Elektrine
EN
Log in Register
Paige Chat Timeline Gallery Friends Lists Email Drive DNS Resolver Domains VPN Kairo Nerve
Remote

Threat Insight

@threatinsight@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Proofpoint's insights on targeted attacks & the security landscape.

1392 Followers
1 Following
23 Posts
Joined February 20, 2024
Threat Insight Blogs:
https://www.proofpoint.com/us/blog/threat-insight
Threat Insight on X:
https://twitter.com/threatinsight
Open post
Threat Insight @threatinsight@infosec.exchange
· 1mo ago

Cybercriminals are exploiting the news of the #COLDCARD hardware wallet vulnerability in phishing attacks to install malware.

A reported flaw in COLDCARD firmware has led to the theft of tens of millions worth of Bitcoin.

Now, Proofpoint has observed social engineering leveraging “hardware audit” themes impersonating COLDCARD in email-based phishing campaigns.

Emails impersonate COLDCARD and purport to highlight a security audit relating to the incident. Messages contain a URL that leads to a site impersonating COLDCARD with a “Start Hardware Audit” button.

If clicked, the button leads to a BAT file hosted on GitHub, which drops an MSI file and ultimately installs ScreenConnect. This can lead to data or financial theft, or to the installation of follow-on malware such as ransomware.

IOCs:

• Sender email - compliance@coldcardteamnews[.]com

• Fake site – coldcardcompliance[.]com

• Payload - hxxps://github[.]com/newallyson/ColdCard/releases/download/5.7/Coldcard_Diagnostic_Tool.bat

• ScreenConnect C2 - activeretirementrelocation[.]com

2
0
1
0
Open post
Threat Insight @threatinsight@infosec.exchange
· 3mo ago

#SocGholish, the “FakeUpdates” web injects framework linked to major ransomware events, has been disrupted by #OperationEndgame

❌ 100 servers and domains worldwide dismantled
❌ 14,971 websites remediated

The action, which took place in June 2026, involved law enforcement agencies in the Netherlands (NHCTU), Canada (RCMP), the United States (FBI), and Germany (BKA).

Our researchers have tracked SocGholish and its operator #TA569 — one of the most prominent cybercriminals in our threat data — since 2018. We were proud to contribute our unique insights to this initiative.

Learn more about SocGholish, TA569, the impact this #takedown will have on the threat landscape, and what website owners can do to protect themselves: https://www.proofpoint.com/us/blog/threat-insight/sayonara-socgholish-operation-endgame-disrupts-major-cybercrime-operation?utm_source=twitter&utm_medium=social_organic

#FakeUpdates #ransomware #malware #LockBit

6
0
0
0
Open post
Threat Insight @threatinsight@infosec.exchange
· 1mo ago

Last week, we partnered with the NSA and other government agencies to publish research on Russia-aligned espionage actor TA488’s abuse of a previously unknown Zimbra mailserver vulnerability.

🚨 Today, we are following up with additional observations of the threat group’s exploitation of a cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA).

This blog shares this update: https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit?utm_source=twitter&utm_medium=social_organic

The activity shows:

• That TA488 has greatly improved its operational security measures
Is writing more subtle and capable malware

• Targets a wide range of sectors but still prioritizes collecting gov't/defense intel

• TA488 is doubling down on “half-click” exploits, now with an infection chain purpose-built for persistent access inside OWA.

⚠️ Organizations should review and audit their Exchange permissions and revoke tokens for affected add-ins. Additional guidance is in our blog.

