New research reveals detailed analysis of DPRK VPN infrastructure used by North Korean operatives abroad.
According to technical analysis published by NK Internet Watch, "Hangro" appears to be a specialized VPN client that enables North Koreans overseas to establish secure…
The value of losses in crypto thefts has soared this year to more than $2 billion over the first six months, the blockchain analytics company Chainalysis says therecord.media/chainalysis-cr…
A recent report reveals that Pakistani freelancers are creating cracking websites linked to stealer malware, using a pay-per-install model, while exploiting SEO tactics to promote these sites amidst low prosecution risks. #cybersecurity#malwareift.tt/bOGhQW7
💸 From dirty crypto to clean money: how Russophone cybercriminals launder illicit crypto profits?
Fake inheritances, shady casinos, fake businesses, and shell companies.
The real bottleneck? Legalization.
🔗 Link in comments
#CTI#CryptoLaundering#DarkWeb
🔎 [THREAD] – New analysis by Intrinsec Cyber Threat Intelligence on the latest operations by Russian-aligned intrusion sets #UAC0050 & #UAC0006📢
🔗 Our Report: intrinsec.com/wp-content/upl…
🔎 [THREAD] – Doppelgänger: A New Disinformation Campaign Spreading on Social Media 📢
📄 A newly released report sheds light on the tactics used by this Russian-linked network to target multiple Western countries.
⬇️
Fake #installers bundled with #infostealers are a constant threat, compromising user credentials and data integrity. These malicious programs often appear in search results and GitHub comments.
Find out more in our blog:⬇️ research.trendmicro.com/427R3LB
🚨 [New Report Alert!]
Our CTI team just published: "Premium Panel: phishing tool used in longstanding campaigns worldwide."
👉 This report reveals insights into a phishing kit used in campaigns for over two years!
📅Read the full report here: intrinsec.com/premium-panel-…
Researcher turns insecure license plate cameras into open source surveillance tool
Privacy advocate draws attention to the fact that hundreds of police surveillance cameras are streaming directly to the open internet.
🔗 404media.co/researcher-tur…
Earth Koshchei’s rogue Remote Desktop Protocol campaign targets government, military, and academia via spear-phishing, with alleged ties to Russia’s intelligence.
Learn more about this new threat actor’s tactic:⬇️ research.trendmicro.com/3DhR710
Hackers claim to have breached Gravy Analytics, a US location data broker selling to government agencies.
They shared 3 samples on a Russian forum, exposing millions of location points across the US, Russia, and Europe.
It's OSINT time! 👇
🎉 Happy New Year!
Our CTI team has just published a new report: "CryptBot: Hunting for Initial Access Vectors."
Here’s what we’ve uncovered about the malware’s spreading methods, originally shared privately with our clients in September. 🧵
🚨 New Report Alert! 🚨
Our CTI team has just released a new report: "Prospero & Proton66: Uncovering the links between bulletproof networks."
Here's what we've uncovered about these two Russian Autonomous Systems and their malicious connections. 🧵
🚨 Mandiant observed #LummaC2 stealers leveraging a new obfuscation technique to thwart analysis tools and stifle reverse engineering efforts.
Read about this tactic, and how we developed an automated method for removing this protection layer → bit.ly/47IImbK
⚠️Hier, un petit malin a enregistré qouv.fr. Son titulaire peut donc créer des sites et envoyer des mails très ressemblants aux vrais .gouv.fr.
Suivant la typo, la comparaison est bluffante (ici, Lucida sans Unicode).
Vigilance sur tous les domaines .gouv.fr !
⚠️ Breaking: North Korea just burned an 0-Day in Chromium.
They used it to install a Windows rootkit and the campaign targeted cryptocurrency platforms and users.
