Check out the latest @RecordedFuture report from @JulianVoeg , Marius, and me on TAG-150, where we break down CastleLoader and CastleRAT (Python + C variants).
Recent TTP: C2 deaddrops on Steam Community pages, marking a new infrastructure tactic
🔗recordedfuture.com/research/from-…
New blog on #Sinobi ransomware! They used an MSP's compromised SonicWall SSL VPN creds for initial access. Decryption is impossible w/o the attacker's private key, unless of course you hooked CryptGenRandom😜
esentire.com/blog/threat-ac…
Seeing a (potential new?) python-based backdoor we're tracking as #PyNightshade for the second time delivered via #ClickFix that uses sockets for C2. Supports several commands from C2, including: remote shell, uploading files from the victim host, and self-deletion. It uses RC4…
Fun tip, if you find you're unable to retrieve a "fileless" stage in a malware chain, e.g. invoked .NET DLL stage, you can download memory dumps from VirusTotal, search through them for known strings or bytes that should be in the payload, open in hex editor, and find the…
New blog is out on #InterlockGroup and has a wealth of TTPs for detection engineers, tools for security researchers, deobfuscated scripts, and a C2 simulation script for #InterlockRAT ! Screenshots below show the deobfuscated PHP-based backdoor and annotated communications of…
2K Followers 2K Following16 year old whimsical wizard and part time fintech phantom. Red Team & Bug Bounty. CPTS,CRTP | Views are my own. Not affiliated with my employer.
659 Followers 1K Following🇮🇹 | IT Engineer with Cyber Security passion | Malware Analysis | Reverse Engineering | CTI
- views and opinions are solely my own -
10K Followers 462 FollowingThreat Researcher at Check Point @_CPResearch_ #DFIR #Reversing - All opinions expressed here are mine only.
https://t.co/iWvwWF1AnN
566 Followers 113 FollowingMalware analyst & reverse engineer 🧠
Threat intel on stealers, RATs, live campaigns 🕵️
Technical analysis. No buzzwords.
📍DM open for research collabs
2K Followers 413 FollowingThreat Intel Specialist and Incident Responder. Private account. All opinions expressed here are mine only.
https://t.co/7dQQO1JwUd
9K Followers 815 FollowingExperts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, #PacketCache, #PolarProxy and #RawCap.
2K Followers 2K FollowingCISO and faculty by day, adversary emulation/tools by night, bad jokes and memes all the time.
Profile photo image credit to Tib3rius.
My dog disapproves.
2K Followers 428 FollowingMalware analysis and reverse engineering. Sometimes I write code to do these things. Founder @InvokeReversing. Tweets are my own.
2K Followers 316 FollowingInfostealer hunter by night, threat actors’ headache 24/7. I track C2s, ruin botnets, and make cybercriminals rethink their life choices
1K Followers 3K FollowingI'm from Waterloo, where the vampires hang out. InfoSec Founder Whisperer. Wrote a book for first-time tech founders. Frequently underestimated. 🇨🇦
654 Followers 983 Following🇩🇰 living in 🇩🇪
Principal IR dude trying to do IR stuff at @InfoGuardAG
https://t.co/odU86jtnLL…
@hackerkartellet.bsky.social
19K Followers 1 Following🍎 🛡️
🛠️ Open-Source Tools
📚 "The Art of Mac Malware" books
🫂 "Objective by the Sea" conference
Support us on https://t.co/tuGceSeyiC 🙏