2
0
2
0
Open post
Threat Insight @threatinsight@infosec.exchange
· 1mo ago
A new blog from Proofpoint AI threat researchers highlights how cybercriminals are incorporating AI tooling and generated material into attack chains. 🔗 https://www.proofpoint.com/us/blog/threat-insight/notes-underground-adversarial-prompt-injection?utm_source=twitter&utm_medium=social_organic We continue to observe activity on underground criminal forums, suggesting that Indirect Prompt Injection (IDPI) could be increasingly leveraged as an intrusion vector. Our blog explores several malicious IDPI methods that are being actively developed into tools and frameworks and advertised for sale. ⤵️ • IDPI via email • IDPI via PDF • IDPI via calendar invite (disguising the prompt as a meeting agenda) • IDPI via malvertising (embedding prompts in webpages) Security teams should be prepared to encounter these techniques in the near future. Which IDPI method most concerns you?
2
0
0
0
Open post
Threat Insight @threatinsight@infosec.exchange
· 2mo ago
Proofpoint researchers have released a technical report on Cruciferra, described by its creators as 'the underground's most lethal crypter.' 🔗: https://www.proofpoint.com/us/blog/threat-insight/unpacking-cruciferra-analysis-sophisticated-crypter-service?utm_source=linkedin&utm_medium=social_organic Crypters are commonly used within the cybercriminal ecosystem to conceal malicious payloads, evade security controls, and improve malware delivery success rates. Cruciferra distinguishes itself through its extensive and unique defense-evasion capabilities, modular design, and highly customized and varied approach to payload protection. The report highlights Cruciferra’s functionalities and observed real-world use, along with campaigns and malware families associated with the service.
2
1
1
0
Open post
Threat Insight @threatinsight@infosec.exchange
· 2mo ago

Our threat researchers have identified a novel #OAuth client ID spoofing technique. It enables attackers to enumerate accounts, all without generating a single successful sign-in event.

The technique evades proper detection of Entra sign-in logs, a primary telemetry source for defending against malicious authentication activity.

If successful, attackers can launch follow-on attacks and potentially evade downstream detections that rely on the application name field being populated.

Our blog covers the technique in depth and shares a simulation of how it works in practice. https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy?utm_source=linkedin&utm_medium=social_organic

2
0
1
0
Open post
Threat Insight @threatinsight@infosec.exchange
· 3mo ago

SpaceX is preparing for a record initial public offering, and cybercriminals are taking note. 👀 

Our researchers have observed TA2730 using #SpaceX’s upcoming IPO in fraudulent emails to lure targets into handing over their credentials to investment platforms.

The campaigns impersonated two financial firms, CommSec and FSM One, to target people in #Australia and #Singapore. The messages purported to invite people to apply for eligibility to purchase SpaceX stock.

Emails contained a URL that led to counterfeit authentication pages designed to harvest user credentials.

🚨 About TA2730: This threat actor is opportunistic and financially motivated, focused on obtaining credentials from the financial sector. It targets organizations globally and usually uses lures related to the "W-8BEN" form, a U.S. tax form for non-U.S. taxpayers.

The SpaceX lure is a departure from TA2730’s typical #socialengineering. But given the attention and hype around the upcoming market debut, this could be an alluring lure, especially to those already customers of the impersonated trading platforms. 

⚠️ Beware of cybercriminals exploiting high-profile stock market debuts and other anticipated technology-sector listings, which may serve as effective social engineering lures.

#stock #stockmarket #emailfraud #TA2730 #cybersecurity

---

TA2730 Phishing Domains:

467jtzbkqcfl22t9hxh[.]live
ddgaoylh4h420fvm7o5[.]live
u7aq3ocwrexd70ulpdj[.]live
zavpejjyz432d577l2e[.]live
8fv4dxp7lx035f8ylk7[.]live
cd7yt860whhm7g7ylj8[.]live
g8iqelymkc4eya9zs49[.]live
hy0zu0fuf7rc2ou5aje[.]live
k1rg2oz4zpzw91pdx90[.]live
ogqw9cpz7t7et3j1rur[.]live

