Sign in

al3x

@cyb3rkitties.bsky.social
580 followers 255 following 45 posts

they/she. spreader of virtual kitties. 🐱 threat intelligence & malware, mostly Russia stuff. probably reading reports. nerdy and witchy things. rabbit holes. naps are underrated.

PostsRepliesMedia
al3x @cyb3rkitties.bsky.social · 19/09/2026
this is why the one most important skill for every CTI and traditional intelligence analyst is CRITICAL THINKING edition.cnn.com/2026/09/18/p...
edition.cnn.com
Exclusive: US military had close call after using AI for false intelligence report, sources say | CNN Politics
The episode shows the risks of using this new, relatively poorly understood technology in the middle of the Iran war
100
Reposted by al3x
Meduza in English @meduza.io · 16/07/2026
Russia's FSB spent over a year trying to build an AI system to scan the news for signs of domestic dissent. The contractor wasn't up to it, and the project was shut down in the fall of 2025, according to an iStories investigation. meduza.io/en/feature/2...
meduza.io
The Russian ‘counterterrorism’ unit behind Alexei Navalny’s poisoning tried to automate its search for domestic dissent using Meta’s Llama 2. After a year and a half, the project collapsed. — Meduza
The FSB’s Second Service is officially charged with protecting the constitutional order and combating terrorism. In practice, the unit works to stamp out dissent in Russia: it has plotted the…
0164
al3x @cyb3rkitties.bsky.social · 15/07/2026
personally I love when CERT-UA shares a load of IOCs and spicy malware names, especially if they’re about Sandworm campaigns. it’s the usual fake microsoft software, but with a twist and some ClickFix: cert.gov.ua/article/6318...
cert.gov.ua
CERT-UA
Урядова команда реагування на комп’ютерні надзвичайні події України, яка функціонує в складі Державної служби спеціального зв’язку та захисту інформації України.
000
Reposted by al3x
Hackers On Planet Earth 🏳️‍🌈🏳️‍⚧️ @hope.net · 15/07/2026
We got talks.
Announcing talk “AI and Hollywood” by Mojo at HOPE 26.
042
Reposted by al3x
Jimmy Wylie @mayahustle.com · 01/04/2026
TIL FLARE distributes educational content for free on GitHub. github.com/mandiant/fla...
github.com
GitHub - mandiant/flare-learning-hub: Free educational content on reverse engineering and malware analysis from the FLARE team · GitHub
Free educational content on reverse engineering and malware analysis from the FLARE team - mandiant/flare-learning-hub
043
al3x @cyb3rkitties.bsky.social · 18/03/2026
the deeper i dig into CTI work, the less i realize how certain intel pieces that seem common knowledge to me are actually shocking for many infosec/cyber practitioners.
100
al3x @cyb3rkitties.bsky.social · 26/11/2025
i love how plenty of government officials are raving about Russia’s hybrid war, but then we still talk about threats and cyber/kinetic/influence campaigns as completely separate efforts. make it make sense 🤷‍♀️
010
Reposted by al3x
TProphet @tprophet.org · 23/09/2025
1/ Hi, I'm TProphet. I write the Telecom Informer for @2600.com. A lot of people have been asking me about www.nbcnews.com/politics/nat... given that I'm somewhat knowledgeable in the area. Here's my take: I'm kind of astonished that this is public, and it isn't normal that it would ever be.
nbcnews.com
Secret Service agents dismantle network that could shut down New York cellphone system
Agents discovered electronic devices in five locations in and around the city that could be used to disable cellphone towers. The system could also be used for criminal activities.
10363178
Reposted by al3x
Matthew Downhour @matthewdownhour.bsky.social · 10/09/2025
The idea that joining NATO would make Ukraine an intolerable threat to Russia is absurd and Poland is demonstrating why: they were just hit by Russian munitions and yet because NATO makes them feel secure they are comfortable literally just calling a meeting rather than a kinetic response
6556105
al3x @cyb3rkitties.bsky.social · 27/08/2025
since everyone seems to be talking “AI” these days—if you’re a reverse engineer, how are you using LLMs to aid your analysis, if at all? #reverseengineering #llm
010
Reposted by al3x
CSIS | Center for Strategic & International Studies @csis.org · 27/08/2025
"Every dollar of oil revenue reduction shrinks Russia’s fiscal cushion, increases reliance on debt issuance, and ratchets up the political pressure on Moscow," notes the CSIS Energy Security and Climate Change Program. Read more about a potential Russian oil surcharge: www.csis.org/analysis/rus...
