Sign in

Calwarez

@calwarez.bsky.social
471 followers 211 following 48 posts

Director for Malicious Infrastructure Discovery @ Recorded Future | Views my own

PostsRepliesMedia
Reposted by Calwarez
Jerri P @whoisnt.bsky.social · 23/07/2026
1/ We just published new research on TAG-195 (“Golden Chickens” / “Venom Spider”), documenting a major evolution of one of cybercrime’s longest-running Malware-as-a-Service ecosystems. We identified 4 previously undocumented malware families, revealing a shift toward modular, operator-driven tooling
recordedfuture.com
TAG-195 Upgrades MaaS Ecosystem with Modular Tools
Insikt Group identifies four new TAG-195 malware families, revealing an architectural transition toward modular, operator-driven tooling in the MaaS ecosystem
134
Reposted by Calwarez
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 09/07/2026
1/ Today @milenkowski.bsky.social from @sentinellabs.bsky.social and I are publishing a project we've been working on over the past few months. We found suspected China- and India-linked espionage actors independently targeting the same victim: #Balochistan Police in #Pakistan. s1.ai/spy2flags
s1.ai
One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement
China and India ran separate espionage operations against the same Pakistani police force, each drawn by different stakes in Pakistan's internal security.
1910
Reposted by Calwarez
Binding Hook @bindinghook.bsky.social · 09/06/2026
In her latest for Binding Hook, @cyberoverdrive.bsky.social argues that Chinese #cyberoperations no longer fit neatly within the traditional ‘advanced persistent threat’ (APT) model and explores why composite responsibility matters. 🪝 Read the full article: bindinghook.com/understandin...
bindinghook.com
Understanding modern Chinese cyber operations means shifting from ‘APT’ to composite responsibility
Cyber operations today can include anything from PLA units to companies acting independently, and often include a mix of actors, complicating attribution and response
0115
Calwarez @calwarez.bsky.social · 24/03/2026
🧵 ICYMI: We just dropped our 2025 Malicious Infrastructure Review! Some of the highlights below👇 #Infosec #CyberThreats 1/6 www.recordedfuture.com/research/202...
132
Reposted by Calwarez
Catalin Cimpanu @campuscodi.risky.biz · 23/03/2026
-Iran internet outage not caused by strikes -Russia expands internet blackout to Sankt Petersburg -Oracle out-of-band security update -Himmelblau vulnerability gives root -Claudy Day vulnerabilities -Leak in German uni campuses platform -Langflow attacks started within a day
1117
Reposted by Calwarez
Lawrence S. @lawrencesec.bsky.social · 18/03/2026
Noticed Microsoft Defender tagging #TheVoidStealer as #WallStealer thanks to some recent abuse_ch uploads. Here’s the threat actor nikoniko (aka “TheVoidStl”) discussing the removal of multiple detections, including WallStealer.
022
Reposted by Calwarez
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 18/02/2026
1/ Today, Insikt Group is publishing on GrayCharlie, a threat actor active since mid-2023 that overlaps with SmartApeSG. GrayCharlie compromises WordPress sites and turns them into malware delivery hubs: www.recordedfuture.com/research/gra...
recordedfuture.com
GrayCharlie Hijacks Law Firm Sites in Suspected Supply-Chain Attack
GrayCharlie turns compromised WordPress sites into malware delivery machines. Discover how this threat actor chains fake browser updates and ClickFix lures to deploy NetSupport RAT, Stealc, and Sectop...
158
Reposted by Calwarez
NCSC UK @ncsc.gov.uk · 19/01/2026
Today the NCSC has issued a warning highlighting Pro-Russian Hacktivist groups are targeting sectors across the UK. All organisations are urged to act now by reviewing and implementing our free guidance to protect against DoS attacks.
ncsc.gov.uk
Pro-Russia hacktivist activity continues to target UK organisations
The NCSC encourages local government and critical infrastructure operators to harden their ‘denial of service’ (DoS) defences
01111
Reposted by Calwarez
Tim Starks @timstarks.bsky.social · 14/01/2026
Predator spyware demonstrates troubleshooting, research-dodging capabilities cyberscoop.com/predator-spy...
cyberscoop.com
Predator spyware demonstrates troubleshooting, researcher-dodging capabilities
Predator spyware operators have the ability to recognize why an infection failed, and the tech has more sophisticated capabilities for averting detection than previously known, according to research p...
