home.social

#red-line — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #red-line, aggregated by home.social.

fetched live
  1. Operation STANDOFF: A Campaign Hiding C2 Behind GitHub Redirects

    VMRay Labs uncovered a sophisticated Russian-speaking cybercriminal operation combining multiple attack vectors on shared infrastructure. The campaign distributes commodity stealers including Raccoon, RedLine, Amadey, SmokeLoader, Socelars, and Glupteba through a pay-per-install loader while enrolling victims into a proxy-botnet. Command-and-control servers on Russian provider TimeWeb use GitHub domain redirects for concealment. A custom multi-operator console called STANDOFF COORD coordinates hands-on-keyboard intrusions targeting Active Directory environments, storing NTLM hashes, Kerberos tickets, and credentials organized by network segments. Additionally, the infrastructure hosts an AI-driven influence operation using industrial-scale Telegram account farms and automated engagement platforms targeting Russian-speaking mobile gaming communities through a portal called Mobile Arena, driving traffic toward gambling sites and malware distribution.

    Pulse ID: 6a5f5a54ab92617993537c0b
    Pulse Link: otx.alienvault.com/pulse/6a5f5
    Pulse Author: AlienVault
    Created: 2026-07-21 11:39:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Amadey #CyberSecurity #GitHub #Glupteba #InfoSec #Malware #OTX #OpenThreatExchange #Proxy #RAT #RedLine #Russia #Telegram #bot #botnet #AlienVault

  2. Operation STANDOFF: A Campaign Hiding C2 Behind GitHub Redirects

    VMRay Labs uncovered a sophisticated Russian-speaking cybercriminal operation combining multiple attack vectors on shared infrastructure. The campaign distributes commodity stealers including Raccoon, RedLine, Amadey, SmokeLoader, Socelars, and Glupteba through a pay-per-install loader while enrolling victims into a proxy-botnet. Command-and-control servers on Russian provider TimeWeb use GitHub domain redirects for concealment. A custom multi-operator console called STANDOFF COORD coordinates hands-on-keyboard intrusions targeting Active Directory environments, storing NTLM hashes, Kerberos tickets, and credentials organized by network segments. Additionally, the infrastructure hosts an AI-driven influence operation using industrial-scale Telegram account farms and automated engagement platforms targeting Russian-speaking mobile gaming communities through a portal called Mobile Arena, driving traffic toward gambling sites and malware distribution.

    Pulse ID: 6a5f5a54ab92617993537c0b
    Pulse Link: otx.alienvault.com/pulse/6a5f5
    Pulse Author: AlienVault
    Created: 2026-07-21 11:39:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Amadey #CyberSecurity #GitHub #Glupteba #InfoSec #Malware #OTX #OpenThreatExchange #Proxy #RAT #RedLine #Russia #Telegram #bot #botnet #AlienVault

  3. Operation STANDOFF: A Campaign Hiding C2 Behind GitHub Redirects

    VMRay Labs uncovered a sophisticated Russian-speaking cybercriminal operation combining multiple attack vectors on shared infrastructure. The campaign distributes commodity stealers including Raccoon, RedLine, Amadey, SmokeLoader, Socelars, and Glupteba through a pay-per-install loader while enrolling victims into a proxy-botnet. Command-and-control servers on Russian provider TimeWeb use GitHub domain redirects for concealment. A custom multi-operator console called STANDOFF COORD coordinates hands-on-keyboard intrusions targeting Active Directory environments, storing NTLM hashes, Kerberos tickets, and credentials organized by network segments. Additionally, the infrastructure hosts an AI-driven influence operation using industrial-scale Telegram account farms and automated engagement platforms targeting Russian-speaking mobile gaming communities through a portal called Mobile Arena, driving traffic toward gambling sites and malware distribution.

    Pulse ID: 6a5f5a54ab92617993537c0b
    Pulse Link: otx.alienvault.com/pulse/6a5f5
    Pulse Author: AlienVault
    Created: 2026-07-21 11:39:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Amadey #CyberSecurity #GitHub #Glupteba #InfoSec #Malware #OTX #OpenThreatExchange #Proxy #RAT #RedLine #Russia #Telegram #bot #botnet #AlienVault

  4. Operation STANDOFF: A Campaign Hiding C2 Behind GitHub Redirects

    VMRay Labs uncovered a sophisticated Russian-speaking cybercriminal operation combining multiple attack vectors on shared infrastructure. The campaign distributes commodity stealers including Raccoon, RedLine, Amadey, SmokeLoader, Socelars, and Glupteba through a pay-per-install loader while enrolling victims into a proxy-botnet. Command-and-control servers on Russian provider TimeWeb use GitHub domain redirects for concealment. A custom multi-operator console called STANDOFF COORD coordinates hands-on-keyboard intrusions targeting Active Directory environments, storing NTLM hashes, Kerberos tickets, and credentials organized by network segments. Additionally, the infrastructure hosts an AI-driven influence operation using industrial-scale Telegram account farms and automated engagement platforms targeting Russian-speaking mobile gaming communities through a portal called Mobile Arena, driving traffic toward gambling sites and malware distribution.

