Sign in

TJ Nel

@idr0p.net
64 followers 119 following 30 posts

Insikt Group @ Recorded Future Malware, AI, data, and coffee.

PostsRepliesMedia
TJ Nel @idr0p.net · 03/07/2026
x.com/RnaudBertran... Interesting pivot; this tells me... Open-weight sovereign deployment stack is a real product category. Nvidia (compute), edge inference vendors, open model labs, and integration middleware players all benefit, regardless of who wins the model-quality race.
x.com
Arnaud Bertrand (@RnaudBertrand) on X
After reflection, this new narrative by Palantir is probably much more consequential than people may assume. Palantir is basically being the canary in the coal mine announcing the death of two major ...
000
Reposted by TJ Nel
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 01/07/2026
Colleagues of mine at Insikt Group just released new research on the Iran-nexus cluster #TAG-182, deploying #MarkiRAT, a malware family previously observed in use by #FerociousKitten, for internal and external surveillance: www.recordedfuture.com/research/nex...
recordedfuture.com
Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool
Discover how Iranian-nexus threat cluster TAG-182 uses MarkiRAT malware and fake VPN/media apps to conduct cyber surveillance operations against domestic targets.
099
TJ Nel @idr0p.net · 04/05/2026
#IYKYK
000
TJ Nel @idr0p.net · 01/05/2026
#CopyFail #CVE-2026-31431... The world's answer to all of the people who forgot to save the su password on that one old VPS. Your patience has been rewarded, my friend 🫡
media.tenor.com
a man with a beard and long hair is looking at the camera
ALT: a man with a beard and long hair is looking at the camera
010
TJ Nel @idr0p.net · 16/04/2026
www.dbreunig.com/2026/04/14/c... one of the strongest post mythos articles in the game right now
dbreunig.com
Cybersecurity Looks Like Proof of Work Now
Is security spending more tokens than your attacker?
000
TJ Nel @idr0p.net · 08/04/2026
After reading about Mythos and remembering the Sora shutdown pressures. I have a strange feeling these pure-play frontier providers (OpenAI, Anthropic) will be like Amazon in the near future.
media.tenor.com
a monopoly man is wearing a top hat and a suit .
ALT: a monopoly man is wearing a top hat and a suit .
000
TJ Nel @idr0p.net · 03/04/2026
Working on #malware analysis #AI #agents reminds me of playing with a #Tamagotchi 😆. Repetitive, sometimes frustrating, but you love to see it evolve! 🤩. Pro Tip: If you are just pointing Claude/Codex/OpenCode at a bunch of analysis tool MCPs... you are doing it wrong and expensively.
A malware tamagotchi prototype dancing on AI paperwork.
000
TJ Nel @idr0p.net · 21/03/2026
Wow! SMCI dropped 33% on this news. That reaction is telling. The market understood immediately that export controls on AI compute are serious business, not theater. The AI race has a resource constraint, and everyone's been watching how aggressively it gets enforced. lowendbox.com/blog/supermi...
lowendbox.com
SuperMicro Founder Indicted on Charges of Smuggling Nvidia GPUs to China
Yih-Shyan “Wally” Liaw, one of the founders of server manufacturer SuperMicro, has been indicted on charges of smuggling billions of dollars' worth of high-end Nvidia GPUs to China.
000
TJ Nel @idr0p.net · 19/03/2026
I'm super excited for this to finally be out!! A TON OF CONTENT for CTI Pros!
021
TJ Nel @idr0p.net · 04/03/2026
October infostealer 🗝️. March extortion emails 📧. 5 months of dwell time. This is what undetected credential compromise looks like in practice. And with AI tools lowering the automation barrier, expect that timeline to speed up fast 🏃. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Hacker mass-mails HungerRush extortion emails to restaurant patrons
Customers of restaurants using the HungerRush point-of-sale (POS) platform say they received emails from a threat actor attempting to extort the company, warning that restaurant and customer data coul...
010
Reposted by TJ Nel
Virus Bulletin @virusbtn.bsky.social · 09/12/2025
Recorded Future’s Insikt Group uncovered four GrayBravo activity clusters. TAG-160 impersonates logistics firms, while TAG-161 impersonates Booking.com, employing ClickFix to deliver CastleLoader and Matanbuchus. www.recordedfuture.com/research/gra...
065
TJ Nel @idr0p.net · 06/12/2025
"There is a lack of consensus regarding the current state of AI malware maturity." So we put together #AIM3 to help #malware researchers describe the maturity level of an #AI_Malware Threat. www.recordedfuture.com/blog/ai-malw...
032
TJ Nel @idr0p.net · 05/12/2025
We all spent the last year vibe coding the shit out of web apps in React without knowing a single thing about JavaScript. Then enters #CVE-2025-55182 #React2Shell... poetry. “The spirits that I summoned I now cannot rid myself of again.”
