home.social

#irontiger — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #irontiger, aggregated by home.social.

  1. The slides botconf.eu/wp-content/uploads/ and video youtube.com/watch?v=713CsmcNE3 of my #Botconf talk about #IronTiger TTPs are online. I discuss recent infection vectors (including a supply chain attack), the evolution of their malware toolkit and targeting, and explain how we attributed these campaigns to #IronTiger #APT27 #APT threat actor

  2. The slides botconf.eu/wp-content/uploads/ and video youtube.com/watch?v=713CsmcNE3 of my #Botconf talk about #IronTiger TTPs are online. I discuss recent infection vectors (including a supply chain attack), the evolution of their malware toolkit and targeting, and explain how we attributed these campaigns to #IronTiger #APT27 #APT threat actor

  3. The slides botconf.eu/wp-content/uploads/ and video youtube.com/watch?v=713CsmcNE3 of my #Botconf talk about #IronTiger TTPs are online. I discuss recent infection vectors (including a supply chain attack), the evolution of their malware toolkit and targeting, and explain how we attributed these campaigns to #IronTiger #APT27 #APT threat actor

  4. The slides botconf.eu/wp-content/uploads/ and video youtube.com/watch?v=713CsmcNE3 of my #Botconf talk about #IronTiger TTPs are online. I discuss recent infection vectors (including a supply chain attack), the evolution of their malware toolkit and targeting, and explain how we attributed these campaigns to #IronTiger #APT27 #APT threat actor

  5. The slides botconf.eu/wp-content/uploads/ and video youtube.com/watch?v=713CsmcNE3 of my #Botconf talk about #IronTiger TTPs are online. I discuss recent infection vectors (including a supply chain attack), the evolution of their malware toolkit and targeting, and explain how we attributed these campaigns to #IronTiger #APT27 #APT threat actor

  6. My latest #APT research on #IronTiger (#APT27/#EmissaryPanda/#LuckyMouse) is out ! It includes analysis of a new version of SysUpdate ported to Linux, a new communication protocol through DNS TXT requests, a VMProtect certificate compromise, and probable infection vector trendmicro.com/en_us/research/

  7. My latest #APT research on #IronTiger (#APT27/#EmissaryPanda/#LuckyMouse) is out ! It includes analysis of a new version of SysUpdate ported to Linux, a new communication protocol through DNS TXT requests, a VMProtect certificate compromise, and probable infection vector trendmicro.com/en_us/research/

  8. My latest #APT research on #IronTiger (#APT27/#EmissaryPanda/#LuckyMouse) is out ! It includes analysis of a new version of SysUpdate ported to Linux, a new communication protocol through DNS TXT requests, a VMProtect certificate compromise, and probable infection vector trendmicro.com/en_us/research/

  9. My latest #APT research on #IronTiger (#APT27/#EmissaryPanda/#LuckyMouse) is out ! It includes analysis of a new version of SysUpdate ported to Linux, a new communication protocol through DNS TXT requests, a VMProtect certificate compromise, and probable infection vector trendmicro.com/en_us/research/

  10. My latest #APT research on #IronTiger (#APT27/#EmissaryPanda/#LuckyMouse) is out ! It includes analysis of a new version of SysUpdate ported to Linux, a new communication protocol through DNS TXT requests, a VMProtect certificate compromise, and probable infection vector trendmicro.com/en_us/research/

  11. #introduction I have been working on targeted attacks for a long time now, first as an incident responder, and now doing threat intelligence at Trend Micro.
    I usually focus for a while on a threat actor, and when I feel I know enough, publish something about it. The fun part is that very often, while investigating a threat actor, you end up finding stuff on another one, which you can add to your TODO list once the current investigation is completed :)
    BTW, this is a good reason to be careful with the attribution out there, infrastructure overlap and tool sharing are common stuff nowadays.

    Some of my previous work on #APT groups:

    #Patchwork:
    trendmicro.com/en_us/research/
    #Confucius:
    trendmicro.com/fr_fr/research/
    trendmicro.com/en_us/research/
    #UrPage/#Bahamut:
    trendmicro.com/en_us/research/
    A bit of all previous actors:
    first.org/resources/papers/tal

    #MuddyWater:
    trendmicro.com/en_us/research/
    documents.trendmicro.com/asset

    Maybe APT37 (unconfirmed):
    trendmicro.com/en_us/research/

    #EarthAkhlut/#Tonto:
    vb2020.vblocalhost.com/uploads
    Operation DRBControl:
    trendmicro.com/vinfo/us/securi
    #EarthBerberoka:
    trendmicro.com/en_us/research/
    trendmicro.com/vinfo/us/securi
    #IronTiger/#EarthSmilodon:
    trendmicro.com/en_no/research/
    trendmicro.com/en_us/research/

  12. #introduction I have been working on targeted attacks for a long time now, first as an incident responder, and now doing threat intelligence at Trend Micro.
    I usually focus for a while on a threat actor, and when I feel I know enough, publish something about it. The fun part is that very often, while investigating a threat actor, you end up finding stuff on another one, which you can add to your TODO list once the current investigation is completed :)
    BTW, this is a good reason to be careful with the attribution out there, infrastructure overlap and tool sharing are common stuff nowadays.