097
Reposted by Calwarez
X_Hunt3r @x-hunt3r.bsky.social · 07/01/2026
Today, we released new @RecordedFuture research detailing BlueDelta’s expanded credential-harvesting activity observed between February and September 2025. #BlueDelta #APT28 #FANCYBEAR #ForestBlizzard #FROZENLAKE #ITG05 #PawnStorm #Sednit #Sofacy #TA422 (1/5) www.recordedfuture.com/research/gru...
recordedfuture.com
GRU-Linked BlueDelta Evolves Credential Harvesting
Insikt Group reveals how GRU-linked BlueDelta evolved credential-harvesting campaigns targeting government, energy, and research organizations across Europe and Eurasia.
175
Reposted by Calwarez
Binding Hook @bindinghook.bsky.social · 10/12/2025
In their latest for Binding Hook, @nca-uk.bsky.social’s William Lyne and @rusi.bsky.social's @jamiemaccoll.bsky.social look at the challenges facing UK law enforcement as cybercriminals become more diverse at home and abroad: bindinghook.com/local-hacker...
bindinghook.com
Local hackers and Russian-speaking cyber criminals stretching UK responses
UK law enforcement must combat a diversifying array of cyber threats in the face of limited resources and a rapidly evolving cyber landscape
065
Reposted by Calwarez
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 09/12/2025
1/ @whoisnt.bsky.social, Marius, and I just published a report on #GrayBravo (formerly TAG-150), a highly adaptive, sophisticated threat actor that we first identified in Sept 2025. It uses a multi-layered infrastructure and responds quickly to exposure: www.recordedfuture.com/research/gra...
recordedfuture.com
GrayBravo’s CastleLoader Activity Clusters Target Multiple Industries
1106
Reposted by Calwarez
Virus Bulletin @virusbtn.bsky.social · 09/12/2025
Recorded Future’s Insikt Group uncovered four GrayBravo activity clusters. TAG-160 impersonates logistics firms, while TAG-161 impersonates Booking.com, employing ClickFix to deliver CastleLoader and Matanbuchus. www.recordedfuture.com/research/gra...
065
Reposted by Calwarez
TJ Nel @idr0p.net · 06/12/2025
"There is a lack of consensus regarding the current state of AI malware maturity." So we put together #AIM3 to help #malware researchers describe the maturity level of an #AI_Malware Threat. www.recordedfuture.com/blog/ai-malw...
032
Reposted by Calwarez
Vas Panagiotopoulos @vaspanagiotopoulos.com · 04/12/2025
⚠️ New victims of Predator #spyware identified, with malicious TikTok links revealing new targets, and evidence showing 🇪🇬Egypt & 🇸🇦Saudi clients still active. ➡️ Ad-based infections confirmed. ➡️ Leaked files & investigation expose post-sanctions Intellexa operations. www.haaretz.com/israel-news/...
177
Reposted by Calwarez
Ron Deibert @rondeibert.bsky.social · 04/12/2025
And check out the companion blog post by @amnestyuk.bsky.social tech with a detailed peek into Intellexa's setup based on leaked materials 👀 Giveaway: Intellexa can observe all of what their gov clients are doing with their hacking tech and more securitylab.amnesty.org/latest/2025/...
securitylab.amnesty.org
To Catch a Predator: Leak exposes the internal operations of Intellexa’s mercenary spyware - Amnesty International Security Lab
Drawing on leaked internal company documents, sales and marketing material, as well as training videos, the “Intellexa Leaks” investigation gives a never-before-seen glimpse of the internal operations...
163
Reposted by Calwarez
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 04/12/2025
1/ Today we release a new report exposing previously undisclosed entities connected to the wider #Intellexa ecosystem as well as newly identified activity clusters in Iraq and indications of activity in Pakistan: www.recordedfuture.com/research/int...
recordedfuture.com
Intellexa’s Global Corporate Web
22618
Reposted by Calwarez
Modat @modat-io.bsky.social · 01/12/2025
Cyber Monday Deal 
Get 6 months of Modat Magnify Pro for just €5 total (save €355).  Use code: MODAT2025CYBERMONDAY   
Try the platform. Run advanced queries. Find what others miss. 
 magnify.modat.io 
#CyberMonday #Cybersecurity #OSINT
011
Reposted by Calwarez
Lawrence S. @lawrencesec.bsky.social · 19/11/2025
1/ United States, Australia, and United Kingdom sanction Russian threat activity enabler Media Land (Yalishanda) and follow up on recent designations targeting Aeza. ofac.treasury.gov/recent-actio...
ofac.treasury.gov
133
Calwarez @calwarez.bsky.social · 06/11/2025
Great read from @lawrencesec.bsky.social & @whoisnt.bsky.social !
