thehappydinoa

@thehappydinoa.dev

aka Aidan | Security Researcher, Developer, and Collaborator at @censysio | Opinions are my own

new writeup: the latest DarkSword operator, chinese-speaking, well over a hundred panels found the whole thing off one http body hash. six panels, two totally different codebases, same guy we're at 7-8 unrelated crews running this leaked ios chain now censys.com/blog/darkswo... #darksword

DarkSword's Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster - Censys

Censys ARC noticed a recent spike in DarkSword hosts and web properties. Here are the IOCs and pivots you need to track the growing threat.

censys.com

I don't talk a lot about work here, but I looked into a phishing campaign that targeted a Belarusian opposition politician and then turned out to also impersonate at least three popular Ukrainian portals (it was also my first blog post for Censys) censys.com/blog/unc1151...

UNC1151 Phishing Email Targeting Belarusian Politician Points to Multi-National Campaign - Censys

New Censys ARC research discovers that UNC1151's phishing email to a Belarusian politician is linked to a much broader campaign.

censys.com

Odyssey Stealer isn't a solo operation. It's a macOS MaaS platform where affiliates rent C2 access to steal crypto. New research: payload analysis, 10 C2s mapped, and the AMOS → Poseidon → Odyssey lineage traced. censys.com/blog/odyssey... #macOS #Malware #OdysseyStealer

Odyssey Stealer: Inside a macOS Crypto-Stealing Operation

Odyssey is a macOS stealer focused on crypto theft. Learn how it works, the risks it poses, and how to defend against it.

censys.com