Will T

@bushidotoken.net

๐Ÿ‡ฌ๐Ÿ‡ง | Senior Threat Intelligence Advisor at Team Cymru | Co-author SANS FOR589 | Co-founder Curated Intel

New Blog! ๐Ÿ‡ฌ๐Ÿ‡ง UK Cybercrime Journal: ExfilSquad Emerges - ExfilSquadโ€™s extortion campaign targets UK public sector orgs, education, and law enforcement - ExfilSquad's primary attack vector involves exploiting CRM platforms and Microsoft Power Pages ๐Ÿ”— blog.bushidotoken.net/2026/09/uk-c...

UK Cybercrime Journal: ExfilSquad Emerges

CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security

blog.bushidotoken.net

New Blog! ๐Ÿ‡ฌ๐Ÿ‡ง UK Cybercrime Journal: ACRO Breach Report โ€” Between July 2021 and June 2023, the UK Criminal Records Office had 3 separate breaches โ€” It had an SQLi attack on its Kentico CMS followed by Mimikatz โ€” 4x Trend Micro AV alerts were ignored ๐Ÿ”— blog.bushidotoken.net/2026/08/uk-c...

UK Cybercrime Journal: ACRO Breach Report

CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security

blog.bushidotoken.net

New Blog! ๐Ÿ‡ฌ๐Ÿ‡ง UK Cybercrime Journal: Carding Tactics & Youth Money Muling - UK law enforcement exposed domestic carding networks and the growing threat of teenage money mules recruited via Snapchat, Instagram, and online gaming services ๐Ÿ”— blog.bushidotoken.net/2026/08/uk-c...

UK Cybercrime Journal: Carding Tactics & Youth Money Muling

CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security

blog.bushidotoken.net

New Blog! ๐Ÿ‡ฌ๐Ÿ‡ง UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026 - In H1 2026, Qilin averaged 8 UK victims per month, 37 in total - Most victims are Small/Medium Enterprises (SMEs) - Salford City College appeared on Qilin & DragonForceโ€™s DLSs ๐Ÿ”— blog.bushidotoken.net/2026/07/uk-c...

UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026

CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security

blog.bushidotoken.net

New Blog! ๐Ÿ‡ฌ๐Ÿ‡ง UK Cybercrime Journal: H1 2026 Social Media Fraud Trends - HMRC Warns TikTok Users - Lloyds Bank says 66% of Fraud Cases Started on Metaย  - UK Finance Recorded ยฃ221.5m Lost to Investment Scams - Fraudsters arrested in Nigeria by the NCA ๐Ÿ”— blog.bushidotoken.net/2026/07/uk-c...

UK Cybercrime Journal: H1 2026 Social Media Fraud Trends

CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security

blog.bushidotoken.net

New Blog! ๐Ÿ‡ฌ๐Ÿ‡ง UK Cybercrime Journal: University of Nottingham Breached by ShinyHunters The education sector in the UK has suffered repeated, significant data breaches in recent years, but ShinyHunters campaign has been one of the worst yet. ๐Ÿ”— blog.bushidotoken.net/2026/07/uk-c...

UK Cybercrime Journal: University of Nottingham Breached by ShinyHunters

CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security

blog.bushidotoken.net

New Blog! ๐Ÿ‡ฌ๐Ÿ‡ง UK Cybercrime Journal: Argos Account Takeover Fraud - Cybercriminals are using leaked credentials to hijack Argos user accounts - They then order and then collect the goods in-person at a physical store and pay with stolen credit cards ๐Ÿ”— blog.bushidotoken.net/2026/07/uk-c...

UK Cybercrime Journal: Argos Account Takeover Fraud

CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security

blog.bushidotoken.net

New Blog! ๐Ÿ‡ฌ๐Ÿ‡ง UK Cybercrime Journal: Hargreaves Landsdown Extortion Attempt by Bashe It appears Bashe weaponised HLโ€™s recent, IT outages & glitches (in Sept 2025 and March 2026) to construct a plausible, but false, narrative of a successful hack. ๐Ÿ”— blog.bushidotoken.net/2026/06/uk-c...