    Pulse ID: 6a5f5a54ab92617993537c0b
    Pulse Link: otx.alienvault.com/pulse/6a5f5
    Pulse Author: AlienVault
    Created: 2026-07-21 11:39:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Amadey #CyberSecurity #GitHub #Glupteba #InfoSec #Malware #OTX #OpenThreatExchange #Proxy #RAT #RedLine #Russia #Telegram #bot #botnet #AlienVault

  5. Operation STANDOFF: A Campaign Hiding C2 Behind GitHub Redirects

    VMRay Labs uncovered a sophisticated Russian-speaking cybercriminal operation combining multiple attack vectors on shared infrastructure. The campaign distributes commodity stealers including Raccoon, RedLine, Amadey, SmokeLoader, Socelars, and Glupteba through a pay-per-install loader while enrolling victims into a proxy-botnet. Command-and-control servers on Russian provider TimeWeb use GitHub domain redirects for concealment. A custom multi-operator console called STANDOFF COORD coordinates hands-on-keyboard intrusions targeting Active Directory environments, storing NTLM hashes, Kerberos tickets, and credentials organized by network segments. Additionally, the infrastructure hosts an AI-driven influence operation using industrial-scale Telegram account farms and automated engagement platforms targeting Russian-speaking mobile gaming communities through a portal called Mobile Arena, driving traffic toward gambling sites and malware distribution.

    Pulse ID: 6a5f5a54ab92617993537c0b
    Pulse Link: otx.alienvault.com/pulse/6a5f5
    Pulse Author: AlienVault
    Created: 2026-07-21 11:39:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Amadey #CyberSecurity #GitHub #Glupteba #InfoSec #Malware #OTX #OpenThreatExchange #Proxy #RAT #RedLine #Russia #Telegram #bot #botnet #AlienVault

  6. #mastobada amour (love 🇬🇧 )

    Redline ed || James Shimoji feat. Rob Laufer - redline day

    you are the air that I breathe
    without you I am incomplete
    you are the only one for me
    though rarely spoken, I know you believe

    I love you (x8)

    it's a redline day, everything's ok
    put your cares away, it's a redline day
    it's a redline day, we can love today
    and I hope you say, it's a redline daaay

    youtube.com/watch?v=KbJanCYONrk

    #redline #anime #musique #music

  7. #mastobada amour (love 🇬🇧 )

    Redline ed || James Shimoji feat. Rob Laufer - redline day

    you are the air that I breathe
    without you I am incomplete
    you are the only one for me
    though rarely spoken, I know you believe

    I love you (x8)

    it's a redline day, everything's ok
    put your cares away, it's a redline day
    it's a redline day, we can love today
    and I hope you say, it's a redline daaay

    youtube.com/watch?v=KbJanCYONrk

    #redline #anime #musique #music

  8. #mastobada amour (love 🇬🇧 )

    Redline ed || James Shimoji feat. Rob Laufer - redline day

    you are the air that I breathe
    without you I am incomplete
    you are the only one for me
    though rarely spoken, I know you believe

    I love you (x8)

    it's a redline day, everything's ok
    put your cares away, it's a redline day
    it's a redline day, we can love today
    and I hope you say, it's a redline daaay

    youtube.com/watch?v=KbJanCYONrk

    #redline #anime #musique #music

  9. A single RedLine C2 pivots into a maritime spear-phishing cluster and attacker-owned infrastructure.

    Pulse ID: 6a473803056ecbd7fb3d40ec
    Pulse Link: otx.alienvault.com/pulse/6a473
    Pulse Author: Tr1sa111
    Created: 2026-07-03 04:18:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Phishing #RedLine #SpearPhishing #bot #Tr1sa111

  10. A single RedLine C2 pivots into a maritime spear-phishing cluster and attacker-owned infrastructure.

    Pulse ID: 6a473803056ecbd7fb3d40ec
    Pulse Link: otx.alienvault.com/pulse/6a473
    Pulse Author: Tr1sa111
    Created: 2026-07-03 04:18:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Phishing #RedLine #SpearPhishing #bot #Tr1sa111

