home.social

#cozybear — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cozybear, aggregated by home.social.

  1. Happy Wednesday everyone!

    This resources has been popping up on my feed everywhere so I took a look at it and I see why! When he is not instructing the #SANS FOR589, Will Thomas is creating highly valuable resources like the Russian APT Tool Matrix.

    Will has taken the time to correlate the tools of Russian #APTs such as #CozyBear and #Sandworm and even supplied the aliases that go along with them as well. This is a great resource if you are an organization who is APT focused to prioritize your threat hunting! Thanks a ton Will!

    Enjoy and Happy Hunting!

    Russian APT Tool Matrix:
    github.com/BushidoUK/Russian-A

    Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #readoftheday #HappyHunting Cyborg Security, Now Part of Intel 471

  2. Splunk provides a detailed analysis of the tactics, techniques, and procedures (TTPs) employed by APT29 in the campaign targeting German political parties with the new WINELOADER backdoor. APT29, aka Midnight Blizzard and Cozy Bear, is publicly attributed to Russian Foreign Intelligence Service (SVR). IOC and Yara rules provided.🔗 splunk.com/en_us/blog/security

    #APT29 #MidnightBlizzard #CozyBear #threatintel #WINELOADER #threatintel #IOC #Russia #cyberespionage

  3. Splunk provides a detailed analysis of the tactics, techniques, and procedures (TTPs) employed by APT29 in the campaign targeting German political parties with the new WINELOADER backdoor. APT29, aka Midnight Blizzard and Cozy Bear, is publicly attributed to Russian Foreign Intelligence Service (SVR). IOC and Yara rules provided.🔗 splunk.com/en_us/blog/security

    #APT29 #MidnightBlizzard #CozyBear #threatintel #WINELOADER #threatintel #IOC #Russia #cyberespionage

  4. Splunk provides a detailed analysis of the tactics, techniques, and procedures (TTPs) employed by APT29 in the campaign targeting German political parties with the new WINELOADER backdoor. APT29, aka Midnight Blizzard and Cozy Bear, is publicly attributed to Russian Foreign Intelligence Service (SVR). IOC and Yara rules provided.🔗 splunk.com/en_us/blog/security

    #APT29 #MidnightBlizzard #CozyBear #threatintel #WINELOADER #threatintel #IOC #Russia #cyberespionage

  5. Splunk provides a detailed analysis of the tactics, techniques, and procedures (TTPs) employed by APT29 in the campaign targeting German political parties with the new WINELOADER backdoor. APT29, aka Midnight Blizzard and Cozy Bear, is publicly attributed to Russian Foreign Intelligence Service (SVR). IOC and Yara rules provided.🔗 splunk.com/en_us/blog/security

    #APT29 #MidnightBlizzard #CozyBear #threatintel #WINELOADER #threatintel #IOC #Russia #cyberespionage

  6. Splunk provides a detailed analysis of the tactics, techniques, and procedures (TTPs) employed by APT29 in the campaign targeting German political parties with the new WINELOADER backdoor. APT29, aka Midnight Blizzard and Cozy Bear, is publicly attributed to Russian Foreign Intelligence Service (SVR). IOC and Yara rules provided.🔗 splunk.com/en_us/blog/security

    #APT29 #MidnightBlizzard #CozyBear #threatintel #WINELOADER #threatintel #IOC #Russia #cyberespionage

  7. #Microsoft has been #pwned for two times in the last six month. Does it change anything?

    Ars Technica: Microsoft finally explains cause of Azure breach: An engineer’s account was hacked.

    Last year #Azure was pwned by #Storm-0558, „a china-based threat actor with activities and methods consistent with espionage objectives.“


    CNN: Russian hackers breached key Microsoft systems.

    And now they are still pwned by #CozyBear, „russian state-backed hackers“. Does anybody care about this?

    We really need to push forward our open source ressources.

    #opensource
  8. #Microsoft has been #pwned for two times in the last six month. Does it change anything?

    Ars Technica: Microsoft finally explains cause of Azure breach: An engineer’s account was hacked.

    Last year #Azure was pwned by #Storm-0558, „a china-based threat actor with activities and methods consistent with espionage objectives.“


    CNN: Russian hackers breached key Microsoft systems.

    And now they are still pwned by #CozyBear, „russian state-backed hackers“. Does anybody care about this?

    We really need to push forward our open source ressources.

    #opensource
  9. #Microsoft has been #pwned for two times in the last six month. Does it change anything?

    Ars Technica: Microsoft finally explains cause of Azure breach: An engineer’s account was hacked.

    Last year #Azure was pwned by #Storm-0558, „a china-based threat actor with activities and methods consistent with espionage objectives.“


    CNN: Russian hackers breached key Microsoft systems.

    And now they are still pwned by #CozyBear, „russian state-backed hackers“. Does anybody care about this?

    We really need to push forward our open source ressources.

    #opensource
  10. #Microsoft has been #pwned for two times in the last six month. Does it change anything?

    Ars Technica: Microsoft finally explains cause of Azure breach: An engineer’s account was hacked.

    Last year #Azure was pwned by #Storm-0558, „a china-based threat actor with activities and methods consistent with espionage objectives.“


    CNN: Russian hackers breached key Microsoft systems.

    And now they are still pwned by #CozyBear, „russian state-backed hackers“. Does anybody care about this?

    We really need to push forward our open source ressources.

    #opensource
  11. #Microsoft has been #pwned for two times in the last six month. Does it change anything?

    Ars Technica: Microsoft finally explains cause of Azure breach: An engineer’s account was hacked.

    Last year #Azure was pwned by #Storm-0558, „a china-based threat actor with activities and methods consistent with espionage objectives.“


    CNN: Russian hackers breached key Microsoft systems.

    And now they are still pwned by #CozyBear, „russian state-backed hackers“. Does anybody care about this?

    We really need to push forward our open source ressources.

    #opensource