Cyber_OSINT

1,077 Followers
14 Following
159 Posts
OSINT treasure hunter, investigator, disciple of Cyber Threat Intel, cyberspace explorer. I enjoy studying APT groups. Opinions are my own.
Interview with Mallox ransomware group

Mallox is certainly one of the longest-lived ransomware groups still in full swing today, we were able to observe its first file samples since June 2021, at

SuspectFile
New Backdoor Created Using Leaked CIA's Hive Malware Discovered in the Wild https://thehackernews.com/2023/01/new-backdoor-created-using-leaked-cias.html
New Backdoor Created Using Leaked CIA's Hive Malware Discovered in the Wild

A new backdoor has been discovered that borrows its features from the leaked CIA's Hive malware suite.

The Hacker News
You Move, They Follow: Uncovering Iran’s Mobile Legal Intercept System - The Citizen Lab

Citizen Lab examined a set of documents leaked to news outlet The Intercept that describe plans to develop and launch an Iranian mobile network, including subscriber management operations and services, and integration with a legal intercept solution. If implemented fully as envisioned, it would enable state authorities to directly monitor, intercept, redirect, degrade or deny all Iranians’ mobile communications, including those who are presently challenging the regime.

The Citizen Lab
Hackers use fear of mobilization to target Russians with phishing attacks https://therecord.media/hackers-use-fear-of-mobilization-to-target-russians-with-phishing-attacks/
Hackers use fear of mobilization to target Russians with phishing attacks

Hackers took advantage of Russian concerns about mobilization to steal credentials through malicious links, according to new research.

The Record from Recorded Future News
Hacked Russian files reveal propaganda agreement with China https://theintercept.com/2022/12/30/russia-china-news-media-agreement/
Hacked Russian Files Reveal Propaganda Agreement With China

In 2021, government officials and media executives from Russia and China discussed the exchange of news and social content.

The Intercept
New Linux malware uses 30 plugin exploits to backdoor WordPress sites

A previously unknown Linux malware has been exploiting 30 vulnerabilities in multiple outdated WordPress plugins and themes to inject malicious JavaScript.

BleepingComputer
IcedID Botnet Distributors Abuse Google PPC to Distribute Malware

We analyze the latest changes in IcedID botnet from a campaign that abuses Google pay per click (PPC) ads to distribute IcedID via malvertising attacks.

Trend Micro
Ghost CMS vulnerable to critical authentication bypass flaw

A critical vulnerability in the Ghost CMS newsletter subscription system could allow external users to create newsletters or modify existing ones so that they contain malicious JavaScript.

BleepingComputer
New STEPPY#KAVACH Attack Campaign Likely Targeting Indian Government: Technical Insights and Detection Using Securonix https://www.securonix.com/blog/new-steppykavach-attack-campaign/
New STEPPY#KAVACH Attack Campaign Likely Targeting Indian Government: Technical Insights and Detection Using Securonix

Securonix
Revealed: The Israeli firm selling ‘dystopian’ hacking capabilities

Meet Toka, the Israeli cyber firm founded by Ehud Barak, that lets clients hack cameras and change their feeds – just like in Hollywood heist movies

Haaretz