Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

OTX Bot

@techbot@social.raytec.co
mastodon 4.6.6
  • Open on social.raytec.co

Currently, this bot follows AlienVault, CryptoCTI, and Cyber74Team on OTX AlienVault. If you have more suggestions, please send a note to @mike@social.raytec.co.

Update 2025/09/15: At the suggestion of an anonymous researcher, I've added the following accounts:

-cyberhunter_nl
-tr2222200
-tr1sa111
-bluenumberone
-dekarituraj
-feisty-swim1410

If they become overwhelming or repetitive I will gladly accept suggestions to remove any.

A little bot maintained by @mike@social.raytec.co to post the latest pulses from Open Threat Exchange.

Profile picture is Beezlebot, the Robot Devil, from Futurama. Header picture is a holograph-stylized image with the word "Malware" highlighted.

Unaffiliated with OTX or AlienVault

WARNING: This is crowdsourced data posted by a bot and is not guaranteed to be complete or accurate. Do not make any decisions or take any actions based solely on this bot's posts. You may not hold the bot, its creator, or any associated person or entity liable for any consequences or damages arising from this information or your actions or inaction based upon it.

#OTX #AlienVault

0 Followers
0 Following
5 Posts
Joined October 10, 2023
Written in:
Python
Written by:
Raymond Tec
Maintainer:
@mike

Posts

Open post
techbot
OTX Bot @techbot@social.raytec.co · Aug 06, 2026
OTX Bot
@techbot@social.raytec.co

Currently, this bot follows AlienVault, CryptoCTI, and Cyber74Team on OTX AlienVault. If you have more suggestions, please send a note to @mike. Update 2025/09/15: At the suggestion of an anonymous researcher, I've added the following accounts: -cyberhunter_nl -tr2222200 -tr1sa111 -bluenumberone -dekarituraj -feisty-swim1410 If they become overwhelming or repetitive I will gladly accept suggestions to remove any. A little bot maintained by @mike to post the latest pulses from Open Threat Exchange. Profile picture is Beezlebot, the Robot Devil, from Futurama. Header picture is a holograph-stylized image with the word "Malware" highlighted. Unaffiliated with OTX or AlienVault WARNING: This is crowdsourced data posted by a bot and is not guaranteed to be complete or accurate. Do not make any decisions or take any actions based solely on this bot's posts. You may not hold the bot, its creator, or any associated person or entity liable for any consequences or damages arising from this information or your actions or inaction based upon it. #OTX #AlienVault

social.raytec.co
Security Update – August 2, 2026 Pulse ID: 6a740db739f5ddf6e048bf0a Pulse Link: https://otx.alienvault.com/pulse/6a740db739f5ddf6e048bf0a Pulse Author: Tr1sa111 Created: 2026-08-06 04:29:43 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111
0
0
0
0
Open post
techbot
OTX Bot @techbot@social.raytec.co · Jul 29, 2026
OTX Bot
@techbot@social.raytec.co

Currently, this bot follows AlienVault, CryptoCTI, and Cyber74Team on OTX AlienVault. If you have more suggestions, please send a note to @mike. Update 2025/09/15: At the suggestion of an anonymous researcher, I've added the following accounts: -cyberhunter_nl -tr2222200 -tr1sa111 -bluenumberone -dekarituraj -feisty-swim1410 If they become overwhelming or repetitive I will gladly accept suggestions to remove any. A little bot maintained by @mike to post the latest pulses from Open Threat Exchange. Profile picture is Beezlebot, the Robot Devil, from Futurama. Header picture is a holograph-stylized image with the word "Malware" highlighted. Unaffiliated with OTX or AlienVault WARNING: This is crowdsourced data posted by a bot and is not guaranteed to be complete or accurate. Do not make any decisions or take any actions based solely on this bot's posts. You may not hold the bot, its creator, or any associated person or entity liable for any consequences or damages arising from this information or your actions or inaction based upon it. #OTX #AlienVault

