Sign in

Expel

@expelsecurity.bsky.social
70 followers 16 following 220 posts

The leader in agentic MDR. 🔗 expel.com

PostsRepliesMedia
Expel @expelsecurity.bsky.social · 20/08/2026
One module throws up a fake Windows lock screen to steal the user’s real password. It even reclaims focus so the victim can’t escape it. Can you spot the fake? (5/7)
100
Expel @expelsecurity.bsky.social · 20/08/2026
The attacker got the user to install an MSI billed as a “PowerShell Cleaner,” hosted on legit-looking Microsoft Azure storage. (2/7)
100
Expel @expelsecurity.bsky.social · 15/07/2026
In April 2026, a Chinese cybercrime group accessed a support rep's device at DigiCert—then used that access to steal code-signing certificates meant for DigiCert customers. We're calling the actors CylindricalCanine. 🧵 1/4
110
Expel @expelsecurity.bsky.social · 02/07/2026
What helps: → Windows 11 (build 10.0.26100.32690+): cross-signing disabled blocks ktapi.sys → VBS + memory integrity: kills shellcode execution → WDAC: best option—allowlist only approved kernel drivers (7/8)
100
Expel @expelsecurity.bsky.social · 02/07/2026
The driver: ktapi.sys, from hardware vendor Kontron. Before our research, it had one Google result. No known abuse. A zero-day at time of publication—absent from every public vulnerable driver blocklist. (3/8)
110
Expel @expelsecurity.bsky.social · 02/07/2026
The Gentlemen ransomware, in a BYOVD attack, used a zero-day exploit to kill EDRs before deploying their payload. The driver they abused wasn't on any public blocklist. Here's our analysis of their techniques. 🧵
210
Expel @expelsecurity.bsky.social · 15/04/2026
The evasion tactic: Attackers are getting sneaky with polyglot files. One variant hides malicious HTML inside an MSIX bundle, then uses the Windows mshta utility to execute it. Traditional sandboxes try to open the MSIX normally and fail, successfully bypassing analysis. 3/7
100
Expel @expelsecurity.bsky.social · 15/04/2026
The bait: The official way to install Claude Code is by copying a command into your terminal. Attackers are cloning Anthropic's documentation pages and swapping the legitimate code with malicious commands. We have spotted 46 unique clone pages in just one month. 2/7
100
Expel @expelsecurity.bsky.social · 15/04/2026
Beware of what you copy and paste. In March 2026, a new watering hole attack called "InstallFix" accounted for 13% of all malware incidents we observed. The lure? Fake install pages for Claude Code. Here is how it works and how to defend your environment. 1/7
110
Expel @expelsecurity.bsky.social · 04/03/2026
We continue to see high volumes of targeted phishing via Microsoft Teams. The following are malicious senders just from this past week: Corporat[@]HelpDeskFoundation[.]onmicrosoft[.]com service[@]helpdeskfoundation[.]onmicrosoft[.]com helpdesk[@]omkarcis[.]online 1/5
100
Expel @expelsecurity.bsky.social · 14/01/2026
Security and finance leaders think they're aligned. Our new research with 300 of them says otherwise. 54% of finance leaders need strategic alignment metrics. Security's giving them maturity metrics instead. The language barrier is real—and fixable. expel.com/blog/new-res...
000
Expel @expelsecurity.bsky.social · 09/12/2025
⚠️ Attackers are buying Google Ads that appear when looking up how to troubleshoot your Mac. The ad takes you to a shared ChatGPT chat that tells you to copy-paste some code. You've just executed malware. Kroll has a solid write-up on the mechanics: www.kroll.com/en/publicati...
000
Expel @expelsecurity.bsky.social · 06/11/2025
We tracked BaoLoader through code-signing certificates across dozens of companies in the US, Panama, and Malaysia. It made up 13% of all commodity malware we identified this quarter. TamperedChef had 34,000+ downloads.
100
Expel @expelsecurity.bsky.social · 05/11/2025
Industry breakdown shows distinct patterns: • Manufacturing: highest total incident volume (overtook financial services) • Healthcare: disproportionately hit by non-targeted malware • Pharma & chemical: highest proportion of identity attacks in top 10
100
Expel @expelsecurity.bsky.social · 05/11/2025
Cloud infrastructure attacks remain low volume (1.1% of total incidents) but are diversifying. Biggest increase: secret key exposure, up 7.8 percentage points from Q2 to 26.8% of cloud incidents. Keys exposed through hardcoded credentials or supply chain attacks like Shai Hulud.
100
Expel @expelsecurity.bsky.social · 05/11/2025
Endpoints tell a different story Non-targeted malware dominates at 64.7% of endpoint incidents. This swung back up from 50.2% in Q2. Attackers are still using traditional tactics—malware, compromising public-facing systems—to get onto devices.
100
Expel @expelsecurity.bsky.social · 05/11/2025
While identity attacks increased QoQ, 54.9% of those attacks were stopped when compromised credentials were entered—meaning controls blocked access before account takeover. Modern identity controls (MFA, conditional access, monitoring) are working when implemented properly.
