Sign in

Tom Hegel

@hegel.bsky.social
2.8K followers 1K following 72 posts

Distinguished Threat Researcher, SentinelLABS Research Lead @SentinelOne. Nation-state operations, research systems & applied AI for threat intelligence. Find me at TomHegel.com

PostsRepliesMedia
Tom Hegel @hegel.bsky.social · 16/09/2026
NEW: We traced Hugging Face records tied to OpenAI’s May 2026 agent activity across two account histories, 0Time and Nyx9. Better detailed timeline, earlier relay code, exploit-oriented capability probing, and ChatGPT identity provisioning. Read Here: s1.ai/hf-agents
s1.ai
Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face
Two Hugging Face accounts reveal that OpenAI's agents staged relay code, internal probes and ChatGPT account registration beyond the published timeline.
010
Reposted by Tom Hegel
The Vertex Project @vertexproject.bsky.social · 16/09/2026
Okay, we’ll stop being cryptic. 👀 We pressed a limited-edition Signals & Stories vinyl to celebrate 10 years of The Vertex Project. 💿 There aren’t many and they’re coming to LABScon in your welcome bags. 🙌 See you in Scottsdale. 💚
0145
Tom Hegel @hegel.bsky.social · 05/06/2026
Excellent vid on running down mystery GPS/GNSS signals over Europe. The collection and pivoting tradecraft here is brilliant. I don't think any of us in the cyber domain will be surprised by the results, but an exciting process nonetheless. www.youtube.com/watch?v=tz23...
youtube.com
Something is jamming GPS over Europe. Here's what we found
YouTube video by Veritasium
186
Tom Hegel @hegel.bsky.social · 02/06/2026
💚 Such a fun conversation with the legends at @vertexproject.bsky.social, listen in here:
090
Reposted by Tom Hegel
Signal @signal.org · 27/04/2026
A response to recent reporting in Germany, in service of clarity and accountability: First, it’s important to be precise when it comes to critical infrastructure like Signal. Signal was not “hacked” — in that our encryption, infrastructure, & the integrity of the app’s code was not compromised. 1/
191317530
Reposted by Tom Hegel
Joseph Menn @joemenn.bsky.social · 24/02/2026
Here we go. Free, no-reg versions of favorite stories from my four years at the Washington Post. First, three pieces from our Pulitzer-finalist series on how India's ruling party coerced U.S. tech giants into violating their own policies. www.washingtonpost.com/world/2023/0...
washingtonpost.com
Under India’s pressure, Facebook let propaganda and hate speech thrive
Facebook has retreated from its professed ideals in India under pressure from Prime Minister Narendra Modi’s Bharatiya Janata Party.
616066
Tom Hegel @hegel.bsky.social · 10/02/2026
Hacktivism and War -- always worth listening to Jim 👇 www.youtube.com/watch?v=sNaO...
youtube.com
LABScon25 Replay | Hacktivism and War: A Clarifying Discussion | Jim Walter
YouTube video by SentinelOne
010
Reposted by Tom Hegel
Tom Hegel @hegel.bsky.social · 05/09/2025
🔥 The lineup this year is incredible, thanks to everyone who submitted! Attendees are in for something special… and for everyone else, expect some major FOMO. events.sentinelone.com/event/LABSco...
events.sentinelone.com
LABScon 2025
022
Tom Hegel @hegel.bsky.social · 05/09/2025
🔥 The lineup this year is incredible, thanks to everyone who submitted! Attendees are in for something special… and for everyone else, expect some major FOMO. events.sentinelone.com/event/LABSco...
events.sentinelone.com
LABScon 2025
022
Tom Hegel @hegel.bsky.social · 04/09/2025
New research from @milenkowski.bsky.social (S1) and @kennethkinion.bsky.social (Validin): 🇰🇵 Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms Research: www.sentinelone.com/labs/contagi... Reuters story: www.reuters.com/world/asia-p...
sentinelone.com
Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms
DPRK-aligned threat actors abuse CTI platforms to detect infrastructure exposure and scout for new assets.
