sp @SP_Intel
Joined May 2015-
Tweets26
-
Followers11
-
Following142
-
Likes15
We’ve been tracking a phishing campaign that has been using open redirects for months, and it continues to evolve and persist. As recently as last week, we detected a spam run that abused a different web app but utilized the same TTPs and infrastructure.
A phishing campaign tries to evade detection by dividing its attachment into code segments and encoding them using various mechanisms. It’s like a jigsaw puzzle that only reveals its malicious intent once all pieces are combined and decoded. Details: msft.it/6019nLKsX
Our work to deliver comprehensive protection involves detecting anomalies as well as identifying threats hiding in plain sight. A sudden spike in the use of JNLP file attachments exposed an email campaign that was observed distributing a new credential-stealing malware.
An active phishing campaign is using a crafty combination of legitimate-looking original sender email addresses, spoofed display sender addresses that contain the target usernames and domains, and display names that mimic legitimate services to try and slip through email filters.
In the past few months, Microsoft has been tracking a dynamic campaign targeting the aerospace and travel sectors with spear-phishing emails that distribute an actively developed loader, which then delivers RevengeRAT or AsyncRAT.
The recent surge of IcedID campaigns indicate that this malware family is likely being used to fill in some of the void left by recent malware infrastructure disruptions. We are tracking multiple active IcedID campaigns of various sizes, delivery methods, and targets.
Phishers continue to find success in using compromised accounts on email marketing services to send malicious emails from legitimate IP ranges and domains. They take advantage of configuration settings that ensure delivery of emails even when the email solution detects phishing.
We're seeing numerous extensive hands-on-keyboard attacks emanating from the Gootkit malware, which is distributed via drive-by downloads as a JavaScript within a ZIP file. The JavaScript is launched via WScript and establishes C2, enabling attackers to take control of devices.
WATCH: This webinar covers insights and details from our investigation into a sprawling email delivery infrastructure that was used to send more than a million emails per month through multiple campaigns from March to December 2020 youtube.com/watch?v=scrs5Z…
We’re tracking a rampant phishing attack that uses DGA domains, free email services, and even compromised email accounts to send massive numbers of phishing emails. These emails are linked by open redirector URLs that begin with a distinct pattern: hxxps://t[.]domain[.]tld/r/?
Your front-row seat to my Mars landing is here. Watch how we did it. #CountdownToMars
Microsoft 365 Defender data shows that the disruption of Emotet infrastructure immediately resulted in the drop in new campaigns. Given Emotet’s reach and role in the deployment of payloads like ransomware, however, customers should ensure continued monitoring and protection.
We detected a recent spike in busines email compromise (BEC) attacks soliciting gift cards primarily targeting K-12 schoolteachers. Attackers impersonate colleagues or school officials to ask recipients to purchase various gift cards.
The increased abuse of legitimate cloud hosting services in malware campaigns.
The increased abuse of legitimate cloud hosting services in malware campaigns.
We’re tracking an active credential phishing attack targeting enterprises that uses multiple sophisticated methods for defense evasion and social engineering. The campaign uses timely lures relevant to remote work, like password updates, conferencing info, helpdesk tickets, etc.
Trickbot disrupted
Our researchers are tracking a phishing infrastructure that’s being used to launch phishing attacks targeting enterprises. The campaign is notable for its use of HTML attachments that pose as Excel files and contain encoded information about targets, indicating prior recon.
Earlier this week we started seeing a spike in the use of password-protected documents in multiple malware campaigns, including Trickbot. These documents are attached to emails that use varying social engineering lures like the typical "order", "invoice", "documents".

Itluhie @Itluhie3605
4 Followers 275 Following
Kapenys @kapenys16628
23 Followers 1K Following
Red Sift @redsift
1K Followers 4K Following Red Sift helps the best security teams understand and remediate #CyberSecurity risk before an incident happens.
Jaba @Jaba_mulata
11 Followers 196 Following
Herbie Zimmerman @HerbieZimmerman
3K Followers 947 Following Previous SOC analyst and still wanna-be malware researcher. Manager @HuntressLabs. Stay awesome folks! https://t.co/iZPu82FWX0
@𝕚𝕞𝕖𝕖 �... @A1m33_m
2K Followers 2K Following Cyber Threat Hunter. I enjoy #crossfit, #cats, #travel. Here for #InfoSec #DFIR #blueteam Twitter
Michael Cyr @Trilobyte_
287 Followers 202 Following Threat Intelligence analyst @ Microsoft. I run a lot of queries. My posts are my own and do not represent my employer.
