#cybertoufan — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cybertoufan, aggregated by home.social.
-
Cyber Toufan appear to have got the hots for Microsoft. #ThreatIntel #cybertoufan
-
Cyber Toufan appear to have got the hots for Microsoft. #ThreatIntel #cybertoufan
-
Cyber Toufan posted a ceasefire message today, which they plan to respect.
They also claimed responsibility for wiping 200 SMBs in Israel just before the ceasefire.
I haven’t seen anything about that, but they have definitely wiped orgs before, eg they were behind the ESET Wiper.
-
Cyber Toufan posted a ceasefire message today, which they plan to respect.
They also claimed responsibility for wiping 200 SMBs in Israel just before the ceasefire.
I haven’t seen anything about that, but they have definitely wiped orgs before, eg they were behind the ESET Wiper.
-
Here's the fax translated to English, contains the usual death threats.
(Also, just below, not captured in the photo is a QR code which redirects to their Telegram channel)
-
Here's the fax translated to English, contains the usual death threats.
(Also, just below, not captured in the photo is a QR code which redirects to their Telegram channel)
-
Cyber Toufan launched a massive cyberattack* on Israel by sending 2500 faxes (yes, faxes) via an online website. I've verified Cyber Toufan sent them.
-
Cyber Toufan launched a massive cyberattack* on Israel by sending 2500 faxes (yes, faxes) via an online website. I've verified Cyber Toufan sent them.
-
Cyber Toufan’s “OpIsrael” for today’s anniversary was to post a gross video of Hamas killing people with a soundtrack.
They failed to actually do anything cyber, and lots of people smashed the clown emoji.
-
Cyber Toufan’s “OpIsrael” for today’s anniversary was to post a gross video of Hamas killing people with a soundtrack.
They failed to actually do anything cyber, and lots of people smashed the clown emoji.
-
Cyber Toufan just reappeared, first time since April. Earlier this year they wiped a bunch of Israeli org’s webservers and dumped info.
This time they say “OpIsrael” and 7 October.
-
Cyber Toufan just reappeared, first time since April. Earlier this year they wiped a bunch of Israeli org’s webservers and dumped info.
This time they say “OpIsrael” and 7 October.
-
R00TK1T Hacker Group Issues Warning to Nestle in Dark Web Post https://thecyberexpress.com/nestle-cyberattack-claims-r00tk1t/ #CyberattackonNestle #Nestlecyberattack #TheCyberExpress #FirewallDaily #DarkWebNews #CyberToufan #R00TK1T
-
Cyber Toufanwas finally added in the @misp MISP galaxy as a threat-actor.#threatintel #threatactors #cybertoufan #misp
Thanks to Mathieu Béligon for the recent contribution.
🔗 https://www.misp-galaxy.org/threat-actor/?h=cyber+toufan#cyber-toufan
🔗 if you want to contribute or update the thret-actor MISP galaxy https://github.com/MISP/misp-galaxy/blob/main/clusters/threat-actor.json -
Cyber Toufanwas finally added in the @misp MISP galaxy as a threat-actor.#threatintel #threatactors #cybertoufan #misp
Thanks to Mathieu Béligon for the recent contribution.
🔗 https://www.misp-galaxy.org/threat-actor/?h=cyber+toufan#cyber-toufan
🔗 if you want to contribute or update the thret-actor MISP galaxy https://github.com/MISP/misp-galaxy/blob/main/clusters/threat-actor.json -
2024 Goals: Don't be personally called out by a state-aligned hacking group for not changing passwords... #CyberToufan
-
2024 Goals: Don't be personally called out by a state-aligned hacking group for not changing passwords... #CyberToufan
-
Berkshire eSupply have filed a data breach notification in Maine: #cybertoufan #threatintel
-
Berkshire eSupply have filed a data breach notification in Maine: #cybertoufan #threatintel
-
The two above orgs are based in the United States.. it looks like #cybertoufan are wiping orgs in the US with connections to Israel. So far it is still restricted targeting though, i.e. they are doing their research.
I still think it’s interesting how asleep the cyber industry is on this - still zero AV detections on the scripts they’re using, tried them with a leading EDR and no rules triggered either.
-
The two above orgs are based in the United States.. it looks like #cybertoufan are wiping orgs in the US with connections to Israel. So far it is still restricted targeting though, i.e. they are doing their research.
I still think it’s interesting how asleep the cyber industry is on this - still zero AV detections on the scripts they’re using, tried them with a leading EDR and no rules triggered either.
-
Berkshire eSupply is also still offline: https://www.berkshireesupply.com #cybertoufan #threatintel
-
Berkshire eSupply is also still offline: https://www.berkshireesupply.com #cybertoufan #threatintel
-
Another update on Cyber Toufan tonight - they've emailed customers of pts-tools.com the following message.
More details here: https://doublepulsar.com/cyber-toufan-goes-oprah-mode-with-free-linux-system-wipes-of-over-100-organisations-eaf249b042dc
-
Another update on Cyber Toufan tonight - they've emailed customers of pts-tools.com the following message.
