๐ฃ๐ง Since early September 2025, the Orange Cyberdefense CSIRT and CyberSOC teams have detected phishing campaigns impersonating Meta, AppSheet and Paypal, leading to malware delivery. Our team tracks this activity under the alias "Metappenzeller".
#CTI #ThreatIntel #Metappenzeller #phishing
23.09.2025 09:37 โ ๐ 0 ๐ 1 ๐ฌ 1 ๐ 0
๐ง Update on MintsLoader: a thread ๐ฝ
MintsLoader is a JavaScript/PowerShell loader that was first detailed by OCD in 2024.
A new version has been around at least since early-June 2025.
#threatintel #cti #mintsloader
03.07.2025 07:43 โ ๐ 3 ๐ 4 ๐ฌ 1 ๐ 0
During our analysis, we noticed a surprising line, likely written by threat actors to prevent AI-powered file scanning
This is actually the first time we observed such an attempt, even though we found it to be unsuccessful with GPT-4o.
17.03.2025 15:56 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
V3 features several changes including new mouse movements speed check.
Recent infection chains includes new intermediary stage (Powershell with AMSI bypass feature which loads a .NET stage) in charge of delivering #stealers.
17.03.2025 15:56 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
๐New version of #Emmenhtal loader actively distributed worldwide since early March, leading to #Lumma or #Rhadamanthys stealers.
Very low AV detection on VT for now.
Similarly to V2, Emmenhtal V3 masquerades as #mp3 or #mp4 files, including relaxation songs.๐งโโ๏ธ
17.03.2025 15:56 โ ๐ 2 ๐ 1 ๐ฌ 1 ๐ 0
๐New version of our #ransomware mapping is out on our GitHub!
โก๏ธhttps://github.com/cert-orangecyberdefense/ransomware_map/blob/main/OCD_WorldWatch_Ransomware-ecosystem-map.pdf
V28 (!) includes latest newcomers and recent ecosystem evolutions.๐
As always, feedback is welcome!
#cti #threatintel
05.03.2025 16:32 โ ๐ 2 ๐ 3 ๐ฌ 0 ๐ 0
Orange Cyberdefense CERT Threat Research: The hidden network map
๐For more than 8 months, our threat researchers from OCD
have worked on mapping China's civil-militaryโindustrial complex when it comes to #cyberespionage operations.
โฏ Consult our newly published deep-dive report and interactive map here:
research.cert.orangecyberdefense.com/hidden-netwo...
25.11.2024 10:59 โ ๐ 5 ๐ 2 ๐ฌ 0 ๐ 0