Will T @bushidotoken.net · 26/09/2026📝 Looking to get into infrastructure analysis for CTI? I recommend studying the following aspects/topics in-depth to get started: PDNS WHOIS Records BGP Peers HTTP Titles, Response Headers & ETags X509 Cert Issuers & Subjects & JA4X JARM SSH Host Keys & HASSH Favicon Hashes OpenDirs 1143
Will T @bushidotoken.net · 25/09/2026New Blog 🇬🇧 UK Cybercrime Journal: Manchester Airport Group Breached by FulcrumSec 🔗 blog.bushidotoken.net/2026/09/uk-c...blog.bushidotoken.netUK Cybercrime Journal: Manchester Airport Group Breached by FulcrumSecCTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security 020
Will T @bushidotoken.net · 15/09/2026I am very glad to finally share publicly some interesting research I’ve been doing into ransomware infrastructure TTPs. This has been a long-running collaboration with a trusted partner who we can’t name but deeply appreciate their support. Read it here 👇 www.team-cymru.com/post/ransomw...team-cymru.comRansomware Incident Response: Infrastructure AnalysisA year of incident response data reveals how Akira, DragonForce & Clop build ransomware infrastructure — and how defenders can hunt it. 065
Will T @bushidotoken.net · 15/09/2026Heads up — @SANSEMEA #CyberThreat2026 lnkd.in/p/gWgqJitalnkd.in#cyberthreat2026 | Will ThomasThe full agenda for SANS EMEA #CyberThreat2026 is now up! Join us on 16-17 November for two days of technical CTI research and war stories. The Two sessions I look forward to the most are: 1) Ivan ... 010
Will T @bushidotoken.net · 03/09/2026New Blog! 🇬🇧 UK Cybercrime Journal: ExfilSquad Emerges - ExfilSquad’s extortion campaign targets UK public sector orgs, education, and law enforcement - ExfilSquad's primary attack vector involves exploiting CRM platforms and Microsoft Power Pages 🔗 blog.bushidotoken.net/2026/09/uk-c...blog.bushidotoken.netUK Cybercrime Journal: ExfilSquad EmergesCTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security 001
Will T @bushidotoken.net · 28/08/2026New Blog! 🇬🇧 UK Cybercrime Journal: ACRO Breach Report — Between July 2021 and June 2023, the UK Criminal Records Office had 3 separate breaches — It had an SQLi attack on its Kentico CMS followed by Mimikatz — 4x Trend Micro AV alerts were ignored 🔗 blog.bushidotoken.net/2026/08/uk-c...blog.bushidotoken.netUK Cybercrime Journal: ACRO Breach ReportCTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security 000
Will T @bushidotoken.net · 22/08/2026New Blog! 🇬🇧 UK Cybercrime Journal: Carding Tactics & Youth Money Muling - UK law enforcement exposed domestic carding networks and the growing threat of teenage money mules recruited via Snapchat, Instagram, and online gaming services 🔗 blog.bushidotoken.net/2026/08/uk-c...blog.bushidotoken.netUK Cybercrime Journal: Carding Tactics & Youth Money MulingCTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security 021
Will T @bushidotoken.net · 12/08/2026New Blog! 🇬🇧 UK Cybercrime Journal: Evolution of Courier Fraud Campaigns 🔗 blog.bushidotoken.net/2026/08/uk-c...blog.bushidotoken.netUK Cybercrime Journal: Evolution of Courier Fraud CampaignsCTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security 000
Will T @bushidotoken.net · 09/08/2026New Blog! 🇬🇧 UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026 - In H1 2026, Qilin averaged 8 UK victims per month, 37 in total - Most victims are Small/Medium Enterprises (SMEs) - Salford City College appeared on Qilin & DragonForce’s DLSs 🔗 blog.bushidotoken.net/2026/07/uk-c...blog.bushidotoken.netUK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security 031
