Sign in

Expel

@expelsecurity.bsky.social
70 followers 16 following 220 posts

The leader in agentic MDR. 🔗 expel.com

PostsRepliesMedia
Expel @expelsecurity.bsky.social · 20/08/2026
Our read, medium confidence: this toolkit belongs to a ransomware group or an initial access broker feeding one. Full breakdown, every module we received, and IOCs on the blog: expel.com/blog/synkloa... (7/7)
expel.com
SynkLoader: when you throw in everything but the kitchen sink
Discover a new malware family, SynkLoder. See how we reverse-engineered its phishing tactics to expose its attack chain.
000
Expel @expelsecurity.bsky.social · 20/08/2026
The attackers went hands-on-keyboard, running commands in real time, until they realized our “network” wasn’t real. Then they disconnected. (6/7)
100
Expel @expelsecurity.bsky.social · 20/08/2026
One module throws up a fake Windows lock screen to steal the user’s real password. It even reclaims focus so the victim can’t escape it. Can you spot the fake? (5/7)
100
Expel @expelsecurity.bsky.social · 20/08/2026
We reverse engineered it, fed it fake data to look like a huge corporate network, and waited. The attackers took the bait and sent down several modules for us to examine. (4/7)
100
Expel @expelsecurity.bsky.social · 20/08/2026
The loader chains Python, C#, C++, and PowerShell to dodge EDR. Everything but the kitchen sink. 😉 (3/7)
100
Expel @expelsecurity.bsky.social · 20/08/2026
The attacker got the user to install an MSI billed as a “PowerShell Cleaner,” hosted on legit-looking Microsoft Azure storage. (2/7)
100
Expel @expelsecurity.bsky.social · 20/08/2026
On August 18, we caught a malware loader we believe to be novel. Entry point: a threat actor phished a client’s user through Microsoft Teams, posing as the IT help desk. We named it SynkLoader. (1/7)
100
Expel @expelsecurity.bsky.social · 04/08/2026
More on the blog: expel.com/blog/chaindr... (6/6)
expel.com
ChainDrop: The Mini Shai Hulud npm worm's latest wave hits keyv and cacheable
A self-propagating npm worm hit keyv, cacheable, and hundreds of dependent packages to steal CI/CD, cloud, and API credentials. Here's what to do now.
000
Expel @expelsecurity.bsky.social · 04/08/2026
➡️ Audit lockfiles for affected package versions and pin to known-clean releases ➡️ Rotate every secret on any host or CI/CD runner that touched a compromised package ➡️ Check GitHub Actions and npm publishing logs for unauthorized activity (5/6)
200
Expel @expelsecurity.bsky.social · 04/08/2026
The payload harvests npm, GitHub, AWS, Kubernetes, and Vault credentials, plus SSH keys, .env files, database strings, and API keys for services like Slack and Stripe—then encrypts and exfiltrates them to GitHub repos and Ethereum smart contracts. (4/6)
100
Expel @expelsecurity.bsky.social · 04/08/2026
Running npm install on an affected package launches a hidden preinstall script (setup.mjs), which pulls a temporary Bun runtime and runs an obfuscated payload (Math_Symbol.js). No extra user interaction required. (3/6)
200
Expel @expelsecurity.bsky.social · 04/08/2026
It started with a compromised GitHub account. Attackers pushed malicious code straight to the main branches, triggering GitHub Actions to build and publish infected updates to npm—complete with valid signatures. (2/6)
100
Expel @expelsecurity.bsky.social · 04/08/2026
A self-propagating npm supply chain worm compromised keyv, cacheable, flat-cache, file-entry-cache, and 800+ downstream packages—stealing CI/CD, cloud, and API credentials along the way. (1/6)
100
Expel @expelsecurity.bsky.social · 15/07/2026
Full technical breakdown, decryption tools, and IOCs here: expel.com/blog/introdu... 4/4
expel.com
Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident
CylindricalCanine is a new threat group within GoldenEyeDog, and they're actively using their malware for email phishing. Here's what you need to know.
