Sign in

Lawrence S.

@lawrencesec.bsky.social
115 followers 198 following 63 posts

🇬🇧 Threat Research @ Recorded Future. I Like Tracking ASNs and ISPs for some reason...

PostsRepliesMedia
Lawrence S. @lawrencesec.bsky.social · 28/08/2026
Fantastic work from BIRN, with new findings on Aeza, including a German AfD figure behind the registration of the sanctioned shell company Smart Digital Ideas. Great to see earlier RecordedFuture research by @whoisnt.bsky.social and me inform the investigation. balkaninsight.com/2026/08/28/g...
balkaninsight.com
German AfD Figure Behind Alleged Serbian Node in Russian Cyber Meddling
BIRN has identified Andreas Maul, a town councillor for Germany’s far-right AfD party, as the man behind a Serbian company sanctioned by the US for aiding a Russian alleged cybercrime service provider...
012
Reposted by Lawrence S.
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 09/07/2026
1/ Today @milenkowski.bsky.social from @sentinellabs.bsky.social and I are publishing a project we've been working on over the past few months. We found suspected China- and India-linked espionage actors independently targeting the same victim: #Balochistan Police in #Pakistan. s1.ai/spy2flags
s1.ai
One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement
China and India ran separate espionage operations against the same Pakistani police force, each drawn by different stakes in Pakistan's internal security.
1910
Reposted by Lawrence S.
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 01/07/2026
Colleagues of mine at Insikt Group just released new research on the Iran-nexus cluster #TAG-182, deploying #MarkiRAT, a malware family previously observed in use by #FerociousKitten, for internal and external surveillance: www.recordedfuture.com/research/nex...
recordedfuture.com
Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool
Discover how Iranian-nexus threat cluster TAG-182 uses MarkiRAT malware and fake VPN/media apps to conduct cyber surveillance operations against domestic targets.
099
Lawrence S. @lawrencesec.bsky.social · 22/05/2026
In August 2025, @whoisnt.bsky.social and I documented how Stark Industries evaded EU sanctions. This week, Dutch authorities arrested two individuals and seized hundreds of servers linked to WorkTitans BV in an investigation into sanctions evasion. www.volkskrant.nl/binnenland/h...
volkskrant.nl
000
Lawrence S. @lawrencesec.bsky.social · 06/05/2026
New from Recorded Future! @whoisnt.bsky.social and I break down Threat Activity Enablers (TAEs), the often overlooked backbone of modern cyber operations. 🔗 www.recordedfuture.com/blog/threat-...
011
Lawrence S. @lawrencesec.bsky.social · 05/05/2026
Great analysis on administrative activity in the leaked Media Land dataset disclosing.observer/2026/04/29/h...
000
Reposted by Lawrence S.
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 04/05/2026
Looking forward to presenting at @pivotcon.bsky.social in Malaga later on this week. So excited to see everyone and dive into the exceptional agenda!
041
Reposted by Lawrence S.
Calwarez @calwarez.bsky.social · 24/03/2026
🧵 ICYMI: We just dropped our 2025 Malicious Infrastructure Review! Some of the highlights below👇 #Infosec #CyberThreats 1/6 www.recordedfuture.com/research/202...
132
Reposted by Lawrence S.
Catalin Cimpanu @campuscodi.risky.biz · 23/03/2026
-Iran internet outage not caused by strikes -Russia expands internet blackout to Sankt Petersburg -Oracle out-of-band security update -Himmelblau vulnerability gives root -Claudy Day vulnerabilities -Leak in German uni campuses platform -Langflow attacks started within a day
1117
Lawrence S. @lawrencesec.bsky.social · 20/03/2026
Microsoft defender is also flagging #TheVoidStealer as #WallStealer. Here’s the threat actor nikoniko (aka “TheVoidStl”) discussing the removal of multiple detections, including WallStealer.
000
Lawrence S. @lawrencesec.bsky.social · 19/03/2026
Recorded Future's annual malicious infrastructure report has finally dropped, and this year, we took a different approach to how we analyze malicious infrastructure👇
063
Reposted by Lawrence S.
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 19/03/2026
1/ Today we’re publishing our annual malicious infrastructure report, providing a broad view of global threat infrastructure. This year, we significantly expanded coverage across malware families, threat categories, and deeper infrastructure insights: www.recordedfuture.com/research/202...
recordedfuture.com
2025 Year in Review: Malicious, Infrastructure
Explore Insikt Group’s 2025 Malicious Infrastructure Report. Gain insights into Cobalt Strike, Vidar infostealers, and AI-driven threats to secure your 2026 strategy.
