Sign in

Intel 471

@intel471.bsky.social
769 followers 2 following 51 posts

Intel 471 specializes in delivering intelligence related to threat actors, threat hunting, financial cybercrime, ransomware, vulnerabilities, malware and underground marketplaces. Listen to our podcast, Cybercrime Exposed, on Spotify and Apple. #infosec

PostsRepliesMedia
Intel 471 @intel471.bsky.social · 22/08/2025
The disruption of the XSS cybercrime forum marked one of the most significant events in cybercrime in 2025. Here's an assessment its future from Intel 471's research and analysis teams: www.intel471.com/blog/after-d...
000
Intel 471 @intel471.bsky.social · 20/08/2025
A new episode of our Cybercrime Exposed podcast is out! DukeEugene is a Russian Android malware dev who has a big problem, and he puts everything on the line to solve it. Link to pod here: www.intel471.com/resources/po...
010
Intel 471 @intel471.bsky.social · 24/07/2025
Jacob Larsen is an #infosec pro who was involuntarily pulled into the dark world of doxing. Intel 471's latest Studio 471 podcast speaks with Jacob about doxing's effects, how sites like Doxbin exploit legal loopholes and how to defend against being doxed. www.youtube.com/watch?v=y5AO...
youtube.com
Defending against doxing ft. Jacob Larsen, Threat Researcher, Offensive Security Lead, CyberCX
YouTube video by Intel 471
000
Intel 471 @intel471.bsky.social · 04/07/2025
Pro-Russian hacktivism campaigns continue to be directed at countries and entities supporting Ukraine. Here's a briefing about new hacktivist groups and the risks. #infosec intel471.com/blog/pro-rus...
intel471.com
Pro-Russian hacktivism: Shifting alliances, new groups and risks
Pro-Russian hacktivism campaigns continued to be directed at countries and entities supporting Ukraine. Here's a briefing about new hacktivist groups and…
000
Intel 471 @intel471.bsky.social · 23/06/2025
The Black Basta ransomware gang contracted a person with the nickname Tinker. Tinker came from Conti and had a knack for running call centres, writing phishing emails and ransom negotiations. More here from Intel 471's Adversary Intelligence team. intel471.com/blog/a-look-...
intel471.com
A look at ‘Tinker,’ Black Basta’s phishing fixer, negotiator
The leader of the Black Basta ransomware group employed a trusted, experienced cybercrime actor nicknamed Tinker who he relied on for phishing content,…
012
Intel 471 @intel471.bsky.social · 23/05/2025
Law enforcement has smashed DanaBot, a data-stealing workhorse administered in Russia and sold to cybercriminals that also had a second, side version likely used for nation-state cyberespionage. Here's Intel 471's in-depth look at its operations. #infosec intel471.com/blog/danabot...
intel471.com
DanaBot malware disrupted, threat actors named
The DanaBot malware was severely disrupted by law enforcement. Here's an in-depth look at this data-stealing workhorse for the cybercriminal underground.
021
Intel 471 @intel471.bsky.social · 16/05/2025
Russian man Andrei Tarasov was indicted on cybercrime charges related to the Angler exploit kit. He was arrested in Germany but slipped away to Russia — despite his anti-Russian views. Research by @intel471.bsky.social #infosec intel471.com/blog/how-an-...
intel471.com
How an alleged Russian hacker slipped away
Russian man Andrei Tarasov was indicted on cybercrime charges related to the Angler exploit kit. He was arrested in Germany but slipped away to Russia —…
000
Intel 471 @intel471.bsky.social · 12/03/2025
Russia-based bulletproof hosting service Zservers was breached, doxxed and sanctioned, but there are signs this cybercrime and ransomware service provider may not be finally done. New research from Intel 471. #infosec intel471.com/blog/zserver...
intel471.com
Zservers: Bulletproof hosting for online crime
Russia-based bulletproof hosting service Zservers was exposed and hit with sanctions. But there are signs it may not have been permanently disrupted.
