#threatintelligence
197 posts · Last used 9d
(truesec.com) Denmark Raises Threat Level for Destructive Cyberattacks Amid Escalating Russian Hybrid Warfare
In brief - This article discusses the increased risk of destructive cyberattacks in Denmark and Europe, driven by Russian hybrid warfare aimed at pressuring nations to reduce support for Ukraine.
Technically - This article categorizes the threat landscape into cybercrime, espionage, and cyber warfare, noting that while crime remains the most common threat, Russian state-sponsored activity is escalating. Technical vectors identified include Distributed Denial of Service (DDoS) attacks, the compromise of CCTV systems, and the manipulation of unprotected critical infrastructure components. Furthermore, the report highlights the use of proxy or disposable agents to target defense sector supply chains, factories, and warehouses through destructive cyber operations.
Source: https://www.truesec.com/hub/blog/danish-intelligence-services-raises-threat-for-destructive-cyberattacks
#ThreatIntelligence #ThreatIntel #Cybersecurity #Infosec
🚨New ransom group blog post!🚨
Group name: cry0
Post title: MinMor Industries
Info: https://cti.fyi/groups/cry0.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
Quiz time: which of these domains is impersonating Apple?
quizearny[.]shop, rewardquiz[.]org look like generic quiz sites. applerewards[.]net is more obvious. All of them belong to a cluster serving identical Apple impersonation content, prompting victims to claim an Apple gift card reward by handing over their personal details. testar[.]ink, "to test", was the first to be created, nearly a month before the others went live, which may say something about how this campaign got started.
What makes this cluster more interesting is what happens after you click the "Claim Your Apple Reward" button on the initial page. Different locations, different device types, different destinations. Classic TDS.
This cluster is a good reminder that brand impersonation lives in the page content, not just the domain name. A quiz site with no Apple in its name can be just as dangerous as an obvious lookalike.
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #axur #lookalike #scam #tds
validx[.]shop looked fine at first glance. "Normal" name servers, a real mail setup, nothing that immediately stood out at the apex level. One subdomain didn't quite fit, though. It was getting DNS queries that were absurdly long and frequent for a new domain that nobody was really visiting. Rather than that being web traffic, we detected it as likely tunneling.
Turns out it wasn't a one-off. The same setup shows up on hundreds of other domains.
The domain names follow a similar pattern: short, brandable and portmanteau-y (i.e., cordkit, zenithly, queuebox), spread across a long list of cheap gTLDs with the same registrar.
The tunnel itself is answering with TXT records like:
⚠️ "H2;n=5;k=3;ol=2004;sz=800;cz=gz"
As best as we can tell, that's a shard count, a reconstruction threshold, a length, a chunk size, and a compression flag. We checked the signature against a number of known DNS tunnelling tools and none of them write a header like this.
We watched two more domains get registered mid-investigation, hours apart, which was fun to see and immediately block
We've got the infrastructure and the method. We haven't got a payload, and we haven't matched this header format to anything documented publicly.
Has anyone else run into this, recognize the TXT format above, or have a sample of a possible malware source? We'd like to hear from you.
