Sign in

Will T

@bushidotoken.net
3.3K followers 674 following 153 posts

🇬🇧 | Senior Threat Intelligence Advisor at Team Cymru | Co-author SANS FOR589 | Co-founder Curated Intel

PostsRepliesMedia
Will T @bushidotoken.net · 26/09/2026
📝 Looking to get into infrastructure analysis for CTI? I recommend studying the following aspects/topics in-depth to get started: PDNS WHOIS Records BGP Peers HTTP Titles, Response Headers & ETags X509 Cert Issuers & Subjects & JA4X JARM SSH Host Keys & HASSH Favicon Hashes OpenDirs
1143
Will T @bushidotoken.net · 25/09/2026
New Blog 🇬🇧 UK Cybercrime Journal: Manchester Airport Group Breached by FulcrumSec 🔗 blog.bushidotoken.net/2026/09/uk-c...
blog.bushidotoken.net
UK Cybercrime Journal: Manchester Airport Group Breached by FulcrumSec
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
020
Will T @bushidotoken.net · 15/09/2026
I am very glad to finally share publicly some interesting research I’ve been doing into ransomware infrastructure TTPs. This has been a long-running collaboration with a trusted partner who we can’t name but deeply appreciate their support. Read it here 👇 www.team-cymru.com/post/ransomw...
team-cymru.com
Ransomware Incident Response: Infrastructure Analysis
A year of incident response data reveals how Akira, DragonForce & Clop build ransomware infrastructure — and how defenders can hunt it.
065
Will T @bushidotoken.net · 15/09/2026
Heads up — @SANSEMEA #CyberThreat2026 lnkd.in/p/gWgqJita
lnkd.in
#cyberthreat2026 | Will Thomas
The full agenda for SANS EMEA #CyberThreat2026 is now up! Join us on 16-17 November for two days of technical CTI research and war stories. The Two sessions I look forward to the most are: 1) Ivan ...
010
Will T @bushidotoken.net · 03/09/2026
New Blog! 🇬🇧 UK Cybercrime Journal: ExfilSquad Emerges - ExfilSquad’s extortion campaign targets UK public sector orgs, education, and law enforcement - ExfilSquad's primary attack vector involves exploiting CRM platforms and Microsoft Power Pages 🔗 blog.bushidotoken.net/2026/09/uk-c...
blog.bushidotoken.net
UK Cybercrime Journal: ExfilSquad Emerges
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
001
Will T @bushidotoken.net · 28/08/2026
New Blog! 🇬🇧 UK Cybercrime Journal: ACRO Breach Report — Between July 2021 and June 2023, the UK Criminal Records Office had 3 separate breaches — It had an SQLi attack on its Kentico CMS followed by Mimikatz — 4x Trend Micro AV alerts were ignored 🔗 blog.bushidotoken.net/2026/08/uk-c...
blog.bushidotoken.net
UK Cybercrime Journal: ACRO Breach Report
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
000
Will T @bushidotoken.net · 22/08/2026
New Blog! 🇬🇧 UK Cybercrime Journal: Carding Tactics & Youth Money Muling - UK law enforcement exposed domestic carding networks and the growing threat of teenage money mules recruited via Snapchat, Instagram, and online gaming services 🔗 blog.bushidotoken.net/2026/08/uk-c...
blog.bushidotoken.net
UK Cybercrime Journal: Carding Tactics & Youth Money Muling
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
021
Will T @bushidotoken.net · 12/08/2026
New Blog! 🇬🇧 UK Cybercrime Journal: Evolution of Courier Fraud Campaigns 🔗 blog.bushidotoken.net/2026/08/uk-c...
blog.bushidotoken.net
UK Cybercrime Journal: Evolution of Courier Fraud Campaigns
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
000
Will T @bushidotoken.net · 09/08/2026
New Blog! 🇬🇧 UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026 - In H1 2026, Qilin averaged 8 UK victims per month, 37 in total - Most victims are Small/Medium Enterprises (SMEs) - Salford City College appeared on Qilin & DragonForce’s DLSs 🔗 blog.bushidotoken.net/2026/07/uk-c...
