Sign in

Nicolas Caproni

@caproni.fr
541 followers 184 following 82 posts

Head of Sekoia Threat Detection & Research (TDR) team • Cyber Threat Intelligence • Detection Engineering • SOC Platform 🇫🇷 🇪🇺 • Hip-Hop • Basketball

PostsRepliesMedia
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 07/09/2026
North Korea’s cyber program was built to serve two purposes: intelligence collection and revenue generation. A new joint report from Sekoia #TDR and @KudelskiSec examines how that system is organized. buff.ly/vmqOr9d
223
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 26/06/2026
Our latest Threat Intelligence report dives deep into ADINT (Advertisement-based Intelligence) to expose how private companies weaponise AdTech mechanisms to harvest intelligence data, fueling the surveillance solutions they sell. www.sekoia.com/blog/sold-to...
123
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 04/12/2025
🇷🇺 French NGO Reporters Without Borders targeted by #Calisto in recent campaign Sekoia #TDR analysed a recent #Calisto (aka #ColdRiver #Star Blizzard) spear-phishing campaign aimed at Reporters sans frontières and other #Ukraine-supporting organisations. blog.sekoia.io/ngo-reporter...
154
Reposted by Nicolas Caproni
Hervé Schauer @herve-schauer.bsky.social · 08/11/2025
Histoire et dissection du 𝑚𝑎𝑙𝑤𝑎𝑟𝑒 ou chargeur malveillant 🇷🇺 #Latrodectus par Pierre Le Bourhis @sekoia.io à #UYBHYS25 @uybhys.bsky.social
152
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 06/11/2025
#TDR analysts dig into a modus operandi targeting the hospitality industry and the related cybercrime ecosystem that facilitates #phishing and #fraud campaigns. blog.sekoia.io/phishing-cam...
153
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 14/10/2025
After our initial #PolarEdge #botnet write-up, we’re happy to announce the second part: “Defrosting PolarEdge’s Backdoor,” a full technical deep-dive into its TLS-based implant. blog.sekoia.io/polaredge-ba...
123
Nicolas Caproni @caproni.fr · 06/10/2025
Je recherche un Threat Researcher pour l’équipe TDR de @sekoia.io ! Vous aimez faire des règles #Sigma et #Yara ? Vous adorez pivoter et traquer les infrastructures (C2) d’attaques des cybercriminels ? Alors cette offre d’emploi est faite pour vous ! www.welcometothejungle.com/en/companies...
welcometothejungle.com
Technical Threat Researcher – Sekoia.io – Permanent contract – Fully-remote
Sekoia.io is looking for a Technical Threat Researcher!
021
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 02/10/2025
Key takeaways: ✉️ API exploitation: attackers leverage an exposed /cgi endpoint to push malicious SMS without authentication 🌐 Scale of exposure: over 18,000 routers accessible on the internet; 572 confirmed vulnerable
111
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 02/10/2025
📱 Silent Smishing: The Hidden Abuse of Cellular Router APIs Our latest #CTI investigation from Sekoia #TDR team uncovers a novel #smishing vector abusing Milesight industrial cellular router APIs to send phishing #SMS at scale. blog.sekoia.io/silent-smish...
164
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 16/09/2025
🐻 #APT28 – Operation Phantom Net Voxel: deep-dive into the latest spear-phishing campaign targeting Ukrainian military administrative staff. blog.sekoia.io/apt28-operat...
122
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 02/09/2025
[Threat investigation alert 🚨] Predators for Hire: A Global Overview of Commercial Surveillance Vendors ➡️ blog.sekoia.io/predators-fo...
124
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 21/07/2025
🔥 Hot summer, sizzling crypto... and scammers turning up the heat 🔥 Back in March, Sekoia #TDR team published a deep-dive report on a #Lazarus cluster we dubbed #ClickFake Interview, leveraging the #ClickFix technique in their #ContagiousInterview campaign.
111
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 08/07/2025
You can find the phishing kit sheets on our blog: blog.sekoia.io/global-analy... And on our Community GitHub: github.com/SEKOIA-IO/Co...
