Sign in

Feike Hacquebord

@feikeh.bsky.social
587 followers 88 following 28 posts

Principal Threat Researcher at TrendAI

PostsRepliesMedia
Feike Hacquebord @feikeh.bsky.social · 14/09/2026
Reading in the news that frontier AI models pose a threat to society? This 150+ page report by Anthropic explains why this might not be far-fetched. There are dozens of case studies inside one large report. Well done by the Threat Intelligence team at Anthropic: www.anthropic.com/threat-intel...
anthropic.com
Countering misuse of AI: September 2026 / Anthropic
Case studies from threat actors disrupted between December 2025 and August 2026 across seven areas of harm, from cyber operations to biological misuse.
000
Feike Hacquebord @feikeh.bsky.social · 10/09/2026
Aircraft broadcast identity, position and trajectory. Ships do the same. Sensors publish data on the open internet. New #TrendAI research found China-aligned ORB networks are harvesting this data at scale, through the same proxy infrastructure used in cyber operations: cdn.sanity.io/files/ch6z6v...
cdn.sanity.io
000
Feike Hacquebord @feikeh.bsky.social · 11/08/2026
Our 2026 H1 APT report on China, DPRK, Russia & Iran aligned activity is out. The common thread: APT actors are folding AI into the attack chain and hiding inside services you already trust. www.trendmicro.com/vinfo/us/sec...
010
Feike Hacquebord @feikeh.bsky.social · 08/06/2026
CVE-2025-8088, a WinRAR flaw, is still exploited by Russia-aligned groups against Ukraine. SHADOW-EARTH-066 (UAC-0226) deploys an evolved GIFTEDCROOK infostealer. Earth Dahu (Gamaredon) uses HTA + Cloudflare Workers. The flaw keeps on working (no WinRAR auto-update). trendmicro.com/en_us/resear...
trendmicro.com
Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open
Two separate Russia-aligned campaigns are still exploiting the WinRAR flaw CVE-2025-8088 against Ukrainian organizations nearly a year after it was patched, showing how unmanaged software keeps an exp...
020
Feike Hacquebord @feikeh.bsky.social · 19/05/2026
When TrendAI detects a C&C, we don't just block it for our customers, we get it removed from the internet. We send an evidence package to CleanDNS, who validates it independently and files a takedown request with the registrar. Domain removed, often within days. www.trendmicro.com/vinfo/us/sec...
trendmicro.com
TrendAI™ and CleanDNS: From Blocking Attacker Infrastructure to Removing It From the Internet
TrendAI™ and CleanDNS have partnered to go beyond blocking malicious domains. Learn how we are actively dismantling the infrastructure that cybercriminals depend on and removing attacker domains from ...
010
Reposted by Feike Hacquebord
Daniel Lunghi @thehellu.bsky.social · 30/04/2026
We investigated a China-aligned #APT that targeted multiple governments and companies with government contracts in Asia. In half of the targets we found a second group with different malware toolkit but sharing the infection vector and some post-exploitation tools. www.trendmicro.com/en_us/resear...
031
Feike Hacquebord @feikeh.bsky.social · 30/04/2026
New research by @thehellu.bsky.social and Lucas Silva: SHADOW-EARTH-053, a China-aligned group exploiting unpatched Microsoft Exchange servers to deploy ShadowPad, web shells, and NOODLERAT against government and defense targets across countries in Asia and EU: www.trendmicro.com/en_us/resear...
trendmicro.com
Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia
A China-aligned threat group is exploiting unpatched Microsoft Exchange vulnerabilities to conduct cyberespionage against government and critical infrastructure targets across Asia and beyond.
020
Feike Hacquebord @feikeh.bsky.social · 20/04/2026
Edge devices are now the #1 entry point for state-sponsored espionage. Exploits cost $30K-$100K vs millions for mobile. China-aligned groups are burning through zero-days, seemingly in a coordinated way. Your edge devices are the new front door for attackers: www.trendmicro.com/vinfo/us/sec...
trendmicro.com
Edge Under Siege: How State-Sponsored Actors Exploit Your Perimeter
Edge devices have become a primary entry point for state-sponsored espionage, giving attackers a cheaper, faster path to network access, credential theft, and traffic interception. Our report examines...
000
Feike Hacquebord @feikeh.bsky.social · 16/04/2026
The APT threat landscape is shaped by the "Digital Autocracy" bloc: an axis between CN, RU, DPRK and IR using AI as a force multiplier. AI is no longer experimental for APT. It is operational. The next 24 months will be a race for "resilience at machine speed." www.trendmicro.com/vinfo/us/sec...
Each country has a distinct AI strategy that shapes their APT operations. 

