Will T

@bushidotoken.net

๐Ÿ‡ฌ๐Ÿ‡ง | Senior Threat Intelligence Advisor at Team Cymru | Co-author SANS FOR589 | Co-founder Curated Intel

New Blog! ๐Ÿ‡ฌ๐Ÿ‡ง UK Cybercrime Journal: H1 2026 Social Media Fraud Trends - HMRC Warns TikTok Users - Lloyds Bank says 66% of Fraud Cases Started on Metaย  - UK Finance Recorded ยฃ221.5m Lost to Investment Scams - Fraudsters arrested in Nigeria by the NCA ๐Ÿ”— blog.bushidotoken.net/2026/07/uk-c...

UK Cybercrime Journal: H1 2026 Social Media Fraud Trends

CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security

blog.bushidotoken.net

New Blog! ๐Ÿ‡ฌ๐Ÿ‡ง UK Cybercrime Journal: University of Nottingham Breached by ShinyHunters The education sector in the UK has suffered repeated, significant data breaches in recent years, but ShinyHunters campaign has been one of the worst yet. ๐Ÿ”— blog.bushidotoken.net/2026/07/uk-c...

UK Cybercrime Journal: University of Nottingham Breached by ShinyHunters

CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security

blog.bushidotoken.net

New Blog! ๐Ÿ‡ฌ๐Ÿ‡ง UK Cybercrime Journal: Argos Account Takeover Fraud - Cybercriminals are using leaked credentials to hijack Argos user accounts - They then order and then collect the goods in-person at a physical store and pay with stolen credit cards ๐Ÿ”— blog.bushidotoken.net/2026/07/uk-c...

UK Cybercrime Journal: Argos Account Takeover Fraud

CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security

blog.bushidotoken.net

New Blog! ๐Ÿ‡ฌ๐Ÿ‡ง UK Cybercrime Journal: Hargreaves Landsdown Extortion Attempt by Bashe It appears Bashe weaponised HLโ€™s recent, IT outages & glitches (in Sept 2025 and March 2026) to construct a plausible, but false, narrative of a successful hack. ๐Ÿ”— blog.bushidotoken.net/2026/06/uk-c...

UK Cybercrime Journal: Hargreaves Landsdown Extortion Attempt by Bashe

CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security

blog.bushidotoken.net

Two of my fav ๐Ÿ‡ฌ๐Ÿ‡ง ๐Ÿ‡จ๐Ÿ‡ฆ experts when it comes to discussing cyber warfare, Philip Ingram and Ian Thornton-Trump, released an interview reviewing in detail the threat landscape of ๐Ÿ‡ท๐Ÿ‡บ Russian cyber operations in the context of the ongoing war in ๐Ÿ‡บ๐Ÿ‡ฆ Ukraine. ๐Ÿ”— youtu.be/p1vl5t4fVWA

How Russiaโ€™s cyber propaganda machine is backfiring on the frontline | Ian Thornton-Trump

YouTube video by Frontline

youtu.be

New Blog! ๐Ÿ‡ฌ๐Ÿ‡ง UK Cybercrime Journal: Sustained DragonForce Campaign Throughout May 2026, the DragonForce RaaS operation claimed seven UK-based companies as its victims by posting them on their Tor data leak site. ๐Ÿ”— blog.bushidotoken.net/2026/06/uk-c...

UK Cybercrime Journal: Sustained DragonForce Campaign

CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security

blog.bushidotoken.net

New ๐Ÿ‡ฌ๐Ÿ‡ง UK Cybercrime Journal Entry: Arup Group Breached by FulcrumSec What do AWS DCs, Disneyland, Wembley Football Stadium, HS2 and HS1 Channel Tunnel Rail Link network, and the Eden Project all have in common? They were engineered by Arup Group ๐Ÿ‘€ blog.bushidotoken.net/2026/06/uk-c...

