alden

@re.wtf

malware enjoyer • macOS security https://alden.io

excited bc today @huntress.com is releasing our analysis of a gnarly intrusion into a web3 company by the DPRK's BlueNoroff!! 🤠 we've observed 8 new pieces of macOS malware from implants to infostealers! and they're actually good (for once)! www.huntress.com/blog/inside-...

Inside the BlueNoroff Web3 macOS Intrusion Analysis | Huntress

Learn how DPRK's BlueNoroff group executed a Web3 macOS intrusion. Explore the attack chain, malware, and techniques in our detailed technical report.

huntress.com

finally got around to rewriting the copy as yara binja plugin! 🥰 has a few quality of life improvements (new formats) and address wildcarding is fixed for ARM! (sorry bout that mac homies) ❤️ it's also now available in the plugin repository! 🔥 github.com/ald3ns/copy-...

Bild

BREAKING: DOGE has uncovered that the CIA spent $10,000,000 on zyns and has been feeding them to analysts to increase productivity! 😱

Cool mint zyn containers that are CIA branded

our network has raised hundreds of dollars to give firefighters the zyn they need to keep protecting LA from the fires. Thank you!!

BildBildBildBild

🧵Today’s blogpost focuses on a newer ransomware variant named SafePay. Needless to say, ransomware sucks. When this new variant appeared, it gained our attention. 👀 Let’s dig into what happened and what makes it tick ⬇️:

A redacted view of the SafePay onion website hosting information about compromised machinesDirectory listing from the attacker's onion siteApache Server info page

I wrote a post on the realities of cloud & webserver ransomware. Check it out to see some of the toolsets & frameworks that can be used for these attacks.

Phil Stokes ⫍🐠⫎@philofishal.bsky.social · 2y ago

🔥 In a report on the state of cloud ransomware, @alex.leetnoob.com has identified several tools designed to target web servers with ransomware or to leverage cloud services to upload files before encrypting local files on an endpoint. s1.ai/cloud-rw