Sign in

Alexander Leslie

@aejleslie.bsky.social
1.1K followers 99 following 206 posts

Cybercrime & Hacktivism @ Recorded Future | Insikt Group | Curated Intelligence | @aejleslie everywhere else.

PostsRepliesMedia
Alexander Leslie @aejleslie.bsky.social · 18/06/2025
🚨 👀 New Insikt Group report! As NATO leaders gather in The Hague next week, the upcoming summit comes under threat from adversary activity: state-sponsored espionage, malign influence operations, and a surge of chatter across the dark web. Blog: www.recordedfuture.com/research/thr...
recordedfuture.com
Threats to the 2025 NATO Summit: Cyber, Influence, and Hybrid Risks
Explore how state-sponsored actors, cybercriminals, and hacktivists are targeting the 2025 NATO Summit. Insight from Recorded Future’s Insikt Group reveals escalating cyber, AI, and hybrid threats fro...
010
Alexander Leslie @aejleslie.bsky.social · 18/06/2025
🇨🇳 🤖 New Insikt Group report! This research details how the People’s Liberation Army is rapidly experimenting with generative AI to augment — and potentially transform — its military intelligence capabilities. Blog: www.recordedfuture.com/research/art...
recordedfuture.com
China’s PLA Leverages Generative AI for Military Intelligence: Insikt Group Report
Explore how China’s PLA is adopting generative AI for military intelligence. This Insikt Group report reveals AI-driven intelligence tools, strategic adaptations, and implications for global security.
021
Alexander Leslie @aejleslie.bsky.social · 17/06/2025
Join me tomorrow for a live briefing on the conflict between Israel and Iran. We’ll address specific geopolitical risks, cybercriminal and hacktivist groups, state-sponsored cyber threats, influence operations, and more. Registration: recordedfuture.registration.goldcast.io/webinar/4b72...
011
Alexander Leslie @aejleslie.bsky.social · 13/06/2025
Thank you to everyone who attended my session at our inaugural Insikt After Dark conference in New York City! I spoke on our recent efforts to disrupt traffer teams, infostealer operators, and global scam infrastructure. It’s always an honor to represent Recorded Future!
000
Alexander Leslie @aejleslie.bsky.social · 13/06/2025
Outstanding work from @julianferdinand.bsky.social, @lawrencesec.bsky.social, and our Malicious Infrastructure Discovery (MID) team. GrayAlpha shows how financially motivated actors operate with APT-level tradecraft. Time to retire old threat models. Think in terms of ecosystems, not just malware.
064
Alexander Leslie @aejleslie.bsky.social · 12/06/2025
Predator isn’t dead — it’s mutating. New reporting from @julianferdinand.bsky.social just dropped. It confirms that Predator C2 is very much alive and attracting new clients. Targets? The same. Activists, politicians, journalists, executives. The spyware economy isn’t slowing — it’s adapting.
042
Alexander Leslie @aejleslie.bsky.social · 22/05/2025
New report! Check it out. 🇷🇺 🇹🇯 This research examines a campaign targeting Tajikistan attributed to Russia-aligned TAG-110 — linked to BlueDelta (APT28). This campaign is likely targeting government, educational, and research institutions. Link: www.recordedfuture.com/research/rus...
recordedfuture.com
TAG-110 Targets Tajikistan: New Macro Word Documents Phishing Tactics
Russia-aligned TAG-110 shifts to .dotm phishing lures in a 2025 campaign against Tajikistan’s public sector, advancing cyber-espionage in Central Asia.
122
Alexander Leslie @aejleslie.bsky.social · 21/05/2025
Good riddance! This should make a sizable dent in the ecosystem. 🪦 Lumma Stealer 🪦 Link: www.europol.europa.eu/media-press/...
europol.europa.eu
Europol and Microsoft disrupt world’s largest infostealer Lumma | Europol
Europol’s European Cybercrime Centre has worked with Microsoft to disrupt Lumma Stealer (“Lumma”), the world’s most significant infostealer threat.