    Some of my previous work on #APT groups:

    #Patchwork:
    trendmicro.com/en_us/research/
    #Confucius:
    trendmicro.com/fr_fr/research/
    trendmicro.com/en_us/research/
    #UrPage/#Bahamut:
    trendmicro.com/en_us/research/
    A bit of all previous actors:
    first.org/resources/papers/tal

    #MuddyWater:
    trendmicro.com/en_us/research/
    documents.trendmicro.com/asset

    Maybe APT37 (unconfirmed):
    trendmicro.com/en_us/research/

    #EarthAkhlut/#Tonto:
    vb2020.vblocalhost.com/uploads
    Operation DRBControl:
    trendmicro.com/vinfo/us/securi
    #EarthBerberoka:
    trendmicro.com/en_us/research/
    trendmicro.com/vinfo/us/securi
    #IronTiger/#EarthSmilodon:
    trendmicro.com/en_no/research/
    trendmicro.com/en_us/research/

  13. #introduction I have been working on targeted attacks for a long time now, first as an incident responder, and now doing threat intelligence at Trend Micro.
    I usually focus for a while on a threat actor, and when I feel I know enough, publish something about it. The fun part is that very often, while investigating a threat actor, you end up finding stuff on another one, which you can add to your TODO list once the current investigation is completed :)
    BTW, this is a good reason to be careful with the attribution out there, infrastructure overlap and tool sharing are common stuff nowadays.

    Some of my previous work on #APT groups:

    #Patchwork:
    trendmicro.com/en_us/research/
    #Confucius:
    trendmicro.com/fr_fr/research/
    trendmicro.com/en_us/research/
    #UrPage/#Bahamut:
    trendmicro.com/en_us/research/
    A bit of all previous actors:
    first.org/resources/papers/tal

    #MuddyWater:
    trendmicro.com/en_us/research/
    documents.trendmicro.com/asset

    Maybe APT37 (unconfirmed):
    trendmicro.com/en_us/research/

    #EarthAkhlut/#Tonto:
    vb2020.vblocalhost.com/uploads
    Operation DRBControl:
    trendmicro.com/vinfo/us/securi
    #EarthBerberoka:
    trendmicro.com/en_us/research/
    trendmicro.com/vinfo/us/securi
    #IronTiger/#EarthSmilodon:
    trendmicro.com/en_no/research/
    trendmicro.com/en_us/research/

  14. #introduction I have been working on targeted attacks for a long time now, first as an incident responder, and now doing threat intelligence at Trend Micro.
    I usually focus for a while on a threat actor, and when I feel I know enough, publish something about it. The fun part is that very often, while investigating a threat actor, you end up finding stuff on another one, which you can add to your TODO list once the current investigation is completed :)
    BTW, this is a good reason to be careful with the attribution out there, infrastructure overlap and tool sharing are common stuff nowadays.

    Some of my previous work on #APT groups:

    #Patchwork:
    trendmicro.com/en_us/research/
    #Confucius:
    trendmicro.com/fr_fr/research/
    trendmicro.com/en_us/research/
    #UrPage/#Bahamut:
    trendmicro.com/en_us/research/
    A bit of all previous actors:
    first.org/resources/papers/tal

    #MuddyWater:
    trendmicro.com/en_us/research/
    documents.trendmicro.com/asset

    Maybe APT37 (unconfirmed):
    trendmicro.com/en_us/research/

    #EarthAkhlut/#Tonto:
    vb2020.vblocalhost.com/uploads
    Operation DRBControl:
    trendmicro.com/vinfo/us/securi
    #EarthBerberoka:
    trendmicro.com/en_us/research/
    trendmicro.com/vinfo/us/securi
    #IronTiger/#EarthSmilodon:
    trendmicro.com/en_no/research/
    trendmicro.com/en_us/research/

  15. #introduction I have been working on targeted attacks for a long time now, first as an incident responder, and now doing threat intelligence at Trend Micro.
    I usually focus for a while on a threat actor, and when I feel I know enough, publish something about it. The fun part is that very often, while investigating a threat actor, you end up finding stuff on another one, which you can add to your TODO list once the current investigation is completed :)
    BTW, this is a good reason to be careful with the attribution out there, infrastructure overlap and tool sharing are common stuff nowadays.

    Some of my previous work on #APT groups:

    #Patchwork:
    trendmicro.com/en_us/research/
    #Confucius:
    trendmicro.com/fr_fr/research/
    trendmicro.com/en_us/research/
    #UrPage/#Bahamut:
    trendmicro.com/en_us/research/
    A bit of all previous actors:
    first.org/resources/papers/tal

    #MuddyWater:
    trendmicro.com/en_us/research/
    documents.trendmicro.com/asset

    Maybe APT37 (unconfirmed):
    trendmicro.com/en_us/research/

    #EarthAkhlut/#Tonto:
    vb2020.vblocalhost.com/uploads
    Operation DRBControl:
    trendmicro.com/vinfo/us/securi
    #EarthBerberoka:
    trendmicro.com/en_us/research/
    trendmicro.com/vinfo/us/securi
    #IronTiger/#EarthSmilodon:
    trendmicro.com/en_no/research/
    trendmicro.com/en_us/research/