X_Hunt3r
@x-hunt3r.bsky.social
Threat Hunting & Research, Network Forensics | Principal Threat Analyst @ Recorded Future | "Undesirable" | Member CuratedIntel | Views and opinions are my own
Colleagues of mine at Insikt Group just released new research on the Iran-nexus cluster #TAG-182, deploying #MarkiRAT, a malware family previously observed in use by #FerociousKitten, for internal and external surveillance: www.recordedfuture.com/research/nex...
Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool
Discover how Iranian-nexus threat cluster TAG-182 uses MarkiRAT malware and fake VPN/media apps to conduct cyber surveillance operations against domestic targets.
recordedfuture.com
1/ Today we’re publishing our annual malicious infrastructure report, providing a broad view of global threat infrastructure. This year, we significantly expanded coverage across malware families, threat categories, and deeper infrastructure insights: www.recordedfuture.com/research/202...
2025 Year in Review: Malicious, Infrastructure
Explore Insikt Group’s 2025 Malicious Infrastructure Report. Gain insights into Cobalt Strike, Vidar infostealers, and AI-driven threats to secure your 2026 strategy.
recordedfuture.com
By me: Microsoft has fixed three zero-day bugs in Windows and Office that are being actively abused by hackers to break into people's computers. Microsoft said three of the exploits are now public. Google, which helped find the bugs, said one of them is under “widespread, active exploitation."
Microsoft says hackers are exploiting critical zero-day bugs to target Windows and Office users | TechCrunch
Critical security flaws targeting Windows and Office users allow hackers to take complete control of a victim's computer by clicking a malicious link or opening a file. Patch now.
techcrunch.com
Today, we released new @RecordedFuture research detailing BlueDelta’s expanded credential-harvesting activity observed between February and September 2025. #BlueDelta #APT28 #FANCYBEAR #ForestBlizzard #FROZENLAKE #ITG05 #PawnStorm #Sednit #Sofacy #TA422 (1/5) www.recordedfuture.com/research/gru...
GRU-Linked BlueDelta Evolves Credential Harvesting
Insikt Group reveals how GRU-linked BlueDelta evolved credential-harvesting campaigns targeting government, energy, and research organizations across Europe and Eurasia.
recordedfuture.com
Today, we released new @RecordedFuture research detailing BlueDelta’s sustained credential-harvesting campaign targeting UKR.NET users between June 2024 and April 2025. www.recordedfuture.com/research/blu... #BlueDelta #APT28 #FANCYBEAR #ForestBlizzard #FROZENLAKE #PawnStorm #Sednit #Sofacy (1/5)
BlueDelta’s Persistent Campaign Against UKR.NET
Discover how Russia’s BlueDelta targets UKR.NET users with advanced credential-harvesting campaigns, evolving tradecraft, and multi-stage phishing techniques.
recordedfuture.com
Great work by Sekoia uncovering new #BlueDelta #APT28 #Sofacy #FancyBear #ForestBlizzard #TAG110 malware samples. Linked to CERT-UA’s BeardShell & Covenant frameworks + revealed fresh weaponized docs & subtle TTPs. Activity ties to Russia-nexus ops incl. Double-Tap. blog.sekoia.io/apt28-operat...
APT28 Operation Phantom Net Voxel
APT28 Operation Phantom Net Voxel: weaponized Office lures, COM-hijack DLL, PNG stego to Covenant Grunt via Koofr, BeardShell on icedrive.
blog.sekoia.io
Ukraine claims cyberattacks on Russian election systems; Moscow confirms disruptions therecord.media/ukraine-clai...
Ukraine claims cyberattacks on Russian election systems; Moscow confirms disruptions
Ukraine said it was responsible for disrupting websites related to Russian election infrastructure as voters went to the polls in occupied territories.
therecord.media
New report published today from our team at Recorded Future: “Russian Influence Assets Converge on Moldovan Elections” www.recordedfuture.com/research/rus...
