Sign in

Lawrence S.

@lawrencesec.bsky.social
116 followers 198 following 63 posts

🇬🇧 Threat Research @ Recorded Future. I Like Tracking ASNs and ISPs for some reason...

PostsRepliesMedia
Lawrence S. @lawrencesec.bsky.social · 28/08/2026
Fantastic work from BIRN, with new findings on Aeza, including a German AfD figure behind the registration of the sanctioned shell company Smart Digital Ideas. Great to see earlier RecordedFuture research by @whoisnt.bsky.social and me inform the investigation. balkaninsight.com/2026/08/28/g...
balkaninsight.com
German AfD Figure Behind Alleged Serbian Node in Russian Cyber Meddling
BIRN has identified Andreas Maul, a town councillor for Germany’s far-right AfD party, as the man behind a Serbian company sanctioned by the US for aiding a Russian alleged cybercrime service provider...
012
Reposted by Lawrence S.
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 09/07/2026
1/ Today @milenkowski.bsky.social from @sentinellabs.bsky.social and I are publishing a project we've been working on over the past few months. We found suspected China- and India-linked espionage actors independently targeting the same victim: #Balochistan Police in #Pakistan. s1.ai/spy2flags
s1.ai
One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement
China and India ran separate espionage operations against the same Pakistani police force, each drawn by different stakes in Pakistan's internal security.
1910
Reposted by Lawrence S.
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 01/07/2026
Colleagues of mine at Insikt Group just released new research on the Iran-nexus cluster #TAG-182, deploying #MarkiRAT, a malware family previously observed in use by #FerociousKitten, for internal and external surveillance: www.recordedfuture.com/research/nex...
recordedfuture.com
Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool
Discover how Iranian-nexus threat cluster TAG-182 uses MarkiRAT malware and fake VPN/media apps to conduct cyber surveillance operations against domestic targets.
099
Lawrence S. @lawrencesec.bsky.social · 22/05/2026
In August 2025, @whoisnt.bsky.social and I documented how Stark Industries evaded EU sanctions. This week, Dutch authorities arrested two individuals and seized hundreds of servers linked to WorkTitans BV in an investigation into sanctions evasion. www.volkskrant.nl/binnenland/h...
volkskrant.nl
000
Lawrence S. @lawrencesec.bsky.social · 06/05/2026
New from Recorded Future! @whoisnt.bsky.social and I break down Threat Activity Enablers (TAEs), the often overlooked backbone of modern cyber operations. 🔗 www.recordedfuture.com/blog/threat-...
011
Lawrence S. @lawrencesec.bsky.social · 05/05/2026
Great analysis on administrative activity in the leaked Media Land dataset disclosing.observer/2026/04/29/h...
000
Reposted by Lawrence S.
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 04/05/2026
Looking forward to presenting at @pivotcon.bsky.social in Malaga later on this week. So excited to see everyone and dive into the exceptional agenda!
041
Reposted by Lawrence S.
Calwarez @calwarez.bsky.social · 24/03/2026
🧵 ICYMI: We just dropped our 2025 Malicious Infrastructure Review! Some of the highlights below👇 #Infosec #CyberThreats 1/6 www.recordedfuture.com/research/202...
132
Reposted by Lawrence S.
Catalin Cimpanu @campuscodi.risky.biz · 23/03/2026
-Iran internet outage not caused by strikes -Russia expands internet blackout to Sankt Petersburg -Oracle out-of-band security update -Himmelblau vulnerability gives root -Claudy Day vulnerabilities -Leak in German uni campuses platform -Langflow attacks started within a day
1117
Lawrence S. @lawrencesec.bsky.social · 20/03/2026
Microsoft defender is also flagging #TheVoidStealer as #WallStealer. Here’s the threat actor nikoniko (aka “TheVoidStl”) discussing the removal of multiple detections, including WallStealer.
000
Lawrence S. @lawrencesec.bsky.social · 19/03/2026
Recorded Future's annual malicious infrastructure report has finally dropped, and this year, we took a different approach to how we analyze malicious infrastructure👇
063
Reposted by Lawrence S.
