home.social

#threatintelligence — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #threatintelligence, aggregated by home.social.

fetched live
  1. 🚨New ransom group blog posts!🚨

    Group name: akira
    Post title: Basic Grain Products
    Info: cti.fyi/groups/akira.html

    Group name: akira
    Post title: CF Supply
    Info: cti.fyi/groups/akira.html

    Group name: akira
    Post title: Alcast
    Info: cti.fyi/groups/akira.html

    Group name: akira
    Post title: i4 Solutions
    Info: cti.fyi/groups/akira.html

    Group name: akira
    Post title: One Vision Imaging
    Info: cti.fyi/groups/akira.html

    Group name: qilin
    Post title: Radiant
    Info: cti.fyi/groups/qilin.html

    #ransomware #cti #threatintelligence #cybersecurity #infosec

  2. 🚨New ransom group blog posts!🚨

    Group name: akira
    Post title: Basic Grain Products
    Info: cti.fyi/groups/akira.html

    Group name: akira
    Post title: CF Supply
    Info: cti.fyi/groups/akira.html

    Group name: akira
    Post title: Alcast
    Info: cti.fyi/groups/akira.html

    Group name: akira
    Post title: i4 Solutions
    Info: cti.fyi/groups/akira.html

    Group name: akira
    Post title: One Vision Imaging
    Info: cti.fyi/groups/akira.html

    Group name: qilin
    Post title: Radiant
    Info: cti.fyi/groups/qilin.html

    #ransomware #cti #threatintelligence #cybersecurity #infosec

  3. 🚨New ransom group blog posts!🚨

    Group name: qilin
    Post title: Urban Worldwide
    Info: cti.fyi/groups/qilin.html

    Group name: qilin
    Post title: PenLink
    Info: cti.fyi/groups/qilin.html

    Group name: qilin
    Post title: Lercher Werkzeugbau
    Info: cti.fyi/groups/qilin.html

    #ransomware #cti #threatintelligence #cybersecurity #infosec

  4. 🚨New ransom group blog posts!🚨

    Group name: qilin
    Post title: Urban Worldwide
    Info: cti.fyi/groups/qilin.html

    Group name: qilin
    Post title: PenLink
    Info: cti.fyi/groups/qilin.html

    Group name: qilin
    Post title: Lercher Werkzeugbau
    Info: cti.fyi/groups/qilin.html

    #ransomware #cti #threatintelligence #cybersecurity #infosec

  5. 🚨New ransom group blog post!🚨

    Group name: blacknevas
    Post title: ASCOM S.p.A. ascom-italy.it serviced by an IT company Emilcom S.r.l. www.emilcom.it
    Info: cti.fyi/groups/blacknevas.html

    #ransomware #cti #threatintelligence #cybersecurity #infosec

  6. 🚨New ransom group blog post!🚨

    Group name: blacknevas
    Post title: ASCOM S.p.A. ascom-italy.it serviced by an IT company Emilcom S.r.l. www.emilcom.it
    Info: cti.fyi/groups/blacknevas.html

    #ransomware #cti #threatintelligence #cybersecurity #infosec

  7. Three actors. Zero sites compromised. Thousands of victims inherited.

    In the third installment of our dropcatch series, we introduce three new opportunistic scavengers: actors who don't hack websites, but dropcatch the domains previous attackers left embedded in tens of thousands of compromised sites to redirect the inherited traffic to their own operations. We call these actors Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel.

    Most notably, in collaboration with @rmceoin, we discovered Shady Squirrel began using their catalogue of dropcatch domains to send traffic to SocGholish shortly after Operation Endgame's disruption of the actor in June.

    ⛔️ Sample IOCs:
    Stuffy Squirrel: gsstats[.]ru, weatherplllatform[.]com
    Shady Squirrel: advanceslibrary[.]com, blacksaltys[.]com
    Swiping Squirrel: blackshelter[.]org, jqueryapihelpers[.]com

    Full indicators on GitHub. infoblox.com/blog/threat-intel

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #phishing

  8. Three actors. Zero sites compromised. Thousands of victims inherited.

    In the third installment of our dropcatch series, we introduce three new opportunistic scavengers: actors who don't hack websites, but dropcatch the domains previous attackers left embedded in tens of thousands of compromised sites to redirect the inherited traffic to their own operations. We call these actors Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel.

    Most notably, in collaboration with @rmceoin, we discovered Shady Squirrel began using their catalogue of dropcatch domains to send traffic to SocGholish shortly after Operation Endgame's disruption of the actor in June.

