#threatintelligence — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #threatintelligence, aggregated by home.social.
-
🚨New ransom group blog post!🚨
Group name: qilin
Post title: FERRARI MANGIMI SRL
Info: https://cti.fyi/groups/qilin.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: qilin
Post title: FERRARI MANGIMI SRL
Info: https://cti.fyi/groups/qilin.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: safepay
Post title: granjarinya.com
Info: https://cti.fyi/groups/safepay.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: safepay
Post title: granjarinya.com
Info: https://cti.fyi/groups/safepay.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: interlock
Post title: Connell Enterprises LLC
Info: https://cti.fyi/groups/interlock.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: interlock
Post title: Connell Enterprises LLC
Info: https://cti.fyi/groups/interlock.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: qilin
Post title: Connections
Info: https://cti.fyi/groups/qilin.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: qilin
Post title: Connections
Info: https://cti.fyi/groups/qilin.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: qilin
Post title: Aletex Group
Info: https://cti.fyi/groups/qilin.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: qilin
Post title: Aletex Group
Info: https://cti.fyi/groups/qilin.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog posts!🚨
Group name: akira
Post title: Basic Grain Products
Info: https://cti.fyi/groups/akira.htmlGroup name: akira
Post title: CF Supply
Info: https://cti.fyi/groups/akira.htmlGroup name: akira
Post title: Alcast
Info: https://cti.fyi/groups/akira.htmlGroup name: akira
Post title: i4 Solutions
Info: https://cti.fyi/groups/akira.htmlGroup name: akira
Post title: One Vision Imaging
Info: https://cti.fyi/groups/akira.htmlGroup name: qilin
Post title: Radiant
Info: https://cti.fyi/groups/qilin.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog posts!🚨
Group name: akira
Post title: Basic Grain Products
Info: https://cti.fyi/groups/akira.htmlGroup name: akira
Post title: CF Supply
Info: https://cti.fyi/groups/akira.htmlGroup name: akira
Post title: Alcast
Info: https://cti.fyi/groups/akira.htmlGroup name: akira
Post title: i4 Solutions
Info: https://cti.fyi/groups/akira.htmlGroup name: akira
Post title: One Vision Imaging
Info: https://cti.fyi/groups/akira.htmlGroup name: qilin
Post title: Radiant
Info: https://cti.fyi/groups/qilin.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog posts!🚨
Group name: qilin
Post title: Urban Worldwide
Info: https://cti.fyi/groups/qilin.htmlGroup name: qilin
Post title: PenLink
Info: https://cti.fyi/groups/qilin.htmlGroup name: qilin
Post title: Lercher Werkzeugbau
Info: https://cti.fyi/groups/qilin.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog posts!🚨
Group name: qilin
Post title: Urban Worldwide
Info: https://cti.fyi/groups/qilin.htmlGroup name: qilin
Post title: PenLink
Info: https://cti.fyi/groups/qilin.htmlGroup name: qilin
Post title: Lercher Werkzeugbau
Info: https://cti.fyi/groups/qilin.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: ransomhouse
Post title: [DISCLOSED]PCL Holding
Info: https://cti.fyi/groups/ransomhouse.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: ransomhouse
Post title: [DISCLOSED]PCL Holding
Info: https://cti.fyi/groups/ransomhouse.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: blacknevas
Post title: ASCOM S.p.A. ascom-italy.it serviced by an IT company Emilcom S.r.l. www.emilcom.it
Info: https://cti.fyi/groups/blacknevas.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: blacknevas
Post title: ASCOM S.p.A. ascom-italy.it serviced by an IT company Emilcom S.r.l. www.emilcom.it
Info: https://cti.fyi/groups/blacknevas.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: incransom
Post title: https://pacific-construction.com/
Info: https://cti.fyi/groups/incransom.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: incransom
Post title: https://pacific-construction.com/
Info: https://cti.fyi/groups/incransom.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: incransom
Post title: cambrialawfirm.com
Info: https://cti.fyi/groups/incransom.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: incransom
Post title: cambrialawfirm.com
Info: https://cti.fyi/groups/incransom.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: ransomhouse
Post title: [DISCLOSED]TECHVENTURES BANK S.A.
Info: https://cti.fyi/groups/ransomhouse.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: ransomhouse
Post title: [DISCLOSED]TECHVENTURES BANK S.A.