Russian Influence Assets Converge on Moldovan Elections
Ahead of Moldova’s 2025 elections, Russia-linked influence operations seek to undermine EU integration, discredit President Sandu, and destabilize democratic processes through coordinated disinformati...
recordedfuture.com
This report on Stark Industries is a fantastic case study in the cat-and-mouse game between hosting providers and law enforcement. The new "Threat Activity Enabler" (TAE) terminology is spot-on and highlights the critical role these providers play in the cybercrime ecosystem.
1/ Today, we published “One Step Ahead: Stark Industries Solutions Preempts EU Sanctions,” revealing how hosting provider #StarkIndustries executed a multi-phase restructuring of its operations, beginning up to a month before #EU sanctions.
Scandi noir meets The Wire... 🇫🇮🚢 The captain of a Russia-linked oil tanker that damaged five subsea cables in the Baltic Sea on Christmas Day was instructed by his shipping company to destroy evidence after the ship was seized by Finnish authorities, according to a wiretap transcript.
Finnish police wiretap reveals Russian ‘shadow fleet’ captain instructed to destroy evidence
The captain of a Russia-linked oil tanker that damaged five subsea cables in the Baltic Sea was reportedly instructed to destroy evidence after the ship was seized by authorities.
therecord.media
Is it really 2025?! Cisco Smart Install and SNMP brute attacks... We are giving the FSB an easy ride. Great report by the Talos team! blog.talosintelligence.com/static-tundra/
Russian state-sponsored espionage group Static Tundra compromises unpatched end-of-life network devices
A Russian state-sponsored group, Static Tundra, is exploiting an old Cisco IOS vulnerability to compromise unpatched network devices worldwide, targeting key sectors for intelligence gathering.
blog.talosintelligence.com
Fantastic new report by @julianferdinand.bsky.social and @aejleslie.bsky.social exposing Lumma’s vast info-stealing ecosystem—where affiliates juggle scams, MaaS platforms, and evasion tools to stay ahead of defenders💪 Great work team 🔥
1/ Today, we release a first-of-its-kind analysis of a set of Lumma affiliates within a vast info-stealing ecosystem, showing their interconnectedness and resilience even after a major law enforcement takedown attempts earlier this year: www.recordedfuture.com/research/beh...
Saher's first blog on the scourge that is ClickFix usage in the espionage space!! Had to sneak in the UNK_RemoteRogue RDP shenanigans as well - a thus far unattributed group we assess to be Russia-aligned, using a pretty fun set of email tactics
My first blog with Proofpoint is live! And we love a good crossover. State-sponsored actors try their hand at ClickFix - the hottest thing in cybercrime. Meet the North Koreans, Iranians, and Russians who are upping their social engineering game www.proofpoint.com/us/blog/thre...
Attention! Check your Compromised Website Report for critical events tagged “fortinet-compromised” and follow Fortinet's mitigation advice on compromised devices: fortinet.com/blog/psirt-b... Data available from 2025-04-11+ shadowserver.org/what-we-do/n...
Snoop, a Romanian investigative journalism outlet, has linked an online advertising company named AdNow to intelligence officials from Russia's FSB and SVR services snoop.ro/pe-urmele-ba...
🪡 Our 2024 Malicious Infrastructure Report showcases the results of our detections across hundreds of malware families and threat actors, revealing victims in 200+ countries and highlighting the global scale of cyber threats. Blog: www.recordedfuture.com/research/202... (1/10)
@volexity.com recently identified multiple Russian threat actors targeting users via #socialengineering + #spearphishing campaigns with Microsoft 365 Device Code authentication (a well-known technique) with alarming success: www.volexity.com/blog/2025/02... #dfir #threatintel #m365security
Multiple Russian Threat Actors Targeting Microsoft Device Code Authentication
Starting in mid-January 2025, Volexity identified several social-engineering and spear-phishing campaigns by Russian threat actors aimed at compromising Microsoft 365 (M365) accounts. These attack cam...