010
Alexander Leslie @aejleslie.bsky.social · 08/05/2025
New report! Check it out. This research examines US-China AI gap and the drivers of competition. Insikt Group assesses that China is unlikely to sustainably surpass the US on its desired timeline to become the world leader in AI by 2030. Link: www.recordedfuture.com/research/mea...
recordedfuture.com
US-China AI Gap: 2025 Analysis of Model Performance, Investment, and Innovation
Explore Insikt Group's in-depth 2025 report on the US-China AI race—comparing funding, talent, regulation, compute capacity, and model benchmarks. Discover why China trails the US and what could chang...
110
Alexander Leslie @aejleslie.bsky.social · 02/05/2025
I had a great time talking with @gregotto.bsky.social from @cyberscoop.bsky.social at RSAC 2025. Always fun! Check out our conversation about my work on cryptoscam gangs, infostealer “traffer” teams, and the “Marko Polo” cybercriminal group. Link: open.spotify.com/episode/70AY...
open.spotify.com
Recorded Future’s Alexander Leslie on the ‘MarkoPolo’ traffer team
Safe Mode Podcast · Episode
022
Alexander Leslie @aejleslie.bsky.social · 02/05/2025
New report! Check it out. This research uncovers two new malware families — TerraStealerV2 and TerraLogger — linked to the financially motivated threat activity group Golden Chickens (VENOM SPIDER). Link: www.recordedfuture.com/research/ter...
recordedfuture.com
Golden Chickens Unveils TerraStealerV2 and TerraLogger: New Credential Theft Tools Identified by Insikt Group
Insikt Group reveals two emerging malware strains—TerraStealerV2 and TerraLogger—linked to Golden Chickens, a threat actor behind credential theft and keylogging MaaS platforms. Learn how these tools ...
131
Alexander Leslie @aejleslie.bsky.social · 29/04/2025
New report! Check it out. This research examines MintsLoader, linked to groups like TAG-124 (LandUpdate808), to deploy capabilities like GhostWeaver and StealC. Link: www.recordedfuture.com/research/unc...
recordedfuture.com
MintsLoader Malware Analysis: Multi-Stage Loader Used by TAG-124 and SocGholish
Discover how MintsLoader operates as a stealthy, obfuscated malware loader distributing GhostWeaver, StealC, and BOINC. Read Recorded Future’s in-depth analysis of its evasion tactics, DGA-based C2s, ...
111
Alexander Leslie @aejleslie.bsky.social · 28/04/2025
Thank you to everyone who attended my session at RSAC 2025 on cryptoscam gangs, infostealer operators, and the notorious “Marko Polo” traffer team. A lot of friendly faces in the crowd! (Find me roaming around this week, I have stickers!)
010
Alexander Leslie @aejleslie.bsky.social · 27/04/2025
See y’all tomorrow! 😎
110
Alexander Leslie @aejleslie.bsky.social · 18/04/2025
New Recorded Future report! Check it out. This research examines the critical role of artificial intelligence in the future economic, regional influence, and national security interests of Iran, and the implementation of those capabilities. Link: www.recordedfuture.com/research/ira...
recordedfuture.com
Iran’s AI Ambitions: National Security, Global Influence, and Strategic Challenges
Explore how Iran is leveraging AI for cyberwarfare, influence ops, military tech, and domestic surveillance. A deep dive into Tehran’s top-down AI strategy, partnerships with China and Russia, and imp...
110
Alexander Leslie @aejleslie.bsky.social · 15/04/2025
“More than 60 people in Tibetan areas of China have been arrested since 2021 for offenses connected to phone and internet use…” “Many of the arrests have involved the possession of outlawed content on phones… sharing of content on social media…” h/t: therecord.media/tibetans-arr...
therecord.media
Chinese police ensnaring Tibetans over phone and internet activity, Human Rights Watch says
Dozens of people in Tibet have been arrested by Chinese authorities in recent years for "simply using a cellphone," according to the nonprofit Human Rights Watch.
110
Alexander Leslie @aejleslie.bsky.social · 14/04/2025
🤖 “Artificial Intelligence has supercharged an array of tax-season scams this year, with fraudsters using deepfake audio and other techniques to intercept funds and trick taxpayers into sending them financial documents.” h/t: therecord.media/hackers-use-...
therecord.media
Hackers using AI-produced audio to impersonate tax preparers, IRS
Artificial Intelligence has supercharged an array of tax-season scams this year, with fraudsters using deepfake audio and other techniques to trick taxpayers into sending them money and financial docu...
