@adorais.bsky.social

Manager, APT Research Team @ Proofpoint

Multiple reports have documented specific TA397 campaigns, this one takes a holistic look at the group's activity and puts forward attribution elements pointing towards Indian state interests alignment. Stellar work by @nickattfield.bsky.social and @threatray.bsky.social's researchers

ThreatInsight@threatinsight.proofpoint.com · last yr.

Just published: A two-part blog series in collaboration with @threatray.bsky.social, which aims to substantiate the claim that #TA397 (Bitter) is an espionage-focused, state-backed threat actor with interests aligned to the Indian state. Part 1: brnw.ch/21wT9A5 Part 2: brnw.ch/21wT9Ad.

Developing story - attack against #BGP peers of a European telco. The malicious emails impersonated that same telco and included the ASN of each recipient in the subject line. The emails contained a password-protected RAR attachment with the malicious payload.

ThreatInsight@threatinsight.proofpoint.com · 2y ago

In December 11 and 12, 2024, a spearphishing campaign targeted at least 20 Autonomous System (AS) owners, predominantly Internet Service Providers (ISPs), and purported to come from the Network Operations Center (NOC) of a prominent European ISP. 🧵⤵️