075
Reposted by Tom Hegel
Catalin Cimpanu @campuscodi.risky.biz · 02/09/2025
The US, AU, and NZ have tested a prototype for a new cyber defense kit designed to connect and help secure any network. The kits are operated by a nine-person team and are intended to be portable and moved to any location in the world. www.defence.gov.au/news-events/...
144
Reposted by Tom Hegel
SentinelOne @sentinelone.com · 26/08/2025
🔥 The hunt is on for the world’s ultimate threat hunter? 🔍 🛡️Introducing Sentinels League: The Threat Hunting World Championships 🛡️ 3 Rounds. 3 Regions. 3 Finalists. Only One World Champion.
253
Reposted by Tom Hegel
Snorre Fagerland @snoffle.bsky.social · 17/06/2025
Someone claiming to be Gonjeshke Darande (Predatory Sparrow) has posted ~2GB of what *appears to be* IranCell subscriber data, covering the 935-939 prefixes. #privacy #breach #mobile #iran
Screenshot from Predatory Swallow's Telegram channel, showing folders purporting to hold IranCell data
041
Tom Hegel @hegel.bsky.social · 09/06/2025
Hefty new drop w/ @milenkowski.bsky.social China-nexus Threat Actors Hammer At the Doors of Top Tier Targets www.sentinelone.com/labs/follow-...
073
Reposted by Tom Hegel
Catalin Cimpanu @campuscodi.risky.biz · 27/05/2025
Dutch intelligence discover a new Russian APT—LAUNDRY BEAR www.aivd.nl/documenten/p... Microsoft calls it Void Blizzard. Their report is here: www.microsoft.com/en-us/securi...
12112
Reposted by Tom Hegel
Greg Lesnewich @greg-l.bsky.social · 21/05/2025
Is the era of the “named actor” done? As the OG adversary sets diverge, get promoted, or move on actors dispersing across the kill chain based on specialized skills increases (ORBs, criminal underground) AND the CTI models maturing… APTs ⬇️⬇️ UNCs ⬆️⬆️
7278
Reposted by Tom Hegel
Tom Hegel @hegel.bsky.social · 08/05/2025
NEW 👉 FreeDrain Unmasked | Uncovering an Industrial-Scale Crypto Theft Network Months-long research project with Validin we just dropped @pivotcon.bsky.social 🖤~40k IOCs: github.com/Validin/indi... 💜 SentinelLabs: s1.ai/freedrain 💙 Validin: www.validin.com/blog/freedra... Enjoy!
085
Tom Hegel @hegel.bsky.social · 08/05/2025
NEW 👉 FreeDrain Unmasked | Uncovering an Industrial-Scale Crypto Theft Network Months-long research project with Validin we just dropped @pivotcon.bsky.social 🖤~40k IOCs: github.com/Validin/indi... 💜 SentinelLabs: s1.ai/freedrain 💙 Validin: www.validin.com/blog/freedra... Enjoy!
085
Reposted by Tom Hegel
visi stark @invisig0th.bsky.social · 29/04/2025
An absolutely stunning look inside @sentinelone.com 's use of #synapse to provide intelligence context to inter-disciplinary intelligence stakeholders in defense of their own org. Truly on the leading edge of the intel driven fusion, collaboration, and impact. 🤩 www.sentinelone.com/labs/top-tie...
sentinelone.com
Top Tier Target | What It Takes to Defend a Cybersecurity Company from Today's Adversaries
This report highlights a rarely-discussed but crucially important attack surface: security vendors themselves.
12410
Reposted by Tom Hegel
Kenneth Kinion @kennethkinion.bsky.social · 24/04/2025
At @pivotcon.bsky.social, I'm presenting with @hegel.bsky.social and Sreekar Madabushi on the first public look at the full scope of a stealthy, long-running phishing network.