blog.bushidotoken.net
UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
031
Will T @bushidotoken.net · 29/07/2026
New Blog! 🇬🇧 UK Cybercrime Journal: H1 2026 Social Media Fraud Trends - HMRC Warns TikTok Users - Lloyds Bank says 66% of Fraud Cases Started on Meta  - UK Finance Recorded £221.5m Lost to Investment Scams - Fraudsters arrested in Nigeria by the NCA 🔗 blog.bushidotoken.net/2026/07/uk-c...
blog.bushidotoken.net
UK Cybercrime Journal: H1 2026 Social Media Fraud Trends
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
010
Will T @bushidotoken.net · 25/07/2026
🔮 New CTI Resource Announcement! 🔮 Project ORBITAL (Operational Relay Box Intelligence, Tracking, & Analysis Lexicon) is the latest open source intelligence (OSINT) collection I’ve created to help educate the industry about ORB Networks. 🔗 blog.bushidotoken.net/2026/07/proj...
092
Will T @bushidotoken.net · 22/07/2026
New Blog! 🇬🇧 UK Cybercrime Journal: H1 2026 Dark Web Seizures & Arrests - Nemesis Dark Web Drug Dealers Arrested - AEGIS Dark Web Drug Market Seizure - Online Killers Marketplace (OKM) Admins Arrested 🔗 blog.bushidotoken.net/2026/07/uk-c...
blog.bushidotoken.net
UK Cybercrime Journal: H1 2026 Dark Web Seizures & Arrests
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
040
Will T @bushidotoken.net · 16/07/2026
New Blog! 🇬🇧 UK Cybercrime Journal: University of Nottingham Breached by ShinyHunters The education sector in the UK has suffered repeated, significant data breaches in recent years, but ShinyHunters campaign has been one of the worst yet. 🔗 blog.bushidotoken.net/2026/07/uk-c...
blog.bushidotoken.net
UK Cybercrime Journal: University of Nottingham Breached by ShinyHunters
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
000
Will T @bushidotoken.net · 08/07/2026
New Blog! 🇬🇧 UK Cybercrime Journal: SMS Blaster Gang Convicted - New details emerge about the use of an SMS Blaster device to send fraudulent text messages as part of an organised criminal operation in London 🔗 blog.bushidotoken.net/2026/07/uk-c...
blog.bushidotoken.net
UK Cybercrime Journal: SMS Blaster Gang Convicted
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
032
Will T @bushidotoken.net · 05/07/2026
New Phishing Campaign: Fake Interviews Offered at Top Brands to harvest Gmail creds, IOCs inside gist.github.com/BushidoUK/57...
gist.github.com
GmailPhishingAlert.md
GitHub Gist: instantly share code, notes, and snippets.
011
Will T @bushidotoken.net · 02/07/2026
New Blog! 🇬🇧 UK Cybercrime Journal: Argos Account Takeover Fraud - Cybercriminals are using leaked credentials to hijack Argos user accounts - They then order and then collect the goods in-person at a physical store and pay with stolen credit cards 🔗 blog.bushidotoken.net/2026/07/uk-c...
blog.bushidotoken.net
UK Cybercrime Journal: Argos Account Takeover Fraud
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
010
Will T @bushidotoken.net · 24/06/2026
New Blog! 🇬🇧 UK Cybercrime Journal: Hargreaves Landsdown Extortion Attempt by Bashe It appears Bashe weaponised HL’s recent, IT outages & glitches (in Sept 2025 and March 2026) to construct a plausible, but false, narrative of a successful hack. 🔗 blog.bushidotoken.net/2026/06/uk-c...
blog.bushidotoken.net
UK Cybercrime Journal: Hargreaves Landsdown Extortion Attempt by Bashe
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
010
Will T @bushidotoken.net · 24/06/2026
Two of my fav 🇬🇧 🇨🇦 experts when it comes to discussing cyber warfare, Philip Ingram and Ian Thornton-Trump, released an interview reviewing in detail the threat landscape of 🇷🇺 Russian cyber operations in the context of the ongoing war in 🇺🇦 Ukraine. 🔗 youtu.be/p1vl5t4fVWA
youtu.be
How Russia’s cyber propaganda machine is backfiring on the frontline | Ian Thornton-Trump
YouTube video by Frontline
041
Will T @bushidotoken.net · 21/06/2026
New Blog! 🇬🇧 UK Cybercrime Journal: Sustained DragonForce Campaign Throughout May 2026, the DragonForce RaaS operation claimed seven UK-based companies as its victims by posting them on their Tor data leak site. 🔗 blog.bushidotoken.net/2026/06/uk-c...
