Don’t Eat The #ChocoPoCs! How Vulnerability Researchers Were Repeatedly Targeted By Trojanised Exploits www.sekoia.com/blog/dont-ea... Discover our joint threat intelligence report with @YesWeHack.
Sekoia
@sekoia.com
Sekoia is the European cybersecurity company building the Cyber Operations Platform for the AI era.
Our latest Threat Intelligence report dives deep into ADINT (Advertisement-based Intelligence) to expose how private companies weaponise AdTech mechanisms to harvest intelligence data, fueling the surveillance solutions they sell. www.sekoia.com/blog/sold-to...
#TDR analysts published a new report detailing #ErrTraffic, a widespread #ClickFix malware distribution framework. ErrTraffic injects malicious JavaScript into compromised WordPress and malicious sites to serve ClickFix lures. blog.sekoia.io/unveiling-er...
🇷🇺 Sekoia #TDR team has just released a comprehensive analysis of how #APT28's arsenal has evolved, from its early to its current operations. blog.sekoia.io/apt28-an-evo...
The second and third parts of our investigation into the #Gamaredon, the cyberespionage group operated by the Russian #FSB, are live! 🪆Part 2 — The loaders buff.ly/bBYZSKa 🪆Part 3 — The stealer & full infrastructure buff.ly/74WHuPd #CTI #TDR #Sekoia
Russia's #FSB-linked #Gamaredon has been hammering Ukraine's government, military & critical infrastructure for over a decade. We went behind the scenes. Tracked their infrastructure. Recovered artefacts from compromised machines. Here's what we found 🧵 buff.ly/6hR2IMj
Part 2 of our #EvilTokens analysis is live. TDR analysts uncovered the AI-augmented features that automate and scale #BEC workflows, marking a breakthrough in the #PhaaS ecosystem. blog.sekoia.io/eviltokens-a...
#TDR analysts uncovered an emerging Phishing-as-a-Service (#PhaaS) platform called #EvilTokens, which offers device code phishing pages and AI-augmented features to automate and scale #BEC workflows. ⬇️ blog.sekoia.io/new-widespre...
#SilverFox is a China-based intrusion set operating on a unique "dual-track" model. While often tracked for their APT-style espionage, our telemetry shows they continuously run broad, opportunistic cybercrime campaigns targeting entities across South Asia. blog.sekoia.io/silver-fox-t...
#OysterLoader (aka #Broomstick or #Cleanup) is not just another downloader. Often serving as a precursor to #Rhysida #ransomware campaigns or distributing commodity malware such as #Vidar, this threat has evolved significantly as we enter 2026. blog.sekoia.io/oysterloader... #Reverse
#TDR analysts deep dived into a widespread malicious JavaScript framework injected into 3,800+ WordPress sites to distribute #NetSupport RAT via the #ClickFix social engineering tactic. blog.sekoia.io/meet-iclickf...
🐧 Leveraging #Landlock Telemetry for #Linux Detection Engineering Sekoia #TDR explores how Linux Landlock telemetry can be leveraged to build high-fidelity, low-noise detections by observing sandbox policy violations. blog.sekoia.io/leveraging-l...
🎅 Check out the first three episodes of our special Advent of Configuration Extraction Part 1: buff.ly/mpEzALh Part 2: buff.ly/agWWCnp Part3: buff.ly/Crz8rDh 🎄 Last part following Monday! 🎄
🇷🇺 French NGO Reporters Without Borders targeted by #Calisto in recent campaign Sekoia #TDR analysed a recent #Calisto (aka #ColdRiver #Star Blizzard) spear-phishing campaign aimed at Reporters sans frontières and other #Ukraine-supporting organisations. blog.sekoia.io/ngo-reporter...
Histoire et dissection du 𝑚𝑎𝑙𝑤𝑎𝑟𝑒 ou chargeur malveillant 🇷🇺 #Latrodectus par Pierre Le Bourhis @sekoia.io à #UYBHYS25 @uybhys.bsky.social
#TDR analysts dig into a modus operandi targeting the hospitality industry and the related cybercrime ecosystem that facilitates #phishing and #fraud campaigns. blog.sekoia.io/phishing-cam...
Discover how #TransparentTribe (#APT36) uses a disguised DESKTOP dropper to deploy #DeskRAT, a Golang RAT, on BOSS Linux endpoints in India. Our Sekoia #TDR report breaks down the full infection chain and stealthy WebSocket C2 communications . Read more 👉 blog.sekoia.io/transparentt...
Our latest technical deep-dive unravels the mystery behind the opaque numeric codes (16, 272, 33554432, etc.) you see in #Microsoft365 audit logs. blog.sekoia.io/userauthenti...
After our initial #PolarEdge #botnet write-up, we’re happy to announce the second part: “Defrosting PolarEdge’s Backdoor,” a full technical deep-dive into its TLS-based implant. blog.sekoia.io/polaredge-ba...
Je recherche un Threat Researcher pour l’équipe TDR de @sekoia.io ! Vous aimez faire des règles #Sigma et #Yara ? Vous adorez pivoter et traquer les infrastructures (C2) d’attaques des cybercriminels ? Alors cette offre d’emploi est faite pour vous ! www.welcometothejungle.com/en/companies...
Technical Threat Researcher – Sekoia.io – Permanent contract – Fully-remote
Sekoia.io is looking for a Technical Threat Researcher!
welcometothejungle.com
📱 Silent Smishing: The Hidden Abuse of Cellular Router APIs Our latest #CTI investigation from Sekoia #TDR team uncovers a novel #smishing vector abusing Milesight industrial cellular router APIs to send phishing #SMS at scale. blog.sekoia.io/silent-smish...
🐻 #APT28 – Operation Phantom Net Voxel: deep-dive into the latest spear-phishing campaign targeting Ukrainian military administrative staff. blog.sekoia.io/apt28-operat...
[Threat investigation alert 🚨] Predators for Hire: A Global Overview of Commercial Surveillance Vendors ➡️ blog.sekoia.io/predators-fo...
🔥 Hot summer, sizzling crypto... and scammers turning up the heat 🔥 Back in March, Sekoia #TDR team published a deep-dive report on a #Lazarus cluster we dubbed #ClickFake Interview, leveraging the #ClickFix technique in their #ContagiousInterview campaign.
🧀 The Sharp Taste of #Mimo’lette: Analyzing Mimo’s Latest Campaign targeting #Craft CMS blog.sekoia.io/the-sharp-ta...
The Sharp Taste of Mimo'lette: Analyzing Mimo’s Latest Campaign targeting Craft CMS
Analysis of the CVE-2025-32432 compromise chain by Mimo: exploitation, loader, crypto miner, proxyware, and detection opportunities.
blog.sekoia.io
🪤 Sekoia #TDR's new exclusive research uncovers the #ViciousTrap, a honeypot network deployed on compromised edge devices. blog.sekoia.io/vicioustrap-...
ViciousTrap - Infiltrate, Control, Lure: Turning edge devices into honeypots en masse.
Discover ViciousTrap, a newly identified threat who turning edge devices into honeypots en masse targeting
blog.sekoia.io
Our new report describes one of the latest observed infection chains (delivering #AsyncRAT) relying on the #Cloudflare tunnel infrastructure and the attacker’s #TTPs with a principal focus on detection opportunities. blog.sekoia.io/detecting-mu...
Since the apparition of the #Interlock ransomware, the Sekoia #TDR team observed its operators evolving, improving their toolset (#LummaStealer and #BerserkStealer), and leveraging new techniques such as #ClickFix to deploy the ransomware payload. blog.sekoia.io/interlock-ra...