Feike Hacquebord

@feikeh.bsky.social

Principal Threat Researcher at TrendAI

CVE-2025-8088, a WinRAR flaw, is still exploited by Russia-aligned groups against Ukraine. SHADOW-EARTH-066 (UAC-0226) deploys an evolved GIFTEDCROOK infostealer. Earth Dahu (Gamaredon) uses HTA + Cloudflare Workers. The flaw keeps on working (no WinRAR auto-update). trendmicro.com/en_us/resear...

Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open

Two separate Russia-aligned campaigns are still exploiting the WinRAR flaw CVE-2025-8088 against Ukrainian organizations nearly a year after it was patched, showing how unmanaged software keeps an exp...

trendmicro.com

When TrendAI detects a C&C, we don't just block it for our customers, we get it removed from the internet. We send an evidence package to CleanDNS, who validates it independently and files a takedown request with the registrar. Domain removed, often within days. www.trendmicro.com/vinfo/us/sec...

TrendAI™ and CleanDNS: From Blocking Attacker Infrastructure to Removing It From the Internet

TrendAI™ and CleanDNS have partnered to go beyond blocking malicious domains. Learn how we are actively dismantling the infrastructure that cybercriminals depend on and removing attacker domains from ...

trendmicro.com

Edge devices are now the #1 entry point for state-sponsored espionage. Exploits cost $30K-$100K vs millions for mobile. China-aligned groups are burning through zero-days, seemingly in a coordinated way. Your edge devices are the new front door for attackers: www.trendmicro.com/vinfo/us/sec...

Edge Under Siege: How State-Sponsored Actors Exploit Your Perimeter

Edge devices have become a primary entry point for state-sponsored espionage, giving attackers a cheaper, faster path to network access, credential theft, and traffic interception. Our report examines...

trendmicro.com

It is not often the public gets to see the impact of Russia-aligned cyber operations. This article by Raphael Satter provides exactly that: Russia-aligned actors compromised 170+ accounts of Ukrainian officials tasked with fighting corruption and unmasking spies. www.reuters.com/world/russia...

Exclusive: Russia-linked hackers compromised scores of Ukrainian prosecutors’ email accounts, data shows

Russia-linked hackers broke into more than 170 email accounts belonging to prosecutors and investigators across Ukraine during the last several ​months, according to data reviewed by Reuters, a campai...

reuters.com

In our most recent report on the Russia-aligned APT group Pawn Storm (APT28, Fancy Bear, Forest Blizzard), we explain how they have been using PRISMEX, a collection of interconnected malware components, to target the defense supply chain of Ukraine and its allies - www.trendmicro.com/en_us/resear...

Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities

This blog discusses the steganography, cloud abuse, and email-based backdoors used against the Ukrainian defense supply chain in the latest Pawn Storm campaign that TrendAI™ Research observed and anal...

trendmicro.com

Navalny was poisoned with exotic frog toxin, five Western nations confirm Multiple labs have independently analyzed biological samples taken from Alexei Navalny’s body and found epibatidine, a highly toxic alkaloid sourced from a South American poisonous frog.

Navalny was poisoned with exotic frog toxin, five Western nations confirm

Five European countries have confirmed that Navalny was poisoned with epibatidine — a high-potency neurotoxin derived from South American poison dart frogs. Traces of the toxin were found in tissue sa...

theins.press

TrendAI formalizes threat attribution as a structured, repeatable discipline by combining standardized evidence scoring, relationship mapping, and bias testing, with a temporary stage that separates clustering from final naming. Article on how we attribute: www.trendmicro.com/vinfo/us/sec...

Threat Attribution Framework: How TrendAI™ Applies Structure Over Speculation

TrendAI™ brings structure and discipline to threat attribution, helping security leaders and teams make informed decisions about cyber risk, incident response, and overall defensive posture.

trendmicro.com

Residential proxies are a key enabler of cybercrime today. This creates a growing need for connection and session-based access control. We used Ja4T fingerprinting that successfully tagged incoming connections from residential proxies to 1,500 IDS systems. www.trendmicro.com/vinfo/us/sec...

The Rise of Residential Proxies as a Cybercrime Enabler

This research discusses how residential proxies help cybercriminals bypass antifraud and IT security systems, and how vulnerabilities in the IoT supply chain are exploited where Android-based devices ...

trendmicro.com

One week ago Lumen/Shadowserver sinkholed Water Barghest C&Cs. Nsocks (alleged seller of Ngioweb bots) apparently suffers from this: US proxies down to 4494 (was 14037), EU proxies down to 2038 (was 9092). I expected a faster recovery. Still expect Water Barghest will make their botnet more robust.

Bild