#mimic — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #mimic, aggregated by home.social.
-
Flux 3 X Mimic: The Next Generation of Video-Action Models
https://bfl.ai/blog/flux-3-mimic
Comments: https://news.ycombinator.com/item?id=49033127
#HackerNews #Flux3 #Mimic #VideoAction #Models #NextGen #AI #Technology
-
Flux 3 X Mimic: The Next Generation of Video-Action Models
https://bfl.ai/blog/flux-3-mimic
Comments: https://news.ycombinator.com/item?id=49033127
#HackerNews #Flux3 #Mimic #VideoAction #Models #NextGen #AI #Technology
-
Inside a Global Procurement-Themed AiTM Phishing Campaign
A sophisticated adversary-in-the-middle phishing campaign is targeting universities, enterprises, and multinational institutions including EU and UN agencies. Active since May 2026, the operation leverages compromised organizational email accounts to distribute procurement-themed lures that mimic requests for information, bid invitations, and project documentation. Victims are redirected through fake document portals, CAPTCHA verification stages, and cloned authentication pages impersonating Microsoft, OpenGov, and financial institutions. The attacker rotates between multiple AiTM phishing kits including EvilProxy, FlowerStorm, and Kali365 to intercept MFA-protected sessions in real time, capturing session tokens and cookies to establish authenticated access. Rather than using newly registered domains, the actor compromises aged domains that have been dormant for years, injecting PHP files to host phishing infrastructure and evade detection through domain reputation systems.
Pulse ID: 6a6015d87a94549d768bc929
Pulse Link: https://otx.alienvault.com/pulse/6a6015d87a94549d768bc929
Pulse Author: AlienVault
Created: 2026-07-22 00:59:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #AitM #CAPTCHA #Cookies #CyberSecurity #EU #Email #InfoSec #MFA #Microsoft #Mimic #OTX #OpenThreatExchange #PHP #Phishing #Proxy #RAT #RCE #bot #AlienVault
-
Inside a Global Procurement-Themed AiTM Phishing Campaign
A sophisticated adversary-in-the-middle phishing campaign is targeting universities, enterprises, and multinational institutions including EU and UN agencies. Active since May 2026, the operation leverages compromised organizational email accounts to distribute procurement-themed lures that mimic requests for information, bid invitations, and project documentation. Victims are redirected through fake document portals, CAPTCHA verification stages, and cloned authentication pages impersonating Microsoft, OpenGov, and financial institutions. The attacker rotates between multiple AiTM phishing kits including EvilProxy, FlowerStorm, and Kali365 to intercept MFA-protected sessions in real time, capturing session tokens and cookies to establish authenticated access. Rather than using newly registered domains, the actor compromises aged domains that have been dormant for years, injecting PHP files to host phishing infrastructure and evade detection through domain reputation systems.
Pulse ID: 6a6015d87a94549d768bc929
Pulse Link: https://otx.alienvault.com/pulse/6a6015d87a94549d768bc929
Pulse Author: AlienVault
Created: 2026-07-22 00:59:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #AitM #CAPTCHA #Cookies #CyberSecurity #EU #Email #InfoSec #MFA #Microsoft #Mimic #OTX #OpenThreatExchange #PHP #Phishing #Proxy #RAT #RCE #bot #AlienVault
-
CW: Adult content
wanders into a dungeon and immediately falls victim to a mimic
#myart #purityknight #mimic #tentacles -
Our {definitely-not-a-Mimic} Chest E. Cognito hopes you know the annual Board Game Flea market at Critical Hit in Cleveland Heights* is happening right now!
Chesty assures us if you get a used board game and open the box it's fun for all (and definitely not a trap)! However, the air quality in northern Ohio might be so please make sure to watch yourselves and take precautions when you go out.
*This post is not sponsored by Critical Hit. They are are a community asset and supportive of many geeky groups in the Cleveland area. They are also friends of the troupe and one of their founders had previously been a Player of the Patchwork!
Find Critical Hit at 13433 Cedar Road, Cleveland Heights, Ohio 44118 or online.
#Theater #Improv #Improvisation #Commedia #CommediaDellArte #Mimic #DnD #DungeonsAndDragons #BoardGames #Gaming #CriticalHit #CriticalHitGames #BoardGameFleaMarket2026 #ShopSmall #FLGS #ClevelandHeights
-
Our {definitely-not-a-Mimic} Chest E. Cognito hopes you know the annual Board Game Flea market at Critical Hit in Cleveland Heights* is happening right now!
Chesty assures us if you get a used board game and open the box it's fun for all (and definitely not a trap)! However, the air quality in northern Ohio might be so please make sure to watch yourselves and take precautions when you go out.
