Sign in

Mandiant (part of Google Cloud)

@mandiant.com
218 followers 1 following 9 posts

We’re determined to make organizations secure against cyber threats and confident in their readiness.

PostsRepliesMedia
Mandiant (part of Google Cloud) @mandiant.com · 02/07/2026
🚨 MAJOR DISRUPTION: Google disrupted the NetNut residential proxy network, which enrolled ~2M home devices into its botnet. We observed 316 distinct threat clusters—cybercrime and espionage groups—using the network to mask activity and launch password spray attacks. 📋 goo.gle/44GKDmL
011
Mandiant (part of Google Cloud) @mandiant.com · 05/06/2026
🚨 UNC3753 is targeting US law firms using vishing and RMM tools for data extortion. In instances linked to UNC3753, individuals posing as IT technicians attempted direct data theft using physical, in-person access. Read more & get IOCs ➔ goo.gle/49HfT8g
000
Mandiant (part of Google Cloud) @mandiant.com · 12/11/2025
The Cybersecurity Forecast 2026 report is here! Based on insights from dozens of Google security leaders and experts, the report helps organizations feel prepared for the year ahead. Read some key highlights, and then download the full report for a deeper look: cloud.google.com/security/res...
021
Mandiant (part of Google Cloud) @mandiant.com · 10/10/2025
Our insights on the widespread Oracle E-Business Suite zero-day exploitation: ✔️ Breakdown and analysis of the campaign ✔️ Deep dive into threat actor’s multi-stage, in-memory Java implant framework ✔️ Recommendations, IOCs, and more for defenders Read now: cloud.google.com/blog/topics/...
010
Mandiant (part of Google Cloud) @mandiant.com · 24/09/2025
BRICKSTORM malware is being used by suspected China-nexus actor, UNC5221, in a stealthy espionage campaign. -Avg dwell time: 393 days -Targets: US legal, SaaS, BPOs & tech firms We have released a scanner, IOCs, and guidance to help defenders. Full analysis here: bit.ly/4pT3pku
120
Mandiant (part of Google Cloud) @mandiant.com · 03/06/2025
🚨 APT41 is using malware, TOUGHPROGRESS, that leverages Google Calendar for command and control. Learn more about the campaign and how GTIG helped disrupt it. Additionally, leverage our included YARA rules, hashes and other IOCs to help defend against this threat: cloud.google.com/blog/topics/...
020
Mandiant (part of Google Cloud) @mandiant.com · 07/05/2025
UNC3944 (Scattered Spider) is a financially-motivated threat actor known for persistent and brazen social engineering, including targeting help desks. Our guidance can help organizations defend against the UNC3944 tactics we have observed when responding to this group. Stay ahead ➡️ bit.ly/3EXHvtE
021
Mandiant (part of Google Cloud) @mandiant.com · 30/04/2025
We tracked 75 zero-days exploited in the wild in 2024. Zero-day use is steadily increasing, notably for espionage. We see more focus on enterprise technologies, over 60% of which were security and networking products. Read the report for metrics, trends and more: cloud.google.com/blog/topics/...
171
Mandiant (part of Google Cloud) @mandiant.com · 23/04/2025
M-Trends 2025 is here! Get data from our investigations, including top initial infection vectors and targeted industries, and dive deep into trends such as rising infostealer use and the DPRK insider threat. We also share recommendations to stay ahead. Read now: cloud.google.com/security/res...
040