UK Cybercrime Journal: Hargreaves Landsdown Extortion Attempt by Bashe

CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security

blog.bushidotoken.net

Two of my fav ๐Ÿ‡ฌ๐Ÿ‡ง ๐Ÿ‡จ๐Ÿ‡ฆ experts when it comes to discussing cyber warfare, Philip Ingram and Ian Thornton-Trump, released an interview reviewing in detail the threat landscape of ๐Ÿ‡ท๐Ÿ‡บ Russian cyber operations in the context of the ongoing war in ๐Ÿ‡บ๐Ÿ‡ฆ Ukraine. ๐Ÿ”— youtu.be/p1vl5t4fVWA

How Russiaโ€™s cyber propaganda machine is backfiring on the frontline | Ian Thornton-Trump

YouTube video by Frontline

youtu.be

New Blog! ๐Ÿ‡ฌ๐Ÿ‡ง UK Cybercrime Journal: Sustained DragonForce Campaign Throughout May 2026, the DragonForce RaaS operation claimed seven UK-based companies as its victims by posting them on their Tor data leak site. ๐Ÿ”— blog.bushidotoken.net/2026/06/uk-c...

UK Cybercrime Journal: Sustained DragonForce Campaign

CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security

blog.bushidotoken.net

New ๐Ÿ‡ฌ๐Ÿ‡ง UK Cybercrime Journal Entry: Arup Group Breached by FulcrumSec What do AWS DCs, Disneyland, Wembley Football Stadium, HS2 and HS1 Channel Tunnel Rail Link network, and the Eden Project all have in common? They were engineered by Arup Group ๐Ÿ‘€ blog.bushidotoken.net/2026/06/uk-c...

UK Cybercrime Journal: Arup Group Breached by FulcrumSec

CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security

blog.bushidotoken.net

๐Ÿ“ฃ I have been wanting to write more regularly for my site blog.bushidotoken.net and have made a new series: The UK Cybercrime Journal. These are short UK cybercrime incident reports with a BLUF, Analyst Comment, and Defensive Takeaways. Starting here: blog.bushidotoken.net/2026/05/uk-c...

UK Cybercrime Journal: Inside the Cl0p attack on South Staffs Water

CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security

blog.bushidotoken.net

New Blog! Stranger Strings: Yurei Ransomware Operator Toolkit Exposed Through my research with Team Cymruโ€™s data, we have discovered another ransomware operatorโ€™s server with Stranger Things-themed tools, check it out๐Ÿ‘‡ www.team-cymru.com/post/yurei-d...

Yurei Double Extortion Ransomware: Operator Toolkit and Analysis

Analyze the Yurei double extortion ransomware campaign, including its toolkit, attack lifecycle, and key tactics used by operators.

team-cymru.com

New Blog! The Beast Returns: Analysis of a Beast Ransomware Server ๐Ÿ‘น In March 2026, Team Cymru detected a Beast operatorโ€™s server that enabled us to understand the flow of their attacks from start, to middle, to the end, including ransomware binaries. www.team-cymru.com/post/beast-r...

Beast Ransomware Toolkit: A Proactive Threat Intelligence Report

Explore our latest threat intelligence report on Beast Ransomware. See the exact incident response tools and TTPs used by operators to bypass EDR and delete backups.

team-cymru.com

๐—ฃ๐—ข๐——๐—–๐—”๐—ฆ๐—ง ๐ŸŽง ๐—›๐—ผ๐˜„ ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฑ ๐—ฆ๐—ต๐—ฎ๐—ฝ๐—ฒ๐—ฑ ๐˜๐—ต๐—ฒ ๐—™๐˜‚๐˜๐˜‚๐—ฟ๐—ฒ ๐—ผ๐—ณ ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† We sat down with Rebecca Taylor from Sophos and @bushidotoken.net from @teamcymrus2.bsky.social to discuss 2025โ€™s highs and lows in cyber and make educated guesses on what to look for in 2026. feeds.soundcloud.com/users/soundc...

Bild

New Blog! ๐Ÿ‘€ In this research, I take a look at the Qilin RaaS in-depth, which has emerged as one of the leading and most innovative ransomware gangs following the takedown of LockBit, the exit scam by ALPHV/BlackCat, and the shutdown of RansomHub. ๐Ÿ”— www.sans.org/blog/evoluti...

Bild