3
0
1
0
Open post
Threat Insight @threatinsight@infosec.exchange
· 1mo ago
Our researchers discovered that a Russia-aligned threat actor was exploiting a previously unknown (zero-day) vulnerability against Zimbra email software. We alerted government partners, with whom we have collaborated on further discovery. Here’s what you need to know: 👉 To execute the exploit, the target needs only to open the email. No social engineering is required to entice or trick a user into clicking a link or opening an attachment. This is dangerous, as the average employee has thousands of emails in their inbox that appear unassuming when opened. 👉 Once triggered, the malware could exfiltrate up to 90 days of emails, credentials, and authentication data, and establish persistent access to the mailbox. 👉 The activity is attributed to TA488 (AKA “Laundry Bear” / “Void Blizzard”). They are likely directed by Russian intelligence with the goal of long-term email collection and surveillance. Read our blog published in coordination with the NSA and FBI: https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit?utm_source=linkedin&utm_medium=social_organic This vulnerability was patched, but TA488 and other Russian espionage actors continue to focus on webmail targeting, using these so-called “half-click” exploits to steal highly sensitive email data. Learn more here: https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits?utm_source=twitter&utm_medium=social_organic Below is a visual of how the attack can look in the inbox. Organizations using Zimbra mailservers should view our blogs and IOCs for awareness.
1
0
2
0
Open post
Threat Insight @threatinsight@infosec.exchange
· 3mo ago

Our new threat research report is a comprehensive overview of TA4922, a newly designated Chinese-speaking, financially motivated threat actor.

We consider it one of the most unique actors we track. 👀

Why? Because it currently conducts more unique campaigns than any other cybercriminal in our telemetry, using a wide variety of lure themes, targeting, and objectives. You’ll see examples in our blog.

Read it now: https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global?utm_source=twitter&utm_medium=social_organic

Campaigns mostly target organizations in Japan, but it’s been expanding globally. 🗺️

This actor blends malicious activity with legitimate tools, trusted software, and cloud hosting services—making its campaigns challenging to detect and defend against.

See our blog for all the details on TA4922, the new payloads it distributes, our defense recommendations, IOCs, and more.

3
0
4
0
Open post
Threat Insight @threatinsight@infosec.exchange
· 2mo ago

Just announced by Europol: the global #OperationEndgame initiative has disrupted the StealC ecosystem, a prominent information-stealing malware operation. Read more: https://www.proofpoint.com/us/blog/threat-insight/stealc-you-later-proofpoint-and-ibm-x-force-support-operation-endgame?utm_source=twitter&utm_medium=social_organic

Supported by data and monitoring from Proofpoint, IBM X-Force, and other intelligence partners, the operation resulted in:

• 66 domains taken down
• 296 servers linked to both Amadey and StealC disrupted
• 25.6 million unique credentials seized from more than 385,000 compromised systems

Since emerging as a malware-as-a-service (#MaaS) offering in January 2023, #StealC has enabled cybercriminals to steal sensitive information from victims and facilitate follow-on attacks against organizations, often causing significant financial and operational harm.

This is a major blow to StealC’s ecosystem. It may experience service interruptions, hindering distribution, reputational damage, and difficulty attracting and retaining customers.

As an official industry partner of Operation Endgame, Proofpoint has now supported six major coordinated disruptions by providing threat intelligence to help authorities impact major cyber threats.

We look forward to our continued collaboration.

2
0
0
0
Open post
Threat Insight @threatinsight@infosec.exchange
· 2mo ago
The #OperationEndgame takedown of the #StealC ecosytem led to the seizure of more than 25.6 million unique credentials stolen from over 385,000 compromised sites. Proofpoint's research team was proud to contribute to the operation alongside industry partners—a major win for cyber defense. On this episode of Discarded, host Selena Larson is joined by Kyle Cucci of Proofpoint and Golo Mühr of IBM X-Force, two threat researchers involved in the disruption. 🎧 https://www.proofpoint.com/us/podcasts/discarded#147309 Tune in for the scoop inside the investigation.
1
0
1
0
Open post
Threat Insight @threatinsight@infosec.exchange
· 4mo ago

Device code phishing is exploding across the threat landscape, with new device code phishing tools emerging every week.

Research blog: https://www.proofpoint.com/us/blog/threat-insight/device-code-phishing-evolution-identity-takeover?utm_source=twitter&utm_medium=social_organic

The technique abuses legitimate enterprise resources for account takeovers. It involves social engineering to trick a target into authorizing a malicious app on their enterprise email accounts.