012
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 08/07/2025
These sheets aim to assist SOC analysts in detecting and investigating #AitM #phishing compromises by offering context, technical details, infrastructure overview, detection opportunities, and more. All are available in the PDF report and our Community GitHub.
112
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 08/07/2025
A few weeks ago, we published our global analysis of Adversary-in-the-Middle #phishing threats, providing actionable intelligence on multiple #AitM phishing kits. This report includes 11 sheets covering the most widespread #AitM phishing kits as of Q1 2025.
152
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 11/06/2025
📝 Our latest #TDR report delivers an in-depth analysis of Adversary-in-the-Middle (#AitM) #phishing threats - targeting Microsoft 365 and Google accounts - and their ecosystem. This report shares actionable intelligence to help analysts detect and investigate AitM phishing.
1107
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 27/05/2025
🧀 The Sharp Taste of #Mimo’lette: Analyzing Mimo’s Latest Campaign targeting #Craft CMS blog.sekoia.io/the-sharp-ta...
blog.sekoia.io
The Sharp Taste of Mimo'lette: Analyzing Mimo’s Latest Campaign targeting Craft CMS
Analysis of the CVE-2025-32432 compromise chain by Mimo: exploitation, loader, crypto miner, proxyware, and detection opportunities.
031
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 22/05/2025
🪤 Sekoia #TDR's new exclusive research uncovers the #ViciousTrap, a honeypot network deployed on compromised edge devices. blog.sekoia.io/vicioustrap-...
blog.sekoia.io
ViciousTrap - Infiltrate, Control, Lure: Turning edge devices into honeypots en masse.
Discover ViciousTrap, a newly identified threat who turning edge devices into honeypots en masse targeting
042
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 23/04/2025
Our new report describes one of the latest observed infection chains (delivering #AsyncRAT) relying on the #Cloudflare tunnel infrastructure and the attacker’s #TTPs with a principal focus on detection opportunities. blog.sekoia.io/detecting-mu...
021
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 16/04/2025
Since the apparition of the #Interlock ransomware, the Sekoia #TDR team observed its operators evolving, improving their toolset (#LummaStealer and #BerserkStealer), and leveraging new techniques such as #ClickFix to deploy the ransomware payload. blog.sekoia.io/interlock-ra...
025
Nicolas Caproni @caproni.fr · 09/04/2025
Pour accélérer son développement, @sekoia.io lève 26 M€ www.lemondeinformatique.fr/actualites/l...
lemondeinformatique.fr
Pour accélérer son développement, Sekoia.io lève 26 M€ - Le Monde Informatique
Après un premier tour de table de 35 M€, Sekoia.io annonce une seconde levée de fonds de 26 M€. Ce financement va servir à l'éditeur de...
021
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 09/04/2025
🎉 It's not about a CTI investigation or a Detection Engineering topic, but today we are happy to announce that Sekoia.io has raised €26m! www.sekoia.io/en/presse/se...
031
Nicolas Caproni @caproni.fr · 02/04/2025
Retrouvez moi toute la journée au Forum INCYBER Europe (#FIC2025) pour Sekoia.io ! Rendez-vous stand #A17 pour échanger !
020
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 31/03/2025
🇰🇵 Sekoia #TDR team investigated a malicious campaign that employs fake job interview websites to deliver backdoors on Windows and macOS - #GolangGhost using #ClickFix tactic. Dubbed #ClickFake Interview, this campaign has been attributed to #Lazarus APT blog.sekoia.io/clickfake-in...
052
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 10/03/2025
The conclusion (part three) of our series on #DetectionEngineering is finally here! buff.ly/dijB0fy
031
Reposted by Nicolas Caproni
crep1x @crep1x.bsky.social · 06/03/2025
#ClearFake variant is now spreading #Rhadamanthys Stealer via #Emmenhtal Loader. cc @plebourhis.bsky.social @sekoia.io 1. ClearFake framework is injected on compromised WordPress and relies on EtherHiding 2. The #ClickFix lure uses a fake Cloudflare Turnstile with unusual web traffic ⬇️
232
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 25/02/2025
Using our #honeypots, we uncovered an unreported #botnet that has been operational since at least the end of November 2023. This #PolarEdge botnet has been focusing on #edge devices, particularly those made by #Cisco, #Asus, #QNAP, and #Synology. buff.ly/4ibOEo8
053
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 24/02/2025
Cyber threats impacting the financial sector: focus on the main actors We're thrilled to announce the release of the latest strategic report by Sekoia #TDR. This analysis highlights key cyber threats to the #financial sector in 2024. buff.ly/3D3IZl7
052
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 04/02/2025
🔍 Large-scale detection engineering: part two! 🚀 In this article, we explore an innovative approach that transforms the execution of automated actions via CI/CD pipelines, enabling effective scaling and alignment with developer and DevOps practices.