AI The Age is ours! �... @aashuirch
119 Followers 512 Following
HireaTab @HireaTab
576 Followers 3K Following Hire, Rent Apple iPad, Samsung Tab at a fraction of cost in Pune, Delhi, India. Event Management #HireaTab https://t.co/iOTKbb5HMf
MEA FactCheck @MEAFactCheck
37K Followers 9 Following Ministry of External Affairs Official FactCheck Account | Countering Disinformation and Fake news
Shashi Tharoor @ShashiTharoor
8.5M Followers 1K Following INC. MP for Thiruvananthapuram. Author of 25 books. Founder @ProfCong. ExMinister ofState, Govt.of India. Former UnderSecretaryGeneral, @UN. Cricket fan.
Prachyam @prachyam7
205K Followers 1K Following Hindus finally have a Netflix-Style platform of their own - #PrachyamTV. Want to contribute to the revolution? Join the Team: write at [email protected]
GemsOfINDOLOGY @GemsOfINDOLOGY
92K Followers 639 Following Preserving the past. Guiding the present. Always asking, never settling
Open Source Intel @Osint613
700K Followers 894 Following Monitoring Real-Time News & Open Source Intelligence • Middle East • US • Global Events • Anything on my mind
DISTRICT INFORMATION ... @Info_Pune
56K Followers 43 Following महाराष्ट्र शासनाच्या माहिती व जनसंपर्क महासंचालनालयांतर्गत जिल्हा माहिती कार्यालय पुणे कार्यालयाचे अधिकृत ट्विटर हँडल
Dr. S. Jaishankar @DrSJaishankar
4.0M Followers 35 Following External Affairs Minister of India. Member of Parliament (Rajya Sabha) from Gujarat State.
President of India @rashtrapatibhvn
27.6M Followers 2 Following Official Twitter account of Rashtrapati Bhavan and is run by the President’s Secretariat | Smt Droupadi Murmu, President of India.
IndianPremierLeague @IPL
9.0M Followers 152 Following Follow to get exclusive and real-time Indian Premier League news and updates.
Patrick Bet-David —... @notPBD
97K Followers 186 Following Clips and commentary | Not affiliated with Patrick Bet-David | Commentary Account
Shiv Aroor @ShivAroor
1.4M Followers 568 Following Managing Editor, @NDTV, Anchor ‘India Matters’ @ 8pm Mon-Fri | ex-@IndiaToday | Founder, @Livefist | Author of the #IndiasMostFearless series
Baba MaChuvera 💫 P... @indian_armada
80K Followers 159 Following Parody Joker. Photoshop for Pun. Be an Unbiased Intellectual, Fandom won't feed ur family. Seems like you have seen my memes before. व्यंगशास्त्र to कामशास्त्र.
Yogi Adityanath @myogiadityanath
32.5M Followers 59 Following मुख्यमंत्री (उत्तर प्रदेश); गोरक्षपीठाधीश्वर, श्री गोरक्षपीठ; सदस्य, विधान सभा, उत्तर प्रदेश; पूर्व सांसद (लोकसभा-लगातार 5 बार) गोरखपुर, उत्तर प्रदेश
Amit Shah @AmitShah
37.1M Followers 316 Following Union Home Minister, Minister of Cooperation and MP, Gandhinagar Lok Sabha. https://t.co/jEf4rOW2AD
Sarbraj Singh Kahlon @sarbrajskahlon
6K Followers 802 Following Community Reporter @OMNIpunjabi on @OMNITelevision | Tweets & re-tweets do not reflect the views of employer.
Sputnik India @Sputnik_India
114K Followers 1K Following News free of Western bias 👉 Follow our X account in Hindi: @SputnikHindi
U.S. Embassy India @USAndIndia
357K Followers 195 Following Official account of U.S. Embassy in India. RTs/links are not endorsement. Follow US Ambassador to India at @USAmbIndia. Terms of use: https://t.co/Hz0PCXRUZ7
Husky Lovers Group @GroupHusky31746
11K Followers 2K Following 👉 Welcome to @grouphusky31746, 🐕 We share daily #husky Contents, 🐾 Follow us if you really love Husky
Donald J. Trump @realDonaldTrump
108.8M Followers 53 Following 45th & 47th President of the United States of America🇺🇸
India in USA @IndianEmbassyUS
208K Followers 1K Following Official Twitter account of the Embassy of India, Washington, DC. #Passport Issue @IndiaPassportDC #Visa @IndiaVisaDC #OCI @IndiaOCIDC
India In Seattle @IndiainSeattle
3K Followers 59 Following Welcome to the Official Twitter Account of the Consulate General of India, Seattle.