075
Reposted by Tom Hegel
John Scott-Railton @jsrailton.bsky.social · 23/04/2025
NEW: Iranian gov hackers targeted #EU Parliament's #Iran delegation chair @hneumannmep.bsky.social Elaborate operation impersonated former #FBI official to seed spyware. Good to see a MEP speaking out & sharing this insidious threat to EU institutions 1/ www.politico.eu/article/euro...
Text from https://www.politico.eu/article/european-parliament-iran-delegation-chair-victim-tehran-linked-hacking-hannah-neumann/Text from https://www.politico.eu/article/european-parliament-iran-delegation-chair-victim-tehran-linked-hacking-hannah-neumann/Text from https://www.politico.eu/article/european-parliament-iran-delegation-chair-victim-tehran-linked-hacking-hannah-neumann/
14423
Reposted by Tom Hegel
StrikeReady Labs @strikereadylabs.com · 11/04/2025
#apt #sidewinder "54th CISM World Military Naval Pentathlon Championship 2025.docx" 40712a087a8280425f1b317e34e265c0329ffb0057be298d519fc5e0af6cb58f -> dirsports.milqq[.]info blank doc decoy
013
Reposted by Tom Hegel
Kenneth Kinion @kennethkinion.bsky.social · 07/04/2025
@bushidotoken.net explored a Meta-themed credential phishing campaign (not "Reality"). From those indicators, I pulled the "Threads" & this is far from an isolated campaign. Found great pivots in registration "Meta"data. (I'll see myself out.) All 762 indicators 💥⤵️ www.validin.com/blog/not_rea...
validin.com
Not Reality: Exploring Meta-themed Phishing with Validin | Validin
Not Reality: Exploring Meta-themed Phishing with Validin
012
Reposted by Tom Hegel
Ryan Naraine @ryanaraine.bsky.social · 01/04/2025
Here's the Lab Dookhtegan segment www.youtube.com/watch?v=g-zj...
youtube.com
Who is this Lab Dookhtegan hack-and-leak operation?
YouTube video by Three Buddy Problem
041
Tom Hegel @hegel.bsky.social · 30/03/2025
Really great episode this week. The Signal ID management mess, and the lab dookhtegan topics.. simply delicious 🤌
092
Tom Hegel @hegel.bsky.social · 28/03/2025
Atomic indicators have value beyond just the day they’re observed - Age alone doesn’t always diminish their usefulness. Attribution challenges aside, this is a common occurrence in both cybercrime and APT campaigns. Looking at you, South Asia!
validin.com
Pulling the Threads on the Phish of Troy Hunt | Validin
Connecting a successful phishing attempt to Scattered Spider through Validin pivoting
020
Tom Hegel @hegel.bsky.social · 26/03/2025
Kryptina RaaS: From Unsellable Cast-off to Enterprise Ransomware www.sentinelone.com/labs/labscon...
sentinelone.com
LABScon24 Replay | Kryptina RaaS: From Unsellable Cast-off to Enterprise Ransomware
Jim Walter reveals how a recent leak provided insight into how Kryptina RaaS has been adapted for use in enterprise attacks.
020
Tom Hegel @hegel.bsky.social · 10/03/2025
Incredibly excited to drop some new research alongside @kennethkinion.bsky.social and Sreekar Madabushi at this years @pivotcon.bsky.social
071
Tom Hegel @hegel.bsky.social · 08/03/2025
Great refresher / inside-scoop on the Lamberts -- #WhereAreTheyNow
011
Reposted by Tom Hegel
StrikeReady Labs @strikereadylabs.com · 28/02/2025
#dprk #apt 2024년 귀속 연말정산 안내문_세한.docx.lnk b81513f0f8d3db382bb8f931bf2b7a0d4f26f74cfcf60b5d889de87ef2f1d543 -> www.roofcolor[.]com/wp-includes/js/src/list.php , www.acschoolcatering[.]com/libraries/src/inc/ decoy:
011
Reposted by Tom Hegel
Andrew (🎃) @athomashemlock.bsky.social · 23/02/2025
Look man, I'm not saying anything but I'm also not NOT saying anything
A meme about how it's weird this keeps happening
2215
Tom Hegel @hegel.bsky.social · 27/02/2025
research.checkpoint.com/2025/modern-...
research.checkpoint.com
Modern Approach to Attributing Hacktivist Groups - Check Point Research
Research by: Itay Cohen (@megabeets_) Over the past few decades, hacktivism has been, in a lot of cases, characterized by minor website defacements and distributed denial-of-service (DDoS) attacks, wh...