social.raytec.co
Analysis of BlueShell Variants Used by APT Groups BlueShell is an open-source remote access trojan developed in Go language, primarily used by Chinese-based threat actors. A variant of BlueShell has been identified in post-intrusion activities by APT groups including BlackTech, targeting organizations in Japan, South Korea, and Thailand. This variant differs from the original through a dedicated dropper mechanism, proxy server-based C2 communication, and anti-forensic capabilities. The dropper deploys the variant to /tmp/kthread, disguises it as a Linux kernel worker process, and removes filesystem traces. Recent variants observed since 2024 include XOR-encoded configuration data and proxy functionality, indicating continuous development. The malware performs hostname verification, validates C2 certificates, and implements commands for file transfer, remote shell, and SOCKS5 proxy capabilities. Pulse ID: 6a69c06b441d532a963887ee Pulse Link: https://otx.alienvault.com/pulse/6a69c06b441d532a963887ee Pulse Author: AlienVault Created: 2026-07-29 08:57:15 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #Chinese #CyberSecurity #InfoSec #Japan #Korea #Linux #Malware #OTX #OpenThreatExchange #Proxy #RAT #RCE #RemoteAccessTrojan #SouthKorea #Thailand #Trojan #bot #socks5 #AlienVault
0
0
0
0
Open post
techbot
OTX Bot @techbot@social.raytec.co · Jul 17, 2026
OTX Bot
@techbot@social.raytec.co

Currently, this bot follows AlienVault, CryptoCTI, and Cyber74Team on OTX AlienVault. If you have more suggestions, please send a note to @mike. Update 2025/09/15: At the suggestion of an anonymous researcher, I've added the following accounts: -cyberhunter_nl -tr2222200 -tr1sa111 -bluenumberone -dekarituraj -feisty-swim1410 If they become overwhelming or repetitive I will gladly accept suggestions to remove any. A little bot maintained by @mike to post the latest pulses from Open Threat Exchange. Profile picture is Beezlebot, the Robot Devil, from Futurama. Header picture is a holograph-stylized image with the word "Malware" highlighted. Unaffiliated with OTX or AlienVault WARNING: This is crowdsourced data posted by a bot and is not guaranteed to be complete or accurate. Do not make any decisions or take any actions based solely on this bot's posts. You may not hold the bot, its creator, or any associated person or entity liable for any consequences or damages arising from this information or your actions or inaction based upon it. #OTX #AlienVault

social.raytec.co
Contagious Interview malware in SVG images: DPRK campaign A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers. Pulse ID: 6a5a8ba0229db5a5b2686baa Pulse Link: https://otx.alienvault.com/pulse/6a5a8ba0229db5a5b2686baa Pulse Author: AlienVault Created: 2026-07-17 20:08:00 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault
1
0
1
0
Open post
techbot
OTX Bot @techbot@social.raytec.co · Jun 19, 2026
OTX Bot
@techbot@social.raytec.co

Currently, this bot follows AlienVault, CryptoCTI, and Cyber74Team on OTX AlienVault. If you have more suggestions, please send a note to @mike. Update 2025/09/15: At the suggestion of an anonymous researcher, I've added the following accounts: -cyberhunter_nl -tr2222200 -tr1sa111 -bluenumberone -dekarituraj -feisty-swim1410 If they become overwhelming or repetitive I will gladly accept suggestions to remove any. A little bot maintained by @mike to post the latest pulses from Open Threat Exchange. Profile picture is Beezlebot, the Robot Devil, from Futurama. Header picture is a holograph-stylized image with the word "Malware" highlighted. Unaffiliated with OTX or AlienVault WARNING: This is crowdsourced data posted by a bot and is not guaranteed to be complete or accurate. Do not make any decisions or take any actions based solely on this bot's posts. You may not hold the bot, its creator, or any associated person or entity liable for any consequences or damages arising from this information or your actions or inaction based upon it. #OTX #AlienVault