*This post is not sponsored by Critical Hit. They are are a community asset and supportive of many geeky groups in the Cleveland area. They are also friends of the troupe and one of their founders had previously been a Player of the Patchwork!
Find Critical Hit at 13433 Cedar Road, Cleveland Heights, Ohio 44118 or online.
#Theater #Improv #Improvisation #Commedia #CommediaDellArte #Mimic #DnD #DungeonsAndDragons #BoardGames #Gaming #CriticalHit #CriticalHitGames #BoardGameFleaMarket2026 #ShopSmall #FLGS #ClevelandHeights
-
Operation Fake KickOff: Attackers Abuse Recruiters and SaaS to Harvest Work Credentials
A sophisticated multi-stage phishing operation has been active since April 2025, systematically exploiting legitimate SaaS platforms and cloud services to steal corporate credentials. The campaign utilizes 232 phishing domains and 80 command-and-control servers, primarily impersonating human resources consulting firms, with Robert Half Inc. and Aquent LLC representing 50% of targeted brands. Attackers leverage legitimate platforms like Salesforce, SendGrid, and Zoho for email delivery, directing victims to fake Calendly interview pages that mimic real recruiter identities. The operation deploys an adversary-in-the-middle toolkit using browser-in-the-box techniques to create replica Google sign-in pages, capable of harvesting credentials and bypassing MFA through email, SMS, Google Authenticator, and prompt notifications. The campaign specifically targets corporate email accounts, filtering out personal providers, with stolen data exfiltrated to Render-hosted servers and Telegram bots.
Pulse ID: 6a57f26f4f7b83bede7d73d8
Pulse Link: https://otx.alienvault.com/pulse/6a57f26f4f7b83bede7d73d8
Pulse Author: AlienVault
Created: 2026-07-15 20:49:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #Browser #Cloud #CyberSecurity #Email #Google #InfoSec #MFA #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RCE #SMS #Telegram #bot #AlienVault
-
Fake crypto scams try to piggyback off SpaceX IPO
Scammers are exploiting public interest in the SpaceX IPO through fraudulent investment portals impersonating SpaceX, Elon Musk, and major financial brands including Fidelity and Robinhood. The campaign uses themed domains to lure victims into fake onboarding processes that mimic legitimate investment procedures, including W-8BEN tax forms for non-U.S. investors. Victims are asked to select investment tiers and ultimately directed to deposit funds via cryptocurrency wallets for Bitcoin, Ethereum, and USDT. The operation mirrors techniques used by threat actor TA2730 but focuses on direct cryptocurrency theft rather than credential harvesting. One Bitcoin wallet associated with the campaign received approximately $8,700. The infrastructure includes randomized domains and SpaceX-themed domains designed to appear legitimate during the investment process.
Pulse ID: 6a57f270713faa71010c16ad
Pulse Link: https://otx.alienvault.com/pulse/6a57f270713faa71010c16ad
Pulse Author: AlienVault
Created: 2026-07-15 20:49:52Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BitCoin #CredentialHarvesting #CyberSecurity #InfoSec #Mimic #OTX #OpenThreatExchange #RAT #RobinHood #bot #cryptocurrency #AlienVault
-
Operation Fake KickOff: Attackers Abuse Recruiters and SaaS to Harvest Work Credentials
A sophisticated multi-stage phishing operation has been active since April 2025, systematically exploiting legitimate SaaS platforms and cloud services to steal corporate credentials. The campaign utilizes 232 phishing domains and 80 command-and-control servers, primarily impersonating human resources consulting firms, with Robert Half Inc. and Aquent LLC representing 50% of targeted brands. Attackers leverage legitimate platforms like Salesforce, SendGrid, and Zoho for email delivery, directing victims to fake Calendly interview pages that mimic real recruiter identities. The operation deploys an adversary-in-the-middle toolkit using browser-in-the-box techniques to create replica Google sign-in pages, capable of harvesting credentials and bypassing MFA through email, SMS, Google Authenticator, and prompt notifications. The campaign specifically targets corporate email accounts, filtering out personal providers, with stolen data exfiltrated to Render-hosted servers and Telegram bots.