010
Alexander Leslie @aejleslie.bsky.social · 14/04/2025
Album of the day. Eclectic, individual, and absorbing. Not everything here works, but that doesn’t matter, because it’s so much fun. Link: open.spotify.com/album/3XFwJR...
open.spotify.com
Where Malefic Icons do Eons Keep
Luminous Veil · Album · 2025 · 8 songs
010
Alexander Leslie @aejleslie.bsky.social · 13/04/2025
“Talos assesses… that multiple threat actors are operating the toll road smishing campaign by leveraging a smishing kit developed by the actor known as ‘Wang Duo Yu’ … used by the organized cybercrime group known as the ‘Smishing Triad.’” h/t: blog.talosintelligence.com/unraveling-t...
blog.talosintelligence.com
Unraveling the U.S. toll road smishing scams
Cisco Talos has observed a widespread and ongoing financial theft SMS phishing (smishing) campaign since October 2024 that targets toll road users in the United States of America.
141
Alexander Leslie @aejleslie.bsky.social · 13/04/2025
👀 🇷🇺 “The Russia-backed threat group Gamaredon, typically known for spreading malware via phishing emails, recently appeared to have used an infected removable drive to target a Ukraine-based military mission of an unnamed Western country…” h/t: therecord.media/gamaredon-re...
therecord.media
Tainted drive appears to be source of malware attack on Western military mission in Ukraine
Researchers at Symantec said the Russia-linked group known as Gamaredon appears to have departed from its usual email phishing tactics in hacking a Western military mission in Ukraine.
131
Alexander Leslie @aejleslie.bsky.social · 13/04/2025
“Deceptive websites hosted on newly registered domains are being used to deliver AndroidOS SpyNote malware… mimic the Google Chrome install page on the Google Play Store…” “While no definitive attribution is currently available, a China nexus is suspected.” h/t: dti.domaintools.com/newly-regist...
dti.domaintools.com
Newly Registered Domains Distributing SpyNote Malware - DomainTools Investigations | DTI
Deceptive websites hosted on newly registered domains are being used to deliver AndroidOS SpyNote malware. These sites mimic the Google Chrome install page on the Google Play Store.
100
Alexander Leslie @aejleslie.bsky.social · 13/04/2025
Album of the day. This rocks. Callback to Swedish blackened death metal. I hear echoes of Sacramentum, Necrophobic, and Dissection here. Riffs, solos, and Lovecraftian aesthetics? Count me in. Link: youtu.be/KUqppuhKVWI?...
youtu.be
The Infernal Deceit - The True Harmful Black (Full Album Premiere)
YouTube video by Black Metal Promotion
100
Alexander Leslie @aejleslie.bsky.social · 13/04/2025
🇬🇧 “British police on Wednesday announced that a 38-year-old Romanian man has been arrested on suspicion of assisting a foreign intelligence service.” “…identified as part of an investigation into a fire at a DHL warehouse in Birmingham.” h/t: therecord.media/romanian-man...
therecord.media
Romanian man arrested in UK on suspicion of aiding Russian sabotage campaign
British police arrested a 38-year-old Romanian man suspected of connections to a fire at a DHL warehouse that appeared to be part of a larger sabotage campaign attributed to Russian intelligence.
110
Alexander Leslie @aejleslie.bsky.social · 12/04/2025
PowerModul: BE1D0FAF1C253FAACBA1059971B01D1D646256D7B2E557DA55ED059542AFDBCD Mythic HTA: AFC7302D0BD55CFC603FDAF58F5483B0CC00D354274F379C75CFA17F6BA6F97D
010
Alexander Leslie @aejleslie.bsky.social · 12/04/2025
🇷🇺 “A little-known hacking group is using custom malware to steal sensitive files from flash drives connected to Russian computers…” “The group… has deployed a tool dubbed PowerModul that includes components designed specifically to target removable media.” h/t: therecord.media/goffee-espio...
therecord.media
Researchers warn about ‘Goffee’ spilling onto Russian flash drives
A cyber-espionage campaign aimed at Russia has added malware that specifically targets flash drives, analysts at Kaspersky said.
