's Avatar

@pdub5.bsky.social

21 Followers  |  31 Following  |  5 Posts  |  Joined: 14.11.2024  |  1.5353

Latest posts by pdub5.bsky.social on Bluesky

Post image

I'm super excited to be speaking at @cyberwarcon.bsky.social
this year! The lineup looks amazing, as always. including a keynote with Dimitri Alperovitch. ๐Ÿคฏ

Check out the full agenda here!
cyberwarcon.com/agenda-25

09.10.2025 14:21 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Join @austinlarsen.me and me next Tuesday for a deep-dive into PRC-nexus threat actor capabilities! Learn about advanced social engineering tactics, novel malware delivery, and strategies to defend your organization.

www.brighttalk.com/webcast/7451...

09.09.2025 22:49 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats | Google Cloud Blog A social engineering campaign leveraging signed malware, evasive tactics, and captive portal hijacking.

New GTIG blog just dropped! ๐Ÿฅธ๐Ÿ‡จ๐Ÿ‡ณ๐ŸŒ๐Ÿ’ผ โ€Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats"! We're analyzing an operation that has it all; AitM, social engineering, signed malware, and more! Get the full breakdown here:
cloud.google.com/blog/topics/...

25.08.2025 16:13 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Preview
Whatโ€™s in an ASP? Creative Phishing Attack on Prominent Academics and Critics of Russia | Google Cloud Blog A Russia-sponsored threat actor is impersonating the U.S. Department of State, and using phishing to gain access to email accounts.

So @gabagool.ing (who will henceforth be referred to as "gabbot") and I wrote some stuff on some ASP phishing campaigns: cloud.google.com/blog/topics/...

Citizen Lab worked closely with one of the targets and shared their work on it also: citizenlab.ca/2025/06/russ...

18.06.2025 17:04 โ€” ๐Ÿ‘ 10    ๐Ÿ” 7    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 2
Preview
COLDRIVER Using New Malware To Steal Documents From Western Targets and NGOs | Google Cloud Blog Russian government-backed group COLDRIVER is using LOSTKEYS malware to steal files and system information from NGOs and western targets.

I wrote some details on LOSTKEYS: malware which we directly attribute to COLDRIVER. They don't deploy it often, but we have seen it a few times and want to make people aware of it.

cloud.google.com/blog/topics/...

07.05.2025 14:13 โ€” ๐Ÿ‘ 18    ๐Ÿ” 14    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1
Preview
a man and a woman are standing next to each other in a room and the man is talking to the woman . ALT: a man and a woman are standing next to each other in a room and the man is talking to the woman .

I thought going overboard on emojis was a requirement for blog announcements?

28.05.2025 18:51 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

๐Ÿšจ Heads up! ๐Ÿšจ APT41 is using Google Calendar ๐Ÿ—“๏ธ as their latest C2 trick. GTIG just pulled back the curtain ๐ŸŽญ on the TOUGHPROGRESS malware campaign and how we shut it down ๐Ÿ’ช. Dive into the details here: ๐Ÿš€https://cloud.google.com/blog/topics/threat-intelligence/apt41-innovative-tactics

28.05.2025 14:11 โ€” ๐Ÿ‘ 8    ๐Ÿ” 4    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 3

@pdub5 is following 20 prominent accounts