Richard Kettleborough @RichKettle07
110K Followers 14 Following Every smile, kind word, and an act of generosity goes on forever || Have a great day ||
KOMO News @komonews
491K Followers 2K Following The latest breaking news, traffic, and weather from Seattle and Western Washington.
Times Algebra @TimesAlgebraIND
780K Followers 239 Following News Updates || Political News || Geopolitical || Election Updates & Analysis ll Movie Review || Reposts not Endorsement
Rohit Sharma @ImRo45
24.3M Followers 44 Following
Python Coding @clcoding
595K Followers 94 Following 🚀 Learn #Python the fun way! 📌 Daily tips, tutorials & projects | Educator | AI Community Partner Free Course https://t.co/l9NKxZVTrz
Dr Kumar Vishvas @DrKumarVishwas
10.0M Followers 90 Following Poet, Farmer, Indian “Koi Deewana Kehta Hai, Koi Pagal Samajhta Hai❤️” If you do “Hindu-Muslim” on my Timeline, you’ll get blocked🇮🇳
Jim Cramer @jimcramer
2.3M Followers 692 Following Host of @madmoneyoncnbc and I run the CNBC Investing Club. Preorder my new book now: https://t.co/uSkNnBTZSl
SpaceX @SpaceX
39.9M Followers 120 Following SpaceX designs, manufactures and launches the world’s most advanced rockets and spacecraft
Rep. Pramila Jayapal @RepJayapal
555K Followers 2K Following Congresswoman, lifelong organizer, mom. Proudly serving WA-7. Chair Emerita @USProgressives. Member @HouseJudiciary, @HouseForeign, @HouseBudgetDems. She/her.
Surya Kumar Yadav @surya_14kumar
4.2M Followers 152 Following ᴅʀᴇᴀᴍ - ᴡᴏʀᴋ - ᴀᴄʜɪᴇᴠᴇ Indian Cricketer 🇮🇳 For inquiries, contact: [email protected]
hardik pandya @hardikpandya7
10.9M Followers 151 Following 🇮🇳 Cricketer For enquiries please contact: [email protected]
Save to Notion @SaveToNotion
217K Followers 2 Following I save your favorite Tweets and Threads to your Notion Workspace! Just follow @SaveToNotion & check the pinned tweet to start, Developed by: @Abdulhade_Ahmad
U.S. Consulate Mumbai @USAndMumbai
105K Followers 2K Following The U.S. Consulate Mumbai connects & promotes mutual understanding between the people of Western India and the United States. Terms of use: https://t.co/RvttqkrH9L
Blood Donors India @BloodDonorsIn
1.2M Followers 3K Following We match blood donors with those in need. In the Mary Meeker Internet Trends Report. Spread the word, help save lives. We save 8 lives/day. No money, only help.
Harsha Bhogle @bhogleharsha
9.0M Followers 164 Following Blessed. Enjoy till it lasts. https://t.co/iqokGKI1hh https://t.co/RKWER8YExc
ICC @ICC
26.5M Followers 588 Following The official Twitter account of the International Cricket Council, world cricket’s governing body.
Microsoft Security @msftsecurity
349K Followers 325 Following We are prioritizing security above all else through our Secure Future Initiative (SFI). Explore SFI principles, pillars, and progress here ⬇️
Avanan (Proud to Join... @AvananSecurity
653 Followers 826 Following The best way to protect Office 365, G Suite, and other enterprise collaboration suites from #Phishing, #Malware, #AccountTakeover, and #DataLoss.
Ankit Anubhav @ankit_anubhav
8K Followers 397 Following Voice of IoT Security & awareness. I make the world of IoT a safer place. Ex- McAfee / FireEye / NewSky
illegalFawn @illegalFawn
9K Followers 803 Following phishing, scam, fraud, identity theft: helping fraudsters in searching for honest professional opportunities
Sergiu Gatlan @serghei
9K Followers 2K Following Cybersecurity/tech reporter @BleepinComputer Signal: serghei.33
NWS Seattle @NWSSeattle
214K Followers 435 Following Official Twitter account for the National Weather Service Seattle. Details: https://t.co/yoQbjVwBSK