021
Reposted by Calwarez
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 22/10/2025
Recorded Future just published Dark Covenant 3.0, revealing how global crackdowns and shifting Russian enforcement are reshaping the cybercriminal underground, exposing ties to state actors and turning cybercrime into a geopolitical tool: www.recordedfuture.com/research/dar...
recordedfuture.com
Dark Covenant 3.0: Controlled Impunity and Russia’s Cybercriminals
Explore how Russia’s cybercriminal ecosystem evolved under Operation Endgame—where state control, selective enforcement, and criminal alliances collide.
077
Calwarez @calwarez.bsky.social · 21/10/2025
Great work by my colleague, @lawrencesec.bsky.social ! He dives deep into the systemic flaw where "neutral" internet governance lets sanctioned ISPs evade restrictions and continue supporting #cyberattacks and #disinformation. A must-read on the infrastructure gap. 👇
051
Reposted by Calwarez
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 07/10/2025
Recorded Future just published a report diving into the Beijing Institute of Electronics Technology and Application (BIETA), which is almost certainly a front for China’s MSS, developing technologies to support intelligence and military missions. Full report: www.recordedfuture.com/research/bie...
recordedfuture.com
BIETA: A Technology Enablement Front for China's MSS
Discover how China's Ministry of State Security (MSS) almost certainly operates BIETA and its subsidiary CIII as public fronts for cyber-espionage, covert communications, and technology acquisition. C...
01613
Reposted by Calwarez
Virtual Routes @virtualroutes.bsky.social · 01/10/2025
👋 Don't miss the first Colloquium session tomorrow! 📌 Mythical Beasts and Where to Find Them: Diving into the Depths of the Global Spyware Market 💡 Jen Roberts (@cyberstatecraft.bsky.social) & @julianferdinand.bsky.social (Recorded Future) 🗓️ October 2, 2025 🕓 16:00 – 17:00 CET
144
Reposted by Calwarez
Virus Bulletin @virusbtn.bsky.social · 18/09/2025
Recorded Future's Insikt Group reports CopyCop, also tracked as Storm 1516, expanding in 2025, adding at least 200 new fictional media websites targeting the United States, France and Canada and using self-hosted LLMs. www.recordedfuture.com/research/cop...
022
Reposted by Calwarez
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 22/09/2025
I'm excited to speak at #VB2025 later this week! I'll be diving into TAG-124, a group whose services are leveraged by a wide range of actors, from cybercriminals to state-sponsored groups. Hit me up if you are in town! www.virusbulletin.com/conference/v...
0189
Reposted by Calwarez
Lawrence S. @lawrencesec.bsky.social · 22/09/2025
The UK has sanctioned Aeza International, citing its involvement in destabilising Ukraine by providing internet services to Russian disinformation campaigns. This follows OFAC sanctions in July. www.gov.uk/government/n...
gov.uk
UK sanctions Georgia-linked supporters of Putin’s illegal war in Ukraine
The UK has announced new sanctions targeting Georgia-linked supporters of Putin’s illegal war in Ukraine.
021
Reposted by Calwarez
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 16/09/2025
Really excited to present at #LABScon25 on ChamelGang‘s most recent campaign targeting the Taliban, a collaborative research project with @milenkowski.bsky.social (SentinelLABS) and @azaka.fun (TeamT5)! www.labscon.io/speakers/jul...
053
Reposted by Calwarez
Lawrence S. @lawrencesec.bsky.social · 11/09/2025
Great blog post from @briankrebs.infosec.exchange.ap.brid.gy on #StarkIndustries. Makes a great point by highlighting it's links to MIRHosting. Where there are Dutch prefixes under these providers, there is usually always MIRHosting upstream.
143
Reposted by Calwarez
Virus Bulletin @virusbtn.bsky.social · 08/09/2025
Insikt Group identifies a new threat actor, TAG-150, active since at least March 2025. Its multi-layered infrastructure is used to deploy likely self-developed malware families, including CastleLoader, CastleBot, and the newly documented CastleRAT. www.recordedfuture.com/research/fro...
043
Reposted by Calwarez
Catalin Cimpanu @campuscodi.risky.biz · 07/09/2025
Recorded Future has spotted two influence operations around the recent India-Pakistan military conflict from May. The networks are tracked as networks as Hidden Charkha (pro-India) and Khyber Defender (pro-Pakistan). www.recordedfuture.com/research/inf...
054
Reposted by Calwarez
Lawrence S. @lawrencesec.bsky.social · 04/09/2025
A significant amount of #CastleLoader C2 infrastructure identified by @julianferdinand.bsky.social was tied to #ThreatActivityEnabler 🇬🇧 FEMO IT SOLUTIONS #AS214351 utilising 🇩🇪 aurologic GmbH #AS30823 as their sole upstream provider. One to watch out for!
142
Calwarez @calwarez.bsky.social · 04/09/2025
Another great report from the team on TAG-150, a sophisticated and rapidly evolving threat actor. 🕵️ Our report documents #CastleRAT for the first time, a new Remote Access Trojan, alongside the previously observed #CastleLoader.