Will T @bushidotoken.net · 29/07/2026New Blog! 🇬🇧 UK Cybercrime Journal: H1 2026 Social Media Fraud Trends - HMRC Warns TikTok Users - Lloyds Bank says 66% of Fraud Cases Started on Meta - UK Finance Recorded £221.5m Lost to Investment Scams - Fraudsters arrested in Nigeria by the NCA 🔗 blog.bushidotoken.net/2026/07/uk-c...blog.bushidotoken.netUK Cybercrime Journal: H1 2026 Social Media Fraud TrendsCTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security 010
Will T @bushidotoken.net · 25/07/2026🔮 New CTI Resource Announcement! 🔮 Project ORBITAL (Operational Relay Box Intelligence, Tracking, & Analysis Lexicon) is the latest open source intelligence (OSINT) collection I’ve created to help educate the industry about ORB Networks. 🔗 blog.bushidotoken.net/2026/07/proj... 092
Will T @bushidotoken.net · 22/07/2026New Blog! 🇬🇧 UK Cybercrime Journal: H1 2026 Dark Web Seizures & Arrests - Nemesis Dark Web Drug Dealers Arrested - AEGIS Dark Web Drug Market Seizure - Online Killers Marketplace (OKM) Admins Arrested 🔗 blog.bushidotoken.net/2026/07/uk-c...blog.bushidotoken.netUK Cybercrime Journal: H1 2026 Dark Web Seizures & ArrestsCTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security 040
Will T @bushidotoken.net · 16/07/2026New Blog! 🇬🇧 UK Cybercrime Journal: University of Nottingham Breached by ShinyHunters The education sector in the UK has suffered repeated, significant data breaches in recent years, but ShinyHunters campaign has been one of the worst yet. 🔗 blog.bushidotoken.net/2026/07/uk-c...blog.bushidotoken.netUK Cybercrime Journal: University of Nottingham Breached by ShinyHuntersCTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security 000
Will T @bushidotoken.net · 08/07/2026New Blog! 🇬🇧 UK Cybercrime Journal: SMS Blaster Gang Convicted - New details emerge about the use of an SMS Blaster device to send fraudulent text messages as part of an organised criminal operation in London 🔗 blog.bushidotoken.net/2026/07/uk-c...blog.bushidotoken.netUK Cybercrime Journal: SMS Blaster Gang ConvictedCTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security 032
Will T @bushidotoken.net · 05/07/2026New Phishing Campaign: Fake Interviews Offered at Top Brands to harvest Gmail creds, IOCs inside gist.github.com/BushidoUK/57...gist.github.comGmailPhishingAlert.mdGitHub Gist: instantly share code, notes, and snippets. 011
Will T @bushidotoken.net · 02/07/2026New Blog! 🇬🇧 UK Cybercrime Journal: Argos Account Takeover Fraud - Cybercriminals are using leaked credentials to hijack Argos user accounts - They then order and then collect the goods in-person at a physical store and pay with stolen credit cards 🔗 blog.bushidotoken.net/2026/07/uk-c...blog.bushidotoken.netUK Cybercrime Journal: Argos Account Takeover FraudCTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security 010
Will T @bushidotoken.net · 24/06/2026New Blog! 🇬🇧 UK Cybercrime Journal: Hargreaves Landsdown Extortion Attempt by Bashe It appears Bashe weaponised HL’s recent, IT outages & glitches (in Sept 2025 and March 2026) to construct a plausible, but false, narrative of a successful hack. 🔗 blog.bushidotoken.net/2026/06/uk-c...blog.bushidotoken.netUK Cybercrime Journal: Hargreaves Landsdown Extortion Attempt by BasheCTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security 010
Will T @bushidotoken.net · 24/06/2026Two of my fav 🇬🇧 🇨🇦 experts when it comes to discussing cyber warfare, Philip Ingram and Ian Thornton-Trump, released an interview reviewing in detail the threat landscape of 🇷🇺 Russian cyber operations in the context of the ongoing war in 🇺🇦 Ukraine. 🔗 youtu.be/p1vl5t4fVWAyoutu.beHow Russia’s cyber propaganda machine is backfiring on the frontline | Ian Thornton-TrumpYouTube video by Frontline 041