Info: https://cti.fyi/groups/ransomhouse.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
Three actors. Zero sites compromised. Thousands of victims inherited.
In the third installment of our dropcatch series, we introduce three new opportunistic scavengers: actors who don't hack websites, but dropcatch the domains previous attackers left embedded in tens of thousands of compromised sites to redirect the inherited traffic to their own operations. We call these actors Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel.
Most notably, in collaboration with @rmceoin, we discovered Shady Squirrel began using their catalogue of dropcatch domains to send traffic to SocGholish shortly after Operation Endgame's disruption of the actor in June.
⛔️ Sample IOCs:
Stuffy Squirrel: gsstats[.]ru, weatherplllatform[.]com
Shady Squirrel: advanceslibrary[.]com, blacksaltys[.]com
Swiping Squirrel: blackshelter[.]org, jqueryapihelpers[.]comFull indicators on GitHub. https://www.infoblox.com/blog/threat-intelligence/dropcatch-scavengers-expired-malicious-domains-become-cash-cows/
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #phishing
-
Three actors. Zero sites compromised. Thousands of victims inherited.
In the third installment of our dropcatch series, we introduce three new opportunistic scavengers: actors who don't hack websites, but dropcatch the domains previous attackers left embedded in tens of thousands of compromised sites to redirect the inherited traffic to their own operations. We call these actors Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel.
Most notably, in collaboration with @rmceoin, we discovered Shady Squirrel began using their catalogue of dropcatch domains to send traffic to SocGholish shortly after Operation Endgame's disruption of the actor in June.
⛔️ Sample IOCs:
Stuffy Squirrel: gsstats[.]ru, weatherplllatform[.]com
Shady Squirrel: advanceslibrary[.]com, blacksaltys[.]com
Swiping Squirrel: blackshelter[.]org, jqueryapihelpers[.]comFull indicators on GitHub. https://www.infoblox.com/blog/threat-intelligence/dropcatch-scavengers-expired-malicious-domains-become-cash-cows/
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #phishing
-
🚨New ransom group blog post!🚨
Group name: SilentRansomGroup
Post title: R...er
Info: https://cti.fyi/groups/SilentRansomGroup.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: SilentRansomGroup
Post title: R...er
Info: https://cti.fyi/groups/SilentRansomGroup.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
💧 🫴 Dropcatching isn't just for domain squatters, it's a goldmine for threat actors looking to hijack established trust. Some registrars make it shockingly easy to snipe high-value domains at auction, even serving up backlink metrics on a silver platter to help buyers find the best targets. A threat actor we track as Sable Squirrel took full advantage of this, spending over 💸 $7 million on dropcaught domains to push malware, run illegal sports streams, and operate a betting ring. That is the highest domain budget we've ever tracked from a single group.
Here's a wild example of what that money buys. In January 2024, they snatched up veinteractive[.]com (previously registered with CSC Digital Brand Services) for $5.7k. It used to belong to a large London-based adtech firm. Sable Squirrel immediately turned it into an ☣️ AsyncRAT C2 and streaming hub. Because of the domain's history, tens of thousands of sites are still reaching out to it, trying to load a legacy tracking script (tag.js) and providing real-time telemetry. If Sable Squirrel was just slightly more creative, they could have easily hosted their malware on that exact URI path and pulled off a massive supply chain attack. And that's just one domain.
We just dropped Part 2 of our series on dropcatching, breaking down Sable Squirrel's entire operation. We're sharing over 10,000 of their domains, including ones that used to belong to the US government, Fortune 100s, and major charities.
Read the full teardown here: https://www.infoblox.com/blog/threat-intelligence/7-million-in-expired-domains-fuel-a-streaming-empire-with-a-malware-secret/
Some Sable Squirrel dropcatch domains:
thebreastcancercharities[.]org
andromda[.]org
d-rev[.]org
churchofreality[.]org
swradioafrica[.]com
americansecuritytoday[.]com
2026worldcupnorthamerica[.]com
poweredbyclear[.]com
fora[.]tv#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #asyncrat #quasarrat #hiddentear #ransomware #rat #vietnam #sportsbetting #gambling #worldcup #streaming #sports #illegal #adtech #backlink
-
💧 🫴 Dropcatching isn't just for domain squatters, it's a goldmine for threat actors looking to hijack established trust. Some registrars make it shockingly easy to snipe high-value domains at auction, even serving up backlink metrics on a silver platter to help buyers find the best targets. A threat actor we track as Sable Squirrel took full advantage of this, spending over 💸 $7 million on dropcaught domains to push malware, run illegal sports streams, and operate a betting ring. That is the highest domain budget we've ever tracked from a single group.