000
Expel @expelsecurity.bsky.social · 15/07/2026
The original Gh0st RAT’s source code became public in 2008. We’re calling this custom version Golden Gh0st RAT. It uses WebSocket and a custom encryption. In the blog, we share tools to decrypt the network traffic and Suricata rules to detect it. 3/4
100
Expel @expelsecurity.bsky.social · 15/07/2026
CylindricalCanine is a part of a larger group known as GoldenEyeDog. The malware they used in the intrusion—and used the certificates to sign—is a malware we’re calling Golden Gh0st Loader. Golden Gh0st Loader decrypts and loads a custom version of Gh0st RAT. 2/4
100
Expel @expelsecurity.bsky.social · 15/07/2026
In April 2026, a Chinese cybercrime group accessed a support rep's device at DigiCert—then used that access to steal code-signing certificates meant for DigiCert customers. We're calling the actors CylindricalCanine. 🧵 1/4
110
Expel @expelsecurity.bsky.social · 06/07/2026
Researchers at Sysdig found JadePuffer used an LLM agent to conduct a ransomware attack. Is this future of ransomware? In this case, a human still steered it and struggled with the basics. expel.com/blog/the-fir...
expel.com
The “first” fully agentic ransomware is here, but we aren’t panicking (yet): Meet JadePuffer
Analysis of agentic ransomware JadePuffer: human operator, LLM agent limits, and why fundamentals still protect defenders.
000
Expel @expelsecurity.bsky.social · 02/07/2026
IOCs—block by filename, driver version may vary: → ktapi.sys (SHA-256: 7ee17efef04bb7c9de90d5210263ed6993f867e5a11f86e65e3bb1362c7de237) → was.exe (SHA-256: c277ae5a4dd62f51de5278790796cd2700de7f77ea17762e97729f27872d076b) Full breakdown by Marcus Hutchins: expel.com/blog/not-ver... (8/8)
expel.com
Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs
How the threat group used a zero-day vulnerability to disable the target's EDR, preventing it from intervening in their ransomware attack.
000
Expel @expelsecurity.bsky.social · 02/07/2026
What helps: → Windows 11 (build 10.0.26100.32690+): cross-signing disabled blocks ktapi.sys → VBS + memory integrity: kills shellcode execution → WDAC: best option—allowlist only approved kernel drivers (7/8)
100
Expel @expelsecurity.bsky.social · 02/07/2026
The result: full kernel-mode function calls from user space. They call PsTerminateProcess directly—bypassing Protected Process and EDR self-defense—in a loop targeting Windows Defender, ESET, Cortex XDR, and SentinelOne. (6/8)
100
Expel @expelsecurity.bsky.social · 02/07/2026
Kernel code execution without triggering PatchGuard: hijack two Win32k syscall stubs that KPP doesn't protect. SMAP is bypassed via KUSER_SHARED_DATA's kernel mapping; SMEP via shellcode written to RWX kernel pool memory. (5/8)
100
Expel @expelsecurity.bsky.social · 02/07/2026
The exploit abuses a vulnerable IOCTL in ktapi.sys to map arbitrary physical memory into the calling process. It then scans the system’s RAM for its own PML4 page table and uses it to assist in reading/writing kernel memory directly from user mode. (4/8)
100
Expel @expelsecurity.bsky.social · 02/07/2026
The driver: ktapi.sys, from hardware vendor Kontron. Before our research, it had one Google result. No known abuse. A zero-day at time of publication—absent from every public vulnerable driver blocklist. (3/8)
110
Expel @expelsecurity.bsky.social · 02/07/2026
The Gentlemen emerged in July 2025 and rely heavily on BYOVD attacks—load a legitimate-but-vulnerable kernel driver, use it to kill endpoint security, then run ransomware. We caught them doing exactly this in early April. (2/8)
100
Expel @expelsecurity.bsky.social · 02/07/2026
The Gentlemen ransomware, in a BYOVD attack, used a zero-day exploit to kill EDRs before deploying their payload. The driver they abused wasn't on any public blocklist. Here's our analysis of their techniques. 🧵
210
Expel @expelsecurity.bsky.social · 13/05/2026
Need a high-level overview of the latest Mini Shai Hulud? Aaron Walton breaks down how the latest supply chain attack happened, what defenders should do now, and prepare for the next one. www.youtube.com/shorts/7x9t6...
