Sign in

François Deruty

@derutyf.bsky.social
312 followers 104 following 47 posts

threat intelligence at www.sekoia.io / former head of cert-fr blog.sekoia.io

PostsRepliesMedia
François Deruty @derutyf.bsky.social · 01/10/2026
Shinyhunters⤵️ www.sekoia.com/blog/gotta-b...
sekoia.com
Gotta Breach 'Em All! The Journey Of ShinyHunters
ShinyHunters has outlasted forum takedowns, arrests, and its founders' convictions. Learn the group's tactics, from stolen S3 buckets to zero-day exploits.
020
François Deruty @derutyf.bsky.social · 27/09/2026
DPRK ⤵️ www.sekoia.com/blog/beyond-...
sekoia.com
Beyond Lazarus: How North Korea Organizes Its Cyber Operations
Co-authored by Sekoia and Kudelski Security, this report maps North Korea’s cyber ecosystem, from state institutions and APT clusters to IT worker operations.
010
François Deruty @derutyf.bsky.social · 03/07/2026
ChocoPoCs ⤵️ www.sekoia.com/blog/dont-ea...
sekoia.com
Don’t eat the ChocoPoCs! How vulnerability researchers were repeatedly targeted by trojanised exploits
This article details a campaign targeting vulnerability researchers with "ChocoPoC" malware embedded inside trojanised Python dependencies. Exploiting the pressure to quickly test new vulnerabilities,...
110
François Deruty @derutyf.bsky.social · 25/06/2026
Adint ⤵️ www.sekoia.com/blog/sold-to...
sekoia.com
Sold to the Highest Bidder: The Escalation of ADINT from Geolocation Tracking to Intrusion Vector
033
François Deruty @derutyf.bsky.social · 23/06/2026
Errtraffic ⤵️ blog.sekoia.io/unveiling-er...
blog.sekoia.io
Unveiling ErrTraffic: inside a growing ClickFix malware distribution framework
This report details the ErrTraffic threat and its associated ecosystem, highlighting three specific campaigns and their operators' arsenal.
000
François Deruty @derutyf.bsky.social · 11/06/2026
APT28 ⤵️ blog.sekoia.io/apt28-an-evo...
blog.sekoia.io
APT28, an evolution of tradecraft
Context Sekoia’s Threat Detection & Research (TDR) team has been tracking APT28 for several years. The intrusion set, also known as Fancy Bear, Forest Blizzard, Sofacy, Pawn Storm or Sednit and public...
011
François Deruty @derutyf.bsky.social · 02/06/2026
Gamaredon ⤵️ blog.sekoia.io/fsbs-matryos...
blog.sekoia.io
FSB’s matryoshka #1/3 - Gamaredon’s gifts that keeps unpacking - GammaPhish and GammaWorm
Part 1 of our FSB Matryoshka series. Discover the context behind Gamaredon's cyberespionage campaigns, introducing GammaPhish and GammaWorm operations.
000
François Deruty @derutyf.bsky.social · 13/04/2026
Eviltokens ⤵️ blog.sekoia.io/new-widespre... blog.sekoia.io/eviltokens-a...
blog.sekoia.io
New widespread EvilTokens kit: device code phishing as-a-service - Part 1
Uncover the new sophisticated EvilTokens device code phishing as-a-service, with AI-augmented features facilitating BEC fraud
010
François Deruty @derutyf.bsky.social · 26/03/2026
Silver fox⤵️ blog.sekoia.io/silver-fox-t...
blog.sekoia.io
Silver Fox: The Only Tax Audit Where the Fine Print Installs Malware
Track the 2025-2026 shift of China-based Silver Fox from financial crime to APT espionage. Discover how they exploit tax-themed phishing and RMM tools to target South Asian entities.
