attribution nightmare - UNK_SmudgedSerpent! A little Charming, a little Muddy, and a lot C5. Targeting policy experts with benign conversation starters, health-themed infra, OnlyOffice spoofs, and RMMs. Check out the full story www.proofpoint.com/us/blog/thre...

05.11.2025 13:37 β€” πŸ‘ 18    πŸ” 12    πŸ’¬ 2    πŸ“Œ 0

Check out the newest intel conference to discover the latest insights into all kinds of statecraft!

28.07.2025 10:17 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Bonus: great coverage of our research in an exclusive from one of my fave reporters @ajvicens.bsky.social www.reuters.com/sustainabili...

17.07.2025 08:52 β€” πŸ‘ 5    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Preview
Phish and Chips: China-Aligned Espionage Actors Ramp Up Taiwan Semiconductor Industry TargetingΒ  | Proofpoint US Key findingsΒ  Between March and June 2025, Proofpoint Threat Research observed three Chinese state-sponsored threat actors conduct targeted phishing campaigns against the Taiwanese

New from the one and only pun-king @mkyo.bsky.social on the increased and ongoing Chinese targeting of semiconductor-related organisations in Taiwan. Edge device exploitation may be the TTP of the moment, but Chinese groups still go phishing when the chips are down www.proofpoint.com/us/blog/thre...

17.07.2025 08:43 β€” πŸ‘ 9    πŸ” 5    πŸ’¬ 1    πŸ“Œ 1
Preview
Comic Sans and Cybercrime: Inside North Korea’s Global Cyber Playbook Podcast Episode Β· DISCARDED: Tales From the Threat Research Trenches Β· 07/01/2025 Β· 53m

New DISCARDED podcast drop! Join
@greg-l.bsky.social and me as we talk about our fave North Korean groups, DPRK as the neglected child, TA406 and the Russian connection, and finally, the dreaded but pervasive IT worker problem podcasts.apple.com/us/podcast/c...
open.spotify.com/episode/01d1...

01.07.2025 16:22 β€” πŸ‘ 8    πŸ” 4    πŸ’¬ 1    πŸ“Œ 0
Preview
10 Things I Hate About Attribution: RomCom vs. TransferLoader | Proofpoint US Threat Research would like to acknowledge and thank the Paranoids, Spur, and Pim Trouerbach for their collaboration to identify, track, and disrupt this activity.Β  Key takeaways

Fun crossover blog about TA829 (RomCom) & TransferLoader with my ecrime pals @selenalarson.bsky.social it’s got it all:

πŸ›°οΈ Popped routers for sending phish

πŸ“Š ACH on attribution

πŸ‘Ύ custom protocols

πŸ‘½ cool malware

πŸ•΅οΈ crime

🎯 espionage

❔many unanswered questions

www.proofpoint.com/us/blog/thre...

30.06.2025 10:04 β€” πŸ‘ 17    πŸ” 12    πŸ’¬ 0    πŸ“Œ 2
Preview
The Bitter End: Unraveling Eight Years of Espionage Anticsβ€”Part One | Proofpoint US This is a two-part blog series, detailing research undertaken in collaboration with Threatray. Part two of this blog series can be found on their website here.Β  Analyst note: Throughout

From phishes to hands-on-keyboard commands πŸ”₯ new @proofpoint.bsky.social research from @nickattfield.bsky.social and @konstantinklinger.bsky.social on Indian state-sponsored actor TA397 (Bitter) with a great story on the steps to technical and political attribution www.proofpoint.com/us/blog/thre...

04.06.2025 11:08 β€” πŸ‘ 11    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Preview
The ClickFix Convergence: How Threat Actors Blur the Lines Podcast Episode Β· DISCARDED: Tales From the Threat Research Trenches Β· 05/14/2025 Β· 36m

Check out the new DISCARDED episode! Had too much fun recording my first podcast with @selenalarson.bsky.social and Sarah on my ClickFix crossover blog!!

Podcast: podcasts.apple.com/us/podcast/d...

Blog: www.proofpoint.com/us/blog/thre...

15.05.2025 15:04 β€” πŸ‘ 9    πŸ” 3    πŸ’¬ 1    πŸ“Œ 1
Preview
TA406 Pivots to the Front | Proofpoint US What happenedΒ  In February 2025, TA406 began targeting government entities in Ukraine, delivering both credential harvesting and malware in its phishing campaigns. The aim of these

@greg-l.bsky.social drops knowledge on TA406 (Konni) as North Korea shows new interest in Ukraine, likely to keep tabs on the progress of the war and Russia's ability to keep pace on the battlefield www.proofpoint.com/us/blog/thre...

13.05.2025 09:53 β€” πŸ‘ 15    πŸ” 13    πŸ’¬ 1    πŸ“Œ 1

Hell no, they are my nemesis. And Josh already offered - no takebacks!!

18.04.2025 20:48 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Thanks to my favorite team buddies for their collab and indulging my slight obsession πŸ’œ @greg-l.bsky.social @mkyo.bsky.social and Josh

18.04.2025 12:54 β€” πŸ‘ 10    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

You love to see it! Talented super friends beating up on the bad guys

17.04.2025 15:17 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Around the World in 90 Days: State-Sponsored Actors Try ClickFix | Proofpoint US Key Findings While primarily a technique affiliated with cybercriminal actors, Proofpoint researchers discovered state-sponsored actors in multiple campaigns using the ClickFix social

My first blog with Proofpoint is live! And we love a good crossover. State-sponsored actors try their hand at ClickFix - the hottest thing in cybercrime. Meet the North Koreans, Iranians, and Russians who are upping their social engineering game www.proofpoint.com/us/blog/thre...

17.04.2025 11:12 β€” πŸ‘ 42    πŸ” 19    πŸ’¬ 1    πŸ“Œ 4

@saffronsec is following 20 prominent accounts