home.social

#urpage — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #urpage, aggregated by home.social.

  1. #introduction I have been working on targeted attacks for a long time now, first as an incident responder, and now doing threat intelligence at Trend Micro.
    I usually focus for a while on a threat actor, and when I feel I know enough, publish something about it. The fun part is that very often, while investigating a threat actor, you end up finding stuff on another one, which you can add to your TODO list once the current investigation is completed :)
    BTW, this is a good reason to be careful with the attribution out there, infrastructure overlap and tool sharing are common stuff nowadays.

    Some of my previous work on #APT groups:

    #Patchwork:
    trendmicro.com/en_us/research/
    #Confucius:
    trendmicro.com/fr_fr/research/
    trendmicro.com/en_us/research/
    #UrPage/#Bahamut:
    trendmicro.com/en_us/research/
    A bit of all previous actors:
    first.org/resources/papers/tal

    #MuddyWater:
    trendmicro.com/en_us/research/
    documents.trendmicro.com/asset

    Maybe APT37 (unconfirmed):
    trendmicro.com/en_us/research/

    #EarthAkhlut/#Tonto:
    vb2020.vblocalhost.com/uploads
    Operation DRBControl:
    trendmicro.com/vinfo/us/securi
    #EarthBerberoka:
    trendmicro.com/en_us/research/
    trendmicro.com/vinfo/us/securi
    #IronTiger/#EarthSmilodon:
    trendmicro.com/en_no/research/
    trendmicro.com/en_us/research/

  2. #introduction I have been working on targeted attacks for a long time now, first as an incident responder, and now doing threat intelligence at Trend Micro.
    I usually focus for a while on a threat actor, and when I feel I know enough, publish something about it. The fun part is that very often, while investigating a threat actor, you end up finding stuff on another one, which you can add to your TODO list once the current investigation is completed :)
    BTW, this is a good reason to be careful with the attribution out there, infrastructure overlap and tool sharing are common stuff nowadays.

    Some of my previous work on #APT groups:

    #Patchwork:
    trendmicro.com/en_us/research/
    #Confucius:
    trendmicro.com/fr_fr/research/
    trendmicro.com/en_us/research/
    #UrPage/#Bahamut:
    trendmicro.com/en_us/research/
    A bit of all previous actors:
    first.org/resources/papers/tal

    #MuddyWater:
    trendmicro.com/en_us/research/
    documents.trendmicro.com/asset

    Maybe APT37 (unconfirmed):
    trendmicro.com/en_us/research/

    #EarthAkhlut/#Tonto:
    vb2020.vblocalhost.com/uploads
    Operation DRBControl:
    trendmicro.com/vinfo/us/securi
    #EarthBerberoka:
    trendmicro.com/en_us/research/
    trendmicro.com/vinfo/us/securi
    #IronTiger/#EarthSmilodon:
    trendmicro.com/en_no/research/
    trendmicro.com/en_us/research/

  3. #introduction I have been working on targeted attacks for a long time now, first as an incident responder, and now doing threat intelligence at Trend Micro.
    I usually focus for a while on a threat actor, and when I feel I know enough, publish something about it. The fun part is that very often, while investigating a threat actor, you end up finding stuff on another one, which you can add to your TODO list once the current investigation is completed :)
    BTW, this is a good reason to be careful with the attribution out there, infrastructure overlap and tool sharing are common stuff nowadays.

    Some of my previous work on #APT groups:

    #Patchwork:
    trendmicro.com/en_us/research/
    #Confucius:
    trendmicro.com/fr_fr/research/
    trendmicro.com/en_us/research/
    #UrPage/#Bahamut:
    trendmicro.com/en_us/research/
    A bit of all previous actors:
    first.org/resources/papers/tal

    #MuddyWater:
    trendmicro.com/en_us/research/
    documents.trendmicro.com/asset

    Maybe APT37 (unconfirmed):
    trendmicro.com/en_us/research/

    #EarthAkhlut/#Tonto:
    vb2020.vblocalhost.com/uploads
    Operation DRBControl:
    trendmicro.com/vinfo/us/securi
    #EarthBerberoka:
    trendmicro.com/en_us/research/
    trendmicro.com/vinfo/us/securi
    #IronTiger/#EarthSmilodon:
    trendmicro.com/en_no/research/
    trendmicro.com/en_us/research/

  4. #introduction I have been working on targeted attacks for a long time now, first as an incident responder, and now doing threat intelligence at Trend Micro.
    I usually focus for a while on a threat actor, and when I feel I know enough, publish something about it. The fun part is that very often, while investigating a threat actor, you end up finding stuff on another one, which you can add to your TODO list once the current investigation is completed :)
    BTW, this is a good reason to be careful with the attribution out there, infrastructure overlap and tool sharing are common stuff nowadays.

    Some of my previous work on #APT groups:

    #Patchwork:
    trendmicro.com/en_us/research/
    #Confucius:
    trendmicro.com/fr_fr/research/
    trendmicro.com/en_us/research/
    #UrPage/#Bahamut:
    trendmicro.com/en_us/research/
    A bit of all previous actors:
    first.org/resources/papers/tal

    #MuddyWater:
    trendmicro.com/en_us/research/
    documents.trendmicro.com/asset

    Maybe APT37 (unconfirmed):
    trendmicro.com/en_us/research/

    #EarthAkhlut/#Tonto:
    vb2020.vblocalhost.com/uploads
    Operation DRBControl:
    trendmicro.com/vinfo/us/securi
    #EarthBerberoka:
    trendmicro.com/en_us/research/
    trendmicro.com/vinfo/us/securi
    #IronTiger/#EarthSmilodon:
    trendmicro.com/en_no/research/
    trendmicro.com/en_us/research/

  5. #introduction I have been working on targeted attacks for a long time now, first as an incident responder, and now doing threat intelligence at Trend Micro.
    I usually focus for a while on a threat actor, and when I feel I know enough, publish something about it. The fun part is that very often, while investigating a threat actor, you end up finding stuff on another one, which you can add to your TODO list once the current investigation is completed :)
    BTW, this is a good reason to be careful with the attribution out there, infrastructure overlap and tool sharing are common stuff nowadays.

    Some of my previous work on #APT groups:

    #Patchwork:
    trendmicro.com/en_us/research/
    #Confucius:
    trendmicro.com/fr_fr/research/
    trendmicro.com/en_us/research/
    #UrPage/#Bahamut:
    trendmicro.com/en_us/research/
    A bit of all previous actors:
    first.org/resources/papers/tal

    #MuddyWater:
    trendmicro.com/en_us/research/
    documents.trendmicro.com/asset

    Maybe APT37 (unconfirmed):
    trendmicro.com/en_us/research/

    #EarthAkhlut/#Tonto:
    vb2020.vblocalhost.com/uploads
    Operation DRBControl:
    trendmicro.com/vinfo/us/securi
    #EarthBerberoka:
    trendmicro.com/en_us/research/
    trendmicro.com/vinfo/us/securi
    #IronTiger/#EarthSmilodon:
    trendmicro.com/en_no/research/
    trendmicro.com/en_us/research/