011
Alexander Leslie @aejleslie.bsky.social · 12/04/2025
New album of the day. A tad disappointing that Elderwind lost most of its Summoning-like folk, atmospheric, and dungeon synth roots. I played The Magic of Nature so much in high school. This is a far cry from that. Link: open.spotify.com/album/0MwCR0...
open.spotify.com
Older Than Ancient
Elderwind · Album · 2025 · 7 songs
120
Alexander Leslie @aejleslie.bsky.social · 12/04/2025
🇲🇦 “Morocco’s national social security agency is investigating a cyberattack… the leak of sensitive personal data… belonging to millions of citizens.” 🇩🇿 “…a politically motivated campaign by Algerian hackers.” h/t: therecord.media/morocco-inve...
therecord.media
Morocco investigates major data breach allegedly by Algerian hackers
The country's national social security agency said the cyberattack resulted in the leak of sensitive personal data reportedly belonging to millions of citizens.
010
Alexander Leslie @aejleslie.bsky.social · 12/04/2025
Interesting blog from Trustwave on new evasion techniques associated with the Tycoon 2FA phishing kit. Concur with the JavaScript findings. Something I’ve recently observed: “prevents right-click … redirects to another site if analysis is suspected.” h/t: www.trustwave.com/en-us/resour...
trustwave.com
Tycoon2FA New Evasion Technique for 2025
The Tycoon 2FA phishing kit has adopted several new evasion techniques aimed at slipping past endpoints and detection systems.
010
Alexander Leslie @aejleslie.bsky.social · 12/04/2025
This is a strong contender for AOTY. Blood Abscission’s 2023 debut was part of my rotation for months, but I think this takes it to the next level. Check it out, if you’re into this kind of thing. Link: youtu.be/7u7cwTnvPUg?...
youtu.be
Blood Abscission - I I (Full album)
YouTube video by Debemur Morti Productions
100
Alexander Leslie @aejleslie.bsky.social · 11/04/2025
“slopsquatting” is hilarious… new favorite term “…a surprisingly effective type of software supply chain attack that emerges when LLMs ‘hallucinate’ package names that don’t actually exist.” h/t: socket.dev/blog/slopsqu...
socket.dev
The Rise of Slopsquatting: How AI Hallucinations Are Fueling...
Slopsquatting is a new supply chain threat where AI-assisted code generators recommend hallucinated packages that attackers register and weaponize.
020
Alexander Leslie @aejleslie.bsky.social · 10/04/2025
If you haven’t seen the news… I’ll be speaking at #RSAC 2025 in a few weeks on my investigations into cryptoscam gangs, infostealer operators, and the notorious “Marko Polo” (“ZeroDay”) traffer team. It’s going to be an exciting session! If you can’t make it, it’ll be recorded. Find me after!
010
Alexander Leslie @aejleslie.bsky.social · 10/04/2025
🇲🇦 🦁 “Researchers have discovered a novel tactic used by Moroccan cybercrime group Atlas Lion [Storm-0539] to attack big-box retailers, apparel companies, restaurants and more.” 🔑 “…enroll its own virtual machines into an organization’s cloud domain…” h/t: therecord.media/atlas-lion-g...
therecord.media
Moroccan cybercrime group Atlas Lion hiding in plain sight during attacks on retailers
Researchers at Expel said a cybercrime group that specializes in gift card fraud used a novel tactic to hide its activities: signing up its own virtual machines (VMs) within a legitimate corporate clo...
010
Alexander Leslie @aejleslie.bsky.social · 03/04/2025
🇺🇦 “Ukraine recorded at least three cyberattacks in March targeting government agencies and critical infrastructure...” 👀 “The attacks were carried out using previously unknown malware — dubbed Wrecksteel — deployed through phishing emails…” h/t: therecord.media/hackers-ukra...
therecord.media
Hackers hit Ukrainian state agencies, critical infrastructure with new ‘Wrecksteel’ malware
A Ukrainian cyber agency said a suspected espionage campaign using the new malware has been active seen the fall, with at least three incidents detected in March.