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 19/03/2026
1/ Today we’re publishing our annual malicious infrastructure report, providing a broad view of global threat infrastructure. This year, we significantly expanded coverage across malware families, threat categories, and deeper infrastructure insights: www.recordedfuture.com/research/202...
recordedfuture.com
2025 Year in Review: Malicious, Infrastructure
Explore Insikt Group’s 2025 Malicious Infrastructure Report. Gain insights into Cobalt Strike, Vidar infostealers, and AI-driven threats to secure your 2026 strategy.
1910
Lawrence S. @lawrencesec.bsky.social · 18/03/2026
Noticed Microsoft Defender tagging #TheVoidStealer as #WallStealer thanks to some recent abuse_ch uploads. Here’s the threat actor nikoniko (aka “TheVoidStl”) discussing the removal of multiple detections, including WallStealer.
022
Reposted by Lawrence S.
Catalin Cimpanu @campuscodi.risky.biz · 20/02/2026
-Even more research on Twitter/X algorithm manipulation -Russia turns on Telegram -Texas sues TP-Link -West Virginia sues Apple -US does dumb things, part 332737232 -Spain arrests hotel hacker -Nigerian hacker sentenced to 8 years -651 cybercrime arrests in Africa -GrayCharlie profile
253
Reposted by Lawrence S.
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 18/02/2026
1/ Today, Insikt Group is publishing on GrayCharlie, a threat actor active since mid-2023 that overlaps with SmartApeSG. GrayCharlie compromises WordPress sites and turns them into malware delivery hubs: www.recordedfuture.com/research/gra...
recordedfuture.com
GrayCharlie Hijacks Law Firm Sites in Suspected Supply-Chain Attack
GrayCharlie turns compromised WordPress sites into malware delivery machines. Discover how this threat actor chains fake browser updates and ClickFix lures to deploy NetSupport RAT, Stealc, and Sectop...
158
Reposted by Lawrence S.
Jerri P @whoisnt.bsky.social · 09/12/2025
CastleLoader in the wild! Four distinct activity clusters, sector-specific targeting of logistics, and high-end tooling like Matanbuchus and CastleRAT.
032
Reposted by Lawrence S.
Virus Bulletin @virusbtn.bsky.social · 09/12/2025
Recorded Future’s Insikt Group uncovered four GrayBravo activity clusters. TAG-160 impersonates logistics firms, while TAG-161 impersonates Booking.com, employing ClickFix to deliver CastleLoader and Matanbuchus. www.recordedfuture.com/research/gra...
065
Reposted by Lawrence S.
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 09/12/2025
2/ Our latest analysis uncovered four distinct activity clusters within GrayBravo’s ecosystem, all leveraging the group’s #CastleLoader malware. Each cluster uses different tactics, techniques, and targets, reinforcing the assessment that GrayBravo runs a #MaaS model.
131
Reposted by Lawrence S.
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 09/12/2025
1/ @whoisnt.bsky.social, Marius, and I just published a report on #GrayBravo (formerly TAG-150), a highly adaptive, sophisticated threat actor that we first identified in Sept 2025. It uses a multi-layered infrastructure and responds quickly to exposure: www.recordedfuture.com/research/gra...
recordedfuture.com
GrayBravo’s CastleLoader Activity Clusters Target Multiple Industries
1106
Lawrence S. @lawrencesec.bsky.social · 05/12/2025
A good piece highlighting the EU's continued inaction following recent sanctions, essentially allowing these enablers to continue their operations.
010
Reposted by Lawrence S.
BleepingComputer @bleepingcomputer.com · 04/12/2025
The Predator spyware from surveillance company Intellexa has been using a zero-click infection mechanism dubbed "Aladdin" that compromised specific targets when simply viewing a malicious advertisement.
bleepingcomputer.com
Predator spyware uses new infection vector for zero-click attacks
The Predator spyware from surveillance company Intellexa has been using a zero-click infection mechanism dubbed "Aladdin" that compromised specific targets when simply viewing a malicious advertisement.
074
Reposted by Lawrence S.
Jurre van Bergen @jurrevanbergen.nl · 04/12/2025
🚨 - New report by Haaretz, Inside Story, Inside-IT and Amnesty International release the Intellexa Leaks. Which exposes Intellexa support staff had access through Teamviewer to customer deployments and confirms found IOC's in the past by civil society. 🧵👇
11117
Reposted by Lawrence S.