UK Cybercrime Journal: Arup Group Breached by FulcrumSec

CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security

blog.bushidotoken.net

๐Ÿ“ฃ I have been wanting to write more regularly for my site blog.bushidotoken.net and have made a new series: The UK Cybercrime Journal. These are short UK cybercrime incident reports with a BLUF, Analyst Comment, and Defensive Takeaways. Starting here: blog.bushidotoken.net/2026/05/uk-c...

UK Cybercrime Journal: Inside the Cl0p attack on South Staffs Water

CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security

blog.bushidotoken.net

New Blog! Stranger Strings: Yurei Ransomware Operator Toolkit Exposed Through my research with Team Cymruโ€™s data, we have discovered another ransomware operatorโ€™s server with Stranger Things-themed tools, check it out๐Ÿ‘‡ www.team-cymru.com/post/yurei-d...

Yurei Double Extortion Ransomware: Operator Toolkit and Analysis

Analyze the Yurei double extortion ransomware campaign, including its toolkit, attack lifecycle, and key tactics used by operators.

team-cymru.com

New Blog! The Beast Returns: Analysis of a Beast Ransomware Server ๐Ÿ‘น In March 2026, Team Cymru detected a Beast operatorโ€™s server that enabled us to understand the flow of their attacks from start, to middle, to the end, including ransomware binaries. www.team-cymru.com/post/beast-r...

Beast Ransomware Toolkit: A Proactive Threat Intelligence Report

Explore our latest threat intelligence report on Beast Ransomware. See the exact incident response tools and TTPs used by operators to bypass EDR and delete backups.

team-cymru.com

๐—ฃ๐—ข๐——๐—–๐—”๐—ฆ๐—ง ๐ŸŽง ๐—›๐—ผ๐˜„ ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฑ ๐—ฆ๐—ต๐—ฎ๐—ฝ๐—ฒ๐—ฑ ๐˜๐—ต๐—ฒ ๐—™๐˜‚๐˜๐˜‚๐—ฟ๐—ฒ ๐—ผ๐—ณ ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† We sat down with Rebecca Taylor from Sophos and @bushidotoken.net from @teamcymrus2.bsky.social to discuss 2025โ€™s highs and lows in cyber and make educated guesses on what to look for in 2026. feeds.soundcloud.com/users/soundc...

Bild

New Blog! ๐Ÿ‘€ In this research, I take a look at the Qilin RaaS in-depth, which has emerged as one of the leading and most innovative ransomware gangs following the takedown of LockBit, the exit scam by ALPHV/BlackCat, and the shutdown of RansomHub. ๐Ÿ”— www.sans.org/blog/evoluti...

Bild

Pleased to share my first official Team Cymru blog that follows on from my webinar last month ๐Ÿ™Œ โ€œUncovering DPRK Remote Workers: Detecting Hidden Threats Through Internet Telemetryโ€ ๐Ÿ‡ฐ๐Ÿ‡ต ๐Ÿ” www.team-cymru.com/post/uncover...

Uncovering DPRK Remote Workers: Detecting Hidden Threats Through Internet Telemetry | Team Cymru

This blog explores unpacks key insights and explains how internet telemetry can be used to detect these threats in the real world.

team-cymru.com

โš ๏ธ IntelBroker was arrested in France ๐Ÿ‡ซ๐Ÿ‡ท in February 2025, and the US ๐Ÿ‡บ๐Ÿ‡ธ is seeking his extradition. How did Law Enforcement Deanonymize IntelBroker? ๐Ÿ” TL;DR: He messed up on the Bitcoin opsec after an undercover officer made a controlled buy ๐Ÿ’ฐ www.justice.gov/usao-sdny/me...

BildBild

#opendir ๐Ÿ‡จ๐Ÿ‡ณ 1.94.184[.]17:8000 Huawei Cloud AS55990 .jsp Godzilla Web Shell 6d403c3fc246d6d493a6f4acc18c1c292f710db6ad9c3ea2ff065595c5ad3c5b /poc.xml contents wqtzskzmtp[.]zaza[.]eu[.]org 101.33.34[.]170 Tencent AS132203

BildBild