Joseph Chen @jspchc
Threat Researcher at @TrendMicroRSRCH Joined January 2013-
Tweets201
-
Followers401
-
Following606
-
Likes3K
TAOTH used spear phishing and a reregistered, previously abandoned update domain to infect devices of dissidents, journalists, and executives in East Asia. Our analysis details their infection methods and defense strategies. See our threat insights: ⬇️ research.trendmicro.com/4oW5c7K
Trend™ Research has identified Earth Lamia as an #APT threat actor that exploits vulnerabilities in web applications to gain access to organizations, using various techniques for data exfiltration. Learn more: ⬇️ research.trendmicro.com/3HbrVLI
Trend Micro's @jspchc writes about an active threat actor, named Earth Lamia, targeting multiple industries in Brazil, India & Southeast Asian countries since at least 2023. The APT primarily exploits vulnerabilities in web applications for access. trendmicro.com/en_us/research…
We released a report on a threat actor using an updated version of #Shadowpad including anti-debugging features, that in some cases deploy a custom ransomware family. We have mainly seen the manufacturing industry being targeted in Europe and Asia trendmicro.com/fr_fr/research… #APT
Discover the threat posed by the cross-platform DarkNimbus backdoor. Earth Minotaur utilizes the MOONSHINE exploit kit to target Android and Windows devices. Read the full report on our blog: ⬇️ research.trendmicro.com/3B9ETXP
Trend Micro's Joseph C Chen & Daniel Lunghi investigate a group named Earth Minotaur that used the MOONSHINE exploit kit leading to the DarkNimbus Android backdoor. MOONSHINE exploit kit targets vulnerabilities in instant messaging apps on Android devices. trendmicro.com/en_us/research…
New research from @jspchc and @thehellu uncovers a campaign leveraging the Moonshine framework to deliver Chrome Nday exploits targeting Android devices. Thanks for giving the credit to my research! #moonshine
New research from @jspchc and @thehellu uncovers a campaign leveraging the Moonshine framework to deliver Chrome Nday exploits targeting Android devices. Thanks for giving the credit to my research! #moonshine
Our latest report presents Earth Minotaur, a threat actor targeting Tibetans and Uyghurs using Moonshine, an exploitation framework for Android described in 2019 by @citizenlab leveraging vulnerabilities in applications embedding old versions of Chrome trendmicro.com/en_us/research…
Trend Micro researchers analyse two distinct attack chains employed by the Earth Estries (aka Salt Typhoon) group that demonstrate the varied tactics, techniques and tools they use to compromise targeted systems. trendmicro.com/en_us/research…
NEW ENTRY: In this report, we detailed how Waterbear and Deuterbear operate, including the stages of infection, command and control (C&C) interaction, and #malware component behavior. Find out more about these two malware variants here: research.trendmicro.com/EarthHundun
Trend Micro's @jspchc & @thehellu look into a new APT campaign, named Earth Krahang, targeting several government entities worldwide, with a strong focus on Southeast Asia. Their investigation identified multiple links between Earth Krahang & Earth Lusca. trendmicro.com/en_us/research…
Our latest report on a CN #APT targeting tens of governments entities worldwide has been published 🥳 After monitoring it for a long time we realized it is likely related to the recent I-Soon company leaks. It discusses their TTPs and provides lots of IOCs trendmicro.com/en_us/research…
🤝 Research helping research 🤝 Our friends at @ThreatFabric was able to use the Lookout Threat Intel team's discovery of DragonEgg and WyrmSpy to tie LightSpy, a known iOS implant and its Android component, to the Chinese threat actor #APT41. threatfabric.com/blogs/lightspy…