⛔ validx[.]shop
⛔ cordkit[.]online
⛔ zenithly[.]best
☠️ 95[.]179[.]159[.]229
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #c2
🚨New ransom group blog post!🚨
Group name: incransom
Post title: bakemyday.se
Info: https://cti.fyi/groups/incransom.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
🚨New ransom group blog posts!🚨
Group name: AuditTeam
Post title: vit.ac.in
Info: https://cti.fyi/groups/AuditTeam.html
Group name: AuditTeam
Post title: TEK SPB
Info: https://cti.fyi/groups/AuditTeam.html
Group name: AuditTeam
Post title: kit-e.jp
Info: https://cti.fyi/groups/AuditTeam.html
Group name: AuditTeam
Post title: krimax.org
Info: https://cti.fyi/groups/AuditTeam.html
Group name: AuditTeam
Post title: gownet.net
Info: https://cti.fyi/groups/AuditTeam.html
Group name: AuditTeam
Post title: dg.ac.kr
Info: https://cti.fyi/groups/AuditTeam.html
Group name: AuditTeam
Post title: buben
Info: https://cti.fyi/groups/AuditTeam.html
Group name: AuditTeam
Post title: Wise IT
Info: https://cti.fyi/groups/AuditTeam.html
Group name: AuditTeam
Post title: palletshop
Info: https://cti.fyi/groups/AuditTeam.html
Group name: AuditTeam
Post title: PIT.local
Info: https://cti.fyi/groups/AuditTeam.html
Group name: AuditTeam
Post title: mansurovogroup
Info: https://cti.fyi/groups/AuditTeam.html
Group name: AuditTeam
Post title: Demidov Steel Group
Info: https://cti.fyi/groups/AuditTeam.html
Group name: AuditTeam
Post title: I-SYS
Info: https://cti.fyi/groups/AuditTeam.html
Group name: AuditTeam
Post title: Mopas Online Supermarket
Info: https://cti.fyi/groups/AuditTeam.html
Group name: AuditTeam
Post title: Trésor Public
Info: https://cti.fyi/groups/AuditTeam.html
Group name: AuditTeam
Post title: joycity
Info: https://cti.fyi/groups/AuditTeam.html
Group name: AuditTeam
Post title: Kawasaki Motors Philippines Corporation
Info: https://cti.fyi/groups/AuditTeam.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
🚨New ransom group blog posts!🚨
Group name: qilin
Post title: Island
Info: https://cti.fyi/groups/qilin.html
Group name: qilin
Post title: XICO
Info: https://cti.fyi/groups/qilin.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
Netskope observed malicious Google Ads redirecting to cross-platform tech-support scams affecting Windows and macOS users across 619 organizations. The abuse of trusted ad delivery on high-traffic sites bypasses traditional web filtering and increases social engineering success. #Malvertising #TechSupportScam #ThreatIntelligence
https://cyberworldops.eu/en/malicious-google-ads-turn-browser-tricks-into-cross-platform-tech
----------------
🦠 Malware Analysis
===================
Settra is a ransomware operation first identified in June 2026 that has already claimed 50-70+ enterprise victims across technology, manufacturing, financial services, healthcare, and retail sectors. The group operates double-extortion: data exfiltration followed by encryption and ransom negotiation via Tox and darknet portals.
🔹 Intrusion Methodology
Human-operated intrusions begin through compromised VPNs or valid accounts. Credential dumping uses Mimikatz and ProcDump. Lateral movement relies on dual-use tools including PAExec and NetExec. Durable remote access is established via Mesh Agent.
Before encryption, operators abuse signed STProcessMonitor drivers via BYOVD to blind endpoint defenses.
🔹 Encryptor Architecture
The encryptor is a two-stage design recovered through offline static reverse engineering by Cynet Research Labs.
Outer loader (win64.exe):
• Password-gated entry
• PEB export hashing for API resolution
• Anti-debugging gates
• ~200,000-round SHA-256 KDF for key derivation
• AES-256-CTR decryption of inner payload
• Custom LP77 decompression
• Process hollowing into a suspended self-copy
Inner PE payload executes systematic anti-forensics:
• Wipes 12 targeted event logs via wevtutil
• Purges Windows Prefetch
• Deletes PowerShell command history
• Wipes USN change journals
• Disables Windows Recovery (reagentc, bcdedit, wbadmin, Disable-ComputerRestore)
• Resizes VSS shadow storage stealthily
• Powers down Hyper-V VMs via WMI (ROOT\virtualization\v2) to release .vhdx file locks
🔹 Cryptography
Files encrypted using Windows CNG (BCryptGenRandom, BCryptEncrypt) with unique symmetric keys wrapped by an embedded 4096-bit RSA-1 public key. Files renamed to .locked (preceded by temporary .locked_wip). The RSA private key is never present on the victim host. The encryptor contains zero C2 network communication stacks, making it fully offline.
🔹 Detection Claims
Cynet claims proactive interception within 1 second of detonation via kernel-level driver decoy traps. This is a vendor claim from the same organization that performed the analysis, so treat with appropriate skepticism.
🔹 Key Takeaways
The encryptor design is notable for its complete lack of network communication, heavy anti-forensics targeting recovery infrastructure, and deliberate Hyper-V shutdown to access locked virtual disks. The BYOVD approach using signed STProcessMonitor drivers is increasingly common in ransomware operations.