Will T @bushidotoken.net · 21/06/2026New Blog! 🇬🇧 UK Cybercrime Journal: Sustained DragonForce Campaign Throughout May 2026, the DragonForce RaaS operation claimed seven UK-based companies as its victims by posting them on their Tor data leak site. 🔗 blog.bushidotoken.net/2026/06/uk-c...blog.bushidotoken.netUK Cybercrime Journal: Sustained DragonForce CampaignCTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security 000
Will T @bushidotoken.net · 15/06/2026New Blog! Ransomware Tool Matrix Project Updates: Three Groups To Track 🔒🛠️ 🔗 blog.bushidotoken.net/2026/06/rans...blog.bushidotoken.netRansomware Tool Matrix Project Updates: Three Groups To TrackCTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security 032
Will T @bushidotoken.net · 14/06/2026I recently experimented with turning one of my blogs from back in 2020 (the pre-AI era!) into an AI-generated video via @NotebookLM and was surprised with the result. 🎥 Video: The Law of the Jungle 🐍 🦁 🦈 🦀 youtu.be/gb1aOjXly7E Original blog: blog.bushidotoken.net/2020/05/cybe...youtu.beThe Law of the Jungle: A Cybersecurity Awareness Video made with NotebookLMYouTube video by BushidoToken 010
Will T @bushidotoken.net · 10/06/2026New 🇬🇧 UK Cybercrime Journal Entry: Arup Group Breached by FulcrumSec What do AWS DCs, Disneyland, Wembley Football Stadium, HS2 and HS1 Channel Tunnel Rail Link network, and the Eden Project all have in common? They were engineered by Arup Group 👀 blog.bushidotoken.net/2026/06/uk-c...blog.bushidotoken.netUK Cybercrime Journal: Arup Group Breached by FulcrumSecCTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security 110
Will T @bushidotoken.net · 03/06/2026New 🇬🇧 UK Cybercrime Journal Entry: British Universities Struck by ShinyHunters Before Exam Season blog.bushidotoken.net/2026/05/uk-c...blog.bushidotoken.net 020
Will T @bushidotoken.net · 27/05/2026New 🇬🇧 UK Cybercrime Journal Entry: £102 million Lost to Scams in 2025 blog.bushidotoken.net/2026/05/uk-c...blog.bushidotoken.netUK Cybercrime Journal: £102 million Lost to Scams in 2025CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security 010
Will T @bushidotoken.net · 24/05/2026📣 I have been wanting to write more regularly for my site blog.bushidotoken.net and have made a new series: The UK Cybercrime Journal. These are short UK cybercrime incident reports with a BLUF, Analyst Comment, and Defensive Takeaways. Starting here: blog.bushidotoken.net/2026/05/uk-c...blog.bushidotoken.netUK Cybercrime Journal: Inside the Cl0p attack on South Staffs WaterCTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security 053
Will T @bushidotoken.net · 01/04/2026New Blog! Stranger Strings: Yurei Ransomware Operator Toolkit Exposed Through my research with Team Cymru’s data, we have discovered another ransomware operator’s server with Stranger Things-themed tools, check it out👇 www.team-cymru.com/post/yurei-d...team-cymru.comYurei Double Extortion Ransomware: Operator Toolkit and AnalysisAnalyze the Yurei double extortion ransomware campaign, including its toolkit, attack lifecycle, and key tactics used by operators. 081
Will T @bushidotoken.net · 18/03/2026New Blog! The Beast Returns: Analysis of a Beast Ransomware Server 👹 In March 2026, Team Cymru detected a Beast operator’s server that enabled us to understand the flow of their attacks from start, to middle, to the end, including ransomware binaries. www.team-cymru.com/post/beast-r...team-cymru.comBeast Ransomware Toolkit: A Proactive Threat Intelligence ReportExplore our latest threat intelligence report on Beast Ransomware. See the exact incident response tools and TTPs used by operators to bypass EDR and delete backups. 077