More details here: https://doublepulsar.com/cyber-toufan-goes-oprah-mode-with-free-linux-system-wipes-of-over-100-organisations-eaf249b042dc
-
-
-
Here’s the video Cyber Toufan posted last month of them accessing the Bitbucket source code repositories of Joomi - a Magento developer (online shopping stores).
The repositories are not public so somehow they got into Joomi.
-
Here’s the video Cyber Toufan posted last month of them accessing the Bitbucket source code repositories of Joomi - a Magento developer (online shopping stores).
The repositories are not public so somehow they got into Joomi.
-
I looked at every single org impacted last night when writing this, and could only find one that admitted a ‘cyber incident’ on their website - on a link buried on their website called ‘client update’.
I’ve seen a few orgs have tried to claim it is fake news to press to try to bury it. It is not fake news. #threatintel #cybertoufan
-
I looked at every single org impacted last night when writing this, and could only find one that admitted a ‘cyber incident’ on their website - on a link buried on their website called ‘client update’.
I’ve seen a few orgs have tried to claim it is fake news to press to try to bury it. It is not fake news. #threatintel #cybertoufan
-
I did a write up about Cyber Toufan - over 100 orgs breached and data dumped, including multiple cyber security vendors, about a third haven't been able to recover after being wiped. Includes TTPs, suggestions.
Customers of customers of customers of customers have been getting emails from threat actor, who are sending what are the first (?) lobbying emails from hack of a supply chain.
-
I did a write up about Cyber Toufan - over 100 orgs breached and data dumped, including multiple cyber security vendors, about a third haven't been able to recover after being wiped. Includes TTPs, suggestions.
Customers of customers of customers of customers have been getting emails from threat actor, who are sending what are the first (?) lobbying emails from hack of a supply chain.
-
The cybercriminals managed to access substantial amounts of confidential information from both companies and government agencies.
#Cybersecurity #IranianGroup #Israel #iran #DataBreach #CyberToufan
-
The cybercriminals managed to access substantial amounts of confidential information from both companies and government agencies.
#Cybersecurity #IranianGroup #Israel #iran #DataBreach #CyberToufan
-
Cyber Toufan have dumped a virtual server image of Israel’s State Payment Gateway online - ecom.gov.il #cybertoufan #threatintel
-
Cyber Toufan have dumped a virtual server image of Israel’s State Payment Gateway online - ecom.gov.il #cybertoufan #threatintel
-
Cyber Toufan have started emailing customers of cybersecurity vendors, asking them to boycott various vendors that operate in Israel.
#Cybertoufan are obtaining the information from the systems of 3 cyber vendors they have breached - Radware, Allot and Max Security. They’ve also dumped data from the vendors - some is spicy, eg revealing alleged western spy front companies. HT @jmeyer for email. #threatintel
-
Cyber Toufan have started emailing customers of cybersecurity vendors, asking them to boycott various vendors that operate in Israel.
#Cybertoufan are obtaining the information from the systems of 3 cyber vendors they have breached - Radware, Allot and Max Security. They’ve also dumped data from the vendors - some is spicy, eg revealing alleged western spy front companies. HT @jmeyer for email. #threatintel
-
Cyber Toufan claims they wiped the Israeli Security Authority in mid November, and that they still haven’t recovered. I just did some digging on this and it checks out. #CyberToufan #threatintel
-
Cyber Toufan claims they wiped the Israeli Security Authority in mid November, and that they still haven’t recovered. I just did some digging on this and it checks out. #CyberToufan #threatintel
-
Cyber Toufan claim to have breached Allot, who do middleware TLS interception appliances for ISPs and Five Eyes. #CyberToufan #threatintel
-
Cyber Toufan claim to have breached Allot, who do middleware TLS interception appliances for ISPs and Five Eyes. #CyberToufan #threatintel
-
I cannot stress enough that more organisations need to be paying attention to defending against Cyber Toufan if they have business interests in Israel, particularly security vendors.
They are not a lame DDoS group, nor are they doing financial extortion. They are wiping large numbers of organisations. I have spoken to a few of the named victims and they are still offline weeks later with limited recovery options as backups were erased.
-
I cannot stress enough that more organisations need to be paying attention to defending against Cyber Toufan if they have business interests in Israel, particularly security vendors.
They are not a lame DDoS group, nor are they doing financial extortion. They are wiping large numbers of organisations. I have spoken to a few of the named victims and they are still offline weeks later with limited recovery options as backups were erased.
-
#CyberToufan latest target is Dorot, some kind of ICS supplier #threatintel
-
#CyberToufan latest target is Dorot, some kind of ICS supplier #threatintel
-
Cyber Toufan continue to break into companies, they're incredibly well organised and disruptive.
Lots of orgs over the past few weeks. Latest is SpaceX. #CyberToufan #threatintel
-
Cyber Toufan continue to break into companies, they're incredibly well organised and disruptive.
Lots of orgs over the past few weeks. Latest is SpaceX. #CyberToufan #threatintel