Julian-Ferdinand Vögele

@julianferdinand.bsky.social

Threat Research @ Recorded Future. Previously @ Security Research Labs. He/Him. 🏳️‍🌈

NEW: I really enjoyed speaking to General Sir Jim Hockenhull a few weeks ago and am grateful the fruits of that conversation can now be published. His message to the British public is stark: “War isn’t going to happen as an away game. If there is a conflict, it will be happening here.”

Britain’s next war won’t be an away game: Q&A with former head of Defence Intelligence

As Chief of Defence Intelligence, General Sir Jim Hockenhull decided to declassify and publish what London knew of Russia’s plans to invade Ukraine, down to a map of the routes its forces would take.

therecord.media

A new Comintern: How the Kremlin lures Western “socialists” into the Russian army The Insider has identified several British and U.S. citizens who were recruited to fight for Russia with the help of “communists” and far-left activists.

A new Comintern: How the Kremlin lures Western “socialists” into the Russian army

Russia has built a network linking socialist and anti-globalist groups abroad under the banner of support for left-wing causes. The effort often starts with…

theins.press

A new ransomware group (who I'm not giving the publicity of naming) is brazenly offering journalists early access to their data leak site in order to increase pressure on victims to make an extortion payment. I'm unaware of other recipients but the message looks mass-sent.

Bild

Another one for the increasingly blurred lines between criminal and state-sponsored hacking groups. Tools and infrastructure used by North Korea’s infamous Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations...

North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn

Cyberattack tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations — further evidence of deepening entan...

therecord.media

ChonkyChicken Malware Steals Chrome Credentials, Moves Laterally and Spies on Victims

ChonkyChicken Malware Steals Chrome Credentials, Moves Laterally and Spies on Victims

ChonkyChicken is a newly identified remote access trojan designed to turn one infected Windows device into a platform for credential theft, network movement, and surveillance. The malware is part of the TAG-195, also called Golden Chickens or Venom Spider, malware-as-a-service ecosystem, which supplies tooling to financially motivated criminal operators. Recent campaigns begin with ClickFix lures, fake verification pages that persuade targets to paste a copied command into the Windows Run dialog. That action downloads an OCX payload and launches it with regsvr32.exe, allowing the first-stage TinyEgg backdoor to establish access before ChonkyChicken is delivered. Readers following  ClickFix attacks using trusted tools  will recognize how this technique shifts the critical action to the victim. Analysts at Recorded Future’s Insikt Group identified the malware while tracking the evolving TAG-195 ecosystem.  TAG-195 threat group associations (Source – Recorded Future) Recorded Future said in a report shared with Cyber Security News (CSN) that ChonkyChicken is a second-stage implant that combines browser theft, interactive session control, remote execution, reconnaissance, and sustained monitoring in one framework. The impact reaches well beyond a stolen password. Attackers can use browser data and active sessions to access business services, map internal systems, and move toward other devices. The threat also reinforces why organizations need to monitor  browser stored credential theft  rather than treating saved passwords as a low-risk convenience. ChonkyChicken Malware ChonkyChicken uses a tailored helper named ChromEggscalator to bypass Chrome App-Bound Encryption protections and collect protected browser secrets. The malware downloads the helper, places it in a temporary directory, executes it through a Windows utility, and sends the collected credential material back to its controller. The malware can also control live Chrome or Edge sessions through Chrome DevTools Protocol automation. It launches a browser out of view with remote debugging enabled, then lets operators interact with an already authenticated session. That means a password reset alone may not remove an attacker who still holds an active browser session. Its lateral movement features give operators several routes across a network. Summary of new TAG-195 malware (Source – Recorded Future) ChonkyChicken can use available credentials or access tokens, check logged-in sessions without generating authentication events, create remote scheduled tasks, scan ports, discover hosts, and identify accessible network shares. This places ChonkyChicken in a different category from basic password stealers. The malware is built to help attackers understand an organization’s network and then use a compromised endpoint as a stepping stone. Similar risks are seen in  browser extension credential theft , where browser access can expose both credentials and active accounts. Modular Spying and Defense ChonkyChicken also collects keystrokes, clipboard contents, audio recordings, and screenshots, giving attackers ongoing visibility into victim activity. A separate modular version can request at least 14 capability plugins only when they are needed, reducing the amount of malicious code initially present on a device. Recent TAG-195 ClickFix infection (Source – Recorded Future) All current TAG-195 families share tactics intended to complicate detection. They use filename checks to avoid running in unwanted environments, keep persistence through Windows Run keys, obscure strings, and abuse regsvr32.exe to load OCX files from user-writable locations. Security teams should watch for  regsvr32 abuse in malware , especially when it involves files in TEMP or AppData. Defenders should restrict pasted-command execution where practical, block regsvr32.exe from loading OCX files from user-writable folders, and alert on suspicious Run key entries. They should also investigate Chrome or Edge processes launched with remote-debugging options, monitor unusual WebSocket traffic, enforce phishing-resistant multifactor authentication, and limit administrator privileges between workstations. Indocators of compromise (IoCs):- Type Indicator Description IP address 70.34.205.43 Shared IP address used by observed TAG-127 ClickFix lure infrastructure Domain screenly.cam ClickFix lure page domain Domain xtrafftrck.net Payload staging and command-and-control domain Domain api.it195f.top TAG-195 infrastructure domain shown in the report URI path gtgate.php Observed controller endpoint path WebSocket endpoint ws://localhost:3000/wsagent Observed Modular ChonkyChicken development or testing endpoint File name TEMP.txt ChonkyChicken execution-attempt log artifact File name C.txt ChromEggscalator operational log artifact File name xlog.txt ChromEggscalator forensic artifact File name chromelevator.ocx ChromEggscalator credential-theft helper file name File name mscom.ocx ChromEggscalator execution detection artifact File name wpadcapture.ocx WPAD helper component referenced by ChonkyChicken File name koki.ocx Modular ChonkyChicken controller file name File name agent.ocx Modular ChonkyChicken controller file name Registry value WinComCtl Run key value used for persistence Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . ALERT!: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure. The post ChonkyChicken Malware Steals Chrome Credentials, Moves Laterally and Spies on Victims appeared first on Cyber Security News .

