Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

The DFIR Report

@TheDFIRReport@infosec.exchange
  • Open on infosec.exchange

Real Intrusions by Real Attackers, the Truth Behind the Intrusion.

Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |

0 Followers
0 Following
14 Posts
Joined November 10, 2022

Posts

Open post
TheDFIRReport
The DFIR Report @TheDFIRReport@infosec.exchange · Aug 07, 2026
The DFIR Report
@TheDFIRReport@infosec.exchange

Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |

infosec.exchange
👤 Analyst Spotlight: Mattie Schuch A cyber threat hunter and detection enthusiast with almost a decade in cyber, focused on building detections, tracking threat actors, and making sense of the chaos they leave behind. Explore their work on The DFIR Report: https://thedfirreport.com/analyst/mittensec/
0
0
0
0
Open post
TheDFIRReport
The DFIR Report @TheDFIRReport@infosec.exchange · Aug 04, 2026
The DFIR Report
@TheDFIRReport@infosec.exchange

Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |

infosec.exchange
EtherRAT brought blockchain-backed C2 into this intrusion. A malicious MSI masquerading as Sysinternals RAMMap deployed EtherRAT, which used EtherHiding to retrieve Ethereum-hosted C2 config updates before pivoting to TryCloudflare infrastructure. Full report: https://thedfirreport.com/2026/05/11/flash-alert-etherrat-and-tuktuk-c2-end-in-the-gentleman-ransomware/ #DFIR #ThreatIntel #DigitalForensics
0
0
0
0
Open post
TheDFIRReport
The DFIR Report @TheDFIRReport@infosec.exchange · Aug 03, 2026
The DFIR Report
@TheDFIRReport@infosec.exchange

Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |

infosec.exchange
From smaller data sets to complex cases, DFIR Labs has case studies you can work through at your own pace — from your first investigation all the way to expert level. Start digging in 👉 https://thedfirreport.com/products/dfir-labs/
0
0
0
0
Open post
TheDFIRReport
The DFIR Report @TheDFIRReport@infosec.exchange · Jul 31, 2026
The DFIR Report
@TheDFIRReport@infosec.exchange

Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |

infosec.exchange
Use DFIR Report’s Threat Feed to gain early, actionable insight into attacker infrastructure before it becomes mainstream. Check it out here 👉 https://thedfirreport.com/products/threat-feed/
0
0
0
0
Open post
TheDFIRReport
The DFIR Report @TheDFIRReport@infosec.exchange · Jul 29, 2026
The DFIR Report
@TheDFIRReport@infosec.exchange

Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |

infosec.exchange
Did you know you can get notified when we publish a new report? Subscribe to our mailing list and receive updates directly in your inbox: https://thedfirreport.com/subscribe/
0
0
0
0
Open post
TheDFIRReport
The DFIR Report @TheDFIRReport@infosec.exchange · Jul 27, 2026
The DFIR Report
@TheDFIRReport@infosec.exchange

Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |

infosec.exchange
RDP bitmap cache artifacts revealed the threat actor opening the Veeam Backup & Replication console, reviewing backup jobs, tape & storage infrastructure — and removing backups from the configuration database. Full report 👇 https://thedfirreport.com/2025/12/17/cats-got-your-files-lynx-ransomware/
0
0
0
0
Open post
TheDFIRReport
The DFIR Report @TheDFIRReport@infosec.exchange · Jul 24, 2026
The DFIR Report
@TheDFIRReport@infosec.exchange

Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |

infosec.exchange
🔒 Private DFIR Reports — From the Front Lines of Incident Response Go beyond high-level threat summaries. Our Private DFIR Reports deliver unredacted, evidence-based intrusion analysis drawn directly from real investigations. Each report provides a ground-truth view of how modern intrusions unfold with detailed timelines, command lines, file paths, and forensic artifacts. 📩 Contact us for details and examples. https://thedfirreport.com/products/threat-intel/private-dfir-reports/
0
0
0
0
Open post
TheDFIRReport
The DFIR Report @TheDFIRReport@infosec.exchange · Jul 21, 2026
The DFIR Report
@TheDFIRReport@infosec.exchange

Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |

infosec.exchange
🐱 Cat’s Got Your Files: Dive Into the Lynx Ransomware Incident! Check out our latest DFIR Report detailing how attackers abused valid credentials to compromise an environment, create persistent high-privilege accounts, and conduct environment mapping and exfiltration before deploying Lynx ransomware. Report: https://thedfirreport.com/2025/11/17/cats-got-your-files-lynx-ransomware/
0
0
0
0
Open post
TheDFIRReport
The DFIR Report @TheDFIRReport@infosec.exchange · Jul 20, 2026
The DFIR Report
@TheDFIRReport@infosec.exchange

Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |

infosec.exchange
On the Exchange email server, the threat actor used a legitimate Windows executable, SystemSettingsAdminFlows.exe, which allows users to customize or configure the system settings to user’s preference. This LOLBIN was used to disable Windows Defender settings on the server. Report: https://thedfirreport.com/2026/02/23/apache-activemq-exploit-leads-to-lockbit-ransomware/
0
0
0
0
Open post
TheDFIRReport
The DFIR Report @TheDFIRReport@infosec.exchange · Jul 14, 2026
The DFIR Report
@TheDFIRReport@infosec.exchange

Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |

infosec.exchange

🚨 Investigation & Collaboration Request

We are currently investigating malicious activity associated with the following LNK file:

1b3089a761da4a9b7a1bfb485cc857969346ce61 — Employment_Verification_Details.lnk

We observed command-and-control communications with:

🌐 work[.]officialm[.]com — VT Score: 0/91 🌐 31[.]192[.]107[.]162:443 — VT Score: 0/91

If you have observed related activity and/or possess additional intelligence, and would like to collaborate, please reach out!

0
0
0
0
Open post
TheDFIRReport
The DFIR Report @TheDFIRReport@infosec.exchange · Jun 30, 2026
The DFIR Report
@TheDFIRReport@infosec.exchange

Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |

infosec.exchange
"From network traffic recorded during the second round of exploitation, we saw the ActiveMQ Server process downloading the malicious XML file containing the commands to be run in the command-line interface: " Report: https://thedfirreport.com/2026/02/23/apache-activemq-exploit-leads-to-lockbit-ransomware/
0
0
0
0
Open post
TheDFIRReport
The DFIR Report @TheDFIRReport@infosec.exchange · Jun 29, 2026
The DFIR Report
@TheDFIRReport@infosec.exchange

Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |

infosec.exchange
➡️ New report out today by Jake, Dino, Ahmed Farouk, @MittenSec, @angelo_violetti, and @r3nzsec. From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira 🔎 A user searching for ManageEngine OpManager was led to a fake download site and installed a trojanized MSI. 🐝 That install launched BumbleBee, which brought in AdaptixC2 and gave the threat actor a foothold in the network. https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira
0
0
0
0
Open post
TheDFIRReport
The DFIR Report @TheDFIRReport@infosec.exchange · Apr 22, 2026
The DFIR Report
@TheDFIRReport@infosec.exchange

Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |

infosec.exchange

We identified an exposed server that provided unusual visibility into a large-scale, multi-victim exploitation and collection operation. Artifacts on the host showed that Claude Code and OpenClaw were embedded in the operator's day-to-day workflow, supporting troubleshooting, orchestration, and refinement of the collection pipeline. Logs indicated more than 900 confirmed compromises...

Read the full report: https://thedfirreport.com/2026/04/22/bissa-scanner-exposed-ai-assisted-mass-exploitation-and-credential-harvesting/

2
0
5
0
Open post
TheDFIRReport
The DFIR Report @TheDFIRReport@infosec.exchange · Mar 25, 2026
The DFIR Report
@TheDFIRReport@infosec.exchange

Real Intrusions by Real Attackers, the Truth Behind the Intrusion. Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |

infosec.exchange

We’re seeing a “Missing Font” ClickFix chain in the wild.

Flow:
1️⃣ Fake “Missing Font” prompt
2️⃣ Leads to a BSOD-style recovery screen
3️⃣ Prompts users to open Terminal/PowerShell directly (skipping the Run dialog) and execute commands

This variant leans into a more convincing multi-step user flow compared to typical ClickFix lures.

Curious if others are seeing similar activity?

#infosec #DFIR #threatintel

infosec.exchange

Infosec Exchange

7
2
9
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 03:24:02 UTC