- China: "Full-Stack Anchor": The only nation capable of sustaining a large-scale AI arms race against the US. End-to-end domestic ecosystem. Expect advanced attacks from China-aligned actors using domestic AI tools, reducing our visibility into how they operate.
 
- Russia: "Sovereign Fortress": Hardware constraints offset by energy resources and increasing reliance on Chinese technology. AI applied to warfare, surveillance, and now embedded in active malware. 

 - North Korea: "Asymmetric Saboteur": Leveraging AI to automate cybercrime, funding the missile program through crypto-theft and deepfake-based social engineering. Reliant on third-party AI platforms and Russian infrastructure support.
062
Feike Hacquebord @feikeh.bsky.social · 16/04/2026
It is not often the public gets to see the impact of Russia-aligned cyber operations. This article by Raphael Satter provides exactly that: Russia-aligned actors compromised 170+ accounts of Ukrainian officials tasked with fighting corruption and unmasking spies. www.reuters.com/world/russia...
reuters.com
Exclusive: Russia-linked hackers compromised scores of Ukrainian prosecutors’ email accounts, data shows
Russia-linked hackers broke into more than 170 email accounts belonging to prosecutors and investigators across Ukraine during the last several ​months, according to data reviewed by Reuters, a campai...
020
Reposted by Feike Hacquebord
Raphael Satter @raphae.li · 15/04/2026
Scoop: Allegedly Russian hackers have broken into more than 170 inboxes belonging to Ukrainian prosecutors and investigators. Could help Moscow keep tabs on Ukrainian counterintelligence and sensitive corruption investigations. www.reuters.com/world/russia...
reuters.com
Exclusive: Russia-linked hackers compromised scores of Ukrainian prosecutors’ email accounts, data shows
Russia-linked hackers broke into more than 170 email accounts belonging to prosecutors and investigators across Ukraine during the last several ​months, according to data reviewed by Reuters, a campai...
52725
Feike Hacquebord @feikeh.bsky.social · 26/03/2026
In our most recent report on the Russia-aligned APT group Pawn Storm (APT28, Fancy Bear, Forest Blizzard), we explain how they have been using PRISMEX, a collection of interconnected malware components, to target the defense supply chain of Ukraine and its allies - www.trendmicro.com/en_us/resear...
trendmicro.com
Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities
This blog discusses the steganography, cloud abuse, and email-based backdoors used against the Ukrainian defense supply chain in the latest Pawn Storm campaign that TrendAI™ Research observed and anal...
020
Feike Hacquebord @feikeh.bsky.social · 06/03/2026
We published this article on "Cyber Considerations for Organizations During Times of Conflict" in 2024. It is worth a read again - www.trendmicro.com/vinfo/us/sec...
trendmicro.com
Cyber Considerations for Organizations During Times of Conflict
This article provides a comprehensive overview of the necessary adjustments and strategies CISOs need to implement to safeguard their organizations’ assets, maintain business continuity, and uphold pu...
000
Feike Hacquebord @feikeh.bsky.social · 17/02/2026
Spammers abused Atlassian Jira’s notifications to bypass email security filters and target government and corporate entities with spam. In one of the campaigns highly skilled Russians working abroad were targeted, even though the motivation looks to be financial - www.trendmicro.com/en_us/resear...
trendmicro.com
000
Reposted by Feike Hacquebord
The Insider @theins.press · 14/02/2026
Navalny was poisoned with exotic frog toxin, five Western nations confirm Multiple labs have independently analyzed biological samples taken from Alexei Navalny’s body and found epibatidine, a highly toxic alkaloid sourced from a South American poisonous frog.
theins.press
Navalny was poisoned with exotic frog toxin, five Western nations confirm