    ⛔️ Sample IOCs:
    Stuffy Squirrel: gsstats[.]ru, weatherplllatform[.]com
    Shady Squirrel: advanceslibrary[.]com, blacksaltys[.]com
    Swiping Squirrel: blackshelter[.]org, jqueryapihelpers[.]com

    Full indicators on GitHub. infoblox.com/blog/threat-intel

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #phishing

  9. 💧 🫴 Dropcatching isn't just for domain squatters, it's a goldmine for threat actors looking to hijack established trust. Some registrars make it shockingly easy to snipe high-value domains at auction, even serving up backlink metrics on a silver platter to help buyers find the best targets. A threat actor we track as Sable Squirrel took full advantage of this, spending over 💸 $7 million on dropcaught domains to push malware, run illegal sports streams, and operate a betting ring. That is the highest domain budget we've ever tracked from a single group.

    Here's a wild example of what that money buys. In January 2024, they snatched up veinteractive[.]com (previously registered with CSC Digital Brand Services) for $5.7k. It used to belong to a large London-based adtech firm. Sable Squirrel immediately turned it into an ☣️ AsyncRAT C2 and streaming hub. Because of the domain's history, tens of thousands of sites are still reaching out to it, trying to load a legacy tracking script (tag.js) and providing real-time telemetry. If Sable Squirrel was just slightly more creative, they could have easily hosted their malware on that exact URI path and pulled off a massive supply chain attack. And that's just one domain.

    We just dropped Part 2 of our series on dropcatching, breaking down Sable Squirrel's entire operation. We're sharing over 10,000 of their domains, including ones that used to belong to the US government, Fortune 100s, and major charities.

    Read the full teardown here: infoblox.com/blog/threat-intel

    Some Sable Squirrel dropcatch domains:

    thebreastcancercharities[.]org
    andromda[.]org
    d-rev[.]org
    churchofreality[.]org
    swradioafrica[.]com
    americansecuritytoday[.]com
    2026worldcupnorthamerica[.]com
    poweredbyclear[.]com
    fora[.]tv

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #asyncrat #quasarrat #hiddentear #ransomware #rat #vietnam #sportsbetting #gambling #worldcup #streaming #sports #illegal #adtech #backlink

  10. 💧 🫴 Dropcatching isn't just for domain squatters, it's a goldmine for threat actors looking to hijack established trust. Some registrars make it shockingly easy to snipe high-value domains at auction, even serving up backlink metrics on a silver platter to help buyers find the best targets. A threat actor we track as Sable Squirrel took full advantage of this, spending over 💸 $7 million on dropcaught domains to push malware, run illegal sports streams, and operate a betting ring. That is the highest domain budget we've ever tracked from a single group.

    Here's a wild example of what that money buys. In January 2024, they snatched up veinteractive[.]com (previously registered with CSC Digital Brand Services) for $5.7k. It used to belong to a large London-based adtech firm. Sable Squirrel immediately turned it into an ☣️ AsyncRAT C2 and streaming hub. Because of the domain's history, tens of thousands of sites are still reaching out to it, trying to load a legacy tracking script (tag.js) and providing real-time telemetry. If Sable Squirrel was just slightly more creative, they could have easily hosted their malware on that exact URI path and pulled off a massive supply chain attack. And that's just one domain.

    We just dropped Part 2 of our series on dropcatching, breaking down Sable Squirrel's entire operation. We're sharing over 10,000 of their domains, including ones that used to belong to the US government, Fortune 100s, and major charities.

    Read the full teardown here: infoblox.com/blog/threat-intel

    Some Sable Squirrel dropcatch domains:

    thebreastcancercharities[.]org
    andromda[.]org
    d-rev[.]org
    churchofreality[.]org
    swradioafrica[.]com
    americansecuritytoday[.]com
    2026worldcupnorthamerica[.]com
    poweredbyclear[.]com
    fora[.]tv

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #asyncrat #quasarrat #hiddentear #ransomware #rat #vietnam #sportsbetting #gambling #worldcup #streaming #sports #illegal #adtech #backlink

  11. 🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)

    OPNsense 26.7.2, released today, includes:

    `os-intrusion-detection-content-at-antiphishing 1.0`

    The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.

    This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.

    Current ecosystem integration:

    • Suricata / suricata-update
    • OPNsense
    • pfSense PR in progress

    The project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).