youtube.com
Mini Shai-Hulud: the wormable attack targeting your supply chain
YouTube video by Expel
010
Expel @expelsecurity.bsky.social · 12/05/2026
Full breakdown—IOCs, attack chain, and step-by-step remediation—on the Expel blog: expel.com/blog/mini-sh... (7/7)
expel.com
Mini Shai Hulud: Cross-ecosystem supply chain worm targeting npm & PyPl
A supply chain worm compromised 170+ npm and PyPI packages. Here's what happened, the IOCs to watch for, and how to respond.
000
Expel @expelsecurity.bsky.social · 12/05/2026
If you suspect compromise: containment before rotation. Disable unauthorized services first, then rotate GitHub PATs, npm publish tokens, AWS access keys, and HashiCorp Vault tokens. Pin your dependencies to verified hashes going forward. (6/7)
100
Expel @expelsecurity.bsky.social · 12/05/2026
Start here if you think you're affected: → Check node_modules for router_init.js → Check .vscode/tasks.json and ~/.claude/settings.json for unauthorized hooks → Disable gh-token-monitor.service if present → DNS-block api.masscan[.]cloud (5/7)
100
Expel @expelsecurity.bsky.social · 12/05/2026
IOCs to hunt for: Domains: filev2.getsession[.]org, api.masscan[.]cloud, git-tanstack[.]com Files: router_init.js, setup.mjs, transformers.pyz Hash: ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c IP: 83[.]142[.]209[.]194 (4/7)
100
Expel @expelsecurity.bsky.social · 12/05/2026
It also injects persistence hooks into Claude Code and VS Code settings—surviving reboots, re-executing on IDE launch. This isn't a one-and-done package compromise. If it gets in, it's trying to stay in. (3/7)
100
Expel @expelsecurity.bsky.social · 12/05/2026
The payload (router_init.js or setup.mjs) profiles the environment and targets: → AWS IAM keys → GitHub Personal Access Tokens → HashiCorp Vault tokens → Kubernetes secretsData exfiltrated via Session Protocol to evade DNS-based blocking. (2/7)
100
Expel @expelsecurity.bsky.social · 12/05/2026
By now you've probably seen the Mini Shai Hulud supply chain story. TeamPCP compromised 170+ npm and PyPI packages—TanStack, Mistral AI, OpenSearch, and more. Here's what you need to know if you're responding right now. (1/7)
100
Expel @expelsecurity.bsky.social · 15/04/2026
Developers are prime targets for cybercriminals, and blindly pasting terminal commands is a massive security risk. Always verify the domain before copying installation instructions, and implement strict execution controls. Read our full breakdown (7/7): expel.com/blog/install...
expel.com
InstallFix: Not the application you were looking for
InstallFix is a new watering hole attack we're seeing, and it leverages Claude Code as the lure. Here's what you need to know.
