home.social

#dga — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #dga, aggregated by home.social.

  1. Two of the biggest heavyweight scam TTPs - malvertising and pig butchering - have combined. In our latest research, we track hundreds of investment‑scam campaigns using this one-two punch to target Japan and the wider Asia region.

    The hybrid approach kicks-off with malvertising ads that impersonate well‑known financial experts, funnel victims through lure sites on RDGA‑generated domains, before finally pulling them into messaging chats run by tireless AI‑style pig butcher bots. The result: an industrial‑scale long con, with individual victims reporting losses of up to ¥10M (~US$63k).

    This model is reused across different campaigns and, by pivoting on DNS, we've so far been able to map out an ecosystem of over 23,000 domains.

    In our latest blog we talk about our first‑hand experience going through the scheme, break down the entire flow, and share all the related IOCs: blogs.infoblox.com/threat-inte

    #Infoblox #InfobloxThreatIntel #dns #threatintel #threatintelligence #malvertising #pigbutchering #rdga #dga #lookalikes #crypto #investment #scam #fraud #cybercrime #cybersecurity #infosec #Japan #Asia #AI

  2. 🎯 Threat Intelligence
    ===================

    Executive summary: SafeBreach Labs' recent research documents renewed and sustained operations by the Iranian state-aligned actor known as Prince of Persia (aka Infy). The report identifies multiple concurrent campaigns using diverse malware variants and C2 infrastructures, with activity observed as recently as December 2025.

    Technical details: The investigation catalogs at least three active variants across the Foudre and Tonnerre families. Notable samples include Foudre v34, Tonnerre v17 (dual-stage DGA), and Tonnerre v50 (unknown DGA). Earlier Tonnerre releases (v12–v16) employed a CRC32-based DGA. Operators also deployed additional components labeled Amaq News Finder, Deep Freeze variants, new MaxPinner builds focused on Telegram content espionage, and an unknown family named Ru.

    Attack mechanics and infrastructure: Multiple campaigns used numerous C2 servers and DGAs in parallel. A distinct operational change was observed with Tonnerre v50: C2 redirection to a Telegram group named سرافراز (sarafraz) and an associated Telegram account @ehsan8999100. The Telegram presence appears to include a bot that likely leverages the Telegram API for command-and-control and exfiltration, replacing prior FTP-based exfiltration techniques.

    Analysis: The actor demonstrates improved operational security and tooling evolution since earlier public reports. Parallel DGA variants and modular families suggest an ability to maintain resilient C2 and flexible exfiltration channels. Use of mainstream messaging platforms for C2/exfiltration indicates an operational shift aimed at blending with legitimate traffic.

    Detection guidance: Monitor for indicators tied to Foudre v34, Tonnerre v17 and v50, and network connections to known C2 hosts and Telegram endpoints associated with the reported group. Look for behavior consistent with multi-stage DGA domain resolution and anomalous outbound traffic to Telegram API endpoints from non-standard hosts.

    Limitations: IoCs and full sample lists are provided in the original appendix; some DGA algorithms (Tonnerre v50) remain unidentified in public reporting. Attribution details include likely Iranian operators but are based on telemetry and actor tooling overlap described by SafeBreach.

    🔹 PrinceOfPersia #Foudre #Tonnerre #DGA #Telegram

    🔗 Source: safebreach.com/blog/prince-of-

  3. Ik zie steeds vaker dit soort van voorwaarden voor opdrachten:

    Toegestane inzetvorm:
    - Medewerker in dienst van leverancier: Ja
    - Leverancier die een zelfstandig #professional doorleent: Nee
    - #DGA: Nee
    - #ZZP: Nee
    - #DUBV: Verschilt per opdracht
    - #Midlance: Ja
    - #Payrolling: Ja

    Dit gaat bijvoorbeeld over een #opdracht bij de #overheid.

    Door dit soort voorwaarden #schijnonzelfstandigheid gepromoot. Een #zelfstandige doet net of hij ergens in dienst is.

    #WetDBA #eenmanszaak #DBA #belasting

  4. #JournéeRGPD sur la conformité dans un paysage juridique en mouvement le 24 juin au #Cnam !

    📝 D'un cas pratique en intelligence artificielle #IA, aux défis posés par l'avalanche de textes (#DSA #DA #RIA #DGA #NIS2), en passant par la #certification et les outils de l'ANSSI, la journée s'annonce riche en débats, réflexions et apprentissages !

    🔗 Inscriptions gratuites mais obligatoires :
    forms.information.cnil.fr/603c

  5. Hey Hollywood! Hey Actors! Hey Producers and Writers!

    Exxon just took your stuff and home. Ruined your world, and they're paying rapists to lie about it.

    Thats as true as anything ever written. As solid as a rock.

    What are you going to do about it?

    Exxon and the oil cons aren't done burning your world.

    What are you going to do about it?


  6. Hey Hollywood! Hey Actors! Hey Producers and Writers!

    Exxon just took your stuff and home. Ruined your world, and they're paying rapists to lie about it.

    Thats as true as anything ever written. As solid as a rock.

    What are you going to do about it?

    Exxon and the oil cons aren't done burning your world.

    What are you going to do about it?

    #SAG #AFTRA #ACTRA #WGA #DGA #Hollywood #LAFires #California
    #Hindlegs #BigGirlPants #BigBoyPants

  7. Hey Hollywood! Hey Actors! Hey Producers and Writers!

    Exxon just took your stuff and home. Ruined your world, and they're paying rapists to lie about it.

    Thats as true as anything ever written. As solid as a rock.

    What are you going to do about it?

    Exxon and the oil cons aren't done burning your world.

    What are you going to do about it?

    #SAG #AFTRA #ACTRA #WGA #DGA #Hollywood #LAFires #California
    #Hindlegs #BigGirlPants #BigBoyPants

  8. Hey Hollywood! Hey Actors! Hey Producers and Writers!

    Exxon just took your stuff and home. Ruined your world, and they're paying rapists to lie about it.

    Thats as true as anything ever written. As solid as a rock.

    What are you going to do about it?

    Exxon and the oil cons aren't done burning your world.

    What are you going to do about it?

    #SAG #AFTRA #ACTRA #WGA #DGA #Hollywood #LAFires #California
    #Hindlegs #BigGirlPants #BigBoyPants

  9. "
    ArianeGroup: Erfolgreicher Testflug für die M51.3 Rakete

    Am 18. November 2023 führten ArianeGroup und die französische Wehrbeschaffungsbehörde (DGA) den ersten erfolgreichen Flugtest einer M51.3 Rakete von der ballistischen Startbasis (BLB) in Biscarrosse im Südwesten Frankreichs aus durch. Eine Pressemitteilung der ArianeGroup.
    "
    raumfahrer.net/arianegroup-erf

    19.11.2023

    #ArianeGroup #Biscarrosse #BLB #DGA #Frankreich #M51 #Militär #Rakete #SLBM