011
François Deruty @derutyf.bsky.social · 20/02/2026
OysterLoader ⤵️ blog.sekoia.io/oysterloader...
blog.sekoia.io
OysterLoader Unmasked: The Multi-Stage Evasion Loader
Unmasking OysterLoader's evasion: from API hammering to custom LZMA. Explore the 4-stage infection chain and its ties to Rhysida ransomware.
010
François Deruty @derutyf.bsky.social · 29/01/2026
IClickfix ⤵️ blog.sekoia.io/meet-iclickf...
blog.sekoia.io
Meet IClickFix: a widespread WordPress-targeting framework using the ClickFix tactic
Uncover IClickFix: a malicious framework exploiting the ClickFix tactic in widespread malware campaigns to deliver NetSupport RAT.
010
François Deruty @derutyf.bsky.social · 14/01/2026
Leveraging Landlock telemetry for Linux detection engineering ⤵️ blog.sekoia.io/leveraging-l...
blog.sekoia.io
Leveraging Landlock telemetry for Linux detection engineering
This blogpost explore how Landlock as an interesting security mechanism and a valuable source of telemetry for detection engineering.
010
François Deruty @derutyf.bsky.social · 07/11/2025
"I paid twice" ⤵️ blog.sekoia.io/phishing-cam...
blog.sekoia.io
Phishing Campaigns "I Paid Twice" Targeting Booking.com Hotels and Customers
Sekoia.io exposes a Booking.com phishing campaign targeting hotels and customers using ClickFix and PureRAT malware.
010
François Deruty @derutyf.bsky.social · 28/10/2025
TransparentTribe⤵️ blog.sekoia.io/transparentt...
blog.sekoia.io
TransparentTribe targets Indian military organisations with DeskRAT
TransparentTribe targets Indian military entities using DeskRAT, a Golang-based remote access Trojan. Learn how this new campaign works.
020
François Deruty @derutyf.bsky.social · 16/09/2025
APT28⤵️ blog.sekoia.io/apt28-operat...
blog.sekoia.io
APT28 Operation Phantom Net Voxel
APT28 Operation Phantom Net Voxel: weaponized Office lures, COM-hijack DLL, PNG stego to Covenant Grunt via Koofr, BeardShell on icedrive.
031
François Deruty @derutyf.bsky.social · 04/09/2025
Predators for hire ⤵️ blog.sekoia.io/predators-fo...
blog.sekoia.io
Predators for Hire: A Global Overview of Commercial Surveillance Vendors
Explore the 2025 landscape of Adversary-in-the-Middle phishing threats with data, trends, and top detection insights.
030
Reposted by François Deruty
TechNadu @technadu.com · 23/06/2025
TechNadu interviewed François Deruty (@derutyf.bsky.social), Chief Intelligence Officer of @sekoia.io, to get answers about innovations observed in cybercrime operations, challenges faced by CIOs, and adjustments to intelligence programs. Read the interview⤵️ #AI #Cybersecurity #GenerativeAI #CTI
technadu.com
Exploiting Vulnerabilities Using AI at Machine Speed, the Alarming Number of Unpatched Devices, and Anticipating How Adversaries Think
Sekoia.io on collaborating with Europol, dynamic behavior modelling for Gen AI threats, and pooling CTI from various sources
021
Reposted by François Deruty
Sekoia @sekoia.com · 11/06/2025
📝 Our latest #TDR report delivers an in-depth analysis of Adversary-in-the-Middle (#AitM) #phishing threats - targeting Microsoft 365 and Google accounts - and their ecosystem. This report shares actionable intelligence to help analysts detect and investigate AitM phishing.
1107
François Deruty @derutyf.bsky.social · 24/05/2025
Vicious trapèze ⤵️ blog.sekoia.io/vicioustrap-...
blog.sekoia.io
ViciousTrap - Infiltrate, Control, Lure: Turning edge devices into honeypots en masse.