buff.ly
Detection engineering at scale: one step closer (part two)
Discover the power of detection engineering and how it can help scale your cybersecurity projects efficiently.
031
Nicolas Caproni @caproni.fr · 29/01/2025
🚨To strengthen the #investigation and #detection capabilities of the Sekoia.io Threat Detection & Research (TDR) team, we are looking for a Senior Technical Threat Researcher! www.welcometothejungle.com/fr/companies... #CTI #DetectionEngineering
welcometothejungle.com
Sr Technical Threat Researcher - Sekoia.io - CDI - Télétravail total
Sekoia.io recrute un(e) Sr Technical Threat Researcher !
054
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 22/01/2025
TDR analysts analysed the supply chain attack targeting Chrome browser extensions, which potentially affected hundreds of thousands of end users in December 2024. buff.ly/4auQ0HN
184
Reposted by Nicolas Caproni
crep1x @crep1x.bsky.social · 20/01/2025
Around 1,000 malicious domains are hosting webpages impersonating Reddit and WeTransfer, redirecting users to download password-protected archives These archives contain an AutoIT dropper, we internally named #SelfAU3 Dropper at @sekoia.io, which executes #Lumma Stealer IoCs ⬇️
296
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 16/01/2025
🔍 TDR analysts discovered a new Adversary-in-the-Middle (#AiTM) #phishing kit, specifically targeting Microsoft 365 accounts and circumventing 2-step verification: Sneaky 2FA blog.sekoia.io/sneaky-2fa-exposing-… #detection #sneaky2fa
blog.sekoia.io
Sneaky 2FA: exposing a new AiTM Phishing-as-a-Service
In this blog post, learn about Sneaky 2FA, a new Adversary-in-the-Middle (AiTM) phishing kit targeting Microsoft 365 accounts.
153
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 13/01/2025
🇷🇺 #DoubleTap Campaign: #Russia-nexus APT possibly related to #APT28 conducts cyber espionage on Central Asia and Kazakhstan diplomatic relations buff.ly/3WEwPG7
175
Reposted by Nicolas Caproni
Sekoia @sekoia.com · 09/01/2025
A look back at #PlugX #worm “sovereign disinfection” campaign
blog.sekoia.io
PlugX worm disinfection campaign feedbacks
Discover how we successfully disinfected thousands of computers infected with the PlugX worm using two remote disinfection methods.
043
Nicolas Caproni @caproni.fr · 09/01/2025
Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation
buff.ly
Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation | Google Cloud Blog
Zero-day exploitation of Ivanti Connect Secure VPN vulnerabilities since as far back as December 2024.
000
Nicolas Caproni @caproni.fr · 09/01/2025
Banshee: The Stealer That "Stole Code" From MacOS XProtect
buff.ly
Banshee: The Stealer That "Stole Code" From MacOS XProtect - Check Point Research
Check Point Researchers uncover a new version of Banshee macOS, finding that its string encryption is the exact copy of Apple's XProtect
000
Nicolas Caproni @caproni.fr · 09/01/2025
Information Stealer Masquerades as LDAPNightmare (CVE-2024-49113) PoC Exploit
buff.ly
Information Stealer Masquerades as LDAPNightmare (CVE-2024-49113) PoC Exploit
Our blog entry discusses a fake PoC exploit for LDAPNightmare (CVE-2024-49113) that is being used to distribute information-stealing malware.
010
Nicolas Caproni @caproni.fr · 06/01/2025
Malicious npm Campaign Targets Ethereum Developers with Fake Hardhat Packages
buff.ly
Malicious npm Campaign Targets Ethereum Developers with Fake...