🔹 ransomware #malware #threatintelligence #BYOVD #reverseengineering
🔗 Source: https://www.cynet.com/settra-ransomware-inside-a-new-enterprise-grade-extortion-threat/
Analysis of the 2005-2008 Exploit.in dump (9,647 accounts, 80,891 posts) links early forum users to later ransomware ecosystem actors. Username matches suggest continuity but are insufficient for attribution alone, highlighting a small durable core. #Cybercrime #Ransomware #ThreatIntelligence
https://cyberworldops.eu/en/inside-exploitin-s-early-database-the-small-core-behind-a-durable
Replying to
Reward: You've received the Summer 2026 Memorial Plaque. It hangs where your incident response plan used to be.
https://www.darkreading.com/cyberattacks-data-breaches/3-cyber-threats-defined-summer-2026
#CyberSecurity #Ransomware #ThreatIntelligence #CriticalInfrastructure #AISecurityThreats #SummerOfCyberChaos (3/3)
🚨New ransom group blog post!🚨
Group name: incransom
Post title: pharma5.ma
Info: https://cti.fyi/groups/incransom.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
Replying to
Reward: You've received a laminated Storm-2570 Awareness Certificate. It does not stop ransomware.
https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments
#Ransomware #ThreatIntelligence #Storm2570 #CyberSecurity #APT #FollowTheTrail (3/3)
🚨New ransom group blog posts!🚨
Group name: Spirals
Post title: Armada Credit Bureau
Info: https://cti.fyi/groups/Spirals.html
Group name: Spirals
Post title: ASYAD GROUP
Info: https://cti.fyi/groups/Spirals.html
Group name: N0n
Post title: FinSoft (Kolibri retail back-office software)
Info: https://cti.fyi/groups/N0n.html
Group name: N0n
Post title: AFRICA-TECH (IT services / document processing)
Info: https://cti.fyi/groups/N0n.html
Group name: N0n
Post title: Fanatics (global sports commerce platform)
Info: https://cti.fyi/groups/N0n.html
Group name: N0n
Post title: United Federation of Teachers
Info: https://cti.fyi/groups/N0n.html
Group name: N0n
Post title: AstraZeneca Türkiye
Info: https://cti.fyi/groups/N0n.html
Group name: N0n
Post title: BeLi Teacher / FSC education centers (AWS)
Info: https://cti.fyi/groups/N0n.html
Group name: N0n
Post title: Argentem Creek Partners (investment firm)
Info: https://cti.fyi/groups/N0n.html
Group name: N0n
Post title: Ministry of Education — Argentina
Info: https://cti.fyi/groups/N0n.html
Group name: N0n
Post title: PayPal support operations (Transcom WorldWide)
Info: https://cti.fyi/groups/N0n.html
Group name: N0n
Post title: STOKR (digital securities platform)
Info: https://cti.fyi/groups/N0n.html
Group name: N0n
Post title: Vietnamese betting operator (GC789 network / Boundless TE)
Info: https://cti.fyi/groups/N0n.html
Group name: N0n
Post title: Konnatus (usucapião legal services)
Info: https://cti.fyi/groups/N0n.html
Group name: N0n
Post title: Inter (Venezuela's largest internet provider)
Info: https://cti.fyi/groups/N0n.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
(intel471.com) SANS 2026 Threat Hunting Survey: Adversaries Prioritize Stealth Over Speed as Defenders Reevaluate AI's Role
In brief - This article discusses the 2026 SANS Threat Hunting Survey, highlighting a shift where adversaries prioritize stealth and living-off-the-land techniques over speed, while defenders face challenges with data quality and a cooling interest in AI-driven hunting.
Technically - This article analyzes the prevalence of 'living-off-the-land' (LotL) tactics, noting that 72.7% of nation-state actors use legitimate admin tools to blend into system activity. It emphasizes the use of anti-forensic tradecraft, such as clearing Windows Event Logs (via wevtutil) and deleting shadow copies to inhibit recovery. The text identifies MITRE ATT&CK technique T1041 (Exfiltration Over C2 Channel) as a dominant observation and stresses the necessity of behavioral baselining to identify anomalies in process lineages and account interactions. Furthermore, it addresses the technical debt of poor data engineering, specifically the lack of normalization across disparate telemetry sources and the risk of visibility gaps created by misconfigured API gateways and SSO proxies.