Discover ViciousTrap, a newly identified threat who turning edge devices into honeypots en masse targeting
030
François Deruty @derutyf.bsky.social · 16/04/2025
Interlock⤵️ blog.sekoia.io/interlock-ra...
blog.sekoia.io
Interlock ransomware evolving under the radar
ClickFix ransomware attack uses deceptive prompts and PowerShell loaders to deploy threats like Interlock under the radar.
010
François Deruty @derutyf.bsky.social · 05/04/2025
Clickfake ⤵️ blog.sekoia.io/clickfake-in...
blog.sekoia.io
From Contagious to ClickFake Interview: Lazarus leveraging the ClickFix tactic
Discover how Lazarus leverages fake job sites in the ClickFake Interview campaign targeting crypto firms using the ClickFix tactic.
010
François Deruty @derutyf.bsky.social · 18/03/2025
Clearfake ⤵️ blog.sekoia.io/clearfakes-n...
blog.sekoia.io
ClearFake’s New Widespread Variant: Increased Web3 Exploitation for Malware Delivery
ClearFake spreads malware via compromised websites, using fake CAPTCHAs, JavaScript injections, and drive-by downloads.
010
François Deruty @derutyf.bsky.social · 25/02/2025
PolarEdge ⤵️ blog.sekoia.io/polaredge-un...
blog.sekoia.io
PolarEdge: Unveiling an uncovered ORB network
Discover PolarEdge, a newly identified botnet targeting edge devices via CVE-2023-20118, using a stealthy TLS backdoor.
020
Reposted by François Deruty
Sekoia @sekoia.com · 24/02/2025
Cyber threats impacting the financial sector: focus on the main actors We're thrilled to announce the release of the latest strategic report by Sekoia #TDR. This analysis highlights key cyber threats to the #financial sector in 2024. buff.ly/3D3IZl7
052
François Deruty @derutyf.bsky.social · 20/02/2025
Cyber threats against financial sector⤵️ blog.sekoia.io/cyber-threat...
blog.sekoia.io
Cyber threats impacting the financial sector in 2024 - focus on the main actors
Delve into Finance-related cyber threats in 2024. Our report highlights major actors and tactics impacting the financial sector.
010
François Deruty @derutyf.bsky.social · 11/02/2025
New paper⤵️ blog.sekoia.io/ratatouille-...
blog.sekoia.io
RATatouille: Cooking Up Chaos in the I2P Kitchen
Discover the challenges of ClickFix12 and the newly identified I2PRAT. Uncover the advanced techniques employed by this multi-stage RAT.
041
François Deruty @derutyf.bsky.social · 04/02/2025
Detection part two⤵️ blog.sekoia.io/detection-en...
blog.sekoia.io
Detection engineering at scale: one step closer (part two)
Discover the power of detection engineering and how it can help scale your cybersecurity projects efficiently.
010
Reposted by François Deruty
Nicolas Caproni @caproni.fr · 29/01/2025
🚨To strengthen the #investigation and #detection capabilities of the Sekoia.io Threat Detection & Research (TDR) team, we are looking for a Senior Technical Threat Researcher! www.welcometothejungle.com/fr/companies... #CTI #DetectionEngineering
welcometothejungle.com
Sr Technical Threat Researcher - Sekoia.io - CDI - Télétravail total
Sekoia.io recrute un(e) Sr Technical Threat Researcher !
054
François Deruty @derutyf.bsky.social · 29/01/2025
If you are passionate about cyber threat intelligence, this offer is for you! ⤵️ www.welcometothejungle.com/fr/companies...
welcometothejungle.com
Sr Technical Threat Researcher - Sekoia.io - CDI - Télétravail total
Sekoia.io recrute un(e) Sr Technical Threat Researcher !
020
François Deruty @derutyf.bsky.social · 23/01/2025
New campaign ⤵️ blog.sekoia.io/targeted-sup...
blog.sekoia.io
Targeted supply chain attack against Chrome browser extensions
In this blog post, learn about the supply chain attack targeting Chrome browser extensions and the associated targeted phishing campaign.
