Alexander Leslie

@aejleslie.bsky.social

Cybercrime & Hacktivism @ Recorded Future | Insikt Group | Curated Intelligence | @aejleslie everywhere else.

🚨 👀 New Insikt Group report! As NATO leaders gather in The Hague next week, the upcoming summit comes under threat from adversary activity: state-sponsored espionage, malign influence operations, and a surge of chatter across the dark web. Blog: www.recordedfuture.com/research/thr...

Threats to the 2025 NATO Summit: Cyber, Influence, and Hybrid Risks

Explore how state-sponsored actors, cybercriminals, and hacktivists are targeting the 2025 NATO Summit. Insight from Recorded Future’s Insikt Group reveals escalating cyber, AI, and hybrid threats fro...

recordedfuture.com

Thank you to everyone who attended my session at our inaugural Insikt After Dark conference in New York City! I spoke on our recent efforts to disrupt traffer teams, infostealer operators, and global scam infrastructure. It’s always an honor to represent Recorded Future!

Bild

Outstanding work from @julianferdinand.bsky.social, @lawrencesec.bsky.social, and our Malicious Infrastructure Discovery (MID) team. GrayAlpha shows how financially motivated actors operate with APT-level tradecraft. Time to retire old threat models. Think in terms of ecosystems, not just malware.

Julian-Ferdinand Vögele@julianferdinand.bsky.social · last yr.

Today we are releasing a report on new infrastructure and tooling linked to GrayAlpha, a financially motivated threat actor overlapping with FIN7 🧵 www.recordedfuture.com/research/gra...

Predator isn’t dead — it’s mutating. New reporting from @julianferdinand.bsky.social just dropped. It confirms that Predator C2 is very much alive and attracting new clients. Targets? The same. Activists, politicians, journalists, executives. The spyware economy isn’t slowing — it’s adapting.

Julian-Ferdinand Vögele@julianferdinand.bsky.social · last yr.

Today we’re publishing new findings on Predator spyware, still active despite global sanctions, now with a new client and ties to a Czech entity. Here’s what we found 🧵 www.recordedfuture.com/research/pre...

New report! Check it out. 🇷🇺 🇹🇯 This research examines a campaign targeting Tajikistan attributed to Russia-aligned TAG-110 — linked to BlueDelta (APT28). This campaign is likely targeting government, educational, and research institutions. Link: www.recordedfuture.com/research/rus...

TAG-110 Targets Tajikistan: New Macro Word Documents Phishing Tactics

Russia-aligned TAG-110 shifts to .dotm phishing lures in a 2025 campaign against Tajikistan’s public sector, advancing cyber-espionage in Central Asia.

recordedfuture.com

Thank you to everyone who attended my session at RSAC 2025 on cryptoscam gangs, infostealer operators, and the notorious “Marko Polo” traffer team. A lot of friendly faces in the crowd! (Find me roaming around this week, I have stickers!)

Bild

“More than 60 people in Tibetan areas of China have been arrested since 2021 for offenses connected to phone and internet use…” “Many of the arrests have involved the possession of outlawed content on phones… sharing of content on social media…” h/t: therecord.media/tibetans-arr...

Chinese police ensnaring Tibetans over phone and internet activity, Human Rights Watch says

Dozens of people in Tibet have been arrested by Chinese authorities in recent years for "simply using a cellphone," according to the nonprofit Human Rights Watch.

therecord.media

“Talos assesses… that multiple threat actors are operating the toll road smishing campaign by leveraging a smishing kit developed by the actor known as ‘Wang Duo Yu’ … used by the organized cybercrime group known as the ‘Smishing Triad.’” h/t: blog.talosintelligence.com/unraveling-t...

Unraveling the U.S. toll road smishing scams

Cisco Talos has observed a widespread and ongoing financial theft SMS phishing (smishing) campaign since October 2024 that targets toll road users in the United States of America.

blog.talosintelligence.com

👀 🇷🇺 “The Russia-backed threat group Gamaredon, typically known for spreading malware via phishing emails, recently appeared to have used an infected removable drive to target a Ukraine-based military mission of an unnamed Western country…” h/t: therecord.media/gamaredon-re...

Tainted drive appears to be source of malware attack on Western military mission in Ukraine

Researchers at Symantec said the Russia-linked group known as Gamaredon appears to have departed from its usual email phishing tactics in hacking a Western military mission in Ukraine.

therecord.media

“Deceptive websites hosted on newly registered domains are being used to deliver AndroidOS SpyNote malware… mimic the Google Chrome install page on the Google Play Store…” “While no definitive attribution is currently available, a China nexus is suspected.” h/t: dti.domaintools.com/newly-regist...

Newly Registered Domains Distributing SpyNote Malware - DomainTools Investigations | DTI

Deceptive websites hosted on newly registered domains are being used to deliver AndroidOS SpyNote malware. These sites mimic the Google Chrome install page on the Google Play Store.

dti.domaintools.com

🇬🇧 “British police on Wednesday announced that a 38-year-old Romanian man has been arrested on suspicion of assisting a foreign intelligence service.” “…identified as part of an investigation into a fire at a DHL warehouse in Birmingham.” h/t: therecord.media/romanian-man...

Romanian man arrested in UK on suspicion of aiding Russian sabotage campaign

British police arrested a 38-year-old Romanian man suspected of connections to a fire at a DHL warehouse that appeared to be part of a larger sabotage campaign attributed to Russian intelligence.

therecord.media

🇷🇺 “A little-known hacking group is using custom malware to steal sensitive files from flash drives connected to Russian computers…” “The group… has deployed a tool dubbed PowerModul that includes components designed specifically to target removable media.” h/t: therecord.media/goffee-espio...

Researchers warn about ‘Goffee’ spilling onto Russian flash drives

A cyber-espionage campaign aimed at Russia has added malware that specifically targets flash drives, analysts at Kaspersky said.

therecord.media

🇲🇦 “Morocco’s national social security agency is investigating a cyberattack… the leak of sensitive personal data… belonging to millions of citizens.” 🇩🇿 “…a politically motivated campaign by Algerian hackers.” h/t: therecord.media/morocco-inve...

Morocco investigates major data breach allegedly by Algerian hackers

The country's national social security agency said the cyberattack resulted in the leak of sensitive personal data reportedly belonging to millions of citizens.

therecord.media

Interesting blog from Trustwave on new evasion techniques associated with the Tycoon 2FA phishing kit. Concur with the JavaScript findings. Something I’ve recently observed: “prevents right-click … redirects to another site if analysis is suspected.” h/t: www.trustwave.com/en-us/resour...

Tycoon2FA New Evasion Technique for 2025

The Tycoon 2FA phishing kit has adopted several new evasion techniques aimed at slipping past endpoints and detection systems.

trustwave.com

“slopsquatting” is hilarious… new favorite term “…a surprisingly effective type of software supply chain attack that emerges when LLMs ‘hallucinate’ package names that don’t actually exist.” h/t: socket.dev/blog/slopsqu...

The Rise of Slopsquatting: How AI Hallucinations Are Fueling...

Slopsquatting is a new supply chain threat where AI-assisted code generators recommend hallucinated packages that attackers register and weaponize.

socket.dev