100
Expel @expelsecurity.bsky.social · 31/10/2025
These malicious ads don't just show up in search results. Windows 11 serves Bing ads directly in the Start menu. That "sponsored" PuTTy result with the lowercase Ts? Yeah, that won’t lead to the real PuTTy; that’ll download OysterLoader.
100
Expel @expelsecurity.bsky.social · 24/10/2025
⚠️Attackers are actively exploiting CVE-2025-59287, a recently identified vulnerability in WSUS. Successful exploitation allows an attacker to run code using SYSTEM privileges. Expel caught & contained incidents related to this in two customer environments this AM. Details: expel.com/blog/wsus-re...
010
Expel @expelsecurity.bsky.social · 23/10/2025
When launched, the trojanized Greenshot shows a fake compliance progress bar for 3 seconds, then confirms "All compliance checks passed!" Meanwhile, the malicious DLL loads updater.dll, which creates persistence via scheduled task and decrypts shellcode from logo.ico.
130
Expel @expelsecurity.bsky.social · 23/10/2025
The attack chain, continued ⛓️ ↳ Indirect syscalls evade EDR hooks by calculating system call numbers from unhooked functions ↳ C2 traffic masquerading as jQuery library requests to dodge TLS inspection
120
Expel @expelsecurity.bsky.social · 23/10/2025
The attack chain ⛓️ ↳ Cache smuggling delivers the payload ↳ DLL sideloading uses the legitimate signed Greenshot.exe to load malicious code ↳ Fake UI shows a "FortiClient compliance checker" progress bar while malware runs
140
Expel @expelsecurity.bsky.social · 08/10/2025
The webpage fetches what claims to be an image (Content-Type: image/jpeg). Browser dutifully caches it. Open it in a hex editor? No JPG header. Just a zip archive wrapped in those magic strings, sitting in your cache waiting to be extracted.
100
Expel @expelsecurity.bsky.social · 08/10/2025
Here's where it gets interesting: The PowerShell script doesn't download anything. It searches your browser's cache for data wrapped between two strings: "bTgQcBpv" and "mX6o0lBw" That data? A zip file the page already smuggled into your cache as a fake JPG.
100
Expel @expelsecurity.bsky.social · 08/10/2025
When you click "Open File Explorer," it copies what looks like a harmless file path to your clipboard: \Public\Support\VPN\ForticlientCompliance.exe But 139 spaces are hiding a PowerShell command above it that your eyes never see.
100
Expel @expelsecurity.bsky.social · 08/10/2025
⚠️ Our threat intel team just caught attackers using a clever new trick to bypass security tools: cache smuggling. Instead of downloading malware, they hide it in fake images that browsers automatically cache. Then PowerShell extracts and runs it—no web requests needed.
100
Expel @expelsecurity.bsky.social · 08/10/2025
The security industry is drowning in threat feeds that don't actually help you stop attacks. We've been working to fix that for years. Today, we’re taking the wraps off our expanded threat intel program: Expel Intel. (1/7)
110
Expel @expelsecurity.bsky.social · 02/10/2025
50k events/day. 0.1% true positive rate. 50 real threats buried. That's what happens when you optimize for integration count, not detection quality. Vendors brag about "300+ integrations" while analysts burn out investigating false positives. Start counting what matters: expel.com/blog/stop-co...
000
Expel @expelsecurity.bsky.social · 21/08/2025
(3/4) If you run ManualFinder in a sandbox, you get an app that actually helps find manuals. Why is this being installed by OneStart? Looking at the website, it describes a free app but no means to download the software willingly. OneStart has been a consistently sketchy app.
100
Expel @expelsecurity.bsky.social · 21/08/2025
(2/4) We observed the activity due to the persistence from OneStart Browser: it made a scheduled task to run a JS file from the user’s temp directory. Eventually, that JS reaches out to mka3e8[.]com and similar domains to download an app “ManualFinder,” also signed.
100
Expel @expelsecurity.bsky.social · 21/08/2025
🚨 A NEW trojan on the block spotted by our threat intel team 👀 We saw files with the code-signing signature “GLINT SOFTWARE SDN. BHD.” due to a JavaScript dropping “ManualFinder” One of their signed files, a PDF editor, turns your device into a residential proxy—ew. 🧵👇
100
Expel @expelsecurity.bsky.social · 01/08/2025
Clicking on the “Dragons Guide” sent us to Bing instead. From Bing, we were able to view one of the several Link-pits we found. We found other sites by looking for webpages with the same “dodecadragons-guide” in the URL.
100
Expel @expelsecurity.bsky.social · 01/08/2025
We also found a few hosting the SEO poisoning. Here are some examples: graduatetutor[.]org, theyansweredthecall[.]com, traykin[.]com, and mediagin[.]net. These websites are “Link-pits.” They hold a large number of pages and keywords to arrive high in search results.
100
Expel @expelsecurity.bsky.social · 01/08/2025
We did some digging and found a bunch of these JavaScript files. The name is always “FULL DOCUMENT.JS” but they come in a ZIP file with the name from the SEO poisoning. The ZIPs were named like the examples below.