032
Reposted by François Deruty
crep1x @crep1x.bsky.social · 20/01/2025
Around 1,000 malicious domains are hosting webpages impersonating Reddit and WeTransfer, redirecting users to download password-protected archives These archives contain an AutoIT dropper, we internally named #SelfAU3 Dropper at @sekoia.io, which executes #Lumma Stealer IoCs ⬇️
296
François Deruty @derutyf.bsky.social · 16/01/2025
New AiTM phishing as a service ⤵️ blog.sekoia.io/sneaky-2fa-e...
blog.sekoia.io
Sneaky 2FA: exposing a new AiTM Phishing-as-a-Service
In this blog post, learn about Sneaky 2FA, a new Adversary-in-the-Middle (AiTM) phishing kit targeting Microsoft 365 accounts.
000
Reposted by François Deruty
InfoSec @infosec.skyfleet.blue · 15/01/2025
FBI deletes Chinese PlugX malware from thousands of US computers
bleepingcomputer.com
FBI deletes Chinese PlugX malware from thousands of US computers
​The U.S. Department of Justice announced today that the FBI has deleted Chinese PlugX malware from over 4,200 computers in networks across the United States.
032
Reposted by François Deruty
jon greig @jgreig.bsky.social · 14/01/2025
The DOJ worked with French authorities and Sekoia.io to remove PlugX malware from thousands of devices around the world therecord.media/doj-deletes-...
therecord.media
DOJ deletes China-linked PlugX malware off more than 4,200 US computers
U.S law enforcement accused the People’s Republic of China of paying hackers that are part of a well-known group called Mustang Panda to deploy the PlugX malware — which allows them to “infect, contro...
0169
François Deruty @derutyf.bsky.social · 14/01/2025
International cooperation, proud of TDR team from @sekoia.io ⤵️ www.justice.gov/opa/pr/justi...
justice.gov
Justice Department and FBI Conduct International Operation to Delete Malware Used by China-Backed Hackers
The Justice Department and FBI today announced a multi-month law enforcement operation that, alongside international partners, deleted “PlugX” malware from thousands of infected computers worldwide. A...
2173
Reposted by François Deruty
Sekoia @sekoia.com · 13/01/2025
🇷🇺 #DoubleTap Campaign: #Russia-nexus APT possibly related to #APT28 conducts cyber espionage on Central Asia and Kazakhstan diplomatic relations buff.ly/3WEwPG7
175
François Deruty @derutyf.bsky.social · 13/01/2025
Double-tap campaign ⤵️ blog.sekoia.io/double-tap-c...
blog.sekoia.io
Double-Tap Campaign : Russia-nexus APT possibly related to APT28 conducts cyber espionage on Central Asia and Kazakhstan diplomatic relations
Uncover the details of UAC-0063 cyberespionage campaign in Kazakhstan and its potential connection to APT28
020
François Deruty @derutyf.bsky.social · 09/01/2025
Feedbacks on a botnet disinfection campaign ⤵️ blog.sekoia.io/plugx-worm-d...
blog.sekoia.io
PlugX worm disinfection campaign feedbacks
Discover how we successfully disinfected thousands of computers infected with the PlugX worm using two remote disinfection methods.
020
François Deruty @derutyf.bsky.social · 19/12/2024
Happy Yara Xmas ! ⤵️ blog.sekoia.io/happy-yara-c...
blog.sekoia.io
Happy YARA Christmas!
Discover daily YARA usage at Sekoia.io TDR. Learn how YARA rules identify threats and aid in investigations and DFIR engagements.
0103
François Deruty @derutyf.bsky.social · 16/12/2024
Want to talk about detection? ⤵️ blog.sekoia.io/detection-en...
blog.sekoia.io
Detection engineering at scale: one step closer (part one)
Discover how Sekoia.io addresses SOC and Detection Engineering challenges with innovative continuous monitoring and review approaches.