Will T @bushidotoken.net · 09/12/2025My latest article for Feedly is about how CTI and Threat Hunting can actually fuse into a single, intelligence-driven workflow instead of operating in silos. If you’re trying to build a more proactive security program, I think you’ll find it useful. 👉 Read it here: feedly.com/ti-essential...feedly.comHow to Integrate CTI with Threat Hunting: A Practical Guide | TI Essentials | Feedly 063
Reposted by Will TKevin Poireault @leekthehack.bsky.social · 09/12/2025𝗣𝗢𝗗𝗖𝗔𝗦𝗧 🎧 𝗛𝗼𝘄 𝟮𝟬𝟮𝟱 𝗦𝗵𝗮𝗽𝗲𝗱 𝘁𝗵𝗲 𝗙𝘂𝘁𝘂𝗿𝗲 𝗼𝗳 𝗖𝘆𝗯𝗲𝗿𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 We sat down with Rebecca Taylor from Sophos and @bushidotoken.net from @teamcymrus2.bsky.social to discuss 2025’s highs and lows in cyber and make educated guesses on what to look for in 2026. feeds.soundcloud.com/users/soundc... 031
Will T @bushidotoken.net · 30/10/2025New Blog 👀 This blog discusses the topic of cybercrime counterintelligence to highlight the growing threat toward the cyber threat intelligence (CTI) and law enforcement (LE) communities ⚠️ 🔗 www.sans.org/blog/for589-... 052
Will T @bushidotoken.net · 22/10/2025Spotted a rather Team Cymru looking fountain here in the Netherlands 🇳🇱 this week! 📸 130
Will T @bushidotoken.net · 18/10/2025New Blog! Lessons from the BlackBasta Ransomware Attack on Capita When a company that manages data for millions of UK citizens falls victim to ransomware, the whole industry should pay attention to it. 📝 blog.bushidotoken.net/2025/10/less...blog.bushidotoken.netLessons from the BlackBasta Ransomware Attack on CapitaCTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security 082
Will T @bushidotoken.net · 06/10/2025New Blog! 👀 In this research, I take a look at the Qilin RaaS in-depth, which has emerged as one of the leading and most innovative ransomware gangs following the takedown of LockBit, the exit scam by ALPHV/BlackCat, and the shutdown of RansomHub. 🔗 www.sans.org/blog/evoluti... 062
Will T @bushidotoken.net · 01/10/2025New Blog! 👀 After the last few large breaches, I discuss several cases in which the customers of major SaaS providers, such as Salesloft, Salesforce, and Snowflake have been extorted by adversaries from the English-speaking #cybercrime communities. 🔗 www.sans.org/blog/hunting... 071
Will T @bushidotoken.net · 22/07/2025Pleased to share I’ll be speaking at Adversary Village in DEFCON33! 091
Will T @bushidotoken.net · 03/07/2025Pleased to share my first official Team Cymru blog that follows on from my webinar last month 🙌 “Uncovering DPRK Remote Workers: Detecting Hidden Threats Through Internet Telemetry” 🇰🇵 🔍 www.team-cymru.com/post/uncover...team-cymru.comUncovering DPRK Remote Workers: Detecting Hidden Threats Through Internet Telemetry | Team CymruThis blog explores unpacks key insights and explains how internet telemetry can be used to detect these threats in the real world. 071
Will T @bushidotoken.net · 27/06/2025⚠️ IntelBroker was arrested in France 🇫🇷 in February 2025, and the US 🇺🇸 is seeking his extradition. How did Law Enforcement Deanonymize IntelBroker? 🔍 TL;DR: He messed up on the Bitcoin opsec after an undercover officer made a controlled buy 💰 www.justice.gov/usao-sdny/me... 071
Will T @bushidotoken.net · 09/06/2025#opendir 🇨🇳 1.94.184[.]17:8000 Huawei Cloud AS55990 .jsp Godzilla Web Shell 6d403c3fc246d6d493a6f4acc18c1c292f710db6ad9c3ea2ff065595c5ad3c5b /poc.xml contents wqtzskzmtp[.]zaza[.]eu[.]org 101.33.34[.]170 Tencent AS132203 171