030
Reposted by TJ Nel
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 29/09/2025
Excited to join a discussion on the second edition of The Mythical Beast by Jen Roberts (@atlanticcouncil.bsky.social), exploring the complex networks behind the spyware ecosystem. This kicks off the new Colloquium series by @virtualroutes.bsky.social: virtual-routes.org/event/mythic...
virtual-routes.org
Mythical Beasts and Where to Find Them: Diving into the Depths of the Global Spyware Market - Virtual Routes Colloquium
The first session of the Virtual Routes Colloquium Fall/Winter series hosts Jen Roberts from Cyber Statecraft Initiative. Jen will present her research on "Mythical Beasts and Where to Find Them: Divi...
01210
Reposted by TJ Nel
Lawrence S. @lawrencesec.bsky.social · 11/09/2025
Great blog post from @briankrebs.infosec.exchange.ap.brid.gy on #StarkIndustries. Makes a great point by highlighting it's links to MIRHosting. Where there are Dutch prefixes under these providers, there is usually always MIRHosting upstream.
143
TJ Nel @idr0p.net · 04/09/2025
Not a lot of public reporting on this, but we are seeing a mountain of activity 👀
033
Reposted by TJ Nel
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 04/09/2025
1/ Today @whoisnt.bsky.social, Marius, and I release a report on a new threat actor, #TAG-150, active since at least March 2025, which stands out for its rapid development, sophistication, responsiveness to reporting, and a large, evolving infrastructure: www.recordedfuture.com/research/fro...
recordedfuture.com
From CastleLoader to CastleRAT: TAG-150 Advances Operations with Multi-Tiered Infrastructure
Insikt Group reveals TAG-150’s multi-tiered infrastructure and CastleRAT malware—an advanced threat actor evolving rapidly with stealth and scale.
196
TJ Nel @idr0p.net · 27/08/2025
Big report from our team at Recorded Future around #ThreatActivityEnablers (all of the hostings and services that power malicious infrastructure). Great Research on #StarkIndustries!
030
TJ Nel @idr0p.net · 27/08/2025
Please give me the strength not to buy this hotswap GPU framework laptop with maxed-out specs. 😬
020
Reposted by TJ Nel
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 26/08/2025
1/ We just released a new report on TAG-144 (also known as Blind Eagle), where we identified five distinct activity clusters that have been active throughout 2024 and 2025, primarily targeting the Colombian government at multiple levels. Link to the report: www.recordedfuture.com/research/tag...
recordedfuture.com
TAG-144’s Persistent Grip on South American Organizations
Persistent cyber operations by TAG-144 (Blind Eagle) continue to target South American, primarily Colombian, government entities through advanced spearphishing and RAT-based malware campaigns. Explore...
165
TJ Nel @idr0p.net · 20/08/2025
🔎 A day in the life of a #Lumma malware operator... this is a must-read! 💪
031
Reposted by TJ Nel
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 05/08/2025
1/ We've just released a new report uncovering new infrastructure tied to multiple activity clusters linked to the Israeli spyware vendor #Candiru across several countries. Full report: www.recordedfuture.com/research/tra...
recordedfuture.com
Tracking Candiru’s DevilsTongue Spyware in Multiple Countries
Recorded Future's Insikt Group uncovers active infrastructure linked to Candiru’s DevilsTongue spyware across multiple countries. Discover how this stealthy spyware targets high-value individuals and ...
11212
TJ Nel @idr0p.net · 23/07/2025
"By 2025, 96% of companies are expected to use public cloud services, and 84% will adopt private cloud services. Additionally, 92% of organizations are projected to implement a multicloud strategy, reflecting the growing trend of cloud adoption across various industries." - Nextwork
000
TJ Nel @idr0p.net · 22/07/2025
Amazing DDoSia Project Research by @calwarez.bsky.social, great work!!! www.recordedfuture.com/research/ana... NoName057(16) had thousands of targets in their crosshairs 🎯, and they utilized their DDoSia Project and a crowdsourced army 🪖 to take them down... This is a must-read Report!
recordedfuture.com
Inside DDoSia: NoName057(16)’s Pro-Russian DDoS Campaign Infrastructure
Discover how NoName057(16) targeted 3,700+ hosts across Europe using its DDoSia platform. This in-depth report reveals multi-tiered C2 infrastructure, attack patterns, and strategic geopolitical motiv...
010
TJ Nel @idr0p.net · 14/07/2025
simonwillison.net/2025/Jul/6/s... This is likely the beginning of the new "open S3 bucket" wave of attacks. MCP is awesome and a greatly needed standard, but we know how this will go for the next year or two. 🫤
simonwillison.net
Supabase MCP can leak your entire SQL database
Here's yet another example of a lethal trifecta attack, where an LLM system combines access to private data, exposure to potentially malicious instructions and a mechanism to communicate data back …
000
TJ Nel @idr0p.net · 11/07/2025
#Remcos #malware is now at v7.0. No significant changes to the payload side, but improvements to enhance reliability and address bugs based on operator experience added. Samples: tria.ge/250709-3vxwa... tria.ge/250710-vba87... Looks to be distributed via email campaigns from reboundue[.]com emails
tria.ge
remcos | e24d9afbc2ed01e348ef6946672ef5f310940dd57a5216d0f1edbe31c919374b | Triage
Check this remcos report malware sample e24d9afbc2ed01e348ef6946672ef5f310940dd57a5216d0f1edbe31c919374b, with a score of 10 out of 10.