034
Intel 471 @intel471.bsky.social · 01/03/2025
The Black Basta data leak exposed critical details about how this damaging ransomware gang operated, including how its top member claims to have eluded law enforcement. New blog here: intel471.com/blog/black-b... #infosec
intel471.com
Black Basta exposed: A look at a cybercrime data leak
Black Basta suffered a leak of 197,000 internal chats messages, which has exposed critical details about how this damaging ransomware gang operated,…
011
Intel 471 @intel471.bsky.social · 10/02/2025
DeepSeek is just the start. China has approved more than 117 LLMs since August 2023 that are all rapidly maturing in capability. Intel 471's Analysis and Cyber Geopolitical Intelligence teams explain here what this means for enterprise risk. #infosec intel471.com/blog/does-de...
020
Intel 471 @intel471.bsky.social · 10/02/2025
Intel 471's very own Senior Intelligence Analyst Ashley Jess has been closely following cybercriminal use and interest in AI. This was a pre-record before DeepSeek popped but it is a great discussion about the potential threats and risks. #infosec intel471.com/blog/how-thr...
intel471.com
How threat actors are using artificial intelligence
Artificial intelligence is a red-hot mess, filled with contradicting predictions over whether it will bring vast benefits. In this Studio 471, Ashley Jess…
030
Intel 471 @intel471.bsky.social · 15/01/2025
Clop, a ransomware/extortion group that targets file transfer systems, revealed the names of 59 businesses that allegedly were impacted by the Cleo vulnerabilities and refused to pay. The group claimed their data will be publicly released on Saturday, with another list to come on Tuesday. #infosec
000
Intel 471 @intel471.bsky.social · 04/12/2024
Ep. 8 of @intel471.bsky.social's Cybercrime Exposed podcast covers Raccoon Stealer, which was a popular and damaging infostealer. But its operator made a critical OPSEC error. Thanks to @crep1x.bsky.social of @sekoia.io. #infosec Full series on Apple and Spotify. intel471.com/resources/po...
intel471.com
Cybercrime Exposed Podcast: Raccoon Stealer
Intel 471 empowers cybersecurity teams worldwide to be proactive with its TITAN platform and comprehensive coverage into the criminal underground.
021
Intel 471 @intel471.bsky.social · 29/11/2024
Hundreds of fake websites have been registered over the last few days spoofing real brands containing "Black Friday" related keywords. These sites are often promoted through SEO tricks and search engine/social media ads. This one was at samsoniteblackfriday[.]shop. #infosec
111
Intel 471 @intel471.bsky.social · 28/11/2024
The breaches linked to customers of Snowflake marked one of the largest data breach waves of 2024. One of the alleged threat actors has been arrested in Canada. This blog is a deep dive into the Com-related threat actor "waifu" or @judische. #infosec intel471.com/blog/how-to-...
intel471.com
How to Defend Against Alleged Snowflake Attacker ‘Judische’
The threat actor behind the compromise of more than 165 organizations using Snowflake credentials stolen by infostealers has reportedly been detained.…
011
Intel 471 @intel471.bsky.social · 28/11/2024
Adversaries try to hide malicious components by renaming them as legitimate Windows binaries. This technique has been used by the Turla threat actor group and others. Here's how to threat hunt for this behavior. #infosec intel471.com/blog/threat-...
intel471.com
Threat Hunting Case Study: Uncovering Turla
Adversaries try to hide malicious components by renaming them as legitimate Windows binaries. This technique has been used by the Turla threat actor group…
010
Intel 471 @intel471.bsky.social · 23/10/2024
Will processing cyber threat intelligence become illegal? Here's a discussion with professor Peter Swire about how data protection schemes can potentially clash with better cybersecurity defences. This is part of @intel471.bsky.social's interview series. #infosec intel471.com/blog/will-pr...
intel471.com
Will Processing CTI Become Legally Risky?
In this Studio 471, Peter Swire discusses the regulatory environment, how it could impact the use of cyber threat intelligence and what could be done to…
000
Intel 471 @intel471.bsky.social · 03/10/2024
We're fielding questions about how Telegram's pledge to turn over phone numbers and IP addresses under valid legal orders will impact visibility into cybercrime. Here's our assessment: intel471.com/blog/are-tel... #infosec
intel471.com
Are Telegram's New Policies Spooking Cybercriminals?