It was first observed around 2020 but has grown in popularity over recent years due to the publication of criminal device code phishing tools and on-demand code generation.

Successful attacks can lead to:

• Full account takeover
• Theft of sensitive information
• Fraud and business email compromise
• Lateral movement within a compromised environment
• Ransomware

Our new research blog explores why adoption of this technique has surged over the past year, shows real campaign examples, and offers defense recommendations.

#socialengineering #accounttakeover #BEC #fraud

3
0
2
0
Open post
Threat Insight @threatinsight@infosec.exchange
· 2mo ago
Proofpoint's threat research team is tracking a password-spraying campaign against the U.S. education sector, using a spoofed user agent so outdated it may predate some of the accounts it targeted. The campaign featured two one-month clusters of spraying activity against roughly 80,000 user accounts across nearly 3,000 tenants. The attacker's tooling left a consistent fingerprint across all malicious events targeting Outlook Mobile (app id: 27922004-5251-4030-b22d-91ecd9a37ea4). Traffic was almost entirely VPN (96%) from data center egress points (99%) with exit nodes rotating on the U.S. East Coast. Some tenants were enumerated A→Z while others Z→A at the same time (Spearman coefficient ranging from -0.87 to +0.89). Two lists (or two operators) splitting a creds dump and each taking a half, perhaps. This observation tells us this wasn't a totally random spray. 🎯 A subset of compromised accounts pivoted to the Microsoft 365 Admin portal (app id: 618dd325-23f6-4b6f-8380-4df78026e39b) within 2 to 4 seconds after compromise. The result: 100% success rate on admin access—the tooling knew which accounts had admin privileges. Proofpoint recommends defenders monitor for successful Outlook Mobile logins followed by a pivot to the M365 Admin portal within <4 seconds using the same VPN node. That speed suggests automated post-compromise tooling, warranting immediate investigation if detected.
1
0
0
0
Open post
Threat Insight @threatinsight@infosec.exchange
· 2mo ago

New from Proofpoint threat research: Chinese cyber-espionage tradecraft is evolving. 🌀

UNK_MassTraction, a newly identified, suspected China-aligned espionage cluster, is targeting U.S. and Canadian universities by compromising mail servers likely to use as an entry point into broader enterprise networks.

The goal: Steal credentials, bypass detection, and gain persistent access to mail servers via a webshell or the VShell backdoor.

Typically, adversaries view the mail server as the primary target, not the access point.

⚠️ Defender takeaway: Treat your internet-facing mail servers with the same priority as VPNs and other edge infrastructure by rapidly patching vulnerabilities and monitoring for post-exploitation activity.

Details on the campaign delivery, exploitation, and IOCs: https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation?utm_source=twitter&utm_medium=social_organic

#Roundcube #vulnerability #espionage #higherEDU

1
2
0
0
Open post
Threat Insight @threatinsight@infosec.exchange
· 2mo ago

Researchers from Proofpoint have reported an increase in AitM activity originating from #NovaCookies, a suspected variant of the #Sneaky2FA phishing kit.

Proofpoint observed an intermittent burst in Sneaky2FA activity until February 2026, when researchers first identified the NovaCookies variant.

Malicious activity intensified from March to May as this new variant was adopted, but declined in June.

While the original Sneaky2FA appeared to focus mainly on Microsoft accounts, the NovaCookies variant includes dedicated flows for other identity providers, including Okta, and Entra domains federated to GoDaddy.

Unlike Sneaky2FA, NovaCookies uses a fully managed phishing-as-a-service (PhaaS) model where affiliates pay to use a PhaaS platform, and the infrastructure is hosted centrally by the PhaaS operator rather than by each affiliate.

In April 2026, Proofpoint’s cloud telemetry captured a shift in the ISPs from which NovaCookies activity originated, a pattern consistent with established tradecraft of migrating hosting or proxy services to evade detection.