Source: https://www.intel471.com/blog/2026-sans-threat-hunting-survey-adversaries-prizing-stealth-over-speed-defenders-cooling-on-ai
#ThreatIntelligence #ThreatIntel #Cybersecurity #Infosec
🚨New ransom group blog posts!🚨
Group name: pear
Post title: Indroj Medical Group Inc.
Info: https://cti.fyi/groups/pear.html
Group name: pear
Post title: Martin Lawrence Galleries
Info: https://cti.fyi/groups/pear.html
Group name: pear
Post title: Westside GI
Info: https://cti.fyi/groups/pear.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
The best time to block the finger protocol (port 79/tcp) outbound from your network was like…the second Clinton administration? But now's a good time too.
#ThreatIntel #ThreatIntelligence #IFIN
🚨New ransom group blog posts!🚨
Group name: Booba Project
Post title: Smart Eye Care
Info: https://cti.fyi/groups/Booba Project.html
Group name: Booba Project
Post title: The Merrimack County
Info: https://cti.fyi/groups/Booba Project.html
Group name: Booba Project
Post title: COSEF - Consorzio di Sviluppo Economico del Friuli
Info: https://cti.fyi/groups/Booba Project.html
#ransomware #cti #threatintelligence #cybersecurity #infosec
Two Check Point critical vulnerabilities are now listed as exploited in the wild.
https://ifin.network/t/cve-2026-85102-and-93616-check-point-security-gateway-rce-path-traversal-exploited/853
#ThreatIntel #ThreatIntelligence #IFIN
🚨New ransom group blog posts!🚨
Group name: BrainCipher
Post title: ACCSync29042019.BAK
Info: https://cti.fyi/groups/BrainCipher.html
Group name: BrainCipher
Post title: BeforeDocSync.BAK
Info: https://cti.fyi/groups/BrainCipher.html
Group name: BrainCipher
Post title: BeforeRemovingNewthings_19052025.bak
Info: https://cti.fyi/groups/BrainCipher.html
Group name: BrainCipher
Post title: COMPANY.zip
Info: https://cti.fyi/groups/BrainCipher.html
Group name: BrainCipher
Post title: Com_ON_20052025BF4Restore.BAK
Info: https://cti.fyi/groups/BrainCipher.html
Group name: BrainCipher
Post title: DATA.zip
Info: https://cti.fyi/groups/BrainCipher.html
Group name: BrainCipher
Post title: Desktop.david.zip
Info: https://cti.fyi/groups/BrainCipher.html
Group name: BrainCipher
Post title: FANTASY_SRV.zip
Info: https://cti.fyi/groups/BrainCipher.html
Group name: BrainCipher
Post title: HRD_Lab_Results.BAK
Info: https://cti.fyi/groups/BrainCipher.html
Group name: BrainCipher
Post title: IGI_Lab_Results.BAK
Info: https://cti.fyi/groups/BrainCipher.html
Group name: BrainCipher
Post title: Report Project1.rptproj.bak
Info: https://cti.fyi/groups/BrainCipher.html
Group name: BrainCipher
Post title: WEX.zip
Info: https://cti.fyi/groups/BrainCipher.html
Group name: BrainCipher
Post title: WINDIAM_ACC_ON_backup_2026_07_18_220022_2852655.bak
Info: https://cti.fyi/groups/BrainCipher.html
Group name: BrainCipher
Post title: WINDIAM_COM_ON_backup_2026_07_18_220022_3321457.bak
Info: https://cti.fyi/groups/BrainCipher.html
Group name: BrainCipher
Post title: Windiam_ACC_OFF.BAK
Info: https://cti.fyi/groups/BrainCipher.html
Group name: BrainCipher
Post title: Windiam_ACC_OFF_backup_2019_05_02_220006_8273415.bak
Info: https://cti.fyi/groups/BrainCipher.html
Group name: BrainCipher
Post title: Windiam_B4V_2018_07_08.bak
Info: https://cti.fyi/groups/BrainCipher.html
Group name: BrainCipher
Post title: Windiam_to_clean.BAK
Info: https://cti.fyi/groups/BrainCipher.html
Group name: BrainCipher
Post title: rst.zip
Info: https://cti.fyi/groups/BrainCipher.html
Group name: BrainCipher
Post title: windiam_net_ON_OpenStock.BAK
Info: https://cti.fyi/groups/BrainCipher.html
#ransomware #cti #threatintelligence #cybersecurity #infosec