social.raytec.co
Analysis of Gamaredon campaign targeting Ukraine weaponizing CVE-2025-8088 A campaign exploiting the WinRAR path-traversal vulnerability CVE-2025-8088 has been actively targeting Ukraine since February 2026, with ongoing activity through June 2026. The operation uses Ukrainian military and conscription-themed documents as lures, distributed as RAR archives. The malicious archives contain NTFS alternate data streams with path-traversal sequences that automatically place LNK files into the Windows Startup folder upon extraction. These shortcuts execute hidden PowerShell stagers incorporating anti-analysis techniques including debugger checks, disk-space verification, and sleep delays to evade sandbox detection. The persistent nature of the attacks demonstrates continuous targeting of Ukrainian entities over a four-month period using social engineering focused on military documentation themes. Pulse ID: 6a34c6344468a941c924c02c Pulse Link: https://otx.alienvault.com/pulse/6a34c6344468a941c924c02c Pulse Author: AlienVault Created: 2026-06-19 04:31:48 Be advised, this data is unverified and should be considered preliminary. Always do further verification. #CyberSecurity #Gamaredon #InfoSec #LNK #Military #OTX #OpenThreatExchange #PowerShell #RAT #SocialEngineering #UK #Ukr #Ukraine #Ukrainian #Vulnerability #WinRAR #Windows #bot #AlienVault
0
0
1
0
Open post
techbot
OTX Bot @techbot@social.raytec.co · Apr 21, 2026
OTX Bot
@techbot@social.raytec.co

Currently, this bot follows AlienVault, CryptoCTI, and Cyber74Team on OTX AlienVault. If you have more suggestions, please send a note to @mike. Update 2025/09/15: At the suggestion of an anonymous researcher, I've added the following accounts: -cyberhunter_nl -tr2222200 -tr1sa111 -bluenumberone -dekarituraj -feisty-swim1410 If they become overwhelming or repetitive I will gladly accept suggestions to remove any. A little bot maintained by @mike to post the latest pulses from Open Threat Exchange. Profile picture is Beezlebot, the Robot Devil, from Futurama. Header picture is a holograph-stylized image with the word "Malware" highlighted. Unaffiliated with OTX or AlienVault WARNING: This is crowdsourced data posted by a bot and is not guaranteed to be complete or accurate. Do not make any decisions or take any actions based solely on this bot's posts. You may not hold the bot, its creator, or any associated person or entity liable for any consequences or damages arising from this information or your actions or inaction based upon it. #OTX #AlienVault

social.raytec.co

Abusing OAuth Device Code Flow

In early 2026, phishing attacks remain a top threat vector in security operations. This analysis covers a novel attack method exploiting Microsoft's OAuth 2.0 Device Authorization Grant (Device Code Flow) to compromise user accounts. Attackers use phishing emails containing Mailchimp's Mandrill service links to bypass security controls, leading victims to fake Adobe-themed websites. The sites abuse legitimate Microsoft authentication mechanisms to obtain access and refresh tokens, granting persistent delegated access to critical resources like Graph API, Teams, Outlook, and SharePoint. The technique leverages shared client IDs across tenants and family of client IDs (FOCI) for lateral movement. Two variants exist: one using external phishing infrastructure with dynamic code generation, and another relying solely on fake meeting invitations containing pre-generated device codes. The attack is particularly effective as it uses legitimate Microsoft services, making detection challenging.

Pulse ID: 69e68ccac96ab3f866763f12
Pulse Link: https://otx.alienvault.com/pulse/69e68ccac96ab3f866763f12
Pulse Author: AlienVault
Created: 2026-04-20 20:30:02

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#Adobe #CyberSecurity #Email #InfoSec #Microsoft #OTX #OpenThreatExchange #Outlook #Phishing #RAT #RCE #SMS #bot #AlienVault

0
0
1
0

Remote instance

social.raytec.co
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 18:15:12 UTC