Intel 471

@intel471.bsky.social

Intel 471 specializes in delivering intelligence related to threat actors, threat hunting, financial cybercrime, ransomware, vulnerabilities, malware and underground marketplaces. Listen to our podcast, Cybercrime Exposed, on Spotify and Apple. #infosec

The Black Basta ransomware gang contracted a person with the nickname Tinker. Tinker came from Conti and had a knack for running call centres, writing phishing emails and ransom negotiations. More here from Intel 471's Adversary Intelligence team. intel471.com/blog/a-look-...

A look at ‘Tinker,’ Black Basta’s phishing fixer, negotiator

The leader of the Black Basta ransomware group employed a trusted, experienced cybercrime actor nicknamed Tinker who he relied on for phishing content,…

intel471.com

Law enforcement has smashed DanaBot, a data-stealing workhorse administered in Russia and sold to cybercriminals that also had a second, side version likely used for nation-state cyberespionage. Here's Intel 471's in-depth look at its operations. #infosec intel471.com/blog/danabot...

DanaBot malware disrupted, threat actors named

The DanaBot malware was severely disrupted by law enforcement. Here's an in-depth look at this data-stealing workhorse for the cybercriminal underground.

intel471.com

Intel 471's very own Senior Intelligence Analyst Ashley Jess has been closely following cybercriminal use and interest in AI. This was a pre-record before DeepSeek popped but it is a great discussion about the potential threats and risks. #infosec intel471.com/blog/how-thr...

How threat actors are using artificial intelligence

Artificial intelligence is a red-hot mess, filled with contradicting predictions over whether it will bring vast benefits. In this Studio 471, Ashley Jess…

intel471.com

Clop, a ransomware/extortion group that targets file transfer systems, revealed the names of 59 businesses that allegedly were impacted by the Cleo vulnerabilities and refused to pay. The group claimed their data will be publicly released on Saturday, with another list to come on Tuesday. #infosec

Hundreds of fake websites have been registered over the last few days spoofing real brands containing "Black Friday" related keywords. These sites are often promoted through SEO tricks and search engine/social media ads. This one was at samsoniteblackfriday[.]shop. #infosec

Bild

The breaches linked to customers of Snowflake marked one of the largest data breach waves of 2024. One of the alleged threat actors has been arrested in Canada. This blog is a deep dive into the Com-related threat actor "waifu" or @judische. #infosec intel471.com/blog/how-to-...

How to Defend Against Alleged Snowflake Attacker ‘Judische’

The threat actor behind the compromise of more than 165 organizations using Snowflake credentials stolen by infostealers has reportedly been detained.…

intel471.com

Adversaries try to hide malicious components by renaming them as legitimate Windows binaries. This technique has been used by the Turla threat actor group and others. Here's how to threat hunt for this behavior. #infosec intel471.com/blog/threat-...

Threat Hunting Case Study: Uncovering Turla

Adversaries try to hide malicious components by renaming them as legitimate Windows binaries. This technique has been used by the Turla threat actor group…

intel471.com

Will processing cyber threat intelligence become illegal? Here's a discussion with professor Peter Swire about how data protection schemes can potentially clash with better cybersecurity defences. This is part of @intel471.bsky.social's interview series. #infosec intel471.com/blog/will-pr...

Will Processing CTI Become Legally Risky?

In this Studio 471, Peter Swire discusses the regulatory environment, how it could impact the use of cyber threat intelligence and what could be done to…

intel471.com

Intel 471 collaborated with great minds in the CTI industry to develop the Cyber Threat Intelligence Capability Maturity Model. It's a methodical way to build a CTI program that establishes focus, satisfies stakeholders and improves security outcomes. intel471.com/blog/introdu...

Introducing the CTI Capability Maturity Model, a resource for…

The CTI Capability Maturity Model (CTI-CMM) is an easy to use, vendor-neutral model that promotes a “stakeholder-first” approach to building a mature CTI…

intel471.com

Intel 471 analyzed recent phishing campaigns by ATLAS LION, a group that specializes in compromising companies gift-card issuing systems. This group is skilled at attacker-in-the-middle phishing, spoofing IDPs and navigating cloud infrastructure. intel471.com/blog/threat-...

Threat Actors Target Gift Card Issuing Systems

ATLAS LION is a threat actor group that uses phishing to gain access to gift-card issuing systems and then generates fraudulent cards.

intel471.com

Our intelligence analysis team has written a cyber threat assessment of the Paris Olympic Games, covering how the Games could be impacted hacktivism, nation-state actors, ongoing geopolitical turmoil and financially motivated threat actors. intel471.com/blog/cyber-t...

Cyber Threat Landscape: 2024 Paris Olympic Games

The infrastructure behind the 2024 Summer Olympics is vast, providing a large potential attack surface. Here's an overview of the threat landscape.

intel471.com

Australia accused 33-year-old Russian Aleksandr Ermakov of the Medibank data breach and extortion attempt. Intel 471 has compiled a profile of Ermakov and his long-known links to cybercrime and ransomware. It's a good read. #infosec intel471.com/blog/mediban...

Medibank’s Attacker: IT Businessman, Claimed Psychologist and Alleged…

Australia has accused Aleksander Ermakov of one of the country's largest data beach and extortion attacks. Intel 471 has compiled a deep profile Ermakov…

intel471.com

Malaysian police have disrupted a massive phishing-as-a-service operation that was the focus of Ep. 1 of our Cybercrime Exposed podcast. Here's the low-down on the threat it posed for enterprise security. #infosec intel471.com/blog/malaysi...

Malaysian Police Disrupt ‘The Phisherman’

Malaysian police disrupted a massive phishing-as-a-service operation called BulletProftLink that Intel 471 has been tracking. Here’s why that’s important for enterprise security.

intel471.com

QR code phishing surged as threat actors suddenly revisited this old technique. Some security software may not extract the links from a QR code because OCRing codes takes a lot of overhead. Here's what we've seen and some defensive tips to keep in mind. #infosec intel471.com/blog/phishin...

Phishing Emails Abusing QR Codes Surge

QR code phishing has surged as cybercriminals revisit this old technique. Here are the trends and how to guard against these kinds of attacks.

intel471.com