🚨The #ClickFix campaign is rising. Threat actors are using sophisticated domains (e.g. consent.oogle[.]it) to deceive victims.
Analysis of Fake Captcha code revealed a PowerShell command pointing to wezimin[.shop/blindspot.mp3 – not an MP3, but an obfuscated .js script.
Pleased to share I was invited on and spoke to the RiskyBiz Podcast about the BlackBasta Leaks with @campuscodi!
🎙️ risky.biz/RBTALKS6/
The leaks represent a great opportunity for cybercrime analysts to understand how these ransomware gangs operate #FOR589@sansforensics
🚨 How was Black Basta structured? What were its members’ roles? How did its infrastructure operate?
Leaked chats reveal a highly organized ransomware group with defined leadership, internal teams, and external affiliates.
More in my article ⬇️
cybercrimediaries.com/post/black-bas…
AS promised , i am done with writing my blog post about #GOZI aka #ISFB, where i went in the depth of analyzing the first loader,uncovering the config decryption routine ,showcasing #malware self-injection ,and the extraction of the 2nd stage.
blu3eye.gitbook.io/malware-insigh…
U may notice that new #Lumma Stealer C2 are Cloudflare blocked
You just need to setup the correct User-Agent (the one that builds use):
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
idk if this is a new feature
U may notice that new #Lumma Stealer C2 are Cloudflare blocked
You just need to setup the correct User-Agent (the one that builds use):
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
idk if this is a new feature https://t.co/EuKrBD2CQR
🔥#InvestigationPath#Exfiltration 🔥 🧵1
1⃣Reconnaissance activity performed:
EcMeun.exe➡️d4cae9981946b6e2fb1cf52eedd10261
2⃣TA opened an elevated command prompt via the EcMenu.exe utility using /RunAdmin from a directory containing rclone tool.
Releasing WebcamBOF📸
github.com/CodeXTF2/Webca…
Webcam capture capability for Cobalt Strike as a BOF, with in-memory download options (as a file or screenshot). USB webcams supported (at least mine is)
Remind me never to use the MF API in BOFs again😭
(god i hate this codebase)
⚡️One Million Dorks - A repository with text files containing a million dorks for finding potentially vulnerable web pages and sensitive data (in Google and other search engines). Can be used with various automation tools.
🎯github.com/HackShiv/OneDo…#bugbounty#cybersecurity
GReAT team's plugin for IDA Pro decompiler won first place 🥇 in the 2024 Hex-Rays IDA Plugin Contest! Grab our secret ingredient for malware reverse engineering and check out the GIFs demonstrating its use if you haven't already – github.com/KasperskyLab/h…
1/5 Cybercriminals are exploiting the rising popularity of #DeepSeek AI by distributing a fake version that delivers infostealer #malware.
This malicious tool deceives users into installing harmful files, leveraging DeepSeek's trusted reputation.
NEW BLOG: How to protect against Device Code Flow abuse (Storm-2372 attacks) and block the authentication flow. Admins, please limit/block Device Code Flows (DCF) in your tenant today or at least start with auditing
Blog: jeffreyappel.nl/how-to-protect…
4K Followers 287 FollowingExpert on cyber threats detection and response. Fast detect and respond to threats with high-fidelity, efficient, actionable security intelligence.
190 Followers 497 FollowingLove/hate relationship with malware that leads to drinking a lot of bourbon. Thoughts are my own and you won't want them anyways.
83 Followers 32 FollowingAsk yourself if what you are doing today is getting you closer to where you want to be tomorrow. Business Administration Real estate management 📉
8K Followers 6K Following#InfoSec professional, husband & father of two (in random order). #BlueTeam #DFIR #APT #CTI #RedTeaming #BSidesZH (RT/Likes ≠ endorsement) 👀➡️#MalwareChallenge
3K Followers 917 Followinghttps://t.co/9I6nRUiFjm is a service that provides threat intelligence data about observed network scanning and cyber attacks.
1K Followers 6K Followingसियावर रामचंद्र की जय पवनसुत हनुमान की जय I tweet about politics•geopolitics•defence and offensive replies to liberandu/leftist-islamic brigade.
52K Followers 6K FollowingWe cover military and political strategies in the Arab and Middle Eastern countries, tracking news, security, and military movements on land, sea, and air.
1K Followers 422 FollowingThreat Intel Researcher.
Opinions are mine.
Special thanks to @censysio , @ValidinLLC & @ReversingLabs for making my research easier.
3K Followers 1K FollowingLearner | CTF with @PwsecTeam | Amature Astronomer |
Tip:- In the world where you can be anything, be Kind.|
Words are of my own, and not of my employer
4K Followers 408 FollowingCEO of World Cyber Health | Founder of @MalwareVillage | Creator of https://t.co/AKyp6xNeDy | Malware Researcher | Keynote | Banned from JSAC
4K Followers 773 Followingit security & cyber guy, research @ https://t.co/M5rsSPPPWy, friendly, swiss | Opinions are my own | also https://t.co/v6cAL269P7
735 Followers 281 FollowingHack and Hack again..
Won Top 3 in the HackTheBox ValentinesDay Tournament.
Won Top 100 in the HacktheBox Cyber Apocalypse event.
10K Followers 1K FollowingCensys is the source for real-time Internet intelligence and actionable threat insights for governments, F500 companies, and leading threat intel providers
4K Followers 360 FollowingSkating fraud and bug preservationist. Shell smuggling business in the past. I once had a Pwnie. Bon pour l'Orient. New(er) Labour.
301K Followers 43 FollowingLeader of the Opposition, 17th WBLA. 3rd Term MLA; @BJP4India MLA from Nandigram.
Previously Cabinet Minister; Govt of WB & 2 term MP (Lok Sabha) from Tamluk.
5K Followers 95 FollowingChatGPT says I'm a cyber researcher :) | donate 💸 to g0njxa.eth 💖 | Bad student, enthusiast, defo not an expert
DMs are open, feel free to reach!
😼☂️🟣