Telegram will now divulge IP addresses and phone numbers in response to valid legal requests. Some cybercriminals are planning to leave Telegram. We…
000
Intel 471 @intel471.bsky.social · 26/09/2024
Russia is a hotbed of cybercriminal activity. Intel 471's Studio 471 podcast spoke with Alec Jackson, an analyst for the U.S. Department of Defense, about why and what the West could do to try to deter it. His answers may surprise. intel471.com/blog/why-rus...
010
Intel 471 @intel471.bsky.social · 29/08/2024
Here is Intel 471's analysis of what effect France's action against Telegram will have on cybercriminal use of the platform, which has been rising for a number of years for a number of reasons. #infosec intel471.com/blog/france-...
intel471.com
France vs. Telegram: What Does it Mean for Cybercrime?
France indicted Telegram CEO Pavel Durov for an alleged failure to cooperate to stop criminal activity on the platform. Intel 471 analyzes how this may…
000
Intel 471 @intel471.bsky.social · 20/08/2024
@intel471.bsky.social's Cybercrime Exposed podcast is back! It's a wild episode about Vyacheslav Penchukov aka "Tank," a Ukrainian threat actor who ran a gang that made at least $70 million through truly organized cybercrime. intel471.com/blog/cybercr...
intel471.com
Cybercrime Exposed Podcast: Tank
In 2006, a new type of malware appeared on the scene. Its name was Zeus. It was enormously profitable for its cybercriminal developers, who used it to…
000
Intel 471 @intel471.bsky.social · 08/08/2024
Intel 471 collaborated with great minds in the CTI industry to develop the Cyber Threat Intelligence Capability Maturity Model. It's a methodical way to build a CTI program that establishes focus, satisfies stakeholders and improves security outcomes. intel471.com/blog/introdu...
intel471.com
Introducing the CTI Capability Maturity Model, a resource for…
The CTI Capability Maturity Model (CTI-CMM) is an easy to use, vendor-neutral model that promotes a “stakeholder-first” approach to building a mature CTI…
010
Intel 471 @intel471.bsky.social · 08/08/2024
Intel 471 analyzed recent phishing campaigns by ATLAS LION, a group that specializes in compromising companies gift-card issuing systems. This group is skilled at attacker-in-the-middle phishing, spoofing IDPs and navigating cloud infrastructure. intel471.com/blog/threat-...
intel471.com
Threat Actors Target Gift Card Issuing Systems
ATLAS LION is a threat actor group that uses phishing to gain access to gift-card issuing systems and then generates fraudulent cards.
000
Intel 471 @intel471.bsky.social · 18/07/2024
Our intelligence analysis team has written a cyber threat assessment of the Paris Olympic Games, covering how the Games could be impacted hacktivism, nation-state actors, ongoing geopolitical turmoil and financially motivated threat actors. intel471.com/blog/cyber-t...
intel471.com
Cyber Threat Landscape: 2024 Paris Olympic Games
The infrastructure behind the 2024 Summer Olympics is vast, providing a large potential attack surface. Here's an overview of the threat landscape.
010
Intel 471 @intel471.bsky.social · 20/02/2024
What lies ahead now after law enforcement's epic p0wning of LockBit, the No. 1 ransomware gang? Here's an analysis from Intel 471's great intelligence team. #infosec intel471.com/blog/what-li...
010
Intel 471 @intel471.bsky.social · 25/01/2024
Australia accused 33-year-old Russian Aleksandr Ermakov of the Medibank data breach and extortion attempt. Intel 471 has compiled a profile of Ermakov and his long-known links to cybercrime and ransomware. It's a good read. #infosec intel471.com/blog/mediban...