We found an encrypted file on the #EarthLusca’s delivery server, a previously unseen #Linux-backdoor from the open-source Windows backdoor Trochilus. Read more: ⬇️ research.trendmicro.com/45VEqCD
Earth Lusca Employs New Linux Backdoor, Uses Cobalt Strike for Lateral Movement trendmicro.com/en_us/research… in collaboration with @jspchc
Our new blog entry details an #infostealer that spreads through campaigns abusing social media ads for fake services claiming to boost productivity, increase reach, or offer teaching assistance via #AI. From researchers, @JaromirHorejsi & @4n6strider: ⬇️ research.trendmicro.com/3R8TBDJ
Trend Micro's @JaromirHorejsi & @jspchc observed two new Water Orthrus campaigns. CopperStealth uses a rootkit to install malware on infected systems, while CopperPhish steals credit card information. trendmicro.com/en_us/research…
Trend Micro's @JaromirHorejsi & @jspchc discovered new malware OpcJacker in the wild. OpcJacker’s main functions include keylogging, taking screenshots, stealing sensitive data from browsers, loading additional modules & replacing cryptocurrency addresses trendmicro.com/en_us/research…
Trend Micro's @jspchc & @JaromirHorejsi discovered a threat actor that was targeting cryptocurrency scam websites. Water Labbu lets other scammers use their social engineering tricks to scam unsuspecting victims. trendmicro.com/en_us/research…
In the first of our two-part #WaterLabbu blog series, we analyze how the group compromises the DApp websites of other scammers to inject malicious scripts that are ultimately designed to steal cryptocurrency from victims. Read more: research.trendmicro.com/3fPFNgN

Daniel Lunghi @thehellu
2K Followers 590 Following Threat researcher @TrendMicroRSRCH mostly focused on #APT
Trend Micro Research @TrendMicroRSRCH
52K Followers 363 Following Security research, news, and information direct from @TrendMicro experts.
sysopfb @sysopfb
4K Followers 762 Following Threat Intel as a reverse-engineer in Crimeware domain. Dubbed "Malware Mangler" by TheRegister. [email protected]
Ian Kenefick @ian_kenefick
2K Followers 2K Following Cyber Threat Intelligence Automation @trendmicroRSRCH B̶l̶u̶e̶S̶k̶y :: https://t.co/lP6THaK5Yj
Ojaswi Kumar Mishra�... @0xojaxwi
73 Followers 2K Following Old-school Malware & Offensive Security REsearcher | ⚡Kernel Pwner⚡
Pin Joe @pin_joe38854
15 Followers 52 Following
Raul 🥛 @Raul_Impact3
2K Followers 6K Following CEO @Impact3Growth (parent co. @MilkRoadDaily) // Obsessed with crypto, marketing & social media
Nguyễn Quân @reuvenb1_1
2 Followers 214 Following
HedyGrote @cA57OU4zIBuxOy
74 Followers 2K Following
spider @LulleLullu63135
132 Followers 3K Following
Super Sheep (@qutluch... @Qutluch
452 Followers 3K Following When these frail shadows we inhabit now have quit the stage, we'll meet and raise a glass again together in Valhalla.
Bahadir @bahadircloud
1 Followers 5K Following
b o o p @boopcorp
1 Followers 12 Following
Đặng Văn Nhất @ngVnNht236409
18 Followers 162 Following
Davey Winder @happygeek
15K Followers 3K Following Senior Contributor @Forbes Contributing Editor @pcpro - he/him - [email protected] - "All My Opinions Are Belong To Me"
Mettursun Beydulla, P... @Mettursun
94 Followers 272 Following
William @hitholy
28 Followers 865 Following
bletchley13(CK) @bletchley13
672 Followers 891 Following CyCraft/Cycarrier Researcher. CTF Player. Founder of BambooFox Reviewbord of HITCON Tweets are mine own
allison elliot @HopeVindy18585
168 Followers 5K Following I'm asimple woman with simple needs strong in my faith. Healing a broken soul
Joe Devanny @josephdevanny
3K Followers 6K Following Senior Lecturer | @warstudies @kingscollegelon | National Security/Cyber Statecraft | Views mine.
Albert Zsigovits @albertzsigovits
2K Followers 2K Following Senior Malware Researcher @VMRay 🤖👾🧬🦠 | #malware #ransomware #dfir #apt #threatintel #threatresearch | Opinions expressed are strictly my own.