  11. A single RedLine C2 pivots into a maritime spear-phishing cluster and attacker-owned infrastructure.

    Pulse ID: 6a473803056ecbd7fb3d40ec
    Pulse Link: otx.alienvault.com/pulse/6a473
    Pulse Author: Tr1sa111
    Created: 2026-07-03 04:18:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Phishing #RedLine #SpearPhishing #bot #Tr1sa111

  12. A single RedLine C2 pivots into a maritime spear-phishing cluster and attacker-owned infrastructure.

    Pulse ID: 6a473803056ecbd7fb3d40ec
    Pulse Link: otx.alienvault.com/pulse/6a473
    Pulse Author: Tr1sa111
    Created: 2026-07-03 04:18:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Phishing #RedLine #SpearPhishing #bot #Tr1sa111

  13. A single RedLine C2 pivots into a maritime spear-phishing cluster and attacker-owned infrastructure.

    Pulse ID: 6a473803056ecbd7fb3d40ec
    Pulse Link: otx.alienvault.com/pulse/6a473
    Pulse Author: Tr1sa111
    Created: 2026-07-03 04:18:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Phishing #RedLine #SpearPhishing #bot #Tr1sa111

  14. A single RedLine C2 pivots into a maritime spear-phishing cluster and attacker-owned infrastructure.

    An investigation beginning with a single RedLine Stealer C2 server from VMRay UniqueSignal evolved into uncovering a targeted Business Email Compromise campaign against South Korean maritime infrastructure. The analysis started with IP 194.156.79.122 on port 55615, leveraging fingerprinting techniques through FOFA and VirusTotal to identify additional C2 infrastructure. Pivoting through communicating files revealed spear-phishing emails targeting Kangrim Heavy Industries, a major South Korean marine boiler manufacturer. The campaign delivered Formbook malware through impersonated maritime supply chain companies. Further infrastructure analysis identified seven fraudulent domains hosted on TheHost LLC infrastructure, utilizing similar naming patterns and TLS certificates. The attack demonstrates sophisticated BEC tactics combining malware delivery with social engineering, mimicking legitimate business correspondence within the maritime shipping sector.

    Pulse ID: 6a464b96bef17724be5668a0
    Pulse Link: otx.alienvault.com/pulse/6a464
    Pulse Author: AlienVault
    Created: 2026-07-02 11:29:26

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Email #FormBook #ICS #InfoSec #Korea #Malware #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RedLine #RedlineStealer #Rust #SocialEngineering #SouthKorea #SpearPhishing #SupplyChain #TLS #VirusTotal #bot #AlienVault

  15. A single RedLine C2 pivots into a maritime spear-phishing cluster and attacker-owned infrastructure.

    An investigation beginning with a single RedLine Stealer C2 server from VMRay UniqueSignal evolved into uncovering a targeted Business Email Compromise campaign against South Korean maritime infrastructure. The analysis started with IP 194.156.79.122 on port 55615, leveraging fingerprinting techniques through FOFA and VirusTotal to identify additional C2 infrastructure. Pivoting through communicating files revealed spear-phishing emails targeting Kangrim Heavy Industries, a major South Korean marine boiler manufacturer. The campaign delivered Formbook malware through impersonated maritime supply chain companies. Further infrastructure analysis identified seven fraudulent domains hosted on TheHost LLC infrastructure, utilizing similar naming patterns and TLS certificates. The attack demonstrates sophisticated BEC tactics combining malware delivery with social engineering, mimicking legitimate business correspondence within the maritime shipping sector.

    Pulse ID: 6a464b96bef17724be5668a0
    Pulse Link: otx.alienvault.com/pulse/6a464
    Pulse Author: AlienVault
    Created: 2026-07-02 11:29:26

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Email #FormBook #ICS #InfoSec #Korea #Malware #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RedLine #RedlineStealer #Rust #SocialEngineering #SouthKorea #SpearPhishing #SupplyChain #TLS #VirusTotal #bot #AlienVault

  16. A single RedLine C2 pivots into a maritime spear-phishing cluster and attacker-owned infrastructure.

    An investigation beginning with a single RedLine Stealer C2 server from VMRay UniqueSignal evolved into uncovering a targeted Business Email Compromise campaign against South Korean maritime infrastructure. The analysis started with IP 194.156.79.122 on port 55615, leveraging fingerprinting techniques through FOFA and VirusTotal to identify additional C2 infrastructure. Pivoting through communicating files revealed spear-phishing emails targeting Kangrim Heavy Industries, a major South Korean marine boiler manufacturer. The campaign delivered Formbook malware through impersonated maritime supply chain companies. Further infrastructure analysis identified seven fraudulent domains hosted on TheHost LLC infrastructure, utilizing similar naming patterns and TLS certificates. The attack demonstrates sophisticated BEC tactics combining malware delivery with social engineering, mimicking legitimate business correspondence within the maritime shipping sector.