blog.bushidotoken.net
UK Cybercrime Journal: Sustained DragonForce Campaign
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
000
Will T @bushidotoken.net · 15/06/2026
New Blog! Ransomware Tool Matrix Project Updates: Three Groups To Track 🔒🛠️ 🔗 blog.bushidotoken.net/2026/06/rans...
blog.bushidotoken.net
Ransomware Tool Matrix Project Updates: Three Groups To Track
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
032
Will T @bushidotoken.net · 14/06/2026
I recently experimented with turning one of my blogs from back in 2020 (the pre-AI era!) into an AI-generated video via @NotebookLM and was surprised with the result. 🎥 Video: The Law of the Jungle 🐍 🦁 🦈 🦀 youtu.be/gb1aOjXly7E Original blog: blog.bushidotoken.net/2020/05/cybe...
youtu.be
The Law of the Jungle: A Cybersecurity Awareness Video made with NotebookLM
YouTube video by BushidoToken
010
Will T @bushidotoken.net · 10/06/2026
New 🇬🇧 UK Cybercrime Journal Entry: Arup Group Breached by FulcrumSec What do AWS DCs, Disneyland, Wembley Football Stadium, HS2 and HS1 Channel Tunnel Rail Link network, and the Eden Project all have in common? They were engineered by Arup Group 👀 blog.bushidotoken.net/2026/06/uk-c...
blog.bushidotoken.net
UK Cybercrime Journal: Arup Group Breached by FulcrumSec
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
110
Will T @bushidotoken.net · 03/06/2026
New 🇬🇧 UK Cybercrime Journal Entry: British Universities Struck by ShinyHunters Before Exam Season blog.bushidotoken.net/2026/05/uk-c...
blog.bushidotoken.net
020
Will T @bushidotoken.net · 27/05/2026
New 🇬🇧 UK Cybercrime Journal Entry: £102 million Lost to Scams in 2025 blog.bushidotoken.net/2026/05/uk-c...
blog.bushidotoken.net
UK Cybercrime Journal: £102 million Lost to Scams in 2025
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
010
Will T @bushidotoken.net · 24/05/2026
📣 I have been wanting to write more regularly for my site blog.bushidotoken.net and have made a new series: The UK Cybercrime Journal. These are short UK cybercrime incident reports with a BLUF, Analyst Comment, and Defensive Takeaways. Starting here: blog.bushidotoken.net/2026/05/uk-c...
blog.bushidotoken.net
UK Cybercrime Journal: Inside the Cl0p attack on South Staffs Water
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
053
Will T @bushidotoken.net · 01/04/2026
New Blog! Stranger Strings: Yurei Ransomware Operator Toolkit Exposed Through my research with Team Cymru’s data, we have discovered another ransomware operator’s server with Stranger Things-themed tools, check it out👇 www.team-cymru.com/post/yurei-d...
team-cymru.com
Yurei Double Extortion Ransomware: Operator Toolkit and Analysis
Analyze the Yurei double extortion ransomware campaign, including its toolkit, attack lifecycle, and key tactics used by operators.
081
Will T @bushidotoken.net · 18/03/2026
New Blog! The Beast Returns: Analysis of a Beast Ransomware Server 👹 In March 2026, Team Cymru detected a Beast operator’s server that enabled us to understand the flow of their attacks from start, to middle, to the end, including ransomware binaries. www.team-cymru.com/post/beast-r...
team-cymru.com
Beast Ransomware Toolkit: A Proactive Threat Intelligence Report
Explore our latest threat intelligence report on Beast Ransomware. See the exact incident response tools and TTPs used by operators to bypass EDR and delete backups.