Pulse ID: 6a57f26f4f7b83bede7d73d8
Pulse Link: https://otx.alienvault.com/pulse/6a57f26f4f7b83bede7d73d8
Pulse Author: AlienVault
Created: 2026-07-15 20:49:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #Browser #Cloud #CyberSecurity #Email #Google #InfoSec #MFA #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RCE #SMS #Telegram #bot #AlienVault
-
Fake crypto scams try to piggyback off SpaceX IPO
Scammers are exploiting public interest in the SpaceX IPO through fraudulent investment portals impersonating SpaceX, Elon Musk, and major financial brands including Fidelity and Robinhood. The campaign uses themed domains to lure victims into fake onboarding processes that mimic legitimate investment procedures, including W-8BEN tax forms for non-U.S. investors. Victims are asked to select investment tiers and ultimately directed to deposit funds via cryptocurrency wallets for Bitcoin, Ethereum, and USDT. The operation mirrors techniques used by threat actor TA2730 but focuses on direct cryptocurrency theft rather than credential harvesting. One Bitcoin wallet associated with the campaign received approximately $8,700. The infrastructure includes randomized domains and SpaceX-themed domains designed to appear legitimate during the investment process.
Pulse ID: 6a57f270713faa71010c16ad
Pulse Link: https://otx.alienvault.com/pulse/6a57f270713faa71010c16ad
Pulse Author: AlienVault
Created: 2026-07-15 20:49:52Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BitCoin #CredentialHarvesting #CyberSecurity #InfoSec #Mimic #OTX #OpenThreatExchange #RAT #RobinHood #bot #cryptocurrency #AlienVault
-
Tomorrowland 2026, Belgium: People of Tomorrow, Targets of Today
Tomorrowland Belgium 2026, spanning two weekends in July at De Schorre in Boom, sold out rapidly, creating opportunities for cybercriminals. Investigation uncovered approximately a dozen fraudulent websites impersonating the festival brand to target ticket seekers and travellers. These scams include fake ticket shops mimicking official sales with countdown timers and fraudulent biometric checks, travel sites offering bogus accommodation and transport packages, and affiliate schemes. The operations harvest complete identity data, payment credentials, and personal information through sophisticated social engineering. Victims lose money with no recourse, face identity theft risks, and ultimately receive invalid or non-existent tickets. The scammers exploit high demand, tight supply, and rushed purchasing decisions, with sites registered weeks in advance and pushed hardest when official tickets are sold out.
Pulse ID: 6a55e306b92e2ed9438ab45f
Pulse Link: https://otx.alienvault.com/pulse/6a55e306b92e2ed9438ab45f
Pulse Author: AlienVault
Created: 2026-07-14 07:19:34Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Biometric #CyberSecurity #InfoSec #Mimic #OTX #OpenThreatExchange #RAT #SocialEngineering #bot #AlienVault
-
Tomorrowland 2026, Belgium: People of Tomorrow, Targets of Today
Tomorrowland Belgium 2026, spanning two weekends in July at De Schorre in Boom, sold out rapidly, creating opportunities for cybercriminals. Investigation uncovered approximately a dozen fraudulent websites impersonating the festival brand to target ticket seekers and travellers. These scams include fake ticket shops mimicking official sales with countdown timers and fraudulent biometric checks, travel sites offering bogus accommodation and transport packages, and affiliate schemes. The operations harvest complete identity data, payment credentials, and personal information through sophisticated social engineering. Victims lose money with no recourse, face identity theft risks, and ultimately receive invalid or non-existent tickets. The scammers exploit high demand, tight supply, and rushed purchasing decisions, with sites registered weeks in advance and pushed hardest when official tickets are sold out.
Pulse ID: 6a55e306b92e2ed9438ab45f
Pulse Link: https://otx.alienvault.com/pulse/6a55e306b92e2ed9438ab45f
Pulse Author: AlienVault
Created: 2026-07-14 07:19:34Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Biometric #CyberSecurity #InfoSec #Mimic #OTX #OpenThreatExchange #RAT #SocialEngineering #bot #AlienVault
-
Today is Embrace Your Geekness Day! But maybe that's everyday when you're in a troupe like The Confused Greenies of Players' Patchwork Theatre Company when you not only do historic Renaissance commedia dell'arte but also parodies of sci-fi, anime, steampunk, fantasy, horror, gaming, and more?
"Being a geek is all about being honest about what you enjoy and not being afraid to demonstrate that affection." --Simon Pegg
#MondayMotivation: July 13, 2026 Embrace Your Geekness Day
#CommediaDellArte #Commedia #Improv #Improvisation #Theater #Comedy #Mask #Dice #D20 #Fantasy #DnD #DungeonsAndDragons #Mimic #Geek
-
Today is Embrace Your Geekness Day! But maybe that's everyday when you're in a troupe like The Confused Greenies of Players' Patchwork Theatre Company when you not only do historic Renaissance commedia dell'arte but also parodies of sci-fi, anime, steampunk, fantasy, horror, gaming, and more?