A malicious npm campaign is targeting Ethereum developers by impersonating Hardhat plugins and the Nomic Foundation, stealing sensitive data like priv...
000
Nicolas Caproni @caproni.fr · 06/01/2025
“Can you try a game I made?” Fake game sites lead to information stealers
buff.ly
“Can you try a game I made?” Fake game sites lead to information stealers
Invitations to try a beta lead to a fake game website where victims will get an information stealer instead of the promised game
000
Nicolas Caproni @caproni.fr · 03/01/2025
🎉 Happy New Year! Hopefully, we'll see as many people as possible here in 2025🤞
010
Nicolas Caproni @caproni.fr · 18/12/2024
“DeceptionAds” — Fake Captcha Driving Infostealer Infections and a Glimpse to the Dark Side of Internet Advertising
buff.ly
“DeceptionAds” — Fake Captcha Driving Infostealer Infections and a Glimpse to the Dark Side of…
By Nati Tal (Head of Guardio Labs)
011
Nicolas Caproni @caproni.fr · 18/12/2024
Effective Phishing Campaign Targeting European Companies and Institutions
buff.ly
Effective Phishing Campaign Targeting European Companies and Institutions
A phishing campaign targeting European companies used fake forms made with HubSpot's Free Form Builder, leading to credential harvesting and Azure account takeover. A phishing campaign targeting…
010
Nicolas Caproni @caproni.fr · 17/12/2024
Hidden in Plain Sight: TA397’s (aka #Bitter) New Attack Chain Delivers Espionage RATs
buff.ly
Hidden in Plain Sight: TA397’s New Attack Chain Delivers Espionage RATs | Proofpoint US
Key findings  Proofpoint observed advanced persistent threat (APT) TA397 targeting a Turkish defense sector organization with a lure about public infrastructure projects in Madagascar.   The attack...
000
Nicolas Caproni @caproni.fr · 17/12/2024
Dragos Industrial Ransomware Analysis: Q3 2024
buff.ly
Dragos Industrial Ransomware Analysis: Q3 2024 | Dragos
The Dragos Ransomware Analysis for Q3 2024 evaluated variants used against industrial organizations worldwide. Learn more about our assessments and findings.
000
Nicolas Caproni @caproni.fr · 17/12/2024
Perfctl malware exploiting exposed Portainer agent and using new SSH persistence
buff.ly
Perfctl malware exploiting exposed Portainer agent and using new SSH persistence
During an incident response for one of our clients, we stumbled upon a server compromised by the now relatively documented 1234 perfctl malware.
000
Nicolas Caproni @caproni.fr · 17/12/2024
A Look Back: The Evolution of Latin American #eCrime Malware in 2024 The evolution of LATAM-based #malware in 2024 highlights the adaptability and ingenuity of its developers, who continue to refine their tools to sustain successful eCrime campaigns.
buff.ly
Latin American eCrime Malware Evolution in 2024 | CrowdStrike
Learn about the 2024 evolution of the LATAM cybercrime landscape, including adversary TTPs and key malware families.
000
Nicolas Caproni @caproni.fr · 15/12/2024
NodeLoader Used to Deliver Malware
buff.ly
NodeLoader Exposed: The Node.js Malware Evading Detection
A technical analysis of how a malware campaign using a game cheat lure leverages Node.js to distribute XMRig, Lumma and Phemedrone Stealer.
020
Nicolas Caproni @caproni.fr · 13/12/2024
Inside a New OT/IoT Cyberweapon: IOCONTROL
buff.ly
Inside a New OT/IoT Cyberweapon: IOCONTROL
Team82 obtained a sample of a custom-built IoT/OT malware called IOCONTROL used by the Iran-affiliated attackers to attack Israel- and U.S.-based OT/IoT devices.
032
Nicolas Caproni @caproni.fr · 13/12/2024
Xloader deep dive: Link-based malware delivery via SharePoint impersonation
buff.ly
Xloader deep dive: Link-based malware delivery via SharePoint impersonation
An in-depth analysis of Xloader malware delivered via spoofed SharePoint notifications.
010