Sign in

Tommy Madjar

@ffforward.bsky.social
443 followers 65 following 11 posts

Threat Researcher @ Proofpoint. Opinions are my own etc

PostsRepliesMedia
Tommy Madjar @ffforward.bsky.social · 20/06/2026
It's one of the pre-built templates that the threat actor can choose from when they use the Clickfix-as-a-service ErrTraffic. And yeah they had a compromised account that was used to get their WordPress instance to inject it.
111
Tommy Madjar @ffforward.bsky.social · 20/06/2026
Yeah it's fixed. However the #ErrTraffic affiliate had only MacOS and Windows configured as target OSes either way, so you wouldn't have seen it on Linux (Same reason it won't show on various URL scanners as default)
120
Tommy Madjar @ffforward.bsky.social · 20/06/2026
Yeah, It's #ErrTraffic, inject in main response. It's a ClickFIx-as-a-Service, this affiliate has a Windows Payload that leads to NetSupport, and the broken Mac one.
000
Tommy Madjar @ffforward.bsky.social · 20/06/2026
Heads up, Gizmodo has been compromised by some #ErrTraffic #ClickFix -as-a-Service affiliate.
040
Tommy Madjar @ffforward.bsky.social · 20/06/2026
Yes, this is ErrTraffic (ClickFix-as-a-Service), inject is in main response.
050
Reposted by Tommy Madjar
ThreatInsight @threatinsight.proofpoint.com · 19/02/2026
Proofpoint threat researchers identified a new malware-as-a-service named #TrustConnect. Notably, it masquerades as a legitimate remote monitoring and management tool, marking an evolution in how attackers weaponize trust around enterprise tooling. See our blog for details: brnw.ch/21x05Vh.
brnw.ch
(Don't) TrustConnect: It's a RAT in an RMM hat | Proofpoint US
Key findings  Proofpoint observed a new malware-as-a-service (MaaS) masquerading as a legitimate remote monitoring and management (RMM) tool. It calls itself TrustConnect.
143
Tommy Madjar @ffforward.bsky.social · 19/02/2026
Would you run AdobeReader.exe from a days-old company called "TrustConnect Software PTY LTD" because they managed to purchase an Extended Validation certificate? Blog w. @selenalarson.bsky.social and @proofpoint.com @threatinsight.proofpoint.com team out now! www.proofpoint.com/us/blog/thre...
010
Reposted by Tommy Madjar
ThreatInsight @threatinsight.proofpoint.com · 20/10/2025
Since 14 October, we’ve tracked a high volume XWorm campaign targeting Germany. The activity is attributed to TA584, a sophisticated #cybercrime group tracked since 2020. Messages are sent from hundreds of compromised sender accounts impersonating ELSTER and contain malicious URLs.
122
Reposted by Tommy Madjar
ThreatInsight @threatinsight.proofpoint.com · 16/06/2025
New ecrime insights: TA4557, known for distributing More_eggs malware, notably expanded to an international audience in recent campaigns. Per our data, the recruiter-focused TA was seen targeting orgs in France, England & Ireland, in addition to typical North America-targeted threats.
122
Tommy Madjar @ffforward.bsky.social · 19/05/2025
There is however at least two separate current malvertising/SEO campaigns, one leading to Bumblebee and one leading to SMOKEDHAM/Thundershell, but it's not from the official website. 2/2
000
Tommy Madjar @ffforward.bsky.social · 19/05/2025
This article that starts getting traction claims that the official RVTools website was distributing a malicious installer leading to Bumblebee. I see zero evidence of this actually being the case. 1/2
111
Reposted by Tommy Madjar
ThreatInsight @threatinsight.proofpoint.com · 31/03/2025
Proofpoint also recently observed this activity delivering GootLoader. Google Ads for a fake document creation app (lawliner[.]com) led to a malicious document creation website, on which users are directed to enter their email address.
142
Tommy Madjar @ffforward.bsky.social · 31/03/2025
Great research on that #GootLoader is now including email in their delivery chain. Please don't download NDAs and other contract templates from free sites without any history.
010
Tommy Madjar @ffforward.bsky.social · 18/11/2024
New blog drop with @selenalarson.bsky.social and the rest of the team. This one covers a lot of threats using the #ClickFix technique to lure targets to infect themselves by pasting malicious CMD/PS code. My "fave" is the chumbox #malvertising on major tech sites. www.proofpoint.com/us/blog/thre...
0104
Tommy Madjar @ffforward.bsky.social · 16/11/2024
Well I guess it's time to try this platform too 😅
130