"Being a geek is all about being honest about what you enjoy and not being afraid to demonstrate that affection." --Simon Pegg
#MondayMotivation: July 13, 2026 Embrace Your Geekness Day
#CommediaDellArte #Commedia #Improv #Improvisation #Theater #Comedy #Mask #Dice #D20 #Fantasy #DnD #DungeonsAndDragons #Mimic #Geek
-
Ever since we staged a DnD themed commedia dell'arte at Pennsic two years, we've made sure to check our camp storage locker for any traps - because you never know when you'll find a Mimic!
We're just coming back from a storage locker run today as we prep for Pennsic started later this month and our three amazing shows! Come laugh at us on:
➤ Peace Thursday (July 30) • 6:00pm • Amphitheatre
"The Unexpected Twin"➤ Middle Saturday (August 1) • 9:00pm • PA Tent
"Pasquella's Powerful Potions"➤ War Wednesday (August 5) • 6:00pm • Amphitheatre
"What Went Down in Goblin Town?"#CommediaDellArte #Commedia #Improv #Improvisation #Theater #Comedy #Mask #Pennsic #PennsicWar #SCA #SocietyForCreativeAnachronism #MySCA #Fantasy #DnD #DungeonsAndDragons #Mimic
-
Ever since we staged a DnD themed commedia dell'arte at Pennsic two years, we've made sure to check our camp storage locker for any traps - because you never know when you'll find a Mimic!
We're just coming back from a storage locker run today as we prep for Pennsic started later this month and our three amazing shows! Come laugh at us on:
➤ Peace Thursday (July 30) • 6:00pm • Amphitheatre
"The Unexpected Twin"➤ Middle Saturday (August 1) • 9:00pm • PA Tent
"Pasquella's Powerful Potions"➤ War Wednesday (August 5) • 6:00pm • Amphitheatre
"What Went Down in Goblin Town?"#CommediaDellArte #Commedia #Improv #Improvisation #Theater #Comedy #Mask #Pennsic #PennsicWar #SCA #SocietyForCreativeAnachronism #MySCA #Fantasy #DnD #DungeonsAndDragons #Mimic
-
How WP-SHELLSTORM Exposed 1.4M WordPress Sites
A financially motivated cybercrime group operating as WP-SHELLSTORM was exposed when their Python SimpleHTTPServer remained open for 22 days, revealing toolkits, logs, and target lists. The operation targeted over 1.4 million domains using 27 weaponized CVEs and deployed more than 5,700 active webshells across WordPress and Joomla platforms. A parallel campaign targeted Apache Nacos, XXL-Job, and Spring Boot infrastructure, exfiltrating 613 configuration files from 11 victims across nine organizations in May 2026, compromising cloud credentials, database passwords, and payment system keys. The Chinese-linked actor utilized sophisticated obfuscated webshells, botnet infrastructure, and implants designed to evade detection by mimicking legitimate system processes.
Pulse ID: 6a54b716f22fd928cabf4eb8
Pulse Link: https://otx.alienvault.com/pulse/6a54b716f22fd928cabf4eb8
Pulse Author: AlienVault
Created: 2026-07-13 09:59:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APAC #Apache #Chinese #Cloud #CyberCrime #CyberSecurity #HTTP #HTTPS #InfoSec #Mimic #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RDP #Word #Wordpress #bot #botnet #AlienVault
-
How WP-SHELLSTORM Exposed 1.4M WordPress Sites
A financially motivated cybercrime group operating as WP-SHELLSTORM was exposed when their Python SimpleHTTPServer remained open for 22 days, revealing toolkits, logs, and target lists. The operation targeted over 1.4 million domains using 27 weaponized CVEs and deployed more than 5,700 active webshells across WordPress and Joomla platforms. A parallel campaign targeted Apache Nacos, XXL-Job, and Spring Boot infrastructure, exfiltrating 613 configuration files from 11 victims across nine organizations in May 2026, compromising cloud credentials, database passwords, and payment system keys. The Chinese-linked actor utilized sophisticated obfuscated webshells, botnet infrastructure, and implants designed to evade detection by mimicking legitimate system processes.
Pulse ID: 6a54b716f22fd928cabf4eb8
Pulse Link: https://otx.alienvault.com/pulse/6a54b716f22fd928cabf4eb8
Pulse Author: AlienVault
Created: 2026-07-13 09:59:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APAC #Apache #Chinese #Cloud #CyberCrime #CyberSecurity #HTTP #HTTPS #InfoSec #Mimic #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RDP #Word #Wordpress #bot #botnet #AlienVault
-
I've been designing monsters for my pathfinder 2e campaign. This is the "natural form" of a type of mimic my players encountered.
#DnD #Pathfinder #TTRPG #Mimic #PF2E -
I've been designing monsters for my pathfinder 2e campaign. This is the "natural form" of a type of mimic my players encountered.