021
Calwarez @calwarez.bsky.social · 28/08/2025
media.tenor.com
a man in a suit and tie is pointing his finger at his eye
ALT: a man in a suit and tie is pointing his finger at his eye
010
Calwarez @calwarez.bsky.social · 27/08/2025
This report on Stark Industries is a fantastic case study in the cat-and-mouse game between hosting providers and law enforcement. The new "Threat Activity Enabler" (TAE) terminology is spot-on and highlights the critical role these providers play in the cybercrime ecosystem.
033
Calwarez @calwarez.bsky.social · 26/08/2025
Highly recommend this report on TAG-144. It breaks down the group's operations into five distinct clusters and reveals some serious tradecraft! From using compromised government emails to hiding payloads in JPGs. A deep dive into a very sophisticated threat.
033
Reposted by Calwarez
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 20/08/2025
1/ Today, we release a first-of-its-kind analysis of a set of Lumma affiliates within a vast info-stealing ecosystem, showing their interconnectedness and resilience even after a major law enforcement takedown attempts earlier this year: www.recordedfuture.com/research/beh...
recordedfuture.com
Behind the Curtain: How Lumma Affiliates Operate
Explore a groundbreaking investigation into Lumma affiliates: uncover their tools, tactics, scams, and integration in the cybercriminal ecosystem. Essential reading for defenders.
22014
Reposted by Calwarez
Virus Bulletin @virusbtn.bsky.social · 11/08/2025
Recorded Future's Insikt Group has identified new infrastructure associated with Candiru, which includes components likely used in the deployment & C2 of Candiru’s DevilsTongue spyware, as well as higher-tier infrastructure used by the spyware operators. www.recordedfuture.com/research/tra...
063
Reposted by Calwarez
Suzanne Smalley @suzannesmalley.bsky.social · 05/08/2025
New active infrastructure for Candiru spyware linked to Hungary and Saudi Arabia identified therecord.media/candiru-spyw...
therecord.media
Active infrastructure for Candiru spyware linked to Hungary, Saudi Arabia
Windows spyware tracked as DevilsTongue — a product of the company Candiru — is likely still active, with clusters appearing in Hungary and Saudi Arabia, researchers said.
01817
Reposted by Calwarez
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 05/08/2025
1/ We've just released a new report uncovering new infrastructure tied to multiple activity clusters linked to the Israeli spyware vendor #Candiru across several countries. Full report: www.recordedfuture.com/research/tra...
recordedfuture.com
Tracking Candiru’s DevilsTongue Spyware in Multiple Countries
Recorded Future's Insikt Group uncovers active infrastructure linked to Candiru’s DevilsTongue spyware across multiple countries. Discover how this stealthy spyware targets high-value individuals and ...
11212
Calwarez @calwarez.bsky.social · 23/07/2025
NoName057(16) is back online and launching new #DDoSia attacks just 6 days after #OperationEastwood. Their new targets? Primarily German and Italian government and municipal websites. Their rapid resurgence highlights their persistence. #Cybersecurity #NoName057
033
Calwarez @calwarez.bsky.social · 22/07/2025
🚨 Our latest Insikt Group report, “Anatomy of DDoSia: NoName057(16)'s DDoS Infrastructure and Targeting”, is now live, providing an in-depth analysis of the pro-Russian hacktivist group’s DDoS campaigns. Get the full details here: www.recordedfuture.com/research/ana... #DDoS #DDoSia #NoName05716 🧵
140
Calwarez @calwarez.bsky.social · 27/06/2025
🚨 More hiring at Recorded Future’s Insikt Group New role: Senior Threat Intelligence Analyst – Russia APT Focus 📍 Arlington VA, Boston MA, UK, or Remote 🎯 Track Russian state activity 🧠 Lead investigations and guide intel coverage Apply: grnh.se/cpizn7d62us
grnh.se
Senior Threat Intelligence Analyst (Russia APT Focus)
Arlington, VA
020
Calwarez @calwarez.bsky.social · 20/06/2025
🚨 We’re hiring at Recorded Future’s Insikt Group Two senior analyst roles are open right now. Both focus on tracking nation-state threats. 🧵
163
Reposted by Calwarez
Catalin Cimpanu @campuscodi.risky.biz · 19/06/2025
The UK NCSC has published two new malware reports, both PDFs: -UMBRELLA STAND-Malware targeting Fortinet devices: www.ncsc.gov.uk/static-asset... -SHOE RACK-A post-exploitation tool for remote shell access & TCP tunnelling through a victim device: www.ncsc.gov.uk/static-asset...
095