Evan Nil @thr33thirty3
131 Followers 2K Following
Skwerenski @skwerenski52621
0 Followers 69 Following
Vico @0xvico
23 Followers 193 Following
eolwral @eolwral
3 Followers 33 Following
despiMe @UI7JRcDpA0XVzb5
2 Followers 468 Following
John @BitsOfBinary
2K Followers 397 Following #threatintel @PwC_UK. Reverse engineering, threat intelligence, YARA. Amateur jazz pianist. All tweets are my own. He/him.
BBcan177 @BBcan177
2K Followers 747 Following Dev of pfBlockerNG | #pfBlockerNG | #pfBlocker | |/r/pfBlockerNG |
Charlie Gardner @zcracga
500 Followers 475 Following Senior threat intelligence analyst @volexity charliegardner on Keybase
D$ @_sinoptik
3 Followers 139 Following
week11y @week11y
95 Followers 3K Following
Aleksandar Milenkoski @milenkowski
2K Followers 586 Following Threat Research | Threat Intelligence | PhD | European Commission Marie Curie Research Fellow 2011-2014 | Personal Profile | 🇩🇪
Andrey Rublev @AndreyR83425761
8 Followers 336 Following
Naveen Selvan @infantnaveen
485 Followers 3K Following Security Researcher II - APT @Zscaler | Asm, Python, ML♥️ | Wannacry Patcher | CTFer-Reverser for Life! | for(;;)exploit() | Tweets are my own | Ex @Trellix
GCnoopy @GCnoopy
3 Followers 81 Following
Ruth @ruthwadsworth3
1K Followers 3K Following
babymilo @BabyMilo2009
5 Followers 656 Following
Travis Green @travisbgreen
671 Followers 2K Following An infosec old & author of TGI HUNT rules. Not the gospel singer. Opinions are my own and not the views of my employer. I don't often check DM here
Charlene @CeeGee2010
567 Followers 5K Following
0x55555 @0x555551
13 Followers 386 Following
Florian Roth ⚡️ @cyb3rops
206K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim
MalwareHunterTeam @malwrhunterteam
244K Followers 38 Following Official MHT Twitter account. Check out ID Ransomware (created by @demonslay335). More photos & gifs, less malware.
blackorbird @blackorbird
35K Followers 671 Following Peace and Love. Just Analysis/Hunter. #APT #threatIntelligence #Exploit #CTI Need Job
ESET Research @ESETresearch
35K Followers 30 Following Security research and breaking news straight from ESET Research Labs.
Virus Bulletin @virusbtn
60K Followers 1K Following Security information portal, testing and certification body. Organisers of the annual Virus Bulletin conference. @[email protected]
Jake Williams @MalwareJake
142K Followers 2K Following Breaker of software | VP R&D @hunterstrategy | CTI/DFIR | @ians_security faculty | Bookings: jake at malwarejake dot com | GSE #150 | He/him
James @James_inthe_box
22K Followers 464 Following
The DFIR Report @TheDFIRReport
62K Followers 0 Following Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Services: https://t.co/XW613EKt2w
Daniel Lunghi @thehellu
2K Followers 590 Following Threat researcher @TrendMicroRSRCH mostly focused on #APT
Joe Słowik 🌻 @jfslowik
28K Followers 1K Following CTI, OT/ICS, DE&TH, and related infosec content. Oh, and memes. And shitposting. Lots of shitposting.
JAMESWT @JAMESWT_WT
37K Followers 507 Following #Independent #Malware #Hunter #CyberSecurity #InfoSec https://t.co/KCFBJcHHcW https://t.co/WODUKncjFy
Trend Micro Research @TrendMicroRSRCH
52K Followers 363 Following Security research, news, and information direct from @TrendMicro experts.
Michael Koczwara @MichalKoczwara
23K Followers 2K Following Threat Researcher/Founder @Intel_Ops_io Threat Intelligence, Adversary Infrastructure Hunting, Curated TI Feed (Coming Soon) https://t.co/VQWaze6gaF
Jazi @h2jazi
8K Followers 530 Following Threat Intel researcher! Technical tweets only; not reflective of employer's views. No endorsement of political groups/entities.