Researchers observed cloud account takeovers targeting specifically the healthcare sector. Notably, Proofpoint detected more than 100 ATOs on the same day in a single tenant in this vertical.

Proofpoint recommends deploying the ATO solution to protect your organization against AiTM originated account takeovers.

Our Cloud Threat Research team will continue monitoring any activity related to the Sneaky2FA and NovaCookies phishing kits and will share any notable trends.

1
0
0
0
Open post
Threat Insight @threatinsight@infosec.exchange
· 4mo ago

In a public service announcement, the FBI warned the transportation and logistics industry about a sharp rise in cyber-enabled cargo theft, an attack vector our researchers have been closely tracking since last year.

The scheme is a collaborative effort between cybercriminals and organized crime gangs, who use hacking and impersonation tactics to hijack high-value freight.

Estimated losses in the United States and Canada reached nearly $725 million in 2025.

Read the full PSA here: https://www.ic3.gov/PSA/2026/PSA260430

See here for our recent research on how these attacks are executed: https://www.proofpoint.com/us/blog/threat-insight/beyond-breach-inside-cargo-theft-actors-post-compromise-playbook?utm_source=twitter&utm_medium=social_organic

2
0
0
0
Open post
Threat Insight @threatinsight@infosec.exchange
· 3mo ago

Proofpoint is proud to announce its acceptance into Europol EC3's Advisory Group on Internet Security (AGIS).

This milestone builds on years of collaboration between Proofpoint and Europol, including recent efforts supporting the disruption of the Tycoon 2FA phishing-as-a-service platform and Operation Endgame.

Cybercrime is a global challenge that no organization can tackle alone.

Through trusted public-private partnerships, intelligence sharing, and coordinated action, we can continue identifying, investigating, and disrupting the criminal infrastructure that threatens organizations across Europe and beyond.

We look forward to working even more closely with Europol and fellow AGIS members to strengthen the security and resilience of Europe's digital ecosystem.

🔗 https://www.proofpoint.com/us/blog/corporate-news/proofpoint-joins-europol-ec3-agis?utm_source=twitter&utm_medium=social_organic

#Europol #partnership #EC3 #cybercrime #OperationEndgame

1
0
0
0
Open post
Threat Insight @threatinsight@infosec.exchange
· 4mo ago

Sarah Sabotka, staff threat researcher at Proofpoint, is speaking at #Layer8Conference — the only event dedicated to #OSINT and #socialengineering threats facing businesses today.

If you're a security leader, you won't want to miss it!

June 5–6 | Boston, MA
Event info: layer8conference.com

1
0
0
0
Open post
Threat Insight @threatinsight@infosec.exchange
· 4mo ago

Device code phishing is exploding, and AiTM actors are getting in on it.

We found ODx phishing-as-a-service providing device code capabilities in addition to their AiTM offerings. ODx is one of the most popular AiTM kits currently. It's also tracked as Storm-1167 and FlowerStorm.

In the observed campaign, the actor used compromised senders to deliver URLs leading to the ODx device code phishing landing page.

The landing pages included multiple different themes, including impersonating SharePoint, Adobe, and DocuSign.

The campaign leveraged ATO jumping, a technique where an attacker compromises an initial email account and then uses it to send phishing links to a wide set of contacts.

ODx’s device code capabilities are using Kali365, a device code PhaaS. Kali365 is just one of many such kits available for purchase. It’s unclear whether ODx stole or purchased Kali365, or partnered with them to integrate directly into their service.

🚨 Device code phishing is insidious. Threat actors abuse the OAuth 2.0 device authorization grant flow to compromise Microsoft 365 or other enterprise user accounts by approving access for actor-controlled applications.

⚠️ Organizations are advised to block device code authentication where possible; require compliant or joined devices via conditional access policies; and train users to recognize device code phishing attacks.

Read more about device code phishing: https://www.proofpoint.com/us/blog/threat-insight/access-granted-phishing-device-code-authorization-account-takeover?utm_source=twitter&utm_medium=social_organic

1
0
0
0
Open post
Threat Insight @threatinsight@infosec.exchange
· 4mo ago

Our award-winning threat research podcast series, Discarded, is celebrating 100 episodes this week! 🎉

Stream now for a trip down memory lane, a few laughs, and a look ahead to what's next in cybersecurity.

