fastfire's Avatar

fastfire

@fastfire.bsky.social

Head of Cyber Threat Intelligence @ WΓΌrth Group, GCTI/CPENT/CEH/CND/CSA/ECSA/ECIH/CTIA, owner of SATAYO CTI platform & deepdarkCTI - member of @CuratedIntel

507 Followers  |  111 Following  |  21 Posts  |  Joined: 25.07.2023  |  1.8497

Latest posts by fastfire.bsky.social on Bluesky

Post image

πŸ“’ New #Insomnia ransomware gang.
☒️ Active since October 2025, 17 victims published on their data leak site.
πŸ‘‰πŸΌ Onion link and TOX ID already available on #deepdarkCTI github.com/fastfire/dee...

07.02.2026 21:38 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

πŸ“Œ How is the ransomware gang landscape evolving after the #RAMP forum seizure?
πŸ”΄ Another well-known forum seems to be becoming a point of reference in this field.
πŸ‘‰πŸΌ We discuss it in the article you can read at this link www.neteye-blog.com/2026/02/from...

04.02.2026 10:53 β€” πŸ‘ 1    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Post image

With 2025 now behind us, we can make some observations regarding the landscape of double-extortion #ransomware #attacks.
❓ Which ransomware gangs were the most active?
❓ Which sectors and countries were most affected?

πŸ‘‰πŸ» Read the full article here www.neteye-blog.com/2026/01/rans...

02.01.2026 13:57 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

πŸ“’ Recap of what happened in #deepdarkCTI in 2025:

βœ… 586 commits
βœ… 35 contributors
βœ… 6,400 stars on GitHub
βœ… 8 articles on www.deepdarkcti.com
βœ… 129 active users within the Telegram channel
βœ… a total of 2,465 sources

πŸ™ Many thanks to the #deepdarkCTI community!

31.12.2025 13:08 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

A new interview is available on the #deepdarkCTI project blog. This time, the interview concerns the #Benzona ransomware gang.
πŸ‘‰ You can read the full interview here deepdarkcti.com/interview-8-...

23.12.2025 23:48 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@ichinin.bsky.social I don't think you read the article carefully; perhaps you just looked at the image. The indicators provided are always contextualized within an analysis ticket. So, yes, it's intelligence.

06.11.2025 12:12 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

πŸ”΄The problem of properly integrating #Threat #Intelligence into #Security #Operations processes is a recurring one.
πŸ“Œ I wrote an article in which I described the integration process we have implemented.
πŸ‘‰πŸ» Read the article here www.neteye-blog.com/2025/11/embe...

05.11.2025 23:28 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

#Ransomware πŸ“£ NEW FEATURE
La nuova sezione RF Domain Monitor permette il monitoraggio costante dei domini sotto controllo #Ransomfeed e di deepdarkCTI project (@fastfire.bsky.social), alla ricerca di variazioni DNS e law enforcement.
1/2

22.10.2025 10:15 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Post image

πŸ“’ We interviewed Gabi, a member of the #Cyber ​​#Toufan group. This group, active since October 2024, has carried out several attacks against #Israeli targets.
The full interview is available at the link deepdarkcti.com/interview-7-...

03.09.2025 20:03 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

πŸ“’ At deepdarkcti.com/details-of-t..., you can find a detailed timeline of the main events related to the alleged seizure of the #XSS forum.
⏰ The timeline is constantly updated, taking into account relevant events that are also occurring in recent days.
#deepdarkCTI

05.08.2025 21:11 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

πŸ“’ A new interview is available on the #deepdarkCTI website. This time, community member #Erez interviewed the founder of the #Devman ransomware gang.
πŸ‘‰πŸ» You can read the full interview at this link deepdarkcti.com/interview-6-...

15.07.2025 08:36 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - fastfire/IsraelIranConflict: List of groups that are carrying out cyber actions in the conflict between Israel and Iran. List of groups that are carrying out cyber actions in the conflict between Israel and Iran. - fastfire/IsraelIranConflict

If you want to contribute, I created this project where I'm cataloging the Telegram channels of the various groups related to the Israel-Iran conflict, shared by @cyberknow.bsky.social github.com/fastfire/Isr...

18.06.2025 20:31 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Loading...

πŸ“’ New Critical Vulnerabilities Disclosed for Citrix Netscaler support.citrix.com/support-home...

17.06.2025 18:49 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

We interviewed #Se7en, the founder of #Exodus #Market, a platform for selling #infostealers #logs.
Read the full interview here deepdarkcti.com/interview-5-...

10.06.2025 19:34 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

New ransomware gang #RunSomeWares DLS. 4 victims claimed. Already indexed on #deepdarkCTI

27.02.2025 15:40 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

New ransomware gang #Anubis DLS. Already indexed on #deepdarkCTI

24.02.2025 23:00 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

βš”οΈ New data leak site: #Kraken ransomware gang. The gang seems to be simply a rebrand of #HelloKitty, as of the 5 victim organizations already declared, 2 (Cisco and CDProject) had already been previously declared.
🎯 The DLS link has already been added to #deepdarkCTI (github.com/fastfire/dee...).

09.02.2025 08:40 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Some updates regarding the #Gravy #Analytics data breach. I analyzed part of the data shared by TA #nightly on #XSS forum. Some of the numbers involved:
13473 applications
396115 ip
3317 organizations
43586 locations
11 countries
330543 partners email accounts

08.01.2025 23:38 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Happy Holidays to the amazing #deepdarkCTI community! Our project has reached 4600 stars this year, since the beginning of the project we have had 93 contributors, in the private Telegram channel there are about 100 users, we have counted over 1900 sources! Thank you all so much!

23.12.2024 11:49 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
GitHub - fastfire/deepdarkCTI: Collection of Cyber Threat Intelligence sources from the deep and dark web Collection of Cyber Threat Intelligence sources from the deep and dark web - fastfire/deepdarkCTI

If you don't already... consider following and supporting #deepdarkCTI github.com/fastfire/dee...

10.12.2024 21:11 β€” πŸ‘ 12    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Post image

When you work together with friends, everything is easier! #CyberSec #ThreatIntelligence

10.12.2024 20:55 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Great list @oxley.io! If you would consider adding my account... thanks!

10.12.2024 20:50 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@fastfire is following 20 prominent accounts