Silas Cutler (p1nk) @silascutler
13K Followers 2K Following You may know me from your logs Research @Censys Advisor @IST_org & #DEVSEC Built @Only_Scans, @mal_share, #KeyDrop
Germán Fernández @1ZRR4H
35K Followers 461 Following 🏴☠️ OFFENSIVE-INTEL 🏴☠️ Cyber Threat Intelligence by Hackers | Security Researcher en https://t.co/rDrSxZASB3 | @CuratedIntel Member | 🥷🧠🇨🇱
x0rz @x0rz
96K Followers 420 Following Cybersecurity & Threat Intelligence. Knowledge is power, France is bacon 🥓
Joe Roosen @JRoosen
8K Followers 1K Following SpyCloud - Director of Security Research, Cryptolaemus Coordinator, Emotet(Ivan)/QBot(Boris) Destroyer, gold prospector & former sysadmin.
sysopfb @sysopfb
4K Followers 762 Following Threat Intel as a reverse-engineer in Crimeware domain. Dubbed "Malware Mangler" by TheRegister. [email protected]
Seongsu Park @unpacker
12K Followers 1K Following Zscaler APT Research | Formerly Kaspersky GREAT | Threat Intelligence Hustler | Tweets are my own | Keybase: @seongsupark | Mastodon: @[email protected]
Unitree @UnitreeRobotics
85K Followers 306 Following High performance civilian robot manufacturer. Please everyone be sure to use the robot in a Friendly and Safe manner. https://t.co/hI6LafokVm
Malfors @MalforsHQ
285 Followers 56 Following Investigation platform. Send us a DM to join beta, follow for product updates.
FOFA @fofabot
12K Followers 191 Following Cybersecurity Search Engine Contact Email: [email protected] Telegram: https://t.co/E5EcKr5Kyl
Hunter For Fun @Thisism23567356
547 Followers 364 Following
Hunt.io @Huntio
3K Followers 917 Following https://t.co/9I6nRUiFjm is a service that provides threat intelligence data about observed network scanning and cyber attacks.
曾哥 @AabyssZG
11K Followers 1K Following 渊龙Sec安全团队(AabyssTeam)创始人 国际云安全联盟(CSA)渗透测试工作组成员 渗透测试 | 造轮达人 | 追洞达人|RedTeam | IOT安全|业余无线电| SecTools | Misc业余选手 | Exploits
Donald J. Trump @realDonaldTrump
108.8M Followers 53 Following 45th & 47th President of the United States of America🇺🇸
CX @cxaqhq
4K Followers 403 Following BG6VVA OSWP 备考OSCP business card:https://t.co/2eYXkaAi6C Github:https://t.co/9HXCpbOWqe
Censys @censysio
10K Followers 1K Following Censys is the source for real-time Internet intelligence and actionable threat insights for governments, F500 companies, and leading threat intel providers
Vico @0xvico
23 Followers 193 Following
eolwral @eolwral
3 Followers 33 Following
Mark Kelly @markkelly0x
743 Followers 427 Following Threat research @Proofpoint 🇨🇳 | Member @CuratedIntel | former @RecordedFuture
OWN @own_fr
2K Followers 130 Following Threat intelligence driven #cybersecurity. #Audit #Consulting #CTI #CERT #SOC
moto_sato @58_158_177_102
9K Followers 2K Following 企業のCSIRTの人兼企業のCTOの人。シンクホールは趣味。書き込む内容は所属に関係しているものもありますが、意見や見解は個人的なもの。意識低い低い系/User side Cyber Security Researcher & sinkholer
Aleksandar Milenkoski @milenkowski
2K Followers 586 Following Threat Research | Threat Intelligence | PhD | European Commission Marie Curie Research Fellow 2011-2014 | Personal Profile | 🇩🇪
Tom Hegel @TomHegel
7K Followers 750 Following Threat Research Lead @SentinelOne, Advisor with @ValidinLLC
Is Now on VT! @Now_on_VT
4K Followers 788 Following Stay ahead of cyber threats. Get real-time alerts on notable APT/FIN/ORB indicators from VirusTotal. A threat intel project by @craiu.