011
Alexander Leslie @aejleslie.bsky.social · 21/03/2025
It’s painful that I have to keep reiterating this, but I’ll say it again… Criminals lie. All the time. They’re looking for a reaction. I’ve dealt with a dozen events this week — ranging from this “Babuk” nonsense to random BreachForums skids — that were all fake. Don’t fall for it.
010
Alexander Leslie @aejleslie.bsky.social · 18/03/2025
💰 🇰🇵 “OKX is temporarily shutting down a popular tool after discovering North Korean hackers were attempting to use it to launder funds stolen from other platforms.” (via @jgreig.bsky.social / @therecordmedia.bsky.social) h/t: therecord.media/crypto-okx-s...
therecord.media
Crypto exchange OKX shuts down tool used by North Korean hackers to launder stolen funds
OKX said it detected a coordinated effort by one of North Korea’s most prolific hacking outfits to misuse its decentralized finance (DeFi) services.
032
Alexander Leslie @aejleslie.bsky.social · 04/03/2025
“…since the beginning of 2022, MI5 has responded to 20 plots by [Iran] ‘presenting potentially lethal threats to British citizens and UK residents.’” Not great. Consider similar plots from Russia and China, and it’s even worse. (via @alexmartin.bsky.social) h/t: therecord.media/iran-britain...
therecord.media
Iran linked to more than 20 plots to kill or kidnap British citizens and residents
The Iranian regime "has become increasingly emboldened, asserting itself more aggressively," including kidnapping and murder plots, said Dan Jarvis, the U.K. government's security minister.
020
Alexander Leslie @aejleslie.bsky.social · 04/03/2025
🇵🇼 “Palau has recovered from a ransomware attack launched by [Qilin] … known for targeting prominent healthcare institutions.” 🇺🇸 “A U.S. Cyber Command ‘defend forward’ team is now on-site conducting forensics collection and analysis…” h/t: therecord.media/palau-health...
therecord.media
Palau health ministry on the mend after Qilin ransomware attack
A U.S. Cyber Command “defend forward” team is now on-site conducting forensics collection and analysis, according to Palau officials.
000
Alexander Leslie @aejleslie.bsky.social · 03/03/2025
🛰️ 🇵🇱 “Poland’s space agency announced on Sunday it had suffered a cyberattack…” 🔑 “Poland has become a prime target for pro-Russian hackers… a potential breach… could expose sensitive defense-related information…” (via @therecordmedia.bsky.social) h/t: therecord.media/poland-space...
therecord.media
Polish space agency investigates cyberattack on its systems
Poland confirmed that state cybersecurity services had detected unauthorized access to the space agency's IT infrastructure and had secured the affected systems.
063
Alexander Leslie @aejleslie.bsky.social · 01/03/2025
Progress. Great work @europol-eu.bsky.social. 👏 “More than two dozen suspected members of a criminal group were recently arrested for allegedly distributing sexual images of minors generated by artificial intelligence.” (via @therecordmedia.bsky.social) h/t: therecord.media/csam-ai-arre...
therecord.media
Global crackdown on AI-generated child sexual abuse material leads to 25 arrests
“Operation Cumberland,” led by Danish law enforcement, included the arrests of more than two dozen suspected members of a group distributing sexual images of minors generated by artificial intelligenc...
000
Alexander Leslie @aejleslie.bsky.social · 28/02/2025
It gets worse. “…analysts at [CISA] were verbally informed that they were not to follow or report on Russian threats…” “The person said work that was being done on something ‘Russia-related’ was in effect ‘nixed’.” h/t: www.theguardian.com/us-news/2025...
theguardian.com
Trump administration retreats in fight against Russian cyber threats
Recent incidents indicate US is no longer characterizing Russia as a cybersecurity threat, marking a radical departure: ‘Putin is on the inside now’
021
Alexander Leslie @aejleslie.bsky.social · 28/02/2025
All that work… down the drain. 🔑: “Russia is also a bastion for cybercrime, with state-linked and criminal ransomware actors striking targets around the globe. The command has become a key player in countering the malicious activity.”