110
Tom Hegel @hegel.bsky.social · 25/02/2025
🚨 New analysis of Ghostwriter activity targeting Ukrainian government & Belarusian opposition s1.ai/ghost-xl
s1.ai
Ghostwriter | New Campaign Targets Ukrainian Government and Belarusian Opposition
Latest Ghostwriter campaign brings Belarusian opposition into its sights for the first time as it continues weaponizing XLS docs to drop malware.
0105
Tom Hegel @hegel.bsky.social · 21/02/2025
Spicy new drop from the team. H/T to @milenkowski.bsky.social, @dakotaindc.bsky.social, Alex Delamotte s1.ai/topsec
s1.ai
Censorship as a Service | Leak Reveals Public-Private Collaboration to Monitor Chinese Cyberspace
Data leak reveals how a top tier cybersecurity vendor helps the PRC enforce content monitoring and manipulation of public opinion in China.
076
Reposted by Tom Hegel
Dan Black @danwblack.bsky.social · 19/02/2025
Today, Google Threat Intelligence is alerting the community to increasing efforts from several Russia state-aligned threat actors (GRU, FSB, etc.) to compromise Signal Messenger accounts. cloud.google.com/blog/topics/...
cloud.google.com
Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger | Google Cloud Blog
Russia state-aligned threat actors target Signal Messenger accounts used by individuals of interest to Russia's intelligence services.
3165115
Reposted by Tom Hegel
The Banshee Queen 👑 @cyberoverdrive.bsky.social · 14/02/2025
If I had a dollar for every single time something is attributed vaguely to “”Mustang Panda”” I could buy a flat in London
4214
Reposted by Tom Hegel
Steven Adair @stevenadair.bsky.social · 14/02/2025
We have been tracking multiple Russian APT groups aggressively targeting organizations with Microsoft Device Code authentication phishing. The attackers got creative with tricking users into granting them access to their accounts. Have a look at our blog for all the details!
0157
Reposted by Tom Hegel
Ben Read @benread.bsky.social · 12/02/2025
Sharing the project I've been working on for the last month. Here's GTIG's paper on the severe threat to national security posed by cyber crime.
cloud.google.com
Cybercrime: A Multifaceted National Security Threat | Google Cloud Blog
Google Threat Intelligence Group discusses the current state of cybercrime, and why it must be considered a national security threat.
0175
Tom Hegel @hegel.bsky.social · 11/02/2025
The American woman arrested last year for assisting DPRK IT Workers pled guilty. but.. Did you know the original a search warrant for her home mentioned a TikTok that happened to show her laptop farm? lol oops www.justice.gov/usao-dc/pr/a...
justice.gov
Arizona Woman Pleads Guilty in Fraud Scheme That Illegally Generated $17 Million in Revenue for North Korea
Christina Marie Chapman, 48, of Litchfield Park, Arizona, pleaded guilty today in U.S. District Court in Washington D.C. in connection with a scheme that assisted overseas IT workers—posing as U.S. ci...
05920
Reposted by Tom Hegel
Matthew Green @matthewdgreen.bsky.social · 07/02/2025
Crap crap crap. www.washingtonpost.com/technology/2...
washingtonpost.com
U.K. orders Apple to let it spy on users’ encrypted accounts
Secret order requires blanket access to protected cloud backups around the world, which if implemented would undermine Apple’s privacy pledge to its users.