000
Reposted by TJ Nel
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 13/06/2025
Today we are releasing a report on new infrastructure and tooling linked to GrayAlpha, a financially motivated threat actor overlapping with FIN7 🧵 www.recordedfuture.com/research/gra...
recordedfuture.com
GrayAlpha Unmasked: New FIN7-Linked Infrastructure, PowerNet Loader, and Fake Update Attacks
Insikt Group exposes GrayAlpha’s evolving infrastructure and infection methods—including PowerNet and MaskBat loaders, fake 7-Zip sites, and the undocumented TAG-124 network—linking the group to FIN7’...
11312
Reposted by TJ Nel
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 12/06/2025
Today we’re publishing new findings on Predator spyware, still active despite global sanctions, now with a new client and ties to a Czech entity. Here’s what we found 🧵 www.recordedfuture.com/research/pre...
recordedfuture.com
Predator Spyware Resurgence: Insikt Group Exposes New Global Infrastructure
Despite sanctions and global scrutiny, Predator spyware operations persist. Insikt Group reveals new infrastructure links in Mozambique, Africa, and Europe, highlighting ongoing threats to civil socie...
11912
Reposted by TJ Nel
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 02/05/2025
Another report by Insikt Group on newly identified malware families #TerraStealerV2 as well as #TerraLogger, both attributed to the threat actor Golden Chickens: www.recordedfuture.com/research/ter...
recordedfuture.com
Golden Chickens Unveils TerraStealerV2 and TerraLogger: New Credential Theft Tools Identified by Insikt Group
Insikt Group reveals two emerging malware strains—TerraStealerV2 and TerraLogger—linked to Golden Chickens, a threat actor behind credential theft and keylogging MaaS platforms. Learn how these tools ...
034
Reposted by TJ Nel
Lesley Carhart @hacks4pancakes.com · 10/02/2025
Oh my god, they just unintentionally wrecked a ton of red team playbooks at the NSA popular.info/p/the-nsas-b...
The memo acknowledges that the list includes many terms that are used by the
NSA in contexts that have nothing to do with
DEI. For example, the term "privilege" is used by the NSA in the context of "privilege escalation." In the intelligence world, privilege escalation refers to "techniques that adversaries use to gain higher-level permissions on a system or network."
1102643729
TJ Nel @idr0p.net · 02/02/2025
Today was the first day I reflexively went to Bsky for a quick check-in on the world of social media. Post-Twitter, as someone who does not use other platforms, I missed seeing authentic commentary without all the other madness.
media.tenor.com
a man in a suit and tie with the words it 's just refreshing behind him
ALT: a man in a suit and tie with the words it 's just refreshing behind him
000
TJ Nel @idr0p.net · 29/01/2025
time.com/7210296/chin... But where is Mistral.AI?
time.com
What Is DeepSeek, the New Chinese OpenAI Rival?
The Chinese company causing turmoil in the American AI industry
000
TJ Nel @idr0p.net · 23/01/2025
Threat model around controlling an AI-driven IDE like Cursor and now Trae (Bytedance) www.trae.ai Imagine being a MiTM of code generation and shipment to git repos. You could lean the developer toward vulnerabilities and Just-in-time code injection for PRs. We will still be busy, that's for sure.
trae.ai
Trae - Ship Faster with Trae
Trae is an adaptive AI IDE that transforms how you work, collaborating with you to run faster.
000
TJ Nel @idr0p.net · 17/01/2025
therecord.media/kristi-noem-... - Give someone a fish... they eat for a day 🍴 - Teach someone to fish... they eat for a lifetime 💪 - Convince someone that fish are evil, and you should not listen to fish or eat anything in general... they starve 💀
therecord.media
Homeland Security nominee Kristi Noem bashes CISA, says agency must be 'smaller, more nimble'
The South Dakota governor said efforts to address foreign disinformation campaigns were "far off mission” for the Cybersecurity and Infrastructure Security Agency.
000
TJ Nel @idr0p.net · 16/01/2025
When top Infostealers do the press rounds 🎬... it's a good reminder for me. Cybercrime isn’t lurking in the shadows anymore—it’s running PR campaigns. The game has changed so much and is probably driving the disruption ops that LE has been doing. 🤔 g0njxa.medium.com/lumma-steale...
g0njxa.medium.com
Lumma Stealer Q&A
The people have spoken, you asked and them replied
000
TJ Nel @idr0p.net · 09/12/2024
The last @returnonsecurity.com newsletter (great stuff, btw) posed an interesting question on the #cybersecurity #talent-gap. But... I think there is population bias because maybe more experienced leaders read this newsletter than #entry-level; so, of course, that's the perceived gap
230