    Pulse ID: 6a464b96bef17724be5668a0
    Pulse Link: otx.alienvault.com/pulse/6a464
    Pulse Author: AlienVault
    Created: 2026-07-02 11:29:26

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Email #FormBook #ICS #InfoSec #Korea #Malware #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RedLine #RedlineStealer #Rust #SocialEngineering #SouthKorea #SpearPhishing #SupplyChain #TLS #VirusTotal #bot #AlienVault

  17. A single RedLine C2 pivots into a maritime spear-phishing cluster and attacker-owned infrastructure.

    An investigation beginning with a single RedLine Stealer C2 server from VMRay UniqueSignal evolved into uncovering a targeted Business Email Compromise campaign against South Korean maritime infrastructure. The analysis started with IP 194.156.79.122 on port 55615, leveraging fingerprinting techniques through FOFA and VirusTotal to identify additional C2 infrastructure. Pivoting through communicating files revealed spear-phishing emails targeting Kangrim Heavy Industries, a major South Korean marine boiler manufacturer. The campaign delivered Formbook malware through impersonated maritime supply chain companies. Further infrastructure analysis identified seven fraudulent domains hosted on TheHost LLC infrastructure, utilizing similar naming patterns and TLS certificates. The attack demonstrates sophisticated BEC tactics combining malware delivery with social engineering, mimicking legitimate business correspondence within the maritime shipping sector.

    Pulse ID: 6a464b96bef17724be5668a0
    Pulse Link: otx.alienvault.com/pulse/6a464
    Pulse Author: AlienVault
    Created: 2026-07-02 11:29:26

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Email #FormBook #ICS #InfoSec #Korea #Malware #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RedLine #RedlineStealer #Rust #SocialEngineering #SouthKorea #SpearPhishing #SupplyChain #TLS #VirusTotal #bot #AlienVault

  18. A single RedLine C2 pivots into a maritime spear-phishing cluster and attacker-owned infrastructure.

    An investigation beginning with a single RedLine Stealer C2 server from VMRay UniqueSignal evolved into uncovering a targeted Business Email Compromise campaign against South Korean maritime infrastructure. The analysis started with IP 194.156.79.122 on port 55615, leveraging fingerprinting techniques through FOFA and VirusTotal to identify additional C2 infrastructure. Pivoting through communicating files revealed spear-phishing emails targeting Kangrim Heavy Industries, a major South Korean marine boiler manufacturer. The campaign delivered Formbook malware through impersonated maritime supply chain companies. Further infrastructure analysis identified seven fraudulent domains hosted on TheHost LLC infrastructure, utilizing similar naming patterns and TLS certificates. The attack demonstrates sophisticated BEC tactics combining malware delivery with social engineering, mimicking legitimate business correspondence within the maritime shipping sector.

    Pulse ID: 6a464b96bef17724be5668a0
    Pulse Link: otx.alienvault.com/pulse/6a464
    Pulse Author: AlienVault
    Created: 2026-07-02 11:29:26

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Email #FormBook #ICS #InfoSec #Korea #Malware #Mimic #OTX #OpenThreatExchange #Phishing #RAT #RedLine #RedlineStealer #Rust #SocialEngineering #SouthKorea #SpearPhishing #SupplyChain #TLS #VirusTotal #bot #AlienVault

  19. Next month: #RedLine closure for construction in Cambridge and Somerville // July 21 - July 30

  20. Next month: #RedLine closure for construction in Cambridge and Somerville // July 21 - July 30

  21. Next month: #RedLine closure for construction in Cambridge and Somerville // July 21 - July 30

  22. Next month: #RedLine closure for construction in Cambridge and Somerville // July 21 - July 30

  23. Next month: #RedLine closure for construction in Cambridge and Somerville // July 21 - July 30

  24. Myself I liked #Redline, #Forsaken and #Spades. #Redline1999 en.wikipedia.org/wiki/Redline... #Forsaken1998 en.wikipedia.org/wiki/Forsake...

    Redline (1999 video game) - Wi...
  25. Everything you need to know about getting around on Calgary Transit during CTrain disruptions

    Most journeys by CTrain are uneventful but construction, emergencies and unexpected incidents may occasionally cause delays or disruptions…
    #Canada #Calgary #BlueLine #CalgaryTransit #CTrain #downtownCalgary #RedLine #TheRedLine
    europesays.com/canada/73644/

  26. Watched #Redline yesterday man what a fun #anime flick, been a while I watched some, amazing 100% hand drawn animation and so many weird and quirky characters, just how I like it.