1910
Lawrence S. @lawrencesec.bsky.social · 18/03/2026
Noticed Microsoft Defender tagging #TheVoidStealer as #WallStealer thanks to some recent abuse_ch uploads. Here’s the threat actor nikoniko (aka “TheVoidStl”) discussing the removal of multiple detections, including WallStealer.
022
Reposted by Lawrence S.
Catalin Cimpanu @campuscodi.risky.biz · 20/02/2026
-Even more research on Twitter/X algorithm manipulation -Russia turns on Telegram -Texas sues TP-Link -West Virginia sues Apple -US does dumb things, part 332737232 -Spain arrests hotel hacker -Nigerian hacker sentenced to 8 years -651 cybercrime arrests in Africa -GrayCharlie profile
253
Reposted by Lawrence S.
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 18/02/2026
1/ Today, Insikt Group is publishing on GrayCharlie, a threat actor active since mid-2023 that overlaps with SmartApeSG. GrayCharlie compromises WordPress sites and turns them into malware delivery hubs: www.recordedfuture.com/research/gra...
recordedfuture.com
GrayCharlie Hijacks Law Firm Sites in Suspected Supply-Chain Attack
GrayCharlie turns compromised WordPress sites into malware delivery machines. Discover how this threat actor chains fake browser updates and ClickFix lures to deploy NetSupport RAT, Stealc, and Sectop...
158
Reposted by Lawrence S.
Jerri P @whoisnt.bsky.social · 09/12/2025
CastleLoader in the wild! Four distinct activity clusters, sector-specific targeting of logistics, and high-end tooling like Matanbuchus and CastleRAT.
032
Reposted by Lawrence S.
Virus Bulletin @virusbtn.bsky.social · 09/12/2025
Recorded Future’s Insikt Group uncovered four GrayBravo activity clusters. TAG-160 impersonates logistics firms, while TAG-161 impersonates Booking.com, employing ClickFix to deliver CastleLoader and Matanbuchus. www.recordedfuture.com/research/gra...
065
Reposted by Lawrence S.
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 09/12/2025
2/ Our latest analysis uncovered four distinct activity clusters within GrayBravo’s ecosystem, all leveraging the group’s #CastleLoader malware. Each cluster uses different tactics, techniques, and targets, reinforcing the assessment that GrayBravo runs a #MaaS model.
131
Reposted by Lawrence S.
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 09/12/2025
1/ @whoisnt.bsky.social, Marius, and I just published a report on #GrayBravo (formerly TAG-150), a highly adaptive, sophisticated threat actor that we first identified in Sept 2025. It uses a multi-layered infrastructure and responds quickly to exposure: www.recordedfuture.com/research/gra...
recordedfuture.com
GrayBravo’s CastleLoader Activity Clusters Target Multiple Industries
1106
Lawrence S. @lawrencesec.bsky.social · 05/12/2025
A good piece highlighting the EU's continued inaction following recent sanctions, essentially allowing these enablers to continue their operations.
010
Reposted by Lawrence S.
BleepingComputer @bleepingcomputer.com · 04/12/2025
The Predator spyware from surveillance company Intellexa has been using a zero-click infection mechanism dubbed "Aladdin" that compromised specific targets when simply viewing a malicious advertisement.
bleepingcomputer.com
Predator spyware uses new infection vector for zero-click attacks
The Predator spyware from surveillance company Intellexa has been using a zero-click infection mechanism dubbed "Aladdin" that compromised specific targets when simply viewing a malicious advertisement.
074
Reposted by Lawrence S.
Jurre van Bergen @jurrevanbergen.nl · 04/12/2025
🚨 - New report by Haaretz, Inside Story, Inside-IT and Amnesty International release the Intellexa Leaks. Which exposes Intellexa support staff had access through Teamviewer to customer deployments and confirms found IOC's in the past by civil society. 🧵👇
11117
Reposted by Lawrence S.
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 04/12/2025
1/ Today we release a new report exposing previously undisclosed entities connected to the wider #Intellexa ecosystem as well as newly identified activity clusters in Iraq and indications of activity in Pakistan: www.recordedfuture.com/research/int...
recordedfuture.com
Intellexa’s Global Corporate Web
22618
Lawrence S. @lawrencesec.bsky.social · 26/11/2025
1/ It's nice to see the topic of bulletproof hosters and Threat Activity Enablers gaining more mainstream attention; however, a bigger problem than endless shell companies exists, and that is RIPE RIR policy. bindinghook.com/neutral-inte...
bindinghook.com
‘Neutral’ internet governance enables sanctions evasion
Internet service providers and hosting companies enable cybercrime and cyber operations. Why don’t sanctions stop them?
121
Reposted by Lawrence S.