Will T @bushidotoken.net · 18/05/2025www.curatedintel.org/2025/05/new-...curatedintel.orgNew Community Resource: Attribution to IPIntroduction The Curated Intelligence community has shared a new collection for CTI analysts and others who perform cybersecurity research d... 091
Will T @bushidotoken.net · 06/05/2025blog.bushidotoken.net/2025/05/rans...blog.bushidotoken.netRansomware Tool Matrix Project Updates: May 2025CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security 041
Reposted by Will TKenneth Kinion @kennethkinion.bsky.social · 07/04/2025@bushidotoken.net explored a Meta-themed credential phishing campaign (not "Reality"). From those indicators, I pulled the "Threads" & this is far from an isolated campaign. Found great pivots in registration "Meta"data. (I'll see myself out.) All 762 indicators 💥⤵️ www.validin.com/blog/not_rea...validin.comNot Reality: Exploring Meta-themed Phishing with Validin | ValidinNot Reality: Exploring Meta-themed Phishing with Validin 012
Will T @bushidotoken.net · 02/04/2025New Blog! Tracking Adversaries: EvilCorp, the RansomHub affiliate blog.bushidotoken.net/2025/04/trac...blog.bushidotoken.netTracking Adversaries: EvilCorp, the RansomHub affiliateCTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security 0127
Will T @bushidotoken.net · 20/03/2025UNC3886 is a very interesting China-nexus APT that I encourage more to CTI analysts to investigate. They are one of the more skilled ones, like Salt or Volt. To help make life easier for some, I’ve manually mapped their TTPs to ATT&CK: github.com/BushidoUK/MI...github.com 180
Will T @bushidotoken.net · 16/03/2025Interesting phishing TTP observed in the wild last year: 1. Send phish to an <org_name>@service-now[.]com inbox 2. A ticket is then auto-created in the platform using servicenow_notification@<org_domain> 3. A link is put in the body of the SNOW ticket that can lead to malware or fake login page 3323
Reposted by Will TCatalin Cimpanu @campuscodi.risky.biz · 15/03/2025@bushidotoken.net has dug up some IOCs for the FBI's recent warning about online file format converters being used to distribute malware Link: x.com/BushidoToken... 1133
Will T @bushidotoken.net · 28/02/2025New Blog! BlackBasta Leaks: Lessons from the Ascension Health attack 🏥🔒 — This is a step-by-step extraction and translation of the leaked conversation between the BlackBasta members during the Ascension Health attack 🔗 blog.bushidotoken.net/2025/02/blac...blog.bushidotoken.netBlackBasta Leaks: Lessons from the Ascension Health attackCTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security 1153
Will T @bushidotoken.net · 15/02/2025New Blog! Investigating Anonymous VPS services used by Ransomware Gangs h/t to @drb_ra for lending me some of their C2 data! Made my life a lot easier 🫡 🔗 blog.bushidotoken.net/2025/02/inve... Podcast version: www.youtube.com/watch?v=xX25... 1124
Will T @bushidotoken.net · 11/02/2025Glad to see LE and Gov keeping up the pressure on ransomware gangs in early 2025 ZSERVERS BPH sanctioned by the UK for enabling LockBit attacks www.gov.uk/government/n... Phobos & 8BASE arrests by international partners www.europol.europa.eu/media-press/...europol.europa.euKey figures behind Phobos and 8Base ransomware arrested in international cybercrime crackdown | EuropolA coordinated international law enforcement action has led to the arrest of four individuals leading the 8Base ransomware group. These individuals, all Russian nationals, are suspected of deploying a ... 081
Will T @bushidotoken.net · 20/01/2025New Blog! Tracking Adversaries: Ghostwriter APT Infrastructure 🇧🇾 blog.bushidotoken.net/2025/01/trac...blog.bushidotoken.netTracking Adversaries: Ghostwriter APT InfrastructureCTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security 0154