16306129
Reposted by Tom Hegel
SentinelLABS @sentinellabs.bsky.social · 03/02/2025
Sneaky! 🫣😶‍🌫️ #DPRK FERRET #macOS #malware has been tricking users into installing backdoors and trying to hide out behind fake Zoom, Chrome and Apple logd files. @philofishal.bsky.social @hegel.bsky.social s1.ai/Ferret
s1.ai
macOS FlexibleFerret | Further Variants of DPRK Malware Family Unearthed
DPRK 'Contagious Interview' campaign continues to target Mac users with new variants of FERRET malware and Github devs with repo spam.
0117
Reposted by Tom Hegel
Tom Hegel @hegel.bsky.social · 31/01/2025
X Phishing | Campaign Targeting High Profile Accounts Returns, Promoting Crypto Scams Blog --> s1.ai/XCrypto
s1.ai
X Phishing | Campaign Targeting High Profile Accounts Returns, Promoting Crypto Scams
SentinelLABS has observed an active phishing campaign targeting high-profile X accounts to hijack and exploit them for fraudulent activity.
182
Reposted by Tom Hegel
1steve 1stone @stonepwn3000.bsky.social · 31/01/2025
Timely research on high-value targeting fro @hegel.bsky.social and the @sentinelone.com team. ITS ALWAYS ABOUT ILLICIT VALID ACCESS FOLKS!!!!!
011
Tom Hegel @hegel.bsky.social · 31/01/2025
X Phishing | Campaign Targeting High Profile Accounts Returns, Promoting Crypto Scams Blog --> s1.ai/XCrypto
s1.ai
X Phishing | Campaign Targeting High Profile Accounts Returns, Promoting Crypto Scams
SentinelLABS has observed an active phishing campaign targeting high-profile X accounts to hijack and exploit them for fraudulent activity.
182
Tom Hegel @hegel.bsky.social · 22/01/2025
Great research here! "PlushDaemon" 👀
011
Reposted by Tom Hegel
Ryan Naraine @ryanaraine.bsky.social · 10/01/2025
New pod is up on YouTube! www.youtube.com/watch?v=sczd...
youtube.com
Hijacking .gov backdoors, Ivanti 0days and a Samsung 0-click vuln
YouTube video by Ryan Naraine
155
Tom Hegel @hegel.bsky.social · 09/01/2025
I’m biased, but wow—it’s so refreshing to get updates that genuinely help me better track threat actors. 🔥 www.validin.com/blog/threat_...
validin.com
Tracking Threat Actors with Validin | Validin
Quickly identify threat actors and discover malicious infrastructure using Validin by viewing detailed descriptions on thousands of threat actors that Validin has cataloged
0113
Reposted by Tom Hegel
John @bigbadw0lf.bsky.social · 09/01/2025
🔥 new blog detailing 0day exploitation of Ivanti appliances as well as some newly observed malware families tracked as PHASEJAM and DRYHOOK. We also detail activity related to the previously observed SPAWN* malware ecosystem tied to China-nexus cluster UNC5337. cloud.google.com/blog/topics/...
cloud.google.com
Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation | Google Cloud Blog
Zero-day exploitation of Ivanti Connect Secure VPN vulnerabilities since as far back as December 2024.
03322
Reposted by Tom Hegel
John Scott-Railton @jsrailton.bsky.social · 30/12/2024
The talented reporting crew of @raphae.li @razhael& @ajvicens.bsky.social point to a recent posting by #BeyondTrust about an incident involving remote support, which sounds a lot like what Treasury has announced. #cybersecurity #infosec www.beyondtrust.com/remote-suppo...
1187
Reposted by Tom Hegel
Tom Hegel @hegel.bsky.social · 27/12/2024
Jaime flagging popular extensions here. My findings/thoughts: 🔹 15ish fresh (this week) domains, each w/ their own extension tie-in. 🔹 Links back to early 2024 extensions, similar abuse, but focused on ad-blocking, AI, youtube, extensions. 🔹 VIBESINT = opportunistic scam. 🧵...
1101