000
Expel @expelsecurity.bsky.social · 15/04/2026
Defense strategy 2, Lock down LoLBins: On Windows, use WDAC policies to restrict unexpected living-off-the-land binaries like mshta and PowerShell. On macOS, lean on EDR and MDM systems to monitor and control the execution of curl and osascript. 6/7
100
Expel @expelsecurity.bsky.social · 15/04/2026
Defense strategy 1, Network & clipboard: Stop the attack early by configuring DNS filtering and Secure Web Gateways to block newly registered domains. Additionally, use browser extensions with clipboard protections to warn users before they paste suspicious code. 5/7
100
Expel @expelsecurity.bsky.social · 15/04/2026
Cross-platform threat: InstallFix targets macOS too, leveraging common tools like curl and osascript. While macOS Tahoe 26.4 added copy/paste warnings, developers (the main targets of this lure) are accustomed to bypassing these prompts for standard tool installations. 4/7
100
Expel @expelsecurity.bsky.social · 15/04/2026
The evasion tactic: Attackers are getting sneaky with polyglot files. One variant hides malicious HTML inside an MSIX bundle, then uses the Windows mshta utility to execute it. Traditional sandboxes try to open the MSIX normally and fail, successfully bypassing analysis. 3/7
100
Expel @expelsecurity.bsky.social · 15/04/2026
The bait: The official way to install Claude Code is by copying a command into your terminal. Attackers are cloning Anthropic's documentation pages and swapping the legitimate code with malicious commands. We have spotted 46 unique clone pages in just one month. 2/7
100
Expel @expelsecurity.bsky.social · 15/04/2026
Beware of what you copy and paste. In March 2026, a new watering hole attack called "InstallFix" accounted for 13% of all malware incidents we observed. The lure? Fake install pages for Claude Code. Here is how it works and how to defend your environment. 1/7
110
Expel @expelsecurity.bsky.social · 31/03/2026
The malware targeted Windows, macOS, and Linux systems. If your systems show signs of compromise, treat your npm tokens, AWS access keys, SSH private keys, and other stored credentials as compromised until you’ve confirmed otherwise. 3/3
020
Expel @expelsecurity.bsky.social · 31/03/2026
The malicious packages are no longer active, but the window was long enough to warrant a thorough hunt to identify possible compromise. Our team has written up what happened, the attack chain, and what to look for. expel.com/blog/securit... 2/3
expel.com
Security alert: Axios npm supply chain attack
The Axios npm package suffered a supply chain attack from March 30-31. The malicious packages are no longer active, but here's what you need to know.
120
Expel @expelsecurity.bsky.social · 31/03/2026
The Axios npm package is a component of many popular applications. Its compromise in turn impacted a lot of systems and software that relied on it. The package was actively serving a remote access trojan to Windows, macOS, and Linux systems. 1/3
120
Expel @expelsecurity.bsky.social · 06/03/2026
Iran's cyber capabilities — ransomware, data wipers, stated intent to target Western infrastructure — aren't theoretical. Expel's James Shank and Iran intel expert Steph Shample give security teams the straight picture: what's real, what it means, and what to do about it. expel.com/resource/ira...
expel.com
Iran cyber threats: What security teams need to know right now | Expel briefing | Expel
What security teams need to know about Iran cyber threats. Expert insights on Iranian capabilities, TTPs, and defensive measures to implement today.
010
Expel @expelsecurity.bsky.social · 04/03/2026
The following is guidance from Microsoft to disable external senders: learn.microsoft.com/en-us/micros... When disabled, your organization will need to whitelist which external organizations can send unsolicited messages. This is a much safer configuration. 5/5
learn.microsoft.com
IT Admins - Manage external meetings and chat with people and organizations using Microsoft identities - Microsoft Teams
For IT admins - Learn how to configure chat and meetings with people outside your organization who use Microsoft Entra ID, Microsoft Teams Essentials, or Skype.
000
Expel @expelsecurity.bsky.social · 04/03/2026
We’ve built out our detections around this activity, but orgs still need to tighten their own controls. The attack tactic has been around for years now: actors send a Teams message, request access via QuickAssist, and then create additional backdoors to the network. 4/5
100
Expel @expelsecurity.bsky.social · 04/03/2026
Even more senders: RyanMorris@seqhelpitsuppnetops[.]onmicrosoft[.]com KevinMoore@secscanappsecopscenter[.]onmicrosoft[.]com ThomasCarter@seqapsitsupportops[.]onmicrosoft[.]com RachelMorgan@ioseccloudsupport[.]onmicrosoft[.]com 3/5
100
Expel @expelsecurity.bsky.social · 04/03/2026
More malicious senders: corporate[@]itelectronicshelpdesk[.]onmicrosoft[.]com HelpDesk[@]officeactions[.]onmicrosoft[.]com it_assistance[@]teams0138[.]onmicrosoft[.]com IT_Assistance@teams0144[.]onmicrosoft[.]com Support@StServiceIT[.]onmicrosoft[.]com 2/5
100
Expel @expelsecurity.bsky.social · 04/03/2026
We continue to see high volumes of targeted phishing via Microsoft Teams. The following are malicious senders just from this past week: Corporat[@]HelpDeskFoundation[.]onmicrosoft[.]com service[@]helpdeskfoundation[.]onmicrosoft[.]com helpdesk[@]omkarcis[.]online 1/5
100