volexity.com
New Insikt Report just landed: RedMike AKA Salt Typhoon targeting of Global Telcos. www.recordedfuture.com/research/red...
recordedfuture.com
🔥 Live streams resume this week! Greg Lesnewich joins us to talk about 100 Days of Yara, some Yara rule tips and the current state of email borne threats! https://buff.ly/4gukMSN 🗓️ Thursday at 2pm CST
100 Days of Yara, Yara Rule Tips and The Current State of Email borne Threats with Greg Lesnewich
Yara is one of the most versatile tools in cyber security. Come learn about creating effective and efficient rules with the creator of the 100 Days of Yara, ...
buff.ly
Ukrainian military officials, lawmakers, and experts are discussing the creation of a separate branch of Ukraine's Armed Forces dedicated to cyberspace operations, according to the General Staff of Ukraine. kyivindependent.com/ukraine-cons...
Ukrainian military considering creation of new cyber army branch
Ukrainian military, lawmakers, and experts discussed the creation of a separate branch of Ukraine's Armed Forces dedicated to cyberspace operations, the General Staff said on Oct. 24.
kyivindependent.com
New report! Check it out. This research examines the operations of Crazy Evil — a Russian-speaking “traffer team” and cryptoscam gang — which has victimized thousands of people with infostealer malware. Blog: www.recordedfuture.com/research/cra... PDF: go.recordedfuture.com/hubfs/report...
"Crazy Evil" Cryptoscam Gang: Unmasking a Global Threat in 2024
Explore how the "Crazy Evil" cryptoscam gang operates, infecting thousands worldwide with infostealer malware. Learn how its tactics pose a threat to the Web3 ecosystem and digital asset security.
recordedfuture.com
New Blog! Tracking Adversaries: Ghostwriter APT Infrastructure 🇧🇾 blog.bushidotoken.net/2025/01/trac...
Tracking Adversaries: Ghostwriter APT Infrastructure
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
blog.bushidotoken.net
UK domain giant Nominet confirms cybersecurity incident linked to Ivanti VPN hacks
UK domain giant Nominet confirms cybersecurity incident linked to Ivanti VPN hacks
Nominet, the U.K. domain registry that maintains .co.uk domains, has experienced a cybersecurity incident that it confirmed is linked to the recent exploitation of a new Ivanti VPN vulnerability. In an email to customers, seen by TechCrunch, Nominet…
tcrn.ch
New report! Check it out. This research examines the global proliferation of Russian surveillance technologies, their use by repressive governments, and possible data-sharing with Russian intelligence. Blog: www.recordedfuture.com/research/tra... PDF: go.recordedfuture.com/hubfs/report...
Unveiling Russian Surveillance Tech Expansion in Central Asia and Latin America
A new report by Recorded Future’s Insikt group finds that countries across Central Asia and Latin America are increasingly basing their digital surveillance practices on Russia's System for Operative ...
recordedfuture.com
Russia's 'Sovereign Runet' initiative aims to isolate its internet from the global web, posing significant challenges to the cybercrime underworld that thrives on international connectivity. #CyberSecurity #Runet www.cybercrimediaries.com/post/russia-...
Russia's Sovereign RuNet: A Challenge to the Cybercrime Underworld?
In this blog, we will explore the extent to which the legislative and technical evolutions of the RuNet have impacted the Russian-speaking..
cybercrimediaries.com
New report! Check it out. This research examines the role of Chinese international communication centers (ICCs) in amplifying propaganda via inauthentic social media activity, foreign influencers, and more. Blog: www.recordedfuture.com/research/bre... PDF: go.recordedfuture.com/hubfs/report...
China’s Propaganda Expansion: Inside the Rise of International Communication Centers (ICCs)
China's ICCs reshape global propaganda via targeted messaging, social media, and influence networks to amplify the Communist Party's voice globally.
recordedfuture.com
Great to be back at Cyber Threat for a third year. Awesome talks, great networking, and a very fresh and fun CTF. #cyberthreat24