S-Owl @Sec_S_Owl
3K Followers 256 Following Security Analyst / Malware Researcher / Threat Intel / APT / Malspam / ばらまきメール回収の会(@bomccss)/ 所属に関係のない個人の意見です。
NSA Cyber @NSACyber
149K Followers 12 Following We protect our nation’s most sensitive systems against cyber threats. Likes, retweets, and follows ≠ endorsement.
OpenAI @OpenAI
4.3M Followers 3 Following OpenAI’s mission is to ensure that artificial general intelligence benefits all of humanity. We’re hiring: https://t.co/dJGr6Lg202
Aidan H @thehappydinoa
1K Followers 894 Following Security Researcher, Developer, and Collaborator at @censysio
Kris McConkey @smoothimpact
5K Followers 837 Following #threatintel and #dfir lead @ PwC. Blue team forever. Christian, husband, dad, coffee addict, bad photographer, awful cyclist. Tweets my own, not PwC's.
CyberSec Taiwan @CyberSecTaiwan
183 Followers 125 Following The latest news and analysis on Taiwan-centric cybersecurity (not affiliated with the CYBERSEC conference & expo)
賴清德Lai Ching-te @ChingteLai
392K Followers 4 Following President of R.O.C. Taiwan. Chairperson of Democratic Progressive Party.
App Economy Insights @EconomyApp
221K Followers 386 Following • App Economy investor • French in Silicon Valley • Gaming industry veteran • Previously @PwC & @BandaiNamcoUS • 200K+ read my newsletter How They Make Money
Steven Adair @stevenadair
3K Followers 412 Following President @Volexity | Malware Analyst's Cookbook | https://t.co/K1nPkanWYC
Phantom X @PhantomXSec
397 Followers 269 Following Security Researcher | Explorer of the Digital Ether | Kimchi Says Hello 🧐. Focused on #Cybercrime #Phishing #APT #ThreatIntel #InfoSec
國防部 Ministry of... @MoNDefense
219K Followers 90 Following The official MND R.O.C. Twitter account! Follow us for the latest news and activities of MND and R.O.C. Armed Forces here. Follow, RTs and Links ≠ Endorsement
ThreatBook @ThreatBookLabs
4K Followers 287 Following Expert on cyber threats detection and response. Fast detect and respond to threats with high-fidelity, efficient, actionable security intelligence.
ShimizuKawasaki @shimizukawasak
1K Followers 113 Following
Ministry of Digital A... @TAIWANmoda
8K Followers 641 Following #TaiwanCanHelp🇹🇼 #FreeTheFuture #IslandOfResilience
zhixiang hao @HaoZhixiang
1K Followers 343 Following APT threat,Web security,Osint Shandong Lanxiang School China。My sample analysis is just for learning research
x86matthew @x86matthew
21K Followers 189 Following C / asm / system emulation / reverse engineering. @the_secret_club
Sixdub @sixdub
11K Followers 1K Following Microsoft Threat Intelligence | Student @ GMU Antonin Scalia Law School | USAFA '10 & USAF Veteran | Focus: Intelligence, Technology, Cyber Law, Leadership
FuYingLab @fuyinglab
390 Followers 1 Following Official NSFOCUS FuYingLab Twitter account. Security information on APT & botnet.
LittleRedBean @LittleRedBean2
92 Followers 428 Following I am just a student ,like watching cartoons,interested in Malware I hope you can have fun in this little rest spot. :)
Botconf @Botconf
4K Followers 1K Following The Botnet and Malware Ecosystems Fighting Conference 12th ed - Workshops & Conference May 2025 in Angers, FR Follow us: https://t.co/wvWVbckCgy
𝚍𝚛𝚎𝚊𝚖�... @bofheaded
1K Followers 1K Following My forte: APT/s Hunting | Attribution and Correlation | TTPs and Attack to TA | Threat Intelligence. [email protected]