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 04/12/2025
1/ Today we release a new report exposing previously undisclosed entities connected to the wider #Intellexa ecosystem as well as newly identified activity clusters in Iraq and indications of activity in Pakistan: www.recordedfuture.com/research/int...
recordedfuture.com
Intellexa’s Global Corporate Web
22618
Lawrence S. @lawrencesec.bsky.social · 26/11/2025
3/ As long as the same LIRs and the same bad actors are able to maintain control of their RIPE resources, the problem will never stop.
000
Lawrence S. @lawrencesec.bsky.social · 26/11/2025
2/ The case of fraud relating to metaspinner GmbH really does spell out the severity of the problem...
100
Lawrence S. @lawrencesec.bsky.social · 26/11/2025
1/ It's nice to see the topic of bulletproof hosters and Threat Activity Enablers gaining more mainstream attention; however, a bigger problem than endless shell companies exists, and that is RIPE RIR policy. bindinghook.com/neutral-inte...
bindinghook.com
‘Neutral’ internet governance enables sanctions evasion
Internet service providers and hosting companies enable cybercrime and cyber operations. Why don’t sanctions stop them?
121
Reposted by Lawrence S.
CyberScoop @cyberscoop.bsky.social · 19/11/2025
The national cyber director and a top FBI official shared more details about the forthcoming Trump administration document Tuesday. via @timstarks.bsky.social cyberscoop.com/trump-cyber-...
cyberscoop.com
Completed draft of cyber strategy emphasizes imposing costs, industry partnership
The forthcoming Trump administration cyber strategy will introduce six key pillars, emphasizing deterrence of cyber threats and enhanced industry partnerships, with action items and deliverables for U...
022
Lawrence S. @lawrencesec.bsky.social · 19/11/2025
3/
020
Lawrence S. @lawrencesec.bsky.social · 19/11/2025
2/ Sanctions include Aeza's entities used to evade recent OFAC and UK sanctions, including Hypercore LTD and SMART DIGITAL IDEAS DOO. Myself and @whoisnt.bsky.social break down these entities in our recent report: www.recordedfuture.com/research/mal...
recordedfuture.com
Malicious Infrastructure Finds Stability with aurologic GmbH
This investigative report reveals how German hosting provider aurologic GmbH has become a central enabler of malicious internet infrastructure, linking numerous threat activity networks while operatin...
120
Lawrence S. @lawrencesec.bsky.social · 19/11/2025
1/ United States, Australia, and United Kingdom sanction Russian threat activity enabler Media Land (Yalishanda) and follow up on recent designations targeting Aeza. ofac.treasury.gov/recent-actio...
ofac.treasury.gov
133
Lawrence S. @lawrencesec.bsky.social · 16/11/2025
This is highly likely CrazyRDP :)
020
Lawrence S. @lawrencesec.bsky.social · 15/11/2025
www.politie.nl/nieuws/2025/...
politie.nl
Duizenden servers in beslaggenomen in omvangrijk cybercrime onderzoek
In een onderzoek naar een malafide hostingbedrijf zijn door het team cybercrime Oost-Nederland duizenden servers in beslaggenomen. Het hostingbedrijf wordt volgens de politie enkel en alleen gebruikt ...
010
Lawrence S. @lawrencesec.bsky.social · 15/11/2025
2/ ASNs believed to be utilised by CrazyRDP were reportedly downstream of aurologic….. lowendspirit.com/discussion/c...
lowendspirit.com
Operation Endgame 3.0 took down 1025 servers including CrazyRDP
Europol and Shadowserver have announced today they have completed "third phase" of Endgame operation targeting infostealer Rhadamanthys, Remote Access Trojan VenomRAT, and the botnet Elysium...
000
Lawrence S. @lawrencesec.bsky.social · 15/11/2025
1/ Reports indicating that CrazyRDP is the bulletproof hoster behind this seizure in the Netherlands. nltimes.nl/2025/11/14/d...
nltimes.nl
Dutch police seize thousands of servers used for ransomware, child sex abuse footage
The Dutch police seized thousands of servers in The Hague and Zoetermeer, used solely for hosting criminal activities. According to the police, the hosting company rented space to criminals to carry o...