077
Will T @bushidotoken.net · 09/12/2025
My latest article for Feedly is about how CTI and Threat Hunting can actually fuse into a single, intelligence-driven workflow instead of operating in silos. If you’re trying to build a more proactive security program, I think you’ll find it useful. 👉 Read it here: feedly.com/ti-essential...
feedly.com
How to Integrate CTI with Threat Hunting: A Practical Guide | TI Essentials | Feedly
063
Reposted by Will T
Kevin Poireault @leekthehack.bsky.social · 09/12/2025
𝗣𝗢𝗗𝗖𝗔𝗦𝗧 🎧 𝗛𝗼𝘄 𝟮𝟬𝟮𝟱 𝗦𝗵𝗮𝗽𝗲𝗱 𝘁𝗵𝗲 𝗙𝘂𝘁𝘂𝗿𝗲 𝗼𝗳 𝗖𝘆𝗯𝗲𝗿𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 We sat down with Rebecca Taylor from Sophos and @bushidotoken.net from @teamcymrus2.bsky.social to discuss 2025’s highs and lows in cyber and make educated guesses on what to look for in 2026. feeds.soundcloud.com/users/soundc...
031
Will T @bushidotoken.net · 30/10/2025
New Blog 👀 This blog discusses the topic of cybercrime counterintelligence to highlight the growing threat toward the cyber threat intelligence (CTI) and law enforcement (LE) communities ⚠️ 🔗 www.sans.org/blog/for589-...
052
Will T @bushidotoken.net · 22/10/2025
Spotted a rather Team Cymru looking fountain here in the Netherlands 🇳🇱 this week! 📸
130
Will T @bushidotoken.net · 18/10/2025
New Blog! Lessons from the BlackBasta Ransomware Attack on Capita When a company that manages data for millions of UK citizens falls victim to ransomware, the whole industry should pay attention to it. 📝 blog.bushidotoken.net/2025/10/less...
blog.bushidotoken.net
Lessons from the BlackBasta Ransomware Attack on Capita
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
082
Will T @bushidotoken.net · 06/10/2025
New Blog! 👀 In this research, I take a look at the Qilin RaaS in-depth, which has emerged as one of the leading and most innovative ransomware gangs following the takedown of LockBit, the exit scam by ALPHV/BlackCat, and the shutdown of RansomHub. 🔗 www.sans.org/blog/evoluti...
062
Will T @bushidotoken.net · 01/10/2025
New Blog! 👀 After the last few large breaches, I discuss several cases in which the customers of major SaaS providers, such as Salesloft, Salesforce, and Snowflake have been extorted by adversaries from the English-speaking #cybercrime communities. 🔗 www.sans.org/blog/hunting...
071
Will T @bushidotoken.net · 24/09/2025
#ThreatHunting
061
Will T @bushidotoken.net · 22/07/2025
Pleased to share I’ll be speaking at Adversary Village in DEFCON33!
091
Will T @bushidotoken.net · 03/07/2025
Pleased to share my first official Team Cymru blog that follows on from my webinar last month 🙌 “Uncovering DPRK Remote Workers: Detecting Hidden Threats Through Internet Telemetry” 🇰🇵 🔍 www.team-cymru.com/post/uncover...
team-cymru.com
Uncovering DPRK Remote Workers: Detecting Hidden Threats Through Internet Telemetry | Team Cymru
This blog explores unpacks key insights and explains how internet telemetry can be used to detect these threats in the real world.
071
Will T @bushidotoken.net · 27/06/2025
⚠️ IntelBroker was arrested in France 🇫🇷 in February 2025, and the US 🇺🇸 is seeking his extradition. How did Law Enforcement Deanonymize IntelBroker? 🔍 TL;DR: He messed up on the Bitcoin opsec after an undercover officer made a controlled buy 💰 www.justice.gov/usao-sdny/me...