133
Reposted by al3x
Anton Gerashchenko @antongerashchenko.bsky.social · 23/08/2025
What's happening with the Russian economy: ◾️ Automotive industry Sales of passenger cars and trucks have dropped due to high loan interest rates. Tens of thousands of vehicles are stuck at the car factories' warehouses with no buyers in sight⤵️
37755165
Reposted by al3x
Gen Michael Hayden @genmhayden.bsky.social · 02/02/2025
They also covered the People of Color in Cryptologic History honorees—like Wash Wong and Ralph Adams.
401674387
Reposted by al3x
Gen Michael Hayden @genmhayden.bsky.social · 02/02/2025
Fellow NSA - National Security Agency veterans. Look at what’s happened at the National Cryptologic Museum. They covered up with brown paper the photos of Women in American Cryptology. All in response to President Trump’s anti-diversity executive order.
918123986667
al3x @cyb3rkitties.bsky.social · 26/01/2025
me: “so you want to transition from IT to security. what do you wanna do in security?” person on the internet: “defense analyst…security analyst” me: “a security analyst can include soc, grc, ir, vulnerability assessment/management, etc. so, what do you wanna do in security?”
010
al3x @cyb3rkitties.bsky.social · 11/12/2024
okay, serious question: why don’t enterprises mandate default adblockers for all users? would it not avoid headaches and a good chunk of credstealing/malware download opportunities?!
121
Reposted by al3x
Mark Chadbourn @chadbourn.bsky.social · 07/12/2024
A Russia/Iran-backed coup of senior Assad regime officers seems to be underway in Damascus. If they’re successful, and they can prevent a conflict with the opposition forces, it will allow them a say in any negotiated settlement.
2138583
Reposted by al3x
Catalin Cimpanu @campuscodi.risky.biz · 07/12/2024
After annulling the first round of the presidential election, Romanian authorities have now raided a local man paying influencers to support the pro-Kremlin candidate--which is against the law in Romania. www.agerpres.ro/justitie/202...
24917
al3x @cyb3rkitties.bsky.social · 05/12/2024
international affairs genie: “hey, it’s almost the end of the year, how bout we all chill out and take a breather?” south korea: “lmao too late” france: “hold my beer”
130
al3x @cyb3rkitties.bsky.social · 05/12/2024
well, this was interesting to say the least. a spectacularly failed “self coup”. www.aljazeera.com/news/2024/12...
aljazeera.com
South Korea’s defence minister resigns over martial law crisis
Defence minister’s resignation follows brief martial law declaration and as Russia-North Korea pact comes into force.
010
al3x @cyb3rkitties.bsky.social · 04/12/2024
media.tenor.com
a cartoon dog is sitting at a table in front of a fire with the words it 's fine everything is fine
ALT: a cartoon dog is sitting at a table in front of a fire with the words it 's fine everything is fine
010
Reposted by al3x
Rob Joyce @rgblights.bsky.social · 04/12/2024
For anyone interested in detection and prevention methods against Salt Typhoon intrusions targeting communication providers, here is a comprehensive guide: media.defense.gov/2024/Dec/03/...
25336
Reposted by al3x
Jake Williams @malwarejake.bsky.social · 28/11/2024
It is the biggest con in cyber security, hands down. There is *no data* that it changes cyber security *outcomes.* I theorize that most people intuitively know this, but because "improving click rate" is easy to track (and game), many performatively champion it as a "good metric" for security.
208512
al3x @cyb3rkitties.bsky.social · 26/11/2024
ah, the joys of building hash tables that refuse to populate.
media.tenor.com
a close up of a white cat 's face with blue eyes looking at the camera .
ALT: a close up of a white cat 's face with blue eyes looking at the camera .