  27. @vicfroh

    #Genocide is my #RedLine

    #ChildSexualAbuse is my #RedLine

    I'm against #ChildSexualAbuse but not against #Pedophila. #Pedophilia refers to the sexual interest in children and not to the sexual abuse. It's an important difference because according to research addressing #stigma surrounding #pedophilia is paramount as stigma contributes to avoidance of help-seeking, which may increase risk of sexual abuse against children: pmc.ncbi.nlm.nih.gov/articles/.

    I hope my opinions really matter.

  28. @vicfroh

    #Genocide is my #RedLine

    #ChildSexualAbuse is my #RedLine

    I'm against #ChildSexualAbuse but not against #Pedophila. #Pedophilia refers to the sexual interest in children and not to the sexual abuse. It's an important difference because according to research addressing #stigma surrounding #pedophilia is paramount as stigma contributes to avoidance of help-seeking, which may increase risk of sexual abuse against children: pmc.ncbi.nlm.nih.gov/articles/.

    I hope my opinions really matter.

  29. @vicfroh

    #Genocide is my #RedLine

    #ChildSexualAbuse is my #RedLine

    I'm against #ChildSexualAbuse but not against #Pedophila. #Pedophilia refers to the sexual interest in children and not to the sexual abuse. It's an important difference because according to research addressing #stigma surrounding #pedophilia is paramount as stigma contributes to avoidance of help-seeking, which may increase risk of sexual abuse against children: pmc.ncbi.nlm.nih.gov/articles/.

    I hope my opinions really matter.

  30. @vicfroh

    #Genocide is my #RedLine

    #ChildSexualAbuse is my #RedLine

    I'm against #ChildSexualAbuse but not against #Pedophila. #Pedophilia refers to the sexual interest in children and not to the sexual abuse. It's an important difference because according to research addressing #stigma surrounding #pedophilia is paramount as stigma contributes to avoidance of help-seeking, which may increase risk of sexual abuse against children: pmc.ncbi.nlm.nih.gov/articles/.

    I hope my opinions really matter.

  31. @vicfroh

    #Genocide is my #RedLine

    #ChildSexualAbuse is my #RedLine

    I'm against #ChildSexualAbuse but not against #Pedophila. #Pedophilia refers to the sexual interest in children and not to the sexual abuse. It's an important difference because according to research addressing #stigma surrounding #pedophilia is paramount as stigma contributes to avoidance of help-seeking, which may increase risk of sexual abuse against children: pmc.ncbi.nlm.nih.gov/articles/.

    I hope my opinions really matter.

  32. After the hyping of data breaches and now that's a regular item on daily news. The spotlight switches to infostealers. A brief explanatory piece on what it is and how they work using #Redline as example. #databreach #infosec #cybersecurity #opsec privacyinsightsolutions.com/bl

  33. After the hyping of data breaches and now that's a regular item on daily news. The spotlight switches to infostealers. A brief explanatory piece on what it is and how they work using #Redline as example. #databreach #infosec #cybersecurity #opsec privacyinsightsolutions.com/bl

  34. *Well, it used to be that, if you had a whole bunch of nuclear weapons, nobody would presume to blast the living daylights out of your capital city. #Moskva #redline #whatredline #diefaster

    RE: https://bsky.app/profile/did:plc:4qyg3stgz7iipt5qhnhu6jis/post/3mm7qfbkk2c25

  35. *Well, it used to be that, if you had a whole bunch of nuclear weapons, nobody would presume to blast the living daylights out of your capital city. #Moskva #redline #whatredline #diefaster

    RE: https://bsky.app/profile/did:plc:4qyg3stgz7iipt5qhnhu6jis/post/3mm7qfbkk2c25

  36. *Well, it used to be that, if you had a whole bunch of nuclear weapons, nobody would presume to blast the living daylights out of your capital city. #Moskva #redline #whatredline #diefaster

    RE: https://bsky.app/profile/did:plc:4qyg3stgz7iipt5qhnhu6jis/post/3mm7qfbkk2c25

  37. *Well, it used to be that, if you had a whole bunch of nuclear weapons, nobody would presume to blast the living daylights out of your capital city. #Moskva #redline #whatredline #diefaster

    RE: https://bsky.app/profile/did:plc:4qyg3stgz7iipt5qhnhu6jis/post/3mm7qfbkk2c25