Five European countries have confirmed that Navalny was poisoned with epibatidine — a high-potency neurotoxin derived from South American poison dart frogs. Traces of the toxin were found in tissue sa...
15534
Feike Hacquebord @feikeh.bsky.social · 12/02/2026
TrendAI formalizes threat attribution as a structured, repeatable discipline by combining standardized evidence scoring, relationship mapping, and bias testing, with a temporary stage that separates clustering from final naming. Article on how we attribute: www.trendmicro.com/vinfo/us/sec...
trendmicro.com
Threat Attribution Framework: How TrendAI™ Applies Structure Over Speculation
TrendAI™ brings structure and discipline to threat attribution, helping security leaders and teams make informed decisions about cyber risk, incident response, and overall defensive posture.
021
Reposted by Feike Hacquebord
ESET Research @esetresearch.bsky.social · 23/01/2026
#BREAKING #ESETresearch identified the wiper #DynoWiper used in an attempted disruptive cyberattack against the Polish energy sector on Dec 29, 2025. At this point, no successful disruption is known, but the malware’s design clearly indicates destructive intent. 1/5
13429
Reposted by Feike Hacquebord
Virus Bulletin @virusbtn.bsky.social · 12/12/2025
Trend Micro tracks SHADOW-VOID-042 spear-phishing (Nov 2025) using Trend Micro-themed lures and a decoy site mimicking Trend’s corporate style, targeting defence, energy, chemicals, cybersecurity and ICT sectors. www.trendmicro.com/en_us/resear...
033
Reposted by Feike Hacquebord
Daniel Lunghi @thehellu.bsky.social · 11/12/2025
We investigated an #APT with links to Void Rabisu (Romcom) that used Trend Micro updates as a lure in a recent campaign involving vulnerability exploitation. There were at least 4 stages before the final payload, some of them being tailored to the targeted machine www.trendmicro.com/en_us/resear...
spear phishing email using Trend Micro updates as a luretargeted industriescomparison between this intrusion set and Void RabisuWebsite mimicking Trend Micro graphical design
011
Feike Hacquebord @feikeh.bsky.social · 11/12/2025
Recently various industries, including Trend Micro, were targeted by a Trend Micro-themed campaign. Trend Vision One™ stopped it early in the kill chain. The campaign somewhat aligns with Void Rabisu (ROMCOM). For now we track this temporarily under SHADOW-VOID-042 www.trendmicro.com/en_us/resear...
trendmicro.com
SHADOW-VOID-042 Targets Multiple Industries with Void Rabisu-like Tactics
020
Feike Hacquebord @feikeh.bsky.social · 22/10/2025
Cyberespionage campaigns are becoming increasingly complex due to the close collaboration between distinct APT groups. Learn how China-aligned Earth Estries provides initial access to compromised assets for Earth Naga (Flax Typhoon) to continue exploitation: www.trendmicro.com/en_us/resear....
trendmicro.com
The Rise of Collaborative Tactics Among China-aligned Cyber Espionage Campaigns
010
Feike Hacquebord @feikeh.bsky.social · 04/06/2025
Residential proxies are a key enabler of cybercrime today. This creates a growing need for connection and session-based access control. We used Ja4T fingerprinting that successfully tagged incoming connections from residential proxies to 1,500 IDS systems. www.trendmicro.com/vinfo/us/sec...
trendmicro.com
The Rise of Residential Proxies as a Cybercrime Enabler
This research discusses how residential proxies help cybercriminals bypass antifraud and IT security systems, and how vulnerabilities in the IoT supply chain are exploited where Android-based devices ...
1169
Feike Hacquebord @feikeh.bsky.social · 24/04/2025
DPRK cybercrime uses Russian infrastructure in Khasan and Khabarovsk, masked by VPNs, proxies, and RDPs. One fictitious DPRK company to lure IT professionals with interviews was BlockNovas. FBI seized BlockNovas' site and a related C&C on April 23, 2025. Read more: www.trendmicro.com/en_us/resear...