130
al3x @cyb3rkitties.bsky.social · 26/11/2024
more fun malware to add to the reversing list
trendmicro.com
Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
011
Reposted by al3x
Joe Slowik @pylos.co · 25/11/2024
#SaltTyphoon
1363
al3x @cyb3rkitties.bsky.social · 23/11/2024
show opinions needed! last week i finally watched “dune: part two”, liked it, and now wondering about dune: prophecy. anyone watched it? is it a yay, nay, or meh?
020
Reposted by al3x
Horkos @wylienewmark.bsky.social · 23/11/2024
Nearest Neighbor? Espionage. www.wired.com/story/russia... Salt Typhoon? Espionage. wapo.st/3CHK3dQ GRU’s use of Moobot? Espionage. www.justice.gov/opa/pr/justi... MSS hack of MSFT? Espionage. www.cisa.gov/sites/defaul... SolarWinds? Espionage. www.lawfaremedia.org/article/sanc...
0237
al3x @cyb3rkitties.bsky.social · 23/11/2024
hello, hi, happy #caturday! can we please bring back the chicken wings cat dance trend? pretty please? youtube.com/shorts/ETIs_...
youtube.com
Chicken wings cat🐔!! dance video ft.Kandy😹 |Subscribe #shorts
YouTube video by Itz me Kandy
010
Reposted by al3x
Cedric Pernet @cedricpernet.bsky.social · 23/11/2024
Awesome research ! - The Nearest Neighbor Attack: How A Russian #APT Weaponized Nearby Wi-Fi Networks for Covert Access - @volexity.com - www.volexity.com/blog/2024/11... #cyberespionage
2145
Reposted by al3x
🕹 RetroReversing - Reverse Retro Games 🕹 @retroreversing.bsky.social · 23/11/2024
Check our our introductory post on Reverse Engineering a NES / Famicom game with Ghidra using the excellent NES decompiler plugin.
buff.ly
Reversing Engineering a NES Game With Ghidra
The home of reverse engineering enthusiasts. Learn about RetroReversing and join the community today!
012
al3x @cyb3rkitties.bsky.social · 22/11/2024
what!! this is neat. didn’t know they had a weekly newsletter on vulnerability research 🤩 blog.exploits.club/exploits-clu...
blog.exploits.club
exploits.club Weekly Newsletter 48 - FireFox Animations, OOO bugs, LibAFL Advanced Fuzzing, and More
Welcome to all our new readers filtering in this week from the Paged Out! #5 community ad. We are happy to know you share our affinity for extremely poor graphic design. Annnnyways 👇 In Case You Mis...
000
Reposted by al3x
Brad @malware-traffic-analysis.net · 22/11/2024
2024-11-22 (Friday) #XLoader / #Formbook: I've been fired by my non-existent HR department. At least I got a "salary-receipt.exe" bazaar.abuse.ch/sample/003b5... Tria.ge and Any.Run don't identify the malware, but Joe Sandbox does: www.joesandbox.com/analysis/156... Also runs in my lab just fine
Screenshot of malicious spam (malspam) with malware file attachment.Traffic from the XLoader (Formbook) infection filtered in Wireshark.
21710
Reposted by al3x
Joseph Menn @joemenn.bsky.social · 22/11/2024
This is wild. Time to mandate 2fa for WiFi. www.volexity.com/blog/2024/11...
volexity.com
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
In early February 2022, notably just ahead of the Russian invasion of Ukraine, Volexity made a discovery that led to one of the most fascinating and complex incident investigations Volexity had ever w...
1179
al3x @cyb3rkitties.bsky.social · 22/11/2024
anyone else with @cyberwarcon.bsky.social FOMO? have fun y’all 🥹 hope to join you next year 💕
240
Reposted by al3x
Ben Read @benread.bsky.social · 15/11/2024
We're hiring a Principal Intel Analyst in the UK. The work is onsite 3 days/week and requires a UK DV clearance. If you fit that description, it's some really cool work. www.google.com/about/career...
google.com
Principal Intelligence Analyst, Mandiant Intelligence — Google Careers
0117
al3x @cyb3rkitties.bsky.social · 22/11/2024
and speaking of advent calendars! this sounds like a lot of fun—advent of radare2 🤩 www.radare.org/advent/
radare.org
Advent Of Radare2
032
al3x @cyb3rkitties.bsky.social · 21/11/2024
truth is that the average cyber attack these days is anything but “sophisticated”. creds are literally found everywhere in various breaches and users have the bad habit to reuse them. then, it’s about some AD discovery and LOLbin type tool for lateral movement + privesc, and we all know how it ends.