#DnD #Pathfinder #TTRPG #Mimic #PF2E -
Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation
A financially motivated campaign identified in April 2026 delivers Vidar stealer and XMRig cryptocurrency miner to victims worldwide through malvertising. Attackers distribute password-protected archives impersonating cracked software, using Go-compiled loaders built with the Factory-v3 framework. The malware employs sophisticated evasion techniques including rogue Authenticode certificates mimicking JustWatch and BleacherReport, file-size inflation to hundreds of MB with null bytes, and AMSI bypass. Once executed, Vidar stealer exfiltrates browser credentials, cookies and cryptocurrency wallets to C2 infrastructure, while XMRig mines Monero cryptocurrency. The operation establishes persistence through registry modifications, scheduled tasks and startup folder scripts. The threat actor, operating under the moniker X3D MINER, primarily targets victims in the U.S. and European Union through a dual-monetization scheme combining credential theft and cryptojacking.
Pulse ID: 6a4d89812b006d2839a4dc49
Pulse Link: https://otx.alienvault.com/pulse/6a4d89812b006d2839a4dc49
Pulse Author: AlienVault
Created: 2026-07-07 23:19:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Cookies #CryptoJacking #CyberSecurity #Europe #EuropeanUnion #InfoSec #Malvertising #Malware #Mimic #OTX #OpenThreatExchange #Password #RAT #Vidar #Word #bot #cryptocurrency #AlienVault
-
Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation
A financially motivated campaign identified in April 2026 delivers Vidar stealer and XMRig cryptocurrency miner to victims worldwide through malvertising. Attackers distribute password-protected archives impersonating cracked software, using Go-compiled loaders built with the Factory-v3 framework. The malware employs sophisticated evasion techniques including rogue Authenticode certificates mimicking JustWatch and BleacherReport, file-size inflation to hundreds of MB with null bytes, and AMSI bypass. Once executed, Vidar stealer exfiltrates browser credentials, cookies and cryptocurrency wallets to C2 infrastructure, while XMRig mines Monero cryptocurrency. The operation establishes persistence through registry modifications, scheduled tasks and startup folder scripts. The threat actor, operating under the moniker X3D MINER, primarily targets victims in the U.S. and European Union through a dual-monetization scheme combining credential theft and cryptojacking.
Pulse ID: 6a4d89812b006d2839a4dc49
Pulse Link: https://otx.alienvault.com/pulse/6a4d89812b006d2839a4dc49
Pulse Author: AlienVault
Created: 2026-07-07 23:19:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Cookies #CryptoJacking #CyberSecurity #Europe #EuropeanUnion #InfoSec #Malvertising #Malware #Mimic #OTX #OpenThreatExchange #Password #RAT #Vidar #Word #bot #cryptocurrency #AlienVault
-
Despite this style of swimwear not being a fashion during the Renaissance era of commedia dell'arte, bikinis do pop up in our troupe more than you'd think, from Star Wars parodies to steampunk fantasies to DnD choose-your-own adventure!
So have a striking Bikini Day 2026!
#CommediaDellArte #Commedia #Improv #Improvisation #Comedy #Mask #Theater #Pennsic #PennsicWar #SCA #SocietyForCreativeAnachronism #MySCA #ClevelandConCoction #CleCon #SciFiCon #Fantasy #DnD #DungeonsAndDragons #Mimic #Bikini #BikiniDay
-
Despite this style of swimwear not being a fashion during the Renaissance era of commedia dell'arte, bikinis do pop up in our troupe more than you'd think, from Star Wars parodies to steampunk fantasies to DnD choose-your-own adventure!
So have a striking Bikini Day 2026!
#CommediaDellArte #Commedia #Improv #Improvisation #Comedy #Mask #Theater #Pennsic #PennsicWar #SCA #SocietyForCreativeAnachronism #MySCA #ClevelandConCoction #CleCon #SciFiCon #Fantasy #DnD #DungeonsAndDragons #Mimic #Bikini #BikiniDay
-
Branded Gambling Campaigns: How Scammers Are Exploiting Trusted Brand Names to Drive Casino Traffic
Scam advertising campaigns have been identified that impersonate trusted brands to redirect consumers to unrelated online gambling sites. These operations utilize paid social media advertisements on platforms like Facebook, Instagram, and TikTok, combined with fake app store pages and Progressive Web Apps. The campaigns target UK consumers primarily, with variants observed in German and Spanish. Scammers impersonate major brands including financial institutions like Monzo, Revolut, and Barclays, as well as household names such as Tesco, Amazon, Netflix, and Facebook. The scheme involves three stages: paid ads claiming brands have launched official casino products, fake landing pages mimicking app stores, and PWAs that redirect to gambling sites through affiliate tracking links. Typical affiliate payouts range from $50 to $350 per depositing player, indicating significant financial motivation behind these operations.
