Reposted by Andrew NorthernCynthia Brumfield @metacurity.com · 14/01/2025The Justice Department and FBI announced a law enforcement operation that, alongside international partners, deleted “PlugX” malware from thousands of infected computers worldwide implanted by Chinese hackers known as “Mustang Panda” or “Twill Typhoon." www.justice.gov/opa/pr/justi...justice.govJustice Department and FBI Conduct International Operation to Delete Malware Used by China-Backed HackersThe Justice Department and FBI today announced a multi-month law enforcement operation that, alongside international partners, deleted “PlugX” malware from thousands of infected computers worldwide. A... 086
Andrew Northern @exraritas.bsky.social · 13/01/2025I wish that I would have known this or have had exposure to this. I was shocked at how defensive I became the first time you edited my work. Sorry for that. I think I am growing and have grown 🌱 010
Reposted by Andrew NorthernPIVOTcon @pivotcon.bsky.social · 01/01/2025Dear Threat Researchers! We wish you a fruitful year full of impactful research! Stay healthy, stay happy and don't stop being awesome! 🥂🕺💃🎇🎆 #HappyNewYear2025 #CTI #PIVOTcon25 #ThreatResearch #ThreatIntel 093
Andrew Northern @exraritas.bsky.social · 01/01/2025Day 1 of giving the murder of crows 🐦⬛ a present 🎁 until we are friends. Today’s present: Part of a Hash Brown 010
Reposted by Andrew NorthernChristian Blichmann 🇺🇦 (also on Mastodon) @admvonschneider.bsky.social · 03/01/2023A while back, I made a thing that turns #BinDiff matches into YARA rules: github.com/google/vxsig #100DaysOfYARAgithub.comGitHub - google/vxsig: Automatically generate AV byte signatures from sets of similar binaries.Automatically generate AV byte signatures from sets of similar binaries. - google/vxsig 0104
Andrew Northern @exraritas.bsky.social · 09/12/2024Man I love Polyphia. open.spotify.com/track/0BE86K...open.spotify.comSweet TeaPolyphia, Aaron Marshall · Muse · Song · 2014 010
Reposted by Andrew NorthernJosh Stroschein | The Cyber Yeti @jstrosch.bsky.social · 01/11/2024🎙️ I'm excited to announce the launch of a new podcast - Behind the Binary! #BehindTheBinary focuses on the stories of the people, technology, and events that have shaped the world of reverse engineering. You can find it on Spotify👇 open.spotify.com/show/3yWgmIu...open.spotify.comBehind the Binary by Google Cloud SecurityPodcast · Josh Stroschein · Welcome to Behind the Binary, the podcast that introduces you to the fascinating people, technology, and tools driving the world of reverse engineering. Join your host, Jos... 093
Reposted by Andrew NorthernSelena Larson @selenalarson.bsky.social · 15/11/2024New episode of DISCARDED where I chat with Genina Po about how she catches phish 🎣 We dive into how to write detections, what to hunt for when finding phish kits, and some of her recent research on phishing scams. Tune in wherever you get your podcasts! Apple: podcasts.apple.com/us/podcast/d...podcasts.apple.comScams, Smishing, and Safety Nets: How Emerging Threats Catches PhishPodcast Episode · DISCARDED: Tales From the Threat Research Trenches · 11/15/2024 · 51m 1124
Reposted by Andrew NorthernKostas @kostastsale.bsky.social · 20/11/2024Such a thorough analysis of #RaspberryRobin in this article that taught me a lot 👇 😂 172
Reposted by Andrew NorthernBrad @malware-traffic-analysis.net · 25/11/20242024-11-25 (Monday): My thanks to the criminals who email malware directly to my inbox. This one is #AgentTesla using #FTP for #data_exfiltration. Sends to FTP server approx every 10 minutes. Attached disk image file: bazaar.abuse.ch/sample/7a11d... Extracted EXE: bazaar.abuse.ch/sample/2362b... 173
Andrew Northern @exraritas.bsky.social · 25/11/2024What if I’m just extremely eager to check in a few thousand times? 020
Andrew Northern @exraritas.bsky.social · 18/11/2024@hultquist.bsky.social hitting us with the hottest phishing lure of all time 160
Andrew Northern @exraritas.bsky.social · 18/11/2024www.proofpoint.com/us/blog/thre...proofpoint.comSecurity Brief: ClickFix Social Engineering Technique Floods Threat Landscape | Proofpoint USWhat happened Proofpoint researchers have identified an increase in a unique social engineering technique called ClickFix. And the lures are getting even more clever. 020
Reposted by Andrew NorthernNathan McNulty @nathanmcnulty.com · 17/11/2024Almost embarrassed to post this, but I've always used Fiddler or Burp for capturing things like this... I didn't have admin rights and was trying to capture network traffic from a pop-up, so Dev Tools wasn't working Apparently this is built into Chrome/Edge! So cool :) edge://net-export/ 1518645
Andrew Northern @exraritas.bsky.social · 16/11/2024Trying to rebuild my following here. Tag other security researchers and professionals in the comments please. I’ll follow back :) 340
Reposted by Andrew NorthernJamie Levy 🦉 @gleeda.bsky.social · 15/11/2024🧵Today’s blogpost focuses on a newer ransomware variant named SafePay. Needless to say, ransomware sucks. When this new variant appeared, it gained our attention. 👀 Let’s dig into what happened and what makes it tick ⬇️: 23612
Andrew Northern @exraritas.bsky.social · 14/11/2024Started out with this set of block words. Quickly learned that there will be many more. 010
Andrew Northern @exraritas.bsky.social · 14/11/2024Meh. A lot of engagement farming here already. Splendid 010
Reposted by Andrew NorthernMyrtus @malwareindepth.com · 14/11/2024#Latrodectus campaign from today gist.github.com/myrtus0x0/cd.... If anything comes of it, I'll put in threadgist.github.comLatrodectus_2024_11_13.mdGitHub Gist: instantly share code, notes, and snippets. 1176
Andrew Northern @exraritas.bsky.social · 14/11/2024Used my AirPods to take a hearing test today. Not surprised at the amount of hearing I have lost. Interesting to see if quantified. 000
Andrew Northern @exraritas.bsky.social · 14/11/2024Probably going to be much more candid on here. We will see. 000
Andrew Northern @exraritas.bsky.social · 14/11/2024It is now 2:45 and I have failed to eat breakfast or lunch but I did manage to write emulation for the server side for a piece of malware I track. 130
Andrew Northern @exraritas.bsky.social · 14/11/2024Got this bad boy tattooed on me a little over a week ago. 010
Andrew Northern @exraritas.bsky.social · 03/07/2023I’m here to shitpost about malware and information security. 030