030
Reposted by al3x
Phil Stokes ⫍🐠⫎ @philofishal.bsky.social · 21/11/2024
Been a while since we've seen #macOS #malware abusing osacompile rather than plain osascript, but #Amos Atomic Stealer is nothing if not adaptable. SHA1: 51ef05c84eea3dde149a5dd3ea9916a824e95afc. A reminder that it's possible (didn't say easy 😅) to reverse compiled #applescript. s1.ai/fadedead
s1.ai
FADE DEAD | Adventures in Reversing Malicious Run-Only AppleScripts - SentinelLabs
We show how to statically reverse run-only AppleScripts for the first time, and in the process reveal new IoCs of a long-running macOS Cryptominer campaign.
02311
Reposted by al3x
Ciaran Martin @ciaranm.bsky.social · 19/11/2024
Quite an evening listening to @mikko.bsky.social open the Museum of Malware Art in Helsinki! Brilliant collection including the 2000 Iloveyou virus commemorated as a hanging collection
3308
Reposted by al3x
techy @techy.detectionengineering.net · 20/11/2024
Det. Eng. Weekly Issue 93 is live! buff.ly/3UWj3xG * 💎 by Andrew VanVleet on resiliency in your detection stack * @anton1chuvakin.bsky.social on alert fatigue and reframing alert labeling to more than just false positives and true positives (more in thread..)
detectionengineering.net
Det. Eng. Weekly #93 - Does a tangodown 3-peat count after a week off?
I take a week off publishing and a ransomware operator gets arrested, coincidence?
12211
Reposted by al3x
Hackread.com @hackread.bsky.social · 20/11/2024
The alleged Phobos ransomware operator has been extradited from South Korea to the US and faces up to 20 years in prison. Read: hackread.com/russian-hack... #CyberSecurity #CyberCrime #Phobos #Ransomware
hackread.com
Russian Hacker Extradited to US for Phobos Ransomware Charges
Follow us on Twitter (X) @Hackread - Facebook @ /Hackread
073
al3x @cyb3rkitties.bsky.social · 19/11/2024
i’m not religious but i’ve always loved the idea of advent calendars. i’m thinking about building one for malware people. like, each day is a surprise new cool malware sample, a useful script, a writeup on a technique. 🤔
3100
al3x @cyb3rkitties.bsky.social · 11/11/2024
oh hai everyone, it’s been a minute since i’ve logged in here. where are all my malware/security research nerdsss?! 🤓💕
030
al3x @cyb3rkitties.bsky.social · 04/10/2023
These past few weeks, I did a thing to try and organize my malware reverse engineering work: a framework that leverages MITRE ATT&CK tactics to guide an analyst through the workflow by looking at keywords and API/function patterns. I hope folks find it useful! cyb3rkitties.github.io/posts/malwar...
cyb3rkitties.github.io
Malware Analysis & Investigation Framework
If you started your malware analysis journey fairly recently, you have probably wondered a few times: where do I start from? What do I prioritize? That’s exactly what happened to me: at times, the a...
000
al3x @cyb3rkitties.bsky.social · 06/07/2023
i have “look for the same people you follow on mastodon” fatigue.
000
al3x @cyb3rkitties.bsky.social · 05/07/2023
bhahahahaha, this is hilarious. it also shows how much many old schoolers aren’t willing to let go of office politics and power.
000
al3x @cyb3rkitties.bsky.social · 04/07/2023
hi hi, visiting from mastodon. here’s a cat pic because why not. do people use hashtags here? #cats
adorable white and brown tabby cat sleeping on a gray couch exhibiting a very satisfied expression
050