Pulse ID: 6a46d12100d65a16f173e8a4
Pulse Link: https://otx.alienvault.com/pulse/6a46d12100d65a16f173e8a4
Pulse Author: AlienVault
Created: 2026-07-02 20:59:13Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Amazon #CyberSecurity #Facebook #InfoSec #Instagram #Mimic #OTX #OpenThreatExchange #RAT #Rust #SocialMedia #UK #bot #AlienVault
-
Branded Gambling Campaigns: How Scammers Are Exploiting Trusted Brand Names to Drive Casino Traffic
Scam advertising campaigns have been identified that impersonate trusted brands to redirect consumers to unrelated online gambling sites. These operations utilize paid social media advertisements on platforms like Facebook, Instagram, and TikTok, combined with fake app store pages and Progressive Web Apps. The campaigns target UK consumers primarily, with variants observed in German and Spanish. Scammers impersonate major brands including financial institutions like Monzo, Revolut, and Barclays, as well as household names such as Tesco, Amazon, Netflix, and Facebook. The scheme involves three stages: paid ads claiming brands have launched official casino products, fake landing pages mimicking app stores, and PWAs that redirect to gambling sites through affiliate tracking links. Typical affiliate payouts range from $50 to $350 per depositing player, indicating significant financial motivation behind these operations.
Pulse ID: 6a46d12100d65a16f173e8a4
Pulse Link: https://otx.alienvault.com/pulse/6a46d12100d65a16f173e8a4
Pulse Author: AlienVault
Created: 2026-07-02 20:59:13Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Amazon #CyberSecurity #Facebook #InfoSec #Instagram #Mimic #OTX #OpenThreatExchange #RAT #Rust #SocialMedia #UK #bot #AlienVault
-
A single RedLine C2 pivots into a maritime spear-phishing cluster and attacker-owned infrastructure.
An investigation beginning with a single RedLine Stealer C2 server from VMRay UniqueSignal evolved into uncovering a targeted Business Email Compromise campaign against South Korean maritime infrastructure. The analysis started with IP 194.156.79.122 on port 55615, leveraging fingerprinting techniques through FOFA and VirusTotal to identify additional C2 infrastructure. Pivoting through communicating files revealed spear-phishing emails targeting Kangrim Heavy Industries, a major South Korean marine boiler manufacturer. The campaign delivered Formbook malware through impersonated maritime supply chain companies. Further infrastructure analysis identified seven fraudulent domains hosted on TheHost LLC infrastructure, utilizing similar naming patterns and TLS certificates. The attack demonstrates sophisticated BEC tactics combining malware delivery with social engineering, mimicking legitimate business correspondence within the maritime shipping sector.
Pulse ID: 6a464b96bef17724be5668a0
Pulse Link: https://otx.alienvault.com/pulse/6a464b96bef17724be5668a0
Pulse Author: AlienVault
Created: 2026-07-02 11:29:26Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Email #FormBook #ICS #InfoSec #Korea #Malware #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RedLine #RedlineStealer #Rust #SocialEngineering #SouthKorea #SpearPhishing #SupplyChain #TLS #VirusTotal #bot #AlienVault
-
A single RedLine C2 pivots into a maritime spear-phishing cluster and attacker-owned infrastructure.
An investigation beginning with a single RedLine Stealer C2 server from VMRay UniqueSignal evolved into uncovering a targeted Business Email Compromise campaign against South Korean maritime infrastructure. The analysis started with IP 194.156.79.122 on port 55615, leveraging fingerprinting techniques through FOFA and VirusTotal to identify additional C2 infrastructure. Pivoting through communicating files revealed spear-phishing emails targeting Kangrim Heavy Industries, a major South Korean marine boiler manufacturer. The campaign delivered Formbook malware through impersonated maritime supply chain companies. Further infrastructure analysis identified seven fraudulent domains hosted on TheHost LLC infrastructure, utilizing similar naming patterns and TLS certificates. The attack demonstrates sophisticated BEC tactics combining malware delivery with social engineering, mimicking legitimate business correspondence within the maritime shipping sector.