020
Reposted by François Deruty
Sekoia @sekoia.com · 27/11/2024
🎯 Ransomware-driven data #exfiltration: techniques and implications Our new #TDR report focuses on the exfiltration techniques leveraged by #ransomware and #extortion groups. buff.ly/415o0ry #ThreatIntelligence #Detection
buff.ly
Ransomware-driven data exfiltration: techniques and implications
Introduction This report focuses on the exfiltration techniques leveraged by ransomware and extortion groups in lucrative campaigns. It aims to provide a comprehensive analysis of the techniques and…
0118
François Deruty @derutyf.bsky.social · 27/11/2024
Wanna talk about exfiltration ? ⤵️ blog.sekoia.io/ransomware-d...
blog.sekoia.io
Ransomware-driven data exfiltration: techniques and implications
Introduction This report focuses on the exfiltration techniques leveraged by ransomware and extortion groups in lucrative campaigns. It aims to provide a comprehensive analysis of the techniques and t...
011
François Deruty @derutyf.bsky.social · 20/11/2024
Helldown ⤵️ blog.sekoia.io/helldown-ran...
blog.sekoia.io
Helldown Ransomware: an overview of this emerging threat
Comprehensive Analysis of Helldown: Tactics, Techniques, and Procedures (TTPs) and Exploitation of Zyxel Vulnerabilities %
010
François Deruty @derutyf.bsky.social · 13/11/2024
New paper ⤵️ blog.sekoia.io/a-three-beat...
blog.sekoia.io
A three beats waltz: The ecosystem behind Chinese state-sponsored cyber threats
Sekoia TDR analysts conduct an assessment of threats regarding the major elections that will occur in 2024.
043
François Deruty @derutyf.bsky.social · 01/05/2024
Assessing cyber threats to elections⤵️ blog.sekoia.io/guarding-dem...
blog.sekoia.io
Guarding Democracy: Assessing Cyber Threats to 2024 Worldwide Elections
Sekoia TDR analysts conduct an assessment of threats regarding the major elections that will occur in 2024.
000
François Deruty @derutyf.bsky.social · 11/03/2024
New paper ⤵️ blog.sekoia.io/the-architec...
blog.sekoia.io
The Architects of Evasion: a Crypters Threat Landscape
Learn about key concepts and different crypters-related activities as well as the lucrative ecosystem of malicious groups that exploit them.
011
François Deruty @derutyf.bsky.social · 02/02/2024
Diceloader ⤵️ blog.sekoia.io/unveiling-th...
blog.sekoia.io
Unveiling the intricacies of DiceLoader
Learn how DiceLoader (also known as Icebot), a malware used by the FIN7 intrusion set, works.
000
François Deruty @derutyf.bsky.social · 05/01/2024
New paper ⤵️ blog.sekoia.io/securing-gol...
blog.sekoia.io
Securing Gold: Assessing Cyber Threats on Paris 2024
This report provides an overview of the various cyber operations likely to impact the next Olympic and Paralympic Games (Paris 2024).
010
Reposted by François Deruty
Sekoia @sekoia.com · 21/12/2023
🪪 Our new blog post explores the importance of Identity and Access Management (#IAM) event #detection. We focus at how Sekoia.io set up detection rules for @okta and @JumpCloud technologies. blog.sekoia.io/iam-detectio... #DetectionEngineering #Cloud #SOCplatform
052
François Deruty @derutyf.bsky.social · 15/12/2023
CALISTO doxxing ⤵️ blog.sekoia.io/calisto-doxx...
blog.sekoia.io
CALISTO doxxing: Sekoia.io findings concurs to Reuters’ investigation on FSB-related Andrey Korine...
Discover activities linking Korinets to CALISTO doxxing in our investigation. Uncover details from emails, domains & servers used to target UK Parliament & Cambridge University.
011