trendmicro.com
Russian Infrastructure Plays Crucial Role in North Korean Cybercrime Operations
151
Feike Hacquebord @feikeh.bsky.social · 11/03/2025
Roman Dobrokhotov and Christo Grozev have extensively reported on FSB and GRU. Read this to learn about their ordeal when a team, led by Marsalek, was hunting them down. The story has fun elements and close calls. It highlights the dangers journalists face as they inform us: theins.ru/en/inv/279034
theins.ru
“Let’s hire an ISIS suicide bomber to blow him up in the street!”: Europe’s most wanted man plotted my murder — and that of my colleague
A jury at the Old Bailey, London’s Central Criminal Court, has just found six of my compatriots — citizens of Bulgaria — guilty of conspiring with the Kremlin to kidnap and possibly murder me and my c...
000
Feike Hacquebord @feikeh.bsky.social · 20/02/2025
Updated Shadowpad malware used in recent attacks against the manufacturing industry led to ransomware in some incidents. Research by @thehellu.bsky.social : www.trendmicro.com/en_us/resear...
trendmicro.com
Updated Shadowpad Malware Leads to Ransomware Deployment
000
Reposted by Feike Hacquebord
Raphael Satter @raphae.li · 17/12/2024
Yet another suspected case of publicly disclosed red team tools being used by an intelligence agency — allegedly the SVR — to conduct a sweeping surveillance operation. (ht @feikeh.bsky.social) www.trendmicro.com/en_us/resear...
trendmicro.com
Earth Koshchei Coopts Red Team Tools in Complex RDP Attacks
086
Reposted by Feike Hacquebord
Stephen Hilt @sjhilt.hilt.zip · 17/12/2024
Earth Koshchei (APT29): A cyberespionage group targeting critical sectors with stealthy techniques. Here’s what you need to know: www.trendmicro.com/en_us/resear... #Cybersecurity #ThreatIntel with @feikeh.bsky.social
trendmicro.com
Earth Koshchei Coopts Red Team Tools in Complex RDP Attacks
043
Feike Hacquebord @feikeh.bsky.social · 17/12/2024
Since Aug 2024 Earth Koshchei (APT29, Midnight Blizzard) used 193 RDP relays and 34 rogue backends against military, MFAs and others. The campaign peak was likely preceded by barely audible campaigns that ended with a bang in Oct 2024. Details and indicators here: www.trendmicro.com/en_us/resear...
trendmicro.com
Earth Koshchei Coopts Red Team Tools in Complex RDP Attacks
087
Reposted by Feike Hacquebord
Daniel Lunghi @thehellu.bsky.social · 05/12/2024
Our latest report presents Earth Minotaur, a threat actor targeting Tibetans and Uyghurs using Moonshine, an exploitation framework for Android apps described in 2019 by @citizenlab.ca leveraging vulnerabilities in applications embedding old versions of Chromium trendmicro.com/en_us/resear...
Attack chain showing attacker generating link on Moonshine, then sending it through targeted application to the victim, which after clicking the links gets compromised and delivered the DarkNimbus backdoorValidation flow that fingerprints the target by looking at user agent and delivering the proper exploitmultiple Chrome vulnerabilities exploited in the third-party applicationsList of Android applications being targeted
Most are very popular in South East Asia
0127
Feike Hacquebord @feikeh.bsky.social · 26/11/2024
One week ago Lumen/Shadowserver sinkholed Water Barghest C&Cs. Nsocks (alleged seller of Ngioweb bots) apparently suffers from this: US proxies down to 4494 (was 14037), EU proxies down to 2038 (was 9092). I expected a faster recovery. Still expect Water Barghest will make their botnet more robust.
121
Feike Hacquebord @feikeh.bsky.social · 19/11/2024
Water Barghest automated each step between finding vulnerable IoT devices to offering them for rent on a commercial residential proxy provider. Water Barghest's infrastructure was used to exploit Cisco IOS XE devices with a 0-day in October 2023. Read more here: www.trendmicro.com/en_us/resear...
trendmicro.com
Inside Water Barghest’s Rapid Exploit-to-Market Strategy for IoT Devices
010