Pulse ID: 6a464b96bef17724be5668a0
Pulse Link: https://otx.alienvault.com/pulse/6a464b96bef17724be5668a0
Pulse Author: AlienVault
Created: 2026-07-02 11:29:26Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Email #FormBook #ICS #InfoSec #Korea #Malware #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RedLine #RedlineStealer #Rust #SocialEngineering #SouthKorea #SpearPhishing #SupplyChain #TLS #VirusTotal #bot #AlienVault
-
Iran-Nexus Disseminates MarkiRAT Surveillance Tool
TAG-182, an Iran-nexus threat cluster, is conducting surveillance operations targeting Iranian citizens both domestically and abroad using MarkiRAT malware. The group distributes fake Android applications masquerading as VPN services and media players through social media platforms, particularly Instagram. Following Iran's partial internet restoration in May 2026 after an 88-day shutdown, these surveillance activities have intensified as Iranian security apparatus seeks to monitor perceived dissidents and anti-government activists. MarkiRAT samples demonstrate tradecraft overlaps with previously documented Ferocious Kitten operations, including use of Background Intelligent Transfer Service (BITS). The group operates infrastructure across multiple autonomous systems, utilizing domains with naming conventions mimicking legitimate services like Microsoft, Google, and Facebook.
Pulse ID: 6a45471afccee96152675f88
Pulse Link: https://otx.alienvault.com/pulse/6a45471afccee96152675f88
Pulse Author: AlienVault
Created: 2026-07-01 16:58:02Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #CyberSecurity #Facebook #Google #Government #InfoSec #Instagram #Iran #Malware #Microsoft #Mimic #OTX #OpenThreatExchange #RAT #RCE #SocialMedia #VPN #bot #AlienVault
-
Iran-Nexus Disseminates MarkiRAT Surveillance Tool
TAG-182, an Iran-nexus threat cluster, is conducting surveillance operations targeting Iranian citizens both domestically and abroad using MarkiRAT malware. The group distributes fake Android applications masquerading as VPN services and media players through social media platforms, particularly Instagram. Following Iran's partial internet restoration in May 2026 after an 88-day shutdown, these surveillance activities have intensified as Iranian security apparatus seeks to monitor perceived dissidents and anti-government activists. MarkiRAT samples demonstrate tradecraft overlaps with previously documented Ferocious Kitten operations, including use of Background Intelligent Transfer Service (BITS). The group operates infrastructure across multiple autonomous systems, utilizing domains with naming conventions mimicking legitimate services like Microsoft, Google, and Facebook.
Pulse ID: 6a45471afccee96152675f88
Pulse Link: https://otx.alienvault.com/pulse/6a45471afccee96152675f88
Pulse Author: AlienVault
Created: 2026-07-01 16:58:02Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #CyberSecurity #Facebook #Google #Government #InfoSec #Instagram #Iran #Malware #Microsoft #Mimic #OTX #OpenThreatExchange #RAT #RCE #SocialMedia #VPN #bot #AlienVault
-
If there's anything that I love drawing, it's tentacles! I've drawn Elana getting nabbed and worse by some fun tentacle buddies that just want to have a little feel, yanno?
https://subscribestar.adult/pyperhaylie
https://naughtynewsroom.carrd.co/
#bondage #Oc #tentacles #elana #redhead #mimic #experiment #portal #prank -
If there's anything that I love drawing, it's tentacles! I've drawn Elana getting nabbed and worse by some fun tentacle buddies that just want to have a little feel, yanno?
https://subscribestar.adult/pyperhaylie
https://naughtynewsroom.carrd.co/
#bondage #Oc #tentacles #elana #redhead #mimic #experiment #portal #prank -
Chest E. Cognito (the resident Definitely-Not-A-Mimic of our troupe) wishes everyone a happy Pride Month 2026 as all humans are equal.... equally tasty! .... Well... it's the thought that counts, right? 🤣
#Mimic #DnD #DungeonsAndDragons #Pride #LGBT #LGBTQ #LGBTQIA #PrideMonth #LoveWins #LoveIsLove #Equality #Acceptance #Improv #Improvisation #Theater #Comedy #Mask #Fantasy
-
Chest E. Cognito (the resident Definitely-Not-A-Mimic of our troupe) wishes everyone a happy Pride Month 2026 as all humans are equal.... equally tasty! .... Well... it's the thought that counts, right? 🤣
#Mimic #DnD #DungeonsAndDragons #Pride #LGBT #LGBTQ #LGBTQIA #PrideMonth #LoveWins #LoveIsLove #Equality #Acceptance #Improv #Improvisation #Theater #Comedy #Mask #Fantasy
-
PLP423_1.1: Hard Case Exploration #art #MastoArt #DigitalArt #DigitalPainting #Photoshop #Sketch #SpeedPaint #ConceptArt #Fantasy #Creature #Briefcase #Mimic
-
This gobbo thought she had made it rich, but when she went to open the treasure chest, all she got was trouble! Gold ribbons shot out, ensnaring her immediately, jerking her off her feet and into the air, where she had no leverage to even fight. Her clothes were stripped off and she was getting wrapped up and brought closer to the mouth of the chest. She had to fight more or she was going to get trapped inside!