    📖 OPNsense Quick Guide

    For users who want to enable the ruleset on OPNsense 26.7.2:

    Quick Guide — Installing Antiphishing on OPNsense 26.7.2

    Project:
    github.com/julioliraup/Antiphi

    Vector / CTI dashboard:
    julioliraup.github.io/AT/

    #Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource

  12. 🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)

    OPNsense 26.7.2, released today, includes:

    `os-intrusion-detection-content-at-antiphishing 1.0`

    The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.

    This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.

    Current ecosystem integration:

    • Suricata / suricata-update
    • OPNsense
    • pfSense PR in progress

    The project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).

    📖 OPNsense Quick Guide

    For users who want to enable the ruleset on OPNsense 26.7.2:

    Quick Guide — Installing Antiphishing on OPNsense 26.7.2

    Project:
    github.com/julioliraup/Antiphi

    Vector / CTI dashboard:
    julioliraup.github.io/AT/

    #Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource

  13. ...the leaderboards where you can see how your contributions stack up against the rest of the community.

    Every submission helps strengthen the intelligence used by CERTs, CSIRTs, and security teams around the world to identify and take action against malicious infrastructure.
    Join the community and turn what you’re seeing into intelligence that helps protect others.

    👉 submit.spamhaus.org

    #ThreatIntelligence #CyberSecurity #Spamhaus #InfoSec #CommunityDefense

    2/2

  14. ...the leaderboards where you can see how your contributions stack up against the rest of the community.

    Every submission helps strengthen the intelligence used by CERTs, CSIRTs, and security teams around the world to identify and take action against malicious infrastructure.
    Join the community and turn what you’re seeing into intelligence that helps protect others.

    👉 submit.spamhaus.org

    #ThreatIntelligence #CyberSecurity #Spamhaus #InfoSec #CommunityDefense

    2/2

  15. ⏰ Don't Miss Your Chance to Speak at FIRST LAC 2026

    Have a story, lesson learned, tool, or innovation to share with the incident response community?
    Submit your proposal for the 2026 FIRST Regional Symposium Latin America & Caribbean and showcase your experience in areas such as:

    🔹 Incident handling case studies
    🔹 Threat intelligence
    🔹 Cloud security
    🔹 AI for incident response
    🔹 Digital forensics
    🔹 DNS, IPv6, and routing security

    📅 Deadline: August 16, 2026

    📧 first.org/events/symposium/lat

    No marketing presentations—technical and community-focused content only.

    #CallForSpeakers #FIRST #CyberSecurity #ThreatIntelligence #DigitalForensics #LACNIC46

  16. ⏰ Don't Miss Your Chance to Speak at FIRST LAC 2026

    Have a story, lesson learned, tool, or innovation to share with the incident response community?
    Submit your proposal for the 2026 FIRST Regional Symposium Latin America & Caribbean and showcase your experience in areas such as:

    🔹 Incident handling case studies
    🔹 Threat intelligence
    🔹 Cloud security
    🔹 AI for incident response
    🔹 Digital forensics
    🔹 DNS, IPv6, and routing security

    📅 Deadline: August 16, 2026

    📧 first.org/events/symposium/lat

    No marketing presentations—technical and community-focused content only.

    #CallForSpeakers #FIRST #CyberSecurity #ThreatIntelligence #DigitalForensics #LACNIC46

  17. 🚨New ransom group blog post!🚨

    Group name: blacknevas
    Post title: Jack Rutherford Customs Brokers Ltd / The Rutherford Group www.therg.ca serviced by an IT company Computer Country & Networks www.computercountry.ca
    Info: cti.fyi/groups/blacknevas.html

    #ransomware #cti #threatintelligence #cybersecurity #infosec

  18. 🚨New ransom group blog post!🚨

    Group name: blacknevas
    Post title: Jack Rutherford Customs Brokers Ltd / The Rutherford Group www.therg.ca serviced by an IT company Computer Country & Networks www.computercountry.ca
    Info: cti.fyi/groups/blacknevas.html

    #ransomware #cti #threatintelligence #cybersecurity #infosec

  19. 🚨New ransom group blog posts!🚨

    Group name: qilin
    Post title: United Association Local Union 345
    Info: cti.fyi/groups/qilin.html

    Group name: qilin
    Post title: Wanted
    Info: cti.fyi/groups/qilin.html

    #ransomware #cti #threatintelligence #cybersecurity #infosec

  20. 🚨New ransom group blog posts!🚨

    Group name: qilin
    Post title: United Association Local Union 345
    Info: cti.fyi/groups/qilin.html

    Group name: qilin
    Post title: Wanted
    Info: cti.fyi/groups/qilin.html

    #ransomware #cti #threatintelligence #cybersecurity #infosec