CyberScoop @cyberscoop.bsky.social · 19/11/2025
The national cyber director and a top FBI official shared more details about the forthcoming Trump administration document Tuesday. via @timstarks.bsky.social cyberscoop.com/trump-cyber-...
cyberscoop.com
Completed draft of cyber strategy emphasizes imposing costs, industry partnership
The forthcoming Trump administration cyber strategy will introduce six key pillars, emphasizing deterrence of cyber threats and enhanced industry partnerships, with action items and deliverables for U...
022
Lawrence S. @lawrencesec.bsky.social · 19/11/2025
1/ United States, Australia, and United Kingdom sanction Russian threat activity enabler Media Land (Yalishanda) and follow up on recent designations targeting Aeza. ofac.treasury.gov/recent-actio...
ofac.treasury.gov
133
Lawrence S. @lawrencesec.bsky.social · 15/11/2025
www.politie.nl/nieuws/2025/...
politie.nl
Duizenden servers in beslaggenomen in omvangrijk cybercrime onderzoek
In een onderzoek naar een malafide hostingbedrijf zijn door het team cybercrime Oost-Nederland duizenden servers in beslaggenomen. Het hostingbedrijf wordt volgens de politie enkel en alleen gebruikt ...
010
Lawrence S. @lawrencesec.bsky.social · 15/11/2025
1/ Reports indicating that CrazyRDP is the bulletproof hoster behind this seizure in the Netherlands. nltimes.nl/2025/11/14/d...
nltimes.nl
Dutch police seize thousands of servers used for ransomware, child sex abuse footage
The Dutch police seized thousands of servers in The Hague and Zoetermeer, used solely for hosting criminal activities. According to the police, the hosting company rented space to criminals to carry o...
131
Lawrence S. @lawrencesec.bsky.social · 12/11/2025
1/ [UPDATE] As of November 10, 2025, metaspinner net GmbH has provided substantial evidence confirming Insikt Group’s original assessment that their identity was unlawfully and fraudulently used in the registration of #AS209800.
121
Reposted by Lawrence S.
Philippe Vynckier @pvynckier.bsky.social · 09/11/2025
German ISP aurologic GmbH Identified as Key Hub for Malicious Hosting Infrastructure gbhackers.com/german-isp-a...
gbhackers.com
German ISP aurologic GmbH Identified as Key Hub for Malicious Hosting Infrastructure
German hosting provider aurologic GmbH has emerged as a critical hub within the global malicious infrastructure ecosystem, according to recent intelligence reporting.
011
Reposted by Lawrence S.
r/blueteamsec bot @r-blueteamsec.bsky.social · 07/11/2025
Malicious Infrastructure Finds Stability with aurologic GmbH
assets.recordedfuture.com
Malicious Infrastructure Finds Stability with aurologic GmbH
011
Reposted by Lawrence S.
InfoSec @infosec.skyfleet.blue · 08/11/2025
German ISP Aurologic GmbH has Become a Central Nexus for Hosting Malicious Infrastructure
cybersecuritynews.com
German ISP Aurologic GmbH has Become a Central Nexus for Hosting Malicious Infrastructure
023
Lawrence S. @lawrencesec.bsky.social · 06/11/2025
1/ New report from myself and @whoisnt.bsky.social: “Malicious Infrastructure Finds Stability with aurologic GmbH.” We uncover how German ISP aurologic GmbH has become a central nexus for high-risk hosting networks, sustaining large concentrations of malicious infrastructure.
162
Reposted by Lawrence S.
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 22/10/2025
Recorded Future just published Dark Covenant 3.0, revealing how global crackdowns and shifting Russian enforcement are reshaping the cybercriminal underground, exposing ties to state actors and turning cybercrime into a geopolitical tool: www.recordedfuture.com/research/dar...
recordedfuture.com
Dark Covenant 3.0: Controlled Impunity and Russia’s Cybercriminals
Explore how Russia’s cybercriminal ecosystem evolved under Operation Endgame—where state control, selective enforcement, and criminal alliances collide.
077
Reposted by Lawrence S.
Calwarez @calwarez.bsky.social · 21/10/2025
Great work by my colleague, @lawrencesec.bsky.social ! He dives deep into the systemic flaw where "neutral" internet governance lets sanctioned ISPs evade restrictions and continue supporting #cyberattacks and #disinformation. A must-read on the infrastructure gap. 👇
051
Reposted by Lawrence S.
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 21/10/2025
Great opinion piece by my colleague @lawrencesec.bsky.social on an extremely timely and important topic!
022
Lawrence S. @lawrencesec.bsky.social · 21/10/2025
🚨 My latest research for @bindinghook is out! I explore how sanctions against #Aeza and #StarkIndustries reveal the limits of current policy, and how #ThreatActivityEnablers exploit RIR policy and company registration frameworks to maintain infrastructure and support ongoing cyber operations.
