Andrew Northern

@exraritas.bsky.social

🔮 Senior Threat Researcher at @proofpoint 🔮 | Kindness and Compassion | Not a reflection of the opinions or policies of my employer | Andrew Northern

The Justice Department and FBI announced a law enforcement operation that, alongside international partners, deleted “PlugX” malware from thousands of infected computers worldwide implanted by Chinese hackers known as “Mustang Panda” or “Twill Typhoon." www.justice.gov/opa/pr/justi...

Justice Department and FBI Conduct International Operation to Delete Malware Used by China-Backed Hackers

The Justice Department and FBI today announced a multi-month law enforcement operation that, alongside international partners, deleted “PlugX” malware from thousands of infected computers worldwide. A...

justice.gov

New episode of DISCARDED where I chat with Genina Po about how she catches phish 🎣 We dive into how to write detections, what to hunt for when finding phish kits, and some of her recent research on phishing scams. Tune in wherever you get your podcasts! Apple: podcasts.apple.com/us/podcast/d...

Scams, Smishing, and Safety Nets: How Emerging Threats Catches Phish

Podcast Episode · DISCARDED: Tales From the Threat Research Trenches · 11/15/2024 · 51m

podcasts.apple.com

Almost embarrassed to post this, but I've always used Fiddler or Burp for capturing things like this... I didn't have admin rights and was trying to capture network traffic from a pop-up, so Dev Tools wasn't working Apparently this is built into Chrome/Edge! So cool :) edge://net-export/

Bild

🧵Today’s blogpost focuses on a newer ransomware variant named SafePay. Needless to say, ransomware sucks. When this new variant appeared, it gained our attention. 👀 Let’s dig into what happened and what makes it tick ⬇️:

A redacted view of the SafePay onion website hosting information about compromised machinesDirectory listing from the attacker's onion siteApache Server info page