071
Will T @bushidotoken.net · 09/06/2025
#opendir 🇨🇳 1.94.184[.]17:8000 Huawei Cloud AS55990 .jsp Godzilla Web Shell 6d403c3fc246d6d493a6f4acc18c1c292f710db6ad9c3ea2ff065595c5ad3c5b /poc.xml contents wqtzskzmtp[.]zaza[.]eu[.]org 101.33.34[.]170 Tencent AS132203
171
Will T @bushidotoken.net · 18/05/2025
www.curatedintel.org/2025/05/new-...
curatedintel.org
New Community Resource: Attribution to IP
Introduction The Curated Intelligence community has shared a new collection for CTI analysts and others who perform cybersecurity research d...
091
Will T @bushidotoken.net · 06/05/2025
blog.bushidotoken.net/2025/05/rans...
blog.bushidotoken.net
Ransomware Tool Matrix Project Updates: May 2025
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
041
Reposted by Will T
Kenneth Kinion @kennethkinion.bsky.social · 07/04/2025
@bushidotoken.net explored a Meta-themed credential phishing campaign (not "Reality"). From those indicators, I pulled the "Threads" & this is far from an isolated campaign. Found great pivots in registration "Meta"data. (I'll see myself out.) All 762 indicators 💥⤵️ www.validin.com/blog/not_rea...
validin.com
Not Reality: Exploring Meta-themed Phishing with Validin | Validin
Not Reality: Exploring Meta-themed Phishing with Validin
012
Will T @bushidotoken.net · 02/04/2025
New Blog! Tracking Adversaries: EvilCorp, the RansomHub affiliate blog.bushidotoken.net/2025/04/trac...
blog.bushidotoken.net
Tracking Adversaries: EvilCorp, the RansomHub affiliate
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
0127
Will T @bushidotoken.net · 20/03/2025
UNC3886 is a very interesting China-nexus APT that I encourage more to CTI analysts to investigate. They are one of the more skilled ones, like Salt or Volt. To help make life easier for some, I’ve manually mapped their TTPs to ATT&CK: github.com/BushidoUK/MI...
github.com
180
Will T @bushidotoken.net · 16/03/2025
Interesting phishing TTP observed in the wild last year: 1. Send phish to an <org_name>@service-now[.]com inbox 2. A ticket is then auto-created in the platform using servicenow_notification@<org_domain> 3. A link is put in the body of the SNOW ticket that can lead to malware or fake login page
3323
Reposted by Will T
Catalin Cimpanu @campuscodi.risky.biz · 15/03/2025
@bushidotoken.net has dug up some IOCs for the FBI's recent warning about online file format converters being used to distribute malware Link: x.com/BushidoToken...
1133
Will T @bushidotoken.net · 28/02/2025
New Blog! BlackBasta Leaks: Lessons from the Ascension Health attack 🏥🔒 — This is a step-by-step extraction and translation of the leaked conversation between the BlackBasta members during the Ascension Health attack 🔗 blog.bushidotoken.net/2025/02/blac...
blog.bushidotoken.net
BlackBasta Leaks: Lessons from the Ascension Health attack
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
1153
Will T @bushidotoken.net · 15/02/2025
New Blog! Investigating Anonymous VPS services used by Ransomware Gangs h/t to @drb_ra for lending me some of their C2 data! Made my life a lot easier 🫡 🔗 blog.bushidotoken.net/2025/02/inve... Podcast version: www.youtube.com/watch?v=xX25...
1124
Will T @bushidotoken.net · 11/02/2025
Glad to see LE and Gov keeping up the pressure on ransomware gangs in early 2025 ZSERVERS BPH sanctioned by the UK for enabling LockBit attacks www.gov.uk/government/n... Phobos & 8BASE arrests by international partners www.europol.europa.eu/media-press/...
europol.europa.eu
Key figures behind Phobos and 8Base ransomware arrested in international cybercrime crackdown | Europol
A coordinated international law enforcement action has led to the arrest of four individuals leading the 8Base ransomware group. These individuals, all Russian nationals, are suspected of deploying a ...
081
Will T @bushidotoken.net · 20/01/2025
New Blog! Tracking Adversaries: Ghostwriter APT Infrastructure 🇧🇾 blog.bushidotoken.net/2025/01/trac...
blog.bushidotoken.net
Tracking Adversaries: Ghostwriter APT Infrastructure
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
0154