Here's a wild example of what that money buys. In January 2024, they snatched up veinteractive[.]com (previously registered with CSC Digital Brand Services) for $5.7k. It used to belong to a large London-based adtech firm. Sable Squirrel immediately turned it into an ☣️ AsyncRAT C2 and streaming hub. Because of the domain's history, tens of thousands of sites are still reaching out to it, trying to load a legacy tracking script (tag.js) and providing real-time telemetry. If Sable Squirrel was just slightly more creative, they could have easily hosted their malware on that exact URI path and pulled off a massive supply chain attack. And that's just one domain.
We just dropped Part 2 of our series on dropcatching, breaking down Sable Squirrel's entire operation. We're sharing over 10,000 of their domains, including ones that used to belong to the US government, Fortune 100s, and major charities.
Read the full teardown here: https://www.infoblox.com/blog/threat-intelligence/7-million-in-expired-domains-fuel-a-streaming-empire-with-a-malware-secret/
Some Sable Squirrel dropcatch domains:
thebreastcancercharities[.]org
andromda[.]org
d-rev[.]org
churchofreality[.]org
swradioafrica[.]com
americansecuritytoday[.]com
2026worldcupnorthamerica[.]com
poweredbyclear[.]com
fora[.]tv#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #asyncrat #quasarrat #hiddentear #ransomware #rat #vietnam #sportsbetting #gambling #worldcup #streaming #sports #illegal #adtech #backlink
-
🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)
OPNsense 26.7.2, released today, includes:
`os-intrusion-detection-content-at-antiphishing 1.0`
The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.
This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.
Current ecosystem integration:
• Suricata / suricata-update
• OPNsense
• pfSense PR in progressThe project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).
📖 OPNsense Quick Guide
For users who want to enable the ruleset on OPNsense 26.7.2:
Quick Guide — Installing Antiphishing on OPNsense 26.7.2
Project:
https://github.com/julioliraup/AntiphishingVector / CTI dashboard:
https://julioliraup.github.io/AT/#Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource
-
🛡️ Antiphishing is now officially available in @opnsense.org (@suricata IDPS)
OPNsense 26.7.2, released today, includes:
`os-intrusion-detection-content-at-antiphishing 1.0`
The plugin integrates the Antiphishing Suricata ruleset into the OPNsense ecosystem.
This is another step toward making community-driven Threat Intelligence directly consumable at the network enforcement layer.
Current ecosystem integration:
• Suricata / suricata-update
• OPNsense
• pfSense PR in progressThe project also recently added NRD-based threat intelligence for proactive phishing infrastructure detection (Suspect domains).
📖 OPNsense Quick Guide
For users who want to enable the ruleset on OPNsense 26.7.2:
Quick Guide — Installing Antiphishing on OPNsense 26.7.2
Project:
https://github.com/julioliraup/AntiphishingVector / CTI dashboard:
https://julioliraup.github.io/AT/#Suricata #OPNsense #ThreatIntelligence #CTI #DetectionEngineering #IDS #IPS #OpenSource
-
🚨New ransom group blog post!🚨
Group name: dragonforce
Post title: GB Group S.A
Info: https://cti.fyi/groups/dragonforce.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: dragonforce
Post title: GB Group S.A
Info: https://cti.fyi/groups/dragonforce.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: qilin
Post title: D & J Beverage Service
Info: https://cti.fyi/groups/qilin.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: qilin
Post title: D & J Beverage Service
Info: https://cti.fyi/groups/qilin.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
...the leaderboards where you can see how your contributions stack up against the rest of the community.
Every submission helps strengthen the intelligence used by CERTs, CSIRTs, and security teams around the world to identify and take action against malicious infrastructure.