Cheers to 100 episodes! 🍾 https://www.proofpoint.com/us/podcasts/discarded#146302?utm_source=twitter&utm_medium=social_organic

1
0
0
0
Open post
Threat Insight @threatinsight@infosec.exchange
· 2mo ago

FIFA FANS ‼️ Cybercriminals are using World Cup excitement to steal your personal info and credit card details. One recent #emailscam we observed used this subject line. ⤵️

Congratulations! You're Eligible for the FIFA World Cup 2026 Giveaway

The email impersonated FIFA, offering free World Cup merchandise in exchange for completing a survey and a small shipping fee.

How the scam works:

📧 A target receives a fake FIFA giveaway email promising free merchandise.

🔗 Clicking the link leads to a convincing fake FIFA website hosted through a Google API URL.

📝 After completing a short survey, the target is prompted to pay a small “shipping fee.”

💳 The fake checkout page captures the victim’s personal information and credit card details.


🚩 Red cards to watch for:

  • Unexpected giveaways or prizes

  • Urgent language like “Offer expires today”

  • Suspicious sender or reply-to addresses

  • Requests for payment to claim a “free” reward

Before participating in any World Cup promotion or #giveaway, verify it’s legitimate through official FIFA channels. A small shipping fee for a “free” prize can end up costing much more.

#FIFAWorldCup #cybersecurity #phishing

0
0
0
0
Open post
Threat Insight @threatinsight@infosec.exchange
· 3mo ago

🚨 New threat research: A likely North Korea-aligned threat cluster, UNK_DeadDrop, is targeting software developers through trusted development platforms and workflows.

🔗 https://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal?utm_source=twitter&utm_medium=social_organic

Over a six-week period, we observed the actor targeting organizations across the technology, cryptocurrency, finance, and education sectors.

Targets were lured through fake recruiter outreach, code review requests, and developer collaboration opportunities designed to deliver #malware and steal credentials and #cryptocurrency assets.

Some key findings:

🔑 Targeting of software developers worldwide, with a particular focus on cryptocurrency and blockchain organizations

🔑 In the observed campaigns, the group sent over 250 emails to individuals in almost 100 organizations, which gave us extensive visibility into the infection chain and evolving TTPs

🔑 Malicious #GitHub repositories and coding projects used to distribute malware

🔑 Abuse of trusted developer tools, including Visual Studio Code, Cursor, and VSIX extensions

🔑 Theft of browser credentials, cryptocurrency wallet data, and other valuable developer assets

This activity shows how North Korean threat actors are evolving beyond traditional fake #jobinterview campaigns and increasingly leveraging trusted developer ecosystems to gain access to cryptocurrency and sensitive credentials.

0
0
1
0
Open post
Threat Insight @threatinsight@infosec.exchange
· 5mo ago

A cargo threat actor’s playbook: revealed. 📖 Proofpoint researchers baited a logistics/transportation industry threat actor into performing its malicious activities in a decoy environment operated by Deception.Pro for over 30 days. 🚚

In a new blog, our team of experts shared their observations, complete with rare, extended visibility into post‑compromise operations, tooling, and decision‑making.

Activities the threat actor performed:

• Delivered malicious payloads via email
• Established persistence with multiple RMM tools
• Use of a previously unknown malware signing‑as‑a‑service capability
• Hands-on-keyboard interaction to access PayPal
• Executed 13 PowerShell scripts to understand targets' financial value

Cargo theft leads to $34 billion in losses annually. These findings offer never-before-seen insight into how financially motivated threat actors operate well beyond initial access.

Read the full blog here: https://www.proofpoint.com/us/blog/threat-insight/beyond-breach-inside-cargo-theft-actors-post-compromise-playbook?utm_source=twitter&utm_medium=social_organic

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)
  • Source code

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 16:28:40 UTC