020
Alexander Leslie @aejleslie.bsky.social · 28/02/2025
Insane scoop from @martinmatishak.bsky.social and @therecordmedia.bsky.social. “Defense Secretary Pete Hegseth last week ordered U.S. Cyber Command to stand down from all planning against Russia, including offensive digital actions…” h/t: therecord.media/hegseth-orde...
therecord.media
Exclusive: Hegseth orders Cyber Command to stand down on Russia planning
The secretary of Defense has ordered U.S. Cyber Command to stand down from all planning against Russia, including offensive digital actions, sources tell Recorded Future News.
064
Alexander Leslie @aejleslie.bsky.social · 28/02/2025
🚨 - The Recorded Future 2024 Malicious Infrastructure Report is here! I know many of you have been looking forward to this! Insikt Group significantly expanded its tracking of malicious infrastructure over the past year. Findings below! Blog: www.recordedfuture.com/research/202...
recordedfuture.com
2024 Malicious Infrastructure Insights: Key Trends and Threats
Explore key 2024 cybercrime trends, including the rise of malware-as-a-service (MaaS), mobile malware, and Chinese and Russian state-sponsored threats. Learn how Insikt Group's expanded tracking enhan...
163
Alexander Leslie @aejleslie.bsky.social · 27/02/2025
🇷🇸 “Cellebrite announced Tuesday that it will no longer allow Serbia to use its software…” “Cellebrite has been ‘systematically deployed’ in Serbia and regularly targets members of civil society, [Amnesty International] said in its report.” h/t: therecord.media/cellebrite-s...
therecord.media
Cellebrite cuts off Serbia over abuse of phone-cracking software against civil society
The decision comes on the heels of an Amnesty International report alleging that Serbian authorities used Cellebrite technology to secretly break into phones belonging to civilians and then installed ...
111
Alexander Leslie @aejleslie.bsky.social · 26/02/2025
I’ve been laughing at this all day. That’s where I’m at. Shocked it isn’t parody.
110
Alexander Leslie @aejleslie.bsky.social · 26/02/2025
🇺🇦 “UAC-0173… has been distributing phishing emails since mid-January, posing as regional offices of Ukraine’s Ministry of Justice…” 🔑 “…the group is likely conducting the attacks for hire and receiving a financial reward from an unnamed source.” h/t: therecord.media/hackers-ukra...
therecord.media
Hackers-for-hire target Ukrainian notaries to manipulate state registries
The hacking group has been distributing phishing emails spoofing officials from Ukraine’s Ministry of Justice. The campaign follows news that suspected Russian military hackers breached Kyiv state reg...
000
Alexander Leslie @aejleslie.bsky.social · 20/02/2025
A tale as old as time. 🇷🇺 “Suspected Russian-speaking hackers are using malicious versions of popular pirated games to install cryptomining software known as XMRig on their victims' devices…” h/t: therecord.media/xmrig-crypto...
therecord.media
Cryptominer hidden in pirated games lands mostly on Russian computers
Cybercriminals are sneaking the cryptominer XMRig into pirated versions of popular games, and Russians appear to be the most frequent victims, according to researchers at Kaspersky.
000
Alexander Leslie @aejleslie.bsky.social · 20/02/2025
I’ve skimmed the leaked Black Basta chat log dump. It’s legit. There’s a lot to unpack, thus running the risk of jumping to premature conclusions. I’ve already seen some off-base stuff. Initial thoughts won’t do it justice, so expect more detailed analysis and commentary in the coming days.
040
Alexander Leslie @aejleslie.bsky.social · 20/02/2025
It’s been… quite the news day. More coherent thoughts tomorrow on these compounding disasters. In the meantime, I’ve found blacksmithing in Kingdom Come: Deliverance II to be cathartic. I’ve been demolishing the same axe over and over all night.
040
Alexander Leslie @aejleslie.bsky.social · 20/02/2025
🇲🇲 “Around 7,000 people rescued from illegal call centers in Myanmar are awaiting transfer to Thailand amid a crackdown on cross-border scam operations…” h/t: therecord.media/thailand-to-...
therecord.media
Thailand to take in 7,000 rescued from illegal cyber scam hubs in Myanmar
Around 7,000 people rescued from illegal call centers in Myanmar are awaiting transfer to Thailand amid a crackdown on cross-border scam operations, Thailand’s Prime Minister Paetongtarn Shinawatra sa...
020