Here's what we know:
Microsoft observed Iranian state-sponsored threat actor Peach Sandstorm deploying a new custom multi-stage backdoor named Tickler in attacks against multiple sectors in the United States and the United Arab Emirates. msft.it/6015lfpO5
Mandiant is releasing details of a suspected Iran-nexus counterintelligence operation aimed at collecting data on Iranians and domestic threats who may be collaborating with intelligence and security agencies abroad, particularly in Israel. cloud.google.com/blog/topics/th…@Mandiant
669 Followers 3K FollowingDFIR, Malware & CTI. Head of a CSIRT. Ex @ANSSI_FR. PhD in intl law. Mostly working on Chinese #APT but also on russian and cybercrime actors #CTI #Malware
54K Followers 3K FollowingEvery day I write about #osint (Open Source Intelligence) tools and techniques. Also little bit about forensics and cybersecurity in general. Work in @netlas_io
117 Followers 290 FollowingVisual artist ▮ Rectangles, existential minimalism and open source libraries provider ▮ Teacher at Panthéon-Sorbonne University ▮ m-l on bsky
108K Followers 2 FollowingMonitor your external network, search the Internet of Things and perform empirical market research. You can also find us on https://t.co/nPLFbFy8R5
53K Followers 763 Following@AtlanticCouncil's Digital Forensic Research Lab. Cultivating a global network of digital forensic analysts (#DigitalSherlocks) to combat disinformation.
10K Followers 2K FollowingSecurityScorecard leads the way in Supply Chain Detection and Response, empowering organizations to swiftly manage and mitigate critical third-party risks.
37K Followers 5K FollowingFounder of Security Affairs, CYBHORUS, and Cybaze. Member Ad-Hoc Working Group on Cyber Threat Landscapes, Ethical Hacker, Security Evangelist, Security Analyst
1K Followers 422 FollowingThreat Intel Researcher.
Opinions are mine.
Special thanks to @censysio , @ValidinLLC & @ReversingLabs for making my research easier.
12K Followers 180 FollowingCrystal™ is the all-in-one blockchain investigative tool, providing a comprehensive view of the public blockchain ecosystem.
6K Followers 286 Following📡🏹🐙 Investigation et action contre les nouvelles menaces.
We investigate / take action against new threats.
Partenaires @debunkcafe & Le Phare (Telegram)
24K Followers 20 FollowingInformations stratégiques, au cœur du renseignement
Quotidien 100% indépendant, disponible en français et anglais
English version: @Intel_Online
1.6M Followers 91 FollowingTrade with Intelligence 🔎 | Cryptocurrency Exchange & Blockchain Analytics Platform | Earn up to $100 in rewards for registering.
10K Followers 1 FollowingOSINT | GEOINT | CYBERSEC | GÉOPOLITIQUE | Nous sensibilisons et appliquons nos techniques de #renseignement aux crises et aux conflits internationaux. 📡
4K Followers 147 FollowingA #SOCplatform boosted by #AI and #threatintelligence, combining #SIEM, #SOAR, #Automation in a single solution. Used by End-users, MSSP and APIs
669 Followers 3K FollowingDFIR, Malware & CTI. Head of a CSIRT. Ex @ANSSI_FR. PhD in intl law. Mostly working on Chinese #APT but also on russian and cybercrime actors #CTI #Malware
9K Followers 11 FollowingProactive Defense Against Future Threats | Pioneering #CyberSec and #ThreatIntelligence in Europe & MENA since ’12.
CTI Platform: #USTA Risk Intel: #BLINDSPOT
1K Followers 139 FollowingTakedown tools for small security teams
Tweets about phishing kit analysis, takedown tips, and new tools
https://t.co/44hDmZ9xnj
18K Followers 801 FollowingThreat Intelligence Analyst |
See my Linktree for other socials |
In case I post false intel, contact me!
Support me: https://t.co/5WgDqr0K8p
🇪🇺🇩🇪🇺🇦🌈
5K Followers 182 FollowingSenior Security Researcher @akamai - Malicious Group - SRT - DoD researcher of the year 2022 - Top 10 web attacks 2023 - CRTO - MSRC Top 75 in Q1/Q2 2025