intel471.com
Medibank’s Attacker: IT Businessman, Claimed Psychologist and Alleged…
Australia has accused Aleksander Ermakov of one of the country's largest data beach and extortion attacks. Intel 471 has compiled a deep profile Ermakov…
000
Intel 471 @intel471.bsky.social · 06/12/2023
@x25princess.bsky.social is a social engineer and red teamer. She does discreet Wi-Fi scans, tries to get into buildings and does USB drops. Would you fall for the tricks? Listen to Ep. 3 of @intel471.bsky.social's Cybercrime Exposed podcast. #infosec intel471.com/blog/cybercr...
intel471.com
Cybercrime Exposed Podcast: Social Engineering
In this episode of Cybercrime Exposed, Bluma Janowitz, a social engineer and red team agent, describes two of her engagements to test an organization’s…
021
Intel 471 @intel471.bsky.social · 09/11/2023
Malaysian police have disrupted a massive phishing-as-a-service operation that was the focus of Ep. 1 of our Cybercrime Exposed podcast. Here's the low-down on the threat it posed for enterprise security. #infosec intel471.com/blog/malaysi...
intel471.com
Malaysian Police Disrupt ‘The Phisherman’
Malaysian police disrupted a massive phishing-as-a-service operation called BulletProftLink that Intel 471 has been tracking. Here’s why that’s important for enterprise security.
011
Intel 471 @intel471.bsky.social · 08/11/2023
Our Cybercrime Exposed podcast is out today and covers Clop, a cybercrime group that in May executed a shocking mass data theft. Equinix's Will Thomas tells the story about this extraordinarily damaging attack and what lies ahead. #infosec intel471.com/blog/cybercr...
intel471.com
Cybercrime Exposed Podcast: The Extortionists
In one long weekend in May 2023, a cybercriminal gang called Clop conducted one of the largest data breaches on record.
011
Intel 471 @intel471.bsky.social · 02/11/2023
QR code phishing surged as threat actors suddenly revisited this old technique. Some security software may not extract the links from a QR code because OCRing codes takes a lot of overhead. Here's what we've seen and some defensive tips to keep in mind. #infosec intel471.com/blog/phishin...
intel471.com
Phishing Emails Abusing QR Codes Surge
QR code phishing has surged as cybercriminals revisit this old technique. Here are the trends and how to guard against these kinds of attacks.
012
Intel 471 @intel471.bsky.social · 20/10/2023
The Ragnar Locker ransomware group’s Tor sites have been taken offline by law enforcement. It appears there will be an announcement later on Friday. We @intel471.bsky.social have been tracking this group. Story by @ajvicens.bsky.social #infosec cyberscoop.com/police-seize...
cyberscoop.com
Police seize Ragnar Locker leak site
A coalition of 16 law enforcement agencies collaborated to seize a site used by the criminal hacking group to extort its victims.
101
Intel 471 @intel471.bsky.social · 04/10/2023
We're launching a new monthly podcast called Cybercrime Exposed, which explores how malicious hackers undermine the computer systems we trust and what we can do to stop them. First episode is out Oct. 11. Subscribe on Spotify, Apple or your favorite pod app: open.spotify.com/show/5UZq5FD... #infosec
open.spotify.com
Cybercrime Exposed
Listen to Cybercrime Exposed on Spotify. The internet is the new frontier of crime. The systems we depend on for our daily lives, business and national security are under assault. Cybercriminals break...
041
Intel 471 @intel471.bsky.social · 04/10/2023
In May, CLOP cybercrime group carried out one of the largest mass attacks against managed file transfer software. Our analysts at Intel 471 looked at vulnerability trends in MFT software to help organizations assess future risk. Here are the results. #infosec intel471.com/blog/managed...
intel471.com
Managed File Transfer Software: Assessing the Risks
Managed File Transfer (MFT) software is a target for cybercriminals looking to steal data. We analyzed vulnerability and threat actor trends from the past five years to illuminate the supply-chain ris...
021
Intel 471 @intel471.bsky.social · 27/09/2023
Ransomware attacks have sharply increased in 2023, and payments to gangs are close to all-time highs. With efforts focused on disruption, why is ransomware stubbornly sticking around? A discussion with Chainalysis CTI Head Jacqueline Burns Koven #infosec intel471.com/blog/why-ran...
intel471.com
Why Ransomware is Stubbornly Sticking Around
In this edition of Studio 471, Jacqueline Burns Koven of Chainalysis discusses how ransomware is evolving and what challenges it poses for defenders.