Join the community and turn what you’re seeing into intelligence that helps protect others.#ThreatIntelligence #CyberSecurity #Spamhaus #InfoSec #CommunityDefense
2/2
-
...the leaderboards where you can see how your contributions stack up against the rest of the community.
Every submission helps strengthen the intelligence used by CERTs, CSIRTs, and security teams around the world to identify and take action against malicious infrastructure.
Join the community and turn what you’re seeing into intelligence that helps protect others.#ThreatIntelligence #CyberSecurity #Spamhaus #InfoSec #CommunityDefense
2/2
-
⏰ Don't Miss Your Chance to Speak at FIRST LAC 2026
Have a story, lesson learned, tool, or innovation to share with the incident response community?
Submit your proposal for the 2026 FIRST Regional Symposium Latin America & Caribbean and showcase your experience in areas such as:🔹 Incident handling case studies
🔹 Threat intelligence
🔹 Cloud security
🔹 AI for incident response
🔹 Digital forensics
🔹 DNS, IPv6, and routing security📅 Deadline: August 16, 2026
📧 https://www.first.org/events/symposium/latam2026/
No marketing presentations—technical and community-focused content only.
#CallForSpeakers #FIRST #CyberSecurity #ThreatIntelligence #DigitalForensics #LACNIC46
-
⏰ Don't Miss Your Chance to Speak at FIRST LAC 2026
Have a story, lesson learned, tool, or innovation to share with the incident response community?
Submit your proposal for the 2026 FIRST Regional Symposium Latin America & Caribbean and showcase your experience in areas such as:🔹 Incident handling case studies
🔹 Threat intelligence
🔹 Cloud security
🔹 AI for incident response
🔹 Digital forensics
🔹 DNS, IPv6, and routing security📅 Deadline: August 16, 2026
📧 https://www.first.org/events/symposium/latam2026/
No marketing presentations—technical and community-focused content only.
#CallForSpeakers #FIRST #CyberSecurity #ThreatIntelligence #DigitalForensics #LACNIC46
-
🚨New ransom group blog post!🚨
Group name: payload
Post title: Zara Investment Holding
Info: https://cti.fyi/groups/payload.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: payload
Post title: Zara Investment Holding
Info: https://cti.fyi/groups/payload.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog posts!🚨
Group name: AiLock
Post title: Yaomasa
Info: https://cti.fyi/groups/AiLock.htmlGroup name: AiLock
Post title: DAISEN
Info: https://cti.fyi/groups/AiLock.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog posts!🚨
Group name: AiLock
Post title: Yaomasa
Info: https://cti.fyi/groups/AiLock.htmlGroup name: AiLock
Post title: DAISEN
Info: https://cti.fyi/groups/AiLock.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: incransom
Post title: clgroup
Info: https://cti.fyi/groups/incransom.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: incransom
Post title: clgroup
Info: https://cti.fyi/groups/incransom.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: blacknevas
Post title: Jack Rutherford Customs Brokers Ltd / The Rutherford Group www.therg.ca serviced by an IT company Computer Country & Networks www.computercountry.ca
Info: https://cti.fyi/groups/blacknevas.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: blacknevas
Post title: Jack Rutherford Customs Brokers Ltd / The Rutherford Group www.therg.ca serviced by an IT company Computer Country & Networks www.computercountry.ca
Info: https://cti.fyi/groups/blacknevas.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: kairos
Post title: Hightech Signs
Info: https://cti.fyi/groups/kairos.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: kairos
Post title: Hightech Signs
Info: https://cti.fyi/groups/kairos.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: incransom
Post title: gamaus.com
Info: https://cti.fyi/groups/incransom.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog post!🚨
Group name: incransom
Post title: gamaus.com
Info: https://cti.fyi/groups/incransom.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog posts!🚨
Group name: qilin
Post title: United Association Local Union 345
Info: https://cti.fyi/groups/qilin.htmlGroup name: qilin
Post title: Wanted
Info: https://cti.fyi/groups/qilin.html#ransomware #cti #threatintelligence #cybersecurity #infosec
-
🚨New ransom group blog posts!🚨
Group name: qilin
Post title: United Association Local Union 345
Info: https://cti.fyi/groups/qilin.htmlGroup name: qilin
Post title: Wanted
Info: https://cti.fyi/groups/qilin.html#ransomware #cti #threatintelligence #cybersecurity #infosec