100
Expel @expelsecurity.bsky.social · 01/08/2025
The JS file contains the following content. It calls GetObject() with content that decodes to "scriptlet:http[:]//0x3e3cb218/vag" That hex? That’s an IP address 👀 62.60.178[.]24 When the script executes, it downloads a remote payload and starts the malware infection.
100
Expel @expelsecurity.bsky.social · 30/06/2025
Spotted in NYC ❎👀 Took cloud security so seriously we actually ended up in the clouds. ☁️ Thanks for having us, Nasdaq!
000
Expel @expelsecurity.bsky.social · 27/05/2025
In media (and cloud) we trust 🫡 Join Pierre Noel on 3rd June at #Infosec2025 for insights on overcoming common cloud transformation challenges in a changing digital media ecosystem. And don't forget to come see us at stand C85 for custom AI portraits and swag. expel.com/infosecurity...
000
Expel @expelsecurity.bsky.social · 23/05/2025
🕷️Operation Endgame just announced disruption of the infrastructure behind Lactrodectus malware, a malware used by ransomware actors to gain access to enterprise networks. But the devs are persistent so we expect them to return. Here are the most recent tactics we've seen: expel.com/blog/followi...
000
Expel @expelsecurity.bsky.social · 06/05/2025
In previous Quarterly Threat Reports, we focused on trends in malware & what our SOC is seeing. For our latest QTR, we focused on attack surface types to create a more tactical approach. However, we still have great data on malware trends we want to share—so here’s the 411: expel.com/blog/mdr-ins...
000
Expel @expelsecurity.bsky.social · 01/05/2025
And with that, #RSAC 2025 comes to an end. 😌 A time was 𝙝𝙖𝙙 at the Expel booth all week long! To everyone who stopped by our booth to chat and see what Expel MDR is all about, thank you. 💚 We couldn't have asked for a better experience. 'Til next time! 👋
000
Expel @expelsecurity.bsky.social · 01/05/2025
"Put these on and pose." 😎🕺 Shout out to everyone who stopped by our booth at #RSAC and partook in all the fun. 💚 Booth S#0535 is still where the party's at so come on by!
000
Expel @expelsecurity.bsky.social · 01/05/2025
How is it already the last day of #RSAC? 🥹 Make sure you don't miss us at booth S#0535 before we close shop at 2pm! 💻 Discover our 130+ tech integrations 🦸 Meet the SOC analysts that are delivering an unbeatable 17-min MTTR 👕 Last chance to grab Expel swag 📸 Get your personalized AI hero portrait
000
Expel @expelsecurity.bsky.social · 30/04/2025
📢 And now, a quick message from Colleen Leary, our in-house swag connoisseur, at #RSAC. Stop by our booth S#0535 to learn more about our unparalleled 17-minute MTTR from our SOC analysts and grab a custom hat before you go! 🧢✨
000
Expel @expelsecurity.bsky.social · 30/04/2025
❎ marks the spot! Our doors are officially open for day 3 of #RSAC at booth S#0535! 🚪🎊
000
Expel @expelsecurity.bsky.social · 29/04/2025
We’re all smiles at #RSAC booth S#0535! We hear it’s because everyone learned about our industry-leading 17-minute MTTR. ⏱️ Come hang with us and see how we do it! 👋
020
Expel @expelsecurity.bsky.social · 29/04/2025
On April 30, our threat intel team will be discussing two of the biggest cybercrime groups making waves: 🕷️ Scattered Spider and 🦁 Atlas Lion. Join us for this LinkedIn Live at 11:30am PT where our experts will share the novel techniques these groups are using, real-world case studies, and more.
010
Expel @expelsecurity.bsky.social · 24/04/2025
Heroes don’t fight alone 🦸‍♂️🦸‍♀️ Expel helps security teams detect and respond to threats faster so they can focus on what matters most. Meet us at #RSAC booth #0535 and never fight threats alone again. expel.com/rsac-2025/?u...
000
Expel @expelsecurity.bsky.social · 22/04/2025
You've got (more secure) mail! 🔒📧 We're excited to announce Expel MDR for email, a major expansion of our service to proactively defend one of the most dangerous threat vectors: email.
100
Expel @expelsecurity.bsky.social · 21/04/2025
Staying ahead of cyber threats requires a proactive approach for threat detection & hunting 🛡️ On May 7, join Expel's Ansh Patnaik & Forrester's Jeff Pollard to hear: ✔️ how threat hunting works in parallel to detection ✔️ threat hunting & detection engineering trends RSVP: expel.com/webinars/for...
000
Expel @expelsecurity.bsky.social · 17/04/2025
🎉 Expel has officially been named a Trusted Cloud Provider by the Cloud Security Alliance (CSA), and we've also joined CSA as a member! This is further confirmation of what we already know—Expel isn’t just another vendor but a committed, proven partner in cloud security. ☁️🔑 expel.com/blog/expel-n...
000