051
Reposted by Lawrence S.
Binding Hook @bindinghook.bsky.social · 21/10/2025
In his latest for Binding Hook, @lawrencesec.bsky.social looks at how internet service providers work within the system to evade sanctions and enable #cyberattacks and #disinformation campaigns: bindinghook.com/neutral-inte...
bindinghook.com
‘Neutral’ internet governance enables sanctions evasion
Internet service providers and hosting companies enable cybercrime and cyber operations. Why don’t sanctions stop them?
062
Reposted by Lawrence S.
Binding Hook @bindinghook.bsky.social · 16/10/2025
#Surveillance has become central to #counterterrorism in democracies, but its spread into daily life raises a key question: how much monitoring can a free society absorb without losing trust? bindinghook.com/why-democrac...
bindinghook.com
Why democracies need emotional resilience against surveillance
Surveillance technologies have become central to democratic counterterrorism, reshaping how citizens relate to the state. By extending into everyday life, these tools not only promise protection but a...
011
Reposted by Lawrence S.
Virtual Routes @virtualroutes.bsky.social · 01/10/2025
👋 Don't miss the first Colloquium session tomorrow! 📌 Mythical Beasts and Where to Find Them: Diving into the Depths of the Global Spyware Market 💡 Jen Roberts (@cyberstatecraft.bsky.social) & @julianferdinand.bsky.social (Recorded Future) 🗓️ October 2, 2025 🕓 16:00 – 17:00 CET
144
Reposted by Lawrence S.
The Banshee Queen 👑 @cyberoverdrive.bsky.social · 24/09/2025
First public report at Recorded Future by yours truly is out! RedNovember (formerly TAG-100, a.k.a. Storm-2077) is a Chinese state-sponsored threat group focused on intelligence collection, especially on flashpoint issues of strategic interest to China. www.recordedfuture.com/research/red...
recordedfuture.com
RedNovember Targets Government, Defense, and Technology Organizations
RedNovember, a likely Chinese state-sponsored cyber-espionage group, has targeted global government, defense, and tech sectors using advanced tools like Pantegana and Cobalt Strike. Discover the lates...
22414
Reposted by Lawrence S.
TProphet @tprophet.org · 23/09/2025
1/ Hi, I'm TProphet. I write the Telecom Informer for @2600.com. A lot of people have been asking me about www.nbcnews.com/politics/nat... given that I'm somewhat knowledgeable in the area. Here's my take: I'm kind of astonished that this is public, and it isn't normal that it would ever be.
nbcnews.com
Secret Service agents dismantle network that could shut down New York cellphone system
Agents discovered electronic devices in five locations in and around the city that could be used to disable cellphone towers. The system could also be used for criminal activities.
10363178
Reposted by Lawrence S.
Catalin Cimpanu @campuscodi.risky.biz · 24/09/2025
-US raids SIM farm in New York -EU airport disruptions caused by ransomware -Thieves steal gold from French museum after cyberattack -SonicWall firmware update removes rootkit -Jaguar ransomware incident extends to October Podcast: risky.biz/RBNEWS482/ Newsletter: news.risky.biz/risky-bullet...
25518
Lawrence S. @lawrencesec.bsky.social · 22/09/2025
The UK has sanctioned Aeza International, citing its involvement in destabilising Ukraine by providing internet services to Russian disinformation campaigns. This follows OFAC sanctions in July. www.gov.uk/government/n...
gov.uk
UK sanctions Georgia-linked supporters of Putin’s illegal war in Ukraine
The UK has announced new sanctions targeting Georgia-linked supporters of Putin’s illegal war in Ukraine.
021
Reposted by Lawrence S.
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 22/09/2025
I'm excited to speak at #VB2025 later this week! I'll be diving into TAG-124, a group whose services are leveraged by a wide range of actors, from cybercriminals to state-sponsored groups. Hit me up if you are in town! www.virusbulletin.com/conference/v...
0189
Reposted by Lawrence S.
Virus Bulletin @virusbtn.bsky.social · 18/09/2025
Recorded Future's Insikt Group reports CopyCop, also tracked as Storm 1516, expanding in 2025, adding at least 200 new fictional media websites targeting the United States, France and Canada and using self-hosted LLMs. www.recordedfuture.com/research/cop...
022
Reposted by Lawrence S.
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 16/09/2025
Really excited to present at #LABScon25 on ChamelGang‘s most recent campaign targeting the Taliban, a collaborative research project with @milenkowski.bsky.social (SentinelLABS) and @azaka.fun (TeamT5)! www.labscon.io/speakers/jul...
053