cybersecuritynews.com

⚡️Update: 7 killed, 15 injured across Ukraine as Russia launches massive ballistic missile, drone attack. Officials in Kryvyi Rih reported that six people were killed, including two children, and eight others injured after a home belonging to a large family was struck by a ballistic missile.

7 killed, 15 injured across Ukraine as Russia launches massive ballistic missile, drone attack

Russia launched dozens of ballistic and cruise missiles, as well as hundreds of drones, towards Ukraine in the early hours of July 30 in yet another large-scale attack. Damage was reported in various ...

kyivindependent.com

So remember last week when we said we hadn’t see TA488/Laundry Bear/Void since Feb? Well... We kinda lied Day before the release, we found em throwing a half click against Outlook to install one of the coolest implants we’ve ever examined: OWAReaper www.proofpoint.com/us/blog/thre...

Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US

Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release

proofpoint.com

NEW: I delved into the mystery of Phineas Fisher, probably the most prolific and public hacker never to have gotten caught. This is what we know about the infamous hacktivist and their spectacular hacks against spyware makers FinFisher and Hacking Team. There will be even more in my upcoming book.

The hacker who humiliated spyware makers and was never caught | TechCrunch

An awe-inspiring hacktivist who hacked two controversial government spyware makers may be the most prolific hacker to have never gotten caught. What do we know about Phineas Fisher?

techcrunch.com

NEW: After a purported crackdown on scam compounds last year, researchers now say at least 25 new scamming sites have opened or expanded in Myanmar. Satellite images show trees being razed and land cleared, with large compounds appearing months later

Satellite Images Reveal How Suspected Scam Compounds Appear Out of Nowhere

Analysis of satellite images of Myanmar shows dozens of alleged scam compounds have appeared in recent months, despite a purported crackdown on the criminal organizations.

wired.com