131
Lawrence S. @lawrencesec.bsky.social · 12/11/2025
3/ metaspinner net GmbH (Hamburg, Germany) has no affiliation with #AS209800, Virtualine Technologies, or any related malicious activity associated with that network.
000
Lawrence S. @lawrencesec.bsky.social · 12/11/2025
2/ A falsified RIPE end-user agreement provided to Insikt Group highlights how a basic verification check against publicly accessible company registration documents could have prevented the fraudulent registration.
100
Lawrence S. @lawrencesec.bsky.social · 12/11/2025
1/ [UPDATE] As of November 10, 2025, metaspinner net GmbH has provided substantial evidence confirming Insikt Group’s original assessment that their identity was unlawfully and fraudulently used in the registration of #AS209800.
121
Reposted by Lawrence S.
Philippe Vynckier @pvynckier.bsky.social · 09/11/2025
German ISP aurologic GmbH Identified as Key Hub for Malicious Hosting Infrastructure gbhackers.com/german-isp-a...
gbhackers.com
German ISP aurologic GmbH Identified as Key Hub for Malicious Hosting Infrastructure
German hosting provider aurologic GmbH has emerged as a critical hub within the global malicious infrastructure ecosystem, according to recent intelligence reporting.
011
Reposted by Lawrence S.
r/blueteamsec bot @r-blueteamsec.bsky.social · 07/11/2025
Malicious Infrastructure Finds Stability with aurologic GmbH
assets.recordedfuture.com
Malicious Infrastructure Finds Stability with aurologic GmbH
011
Reposted by Lawrence S.
InfoSec @infosec.skyfleet.blue · 08/11/2025
German ISP Aurologic GmbH has Become a Central Nexus for Hosting Malicious Infrastructure
cybersecuritynews.com
German ISP Aurologic GmbH has Become a Central Nexus for Hosting Malicious Infrastructure
023
Lawrence S. @lawrencesec.bsky.social · 06/11/2025
/10 Dive into the full report “Malicious Infrastructure Finds Stability with Aurologic GmbH” for the data, analysis, and context behind this ecosystem: www.recordedfuture.com/research/mal...
recordedfuture.com
Malicious Infrastructure Finds Stability with aurologic GmbH
This investigative report reveals how German hosting provider aurologic GmbH has become a central enabler of malicious internet infrastructure, linking numerous threat activity networks while operatin...
030
Lawrence S. @lawrencesec.bsky.social · 06/11/2025
9/Aeza Group continues to rely on aurologic for a large share of its connectivity, announcing roughly half of its IP space, despite recent sanctions by the US and the UK.
140
Lawrence S. @lawrencesec.bsky.social · 06/11/2025
8/ Femo IT Solutions was allocated a /24 prefix from a /17 network registered to the Iranian Research Organization for Science and Technology (IROST), the same origin seen in allocations to other TAEs such as Global Connectivity Solutions and Aeza Group.
131
Lawrence S. @lawrencesec.bsky.social · 06/11/2025
7/ Femo IT Solutions Ltd #AS214351 is a UK-registered network with close operational ties to self-proclaimed bulletproof hoster “Defhost”, who offer “Germany-only” abuse-resilient services on underground forums.
120
Lawrence S. @lawrencesec.bsky.social · 06/11/2025
6/ Virtualine Technologies is a Russia-linked TAE with operational ties to multiple organizations used to register and control IP space, masking ownership and maintaining operational control through networks like Railnet.
120
Lawrence S. @lawrencesec.bsky.social · 06/11/2025
5/ Railnet’s elevated abuse levels followed the transfer of Metaspinner Net IP space to Lanedonet, networks assessed with high probability to have impersonated legitimate companies, under the control of actors tied to Virtualine Technologies.
120
Lawrence S. @lawrencesec.bsky.social · 06/11/2025
4/ Railnet LLC #AS214943 is one of the largest sources of malicious infrastructure observed by Insikt Group, with over 80 validated C2 servers currently active on the network.
120