Jerri P

@whoisnt.bsky.social

Threat Research @ Recorded Future

1/ We just published new research on TAG-195 (“Golden Chickens” / “Venom Spider”), documenting a major evolution of one of cybercrime’s longest-running Malware-as-a-Service ecosystems. We identified 4 previously undocumented malware families, revealing a shift toward modular, operator-driven tooling

TAG-195 Upgrades MaaS Ecosystem with Modular Tools

Insikt Group identifies four new TAG-195 malware families, revealing an architectural transition toward modular, operator-driven tooling in the MaaS ecosystem

recordedfuture.com

1/ Today we’re publishing our annual malicious infrastructure report, providing a broad view of global threat infrastructure. This year, we significantly expanded coverage across malware families, threat categories, and deeper infrastructure insights: www.recordedfuture.com/research/202...

2025 Year in Review: Malicious, Infrastructure

Explore Insikt Group’s 2025 Malicious Infrastructure Report. Gain insights into Cobalt Strike, Vidar infostealers, and AI-driven threats to secure your 2026 strategy.

recordedfuture.com

CastleLoader in the wild! Four distinct activity clusters, sector-specific targeting of logistics, and high-end tooling like Matanbuchus and CastleRAT.

Julian-Ferdinand Vögele@julianferdinand.bsky.social · 8mo ago

1/ @whoisnt.bsky.social, Marius, and I just published a report on #GrayBravo (formerly TAG-150), a highly adaptive, sophisticated threat actor that we first identified in Sept 2025. It uses a multi-layered infrastructure and responds quickly to exposure: www.recordedfuture.com/research/gra...