040
Intel 471 @intel471.bsky.social · 16/09/2023
The Bumblebee malware loader is used as a gateway to eventually launch ransomware attacks. Intel 471's Malware Intelligence systems and team have uncovered new techniques used to distribute it. Here's how to defend against it. #infosec intel471.com/blog/bumbleb...
intel471.com
Bumblebee Loader Resurfaces in New Campaign
The Bumblebee malware loader is used as a gateway to launch ransomware attacks. Intel 471's Malware Intelligence systems have uncovered new techniques being used to distribute it. Here's how to defend...
012
Intel 471 @intel471.bsky.social · 14/09/2023
Third-party vendors and suppliers are sources of cybersecurity risk. Intel 471 collects from data sources that can help mitigate those risks. This post gives several use cases for how to use our data and cyber threat intelligence to prevent ransomware and breaches: intel471.com/blog/reducin...
intel471.com
Reducing Risk with Third-Party Attack Surface Monitoring
How can organizations monitor the cybersecurity risks that come from third parties and their suppliers? Monitoring the attack surface of partners can illuminate risks. Here's how to do it.
120
Intel 471 @intel471.bsky.social · 08/09/2023
The US and UK have sanctioned more individuals and indicted some related to Trickbot and Conti. This a blow against a flagrant and mostly Russian cybercriminal ecosystem, which Intel 471 follows closely. More on our blog: intel471.com/blog/more-tr...
intel471.com
More Alleged TrickBot and Conti Gang Members Sanctioned, Charged
The U.S. and U.K. sanctioned 11 individuals related to the TrickBot botnet and Conti ransomware groups, while the U.S. unsealed criminal charges against nine people. The actions are part of multinatio...
000
Intel 471 @intel471.bsky.social · 08/08/2023
Our annual Cyber Threat Report has been released, and it gives great detail about trends in malware, ransomware, hacktivism, threat actors TTPs, underground markets and much more. #infosec intel471.com/resources/whitepapers/…
020
Intel 471 @intel471.bsky.social · 28/07/2023
We have an exciting announcement in time for Black Hat in about two weeks for cyber threat intelligence professionals and other #infosec practitioners interested in using CTI. Stay alert for a forthcoming blog post soon.
010
Intel 471 @intel471.bsky.social · 27/07/2023
Vulnerability monitoring helps organizations reduce their own risks and supplier risks. We monitor how threat actors in the underground are discussing, productizing and selling vulnerabilities and exploits: intel471.com/blog/vulnerability-mon… #infosec
010
Intel 471 @intel471.bsky.social · 13/07/2023
Stolen credentials lead to ransomware and breaches. Strong authentication is the best defense. Here's a discussion with Intel 471 and Okta on the state of strong authentication and initial access brokering. #infosec intel471.com/blog/stopping-the-reus…
intel471.com
Stopping the Reuse of Credentials and Session Tokens
Join us into the world of cybercrime. In this episode of Studio 471, Brett Winterford of Okta and Intel 471’s Jeremy Kirk discuss strong authentication, paths to strengthening authentication and wha...
110
Intel 471 @intel471.bsky.social · 23/06/2023
The CLOP ransomware/extortion group is a persistent and damaging threat actor. Here are some key observations from Intel 471 about its latest mass attack exploiting the MOVEit file transfer software. #infosec intel471.com/blog/insights-from-clo…
022
Intel 471 @intel471.bsky.social · 08/06/2023
Gray market cryptocurrency exchanges that serve cybercriminals are innovating as law enforcement pressure increases. Here's an excerpt from a new report on how these services are evolving: intel471.com/blog/how-gray-market-c… #infosec
000
Intel 471 @intel471.bsky.social · 05/06/2023
Cyber HUMINT (human intelligence) requires patience and experience to collect but results in quality threat intel. Here's a three-part series on cyber HUMINT by Chief Intelligence Officer Michael DeBolt: intel471.com/blog/gaining-the-intel… #infosec
030