#apt 7d35283f975f9d7a2ff335706527771bf3d7e75f8b6c8762f6165adcfe8d2cf5 ASEAN Semiconductor Roadmap 2026_2030_Draft v0 (For Input)_for ATF-JCC.docx web-api.nrilsnalnrlne.workers[.]dev
StrikeReady Labs
@strikereadylabs.com
https://strikeready.com/blog.html Download live malware samples mentioned here: https://github.com/StrikeReady-Inc/samples If you prefer marketing (our product is great!) subscribe to our main page @strikeready.com
these scams are pretty solid. they grab the list of applications from publicly hosted "construction permit" type city governments, and then send you a relatively small invoice to pay for "approval".
interesting #dailyphish using shopify's CDN for hosting payload cdn.shopify[.]com/s/files/1/0743/9509/1080/files/Document_for_your_review.pdf?v=1784829484
#apt 219cf82c137680ab000d1d2031a37f2680464d0372a3f1c46d21acfef695cdbd Ltr. No.15(2)R-22.zip
#apt #sweetspecter 41c7346a20b1ed3d204ec9648019c39f6af7153cbb5ab09df64128930094224f Trump's latest measures against Iran.doc 1a370844a2adf5d685639cf7c524c033f71a7c3951c6237d24d7fc536b6c57ad Trump's latest measures against Iran.rar
"send me money please" continues to be an effective scam with very little downside
#apt "Updated Educational Programs and Main Disciplines at NATO School Oberammergau (NSO).html" 76d07f53e9e727ac7368614d149caf981e8551d2c2fa38e9bae726ebe2f8d7ef -> winserviceguard[.]center 485a9f51bd195ce1bf06c96c1bc2e421 <-"Russias war against Ukraine EU sanctions Consilium.html"
Nice report from our friends at @rapid7.com on this threat actor www.rapid7.com/blog/post/tr...
Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain
Rapid7 researchers have identified a sophisticated malware campaign attributed to the threat actor "Dropping Elephant," characterized by the use of a China-themed decoy document to deliver a heavily r...
rapid7.com
#apt #in a8ecbd9c049044ca4990a0e5960d19ce782a3b42d7763e9693d7c91ead24a0b7 GRES3001.lnk -> chinagreenenergy[.]org
Always interesting to see what a live phish from #unc1151 looks like 845474a60e029ac8b361a89edfee507d59318c52c6e48f36e6bd30626f09b3f0 Certificate.pdf
#ESETresearch uncovered a new compromise that we attribute to #FrostyNeighbor, using links in malicious PDFs sent via spearphishing attachments to target governmental organizations in Ukraine. @dmnsch welivesecurity.com/en/eset-rese... 1/5
#apt 1fbf27bc3584283668174213d8f3ca441215e5556d924f42fbe0d9ba8afc334b Russias war against Ukraine EU sanctions Consilium.html
edb3b8ef7949fad5a5c0b88f744e4e4a2acd40fe287bec8604ebe8dee9ab3a51 ASEAN 2026 Attendance Meeting (2).zip typical apt lure, but with ransomware filenames, makes this researcher call shenanigans
#malware #dailyopendir meetingszoom[.]com b91ca87a2ce64f025c27a4a7d58f4b61f7b9b043251abab0a138345b5cae322f zoom_meeting.zip
this actor has sent an email like this to dozens of governments, every single day, for the past 15 years. it takes them a few weeks to get banned from outlook/gmail/yahoo/etc and they move to a new one #daily_notaphish_just_weird
Are you flagging on .csproj files inside archives, being delivered by email?
After a lull in activity targeting Europe from mid-2023 to mid-2025, the China-aligned espionage actor #TA416 (RedDelta, Vertigo Panda, Red Lich) has resumed targeting European government and diplomatic entities, with a recent expansion to the Middle East. brnw.ch/21x1f0j
This "JWT_SESSION" cookie sure looks funky, with base64 encoded data between "metaPrefix" and "metaSuffix"! 🔥 66.234.147.10:8080
susp #redteam OSCE_Election_Security_Checklist_v2.pdf.exe 600710c6ad0e4260a3879d36c5455e71 66.234.147.10