#bondage #bound #victim #damsel #damselindistress #did #mimic #goblin -
This gobbo thought she had made it rich, but when she went to open the treasure chest, all she got was trouble! Gold ribbons shot out, ensnaring her immediately, jerking her off her feet and into the air, where she had no leverage to even fight. Her clothes were stripped off and she was getting wrapped up and brought closer to the mouth of the chest. She had to fight more or she was going to get trapped inside!
#bondage #bound #victim #damsel #damselindistress #did #mimic #goblin -
Fake Software Tutorials on TikTok Spread Vidar Stealer
Threat actors are leveraging TikTok and Instagram Reels to distribute the Vidar infostealer through fake software tutorials. Two distinct campaigns use short-form videos disguised as tutorials for unlocking premium software like Spotify. The first campaign uses accounts mimicking official Windows profiles with AI-voiced clips instructing users to run PowerShell commands that download Vidar from lookalike domains. One video achieved over 100,000 views. The second campaign uses ordinary accounts posting music-backed clips that bait users in comments to receive malicious links via direct message. These campaigns exploit platform recommendation algorithms by encouraging saves and shares. Vidar is sold as a service for $300 lifetime license and harvests credentials, financial data and authentication tokens.
Pulse ID: 6a298f548047c70cc9e2f4ee
Pulse Link: https://otx.alienvault.com/pulse/6a298f548047c70cc9e2f4ee
Pulse Author: AlienVault
Created: 2026-06-10 16:22:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #FinancialData #InfoSec #InfoStealer #Instagram #Mimic #OTX #OpenThreatExchange #PowerShell #Vidar #Windows #bot #AlienVault
-
Fake Software Tutorials on TikTok Spread Vidar Stealer
Threat actors are leveraging TikTok and Instagram Reels to distribute the Vidar infostealer through fake software tutorials. Two distinct campaigns use short-form videos disguised as tutorials for unlocking premium software like Spotify. The first campaign uses accounts mimicking official Windows profiles with AI-voiced clips instructing users to run PowerShell commands that download Vidar from lookalike domains. One video achieved over 100,000 views. The second campaign uses ordinary accounts posting music-backed clips that bait users in comments to receive malicious links via direct message. These campaigns exploit platform recommendation algorithms by encouraging saves and shares. Vidar is sold as a service for $300 lifetime license and harvests credentials, financial data and authentication tokens.
Pulse ID: 6a298f548047c70cc9e2f4ee
Pulse Link: https://otx.alienvault.com/pulse/6a298f548047c70cc9e2f4ee
Pulse Author: AlienVault
Created: 2026-06-10 16:22:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #FinancialData #InfoSec #InfoStealer #Instagram #Mimic #OTX #OpenThreatExchange #PowerShell #Vidar #Windows #bot #AlienVault
-
https://www.alojapan.com/1494567/got-a-critical-hit-while-eating-dragon-quest-ice-cream-%f0%9f%92%a5-shorts/ Got a Critical Hit while eating Dragon Quest ice cream! 💥 #shorts #BaskinRobbins #DragonQuest #eating #IceCream #JapaneseStuffChannel #JapaneseStuffChannel #jsc #mimic #アイス #サーティワン #ドラゴンクエスト Got a Critical Hit while eating Dragon Quest ice cream! 💥 #shorts Tried to eat Baskin-Robbins’ Dragon Quest collab flavor “Critical Hit!”, but an unexpected mishap happened… The “Ice Cream Mimic” (Kuibako) suddenly fell over, as if it was too hungry to wa
-
During our troupe's 20th birthday celebrations last weekend, one of our earliest Players of the Patchwork Julie got to meet Chest E. Cognito, one of our newest {definitely-not-a-Mimic} characters!
What's a little light nomming amongst friends? 😁
#CommediaDellArte #Commedia #Improv #Improvisation #Theater #DnD #Mimic #Nom #NomNomNom #Birthday
-
During our troupe's 20th birthday celebrations last weekend, one of our earliest Players of the Patchwork Julie got to meet Chest E. Cognito, one of our newest {definitely-not-a-Mimic} characters!
What's a little light nomming amongst friends? 😁
#CommediaDellArte #Commedia #Improv #Improvisation #Theater #DnD #Mimic #Nom #NomNomNom #Birthday
-
How Gut Bacteria May Affect the Outcome of Cancer Immunotherapy
-
How Gut Bacteria May Affect the Outcome of Cancer Immunotherapy