Sign in

marktsec

@marktsec.bsky.social
108 followers 15 following 717 posts

💫Threat Intel💫 Automation💫 Threat Analysis 💫OSINT💫 Testing 💫Network Security💫 github.com/marktsec

PostsRepliesMedia
marktsec @marktsec.bsky.social · 15h
AutoLogin - Phishing Automation Framework Update: Google AutoLogin v2 Phishing kits are becoming automation frameworks #ThreatIntel
110
marktsec @marktsec.bsky.social · 02/10/2026
A very interesting Windows persistence technique from Praetorian. The research abuses mandatory user profiles and ntuser.man to achieve registry-based persistence without modifying the live registry through the usual APIs. praetorian.com/blog/corrupt...
110
marktsec @marktsec.bsky.social · 21/09/2026
AI infrastructure is becoming another underground service. A new marketplace advertises one API key for multiple LLMs, plus custom "uncensored coder" models targeting reverse engineering, malware, exploits and automation.
242
marktsec @marktsec.bsky.social · 20/09/2026
ShinyHunters reportedly breached and defaced Cl0p's leak site and is now publicly demanding payment from the operators. A new DLS update gives Cl0p 66 hours and threatens to expose alleged payment information from previous victims.
122
marktsec @marktsec.bsky.social · 19/09/2026
ICMacOS is building a MaaS offering around macOS malware. The stealer claims support for macOS 10.12+ across Intel and Apple Silicon. Its panel adds build/log analytics, custom VPS integration and Telegram alerts for incoming logs.
262
marktsec @marktsec.bsky.social · 12/09/2026
1/ A new Dark Project ransomware affiliate program is advertising a Go-based locker targeting Windows, UNIX, ESXi, NAS and BSD environments. The program also offers a separate "data ransom" model with a 90/10 affiliate split. #ThreatIntel
111
marktsec @marktsec.bsky.social · 11/09/2026
Detecting and countering misuse of AI: September 2026 www.anthropic.com/threat-intel...
anthropic.com
Countering misuse of AI: September 2026 / Anthropic
Case studies from threat actors disrupted between December 2025 and August 2026 across seven areas of harm, from cyber operations to biological misuse.
000
marktsec @marktsec.bsky.social · 04/09/2026
thehackernews.com/2026/09/russ...
thehackernews.com
Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis
Russia-aligned UAC-0099 used GuardBreaker prompt injection in a malicious VBS script to interfere with AI-assisted code analysis.
010
marktsec @marktsec.bsky.social · 04/09/2026
Detection evasion is being sold as a service. A new underground service advertises EXE "crypting" with: - SmartScreen bypass - Defender bypass - EDR bypass - EXE/DLL sideloading - ClickFix support - Custom stubs They claim to process RATs, stealers and other files.
111
marktsec @marktsec.bsky.social · 29/08/2026
AI isn't just finding vulnerabilities anymore. James Kettle from PortSwigger asked a more interesting question: Can an autonomous AI system actually invent new attack techniques? Their answer: apparently, yes. portswigger.net/research/can...
portswigger.net
Can AI do novel security research? Meet the HTTP Terminator
Abstract We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Buildi
021
marktsec @marktsec.bsky.social · 28/08/2026
Hyflock RaaS is building an AI-powered C2 The ransomware group claims its new custom C2 uses an LLM agent to operate the platform and interact with custom modules.
123
marktsec @marktsec.bsky.social · 22/08/2026
1/ 🚨 A new Trezor-focused phishing tool is being advertised on underground forums. Unlike typical fake-wallet phishing, the seller claims it can inject the phishing flow directly into Trezor Suite without modifying the legitimate application files. #ThreatIntel
120
marktsec @marktsec.bsky.social · 21/08/2026
A new research from SpecterOps shows how Chromium extensions can be abused as a persistence mechanism effectively turning the browser itself into a C2 channel. specterops.io/blog/2026/08...
specterops.io
Attack of The Extensions
Learn how Chromium browser extensions can be silently sideloaded to establish persistent C2 access and how to detect it with Sysmon.
010
marktsec @marktsec.bsky.social · 21/08/2026
🧵 1/ A newly advertised Windows remote administration tool, Hydra Remote, combines HVNC with browser-session cloning and credential recovery. The most interesting capability: cloning existing browser profiles into a hidden session. #ThreatIntel
141
marktsec @marktsec.bsky.social · 15/08/2026
🧵1/ Volta Stealer v2.0 released, and the update is focused heavily on scaling operations. The new release adds major changes to its delivery infrastructure, data collection, filtering and operator workflow. Here are some of the more interesting changes: #ThreatIntel
120
marktsec @marktsec.bsky.social · 15/08/2026
🧵 1/ A relatively new MaaS stealer called Remus is positioning itself as more than another credential stealer. Its standout feature isn't just what it collects, but how it measures whether the collection actually succeeded. #ThreatIntel
120
marktsec @marktsec.bsky.social · 14/08/2026
🧵 1/ A new wave of ransomware brands is emerging, but the interesting part isn't the encryption. Across recent RaaS programs, operators are competing on operational capabilities and victim pressure, not just lockers. #ThreatIntel #Ransomware
164
marktsec @marktsec.bsky.social · 08/08/2026
1/ 🧵 A new Bee Stealer v2.1 update introduces an interesting feature: an AI-generated profile of the victim. Instead of simply collecting credentials, the stealer reportedly feeds parts of the stolen log to an AI model to generate a summary of the victim. #ThreatIntel
122
marktsec @marktsec.bsky.social · 08/08/2026
1/ 🧵 A relatively new infostealer called WARDEN is being advertised with an interesting architecture. Rather than focusing only on collecting credentials, the project appears designed as a large-scale data collection and processing platform. #ThreatIntel
121
marktsec @marktsec.bsky.social · 31/07/2026
🧵1/5 The developers behind Stealc have released Stealc v3, a major redesign that shifts the project beyond a traditional stealer. The most notable changes aren't new collection capabilities, they're improvements to deployment, scalability and operator experience. #ThreatIntel
111
marktsec @marktsec.bsky.social · 25/07/2026
🧵1/ The Gentlemen RaaS operators have announced several updates for affiliates, but two additions stand out: Active Directory credential harvesting and an AI-assisted data analysis service designed to support ransom negotiations.#ThreatIntel #Ransomware #RaaS
121
marktsec @marktsec.bsky.social · 25/07/2026
🧵1/ A recently advertised phishing framework "AutoLogin Phishing kit" suggests phishing tooling is evolving beyond static login pages. The project is marketed as a browser automation platform using real Chrome instances to interact with legitimate login flows. #ThreatIntel
121
marktsec @marktsec.bsky.social · 17/07/2026
🧵1/ A custom ransomware project was recently advertised on cybercrime forum, and its feature list provides an interesting snapshot of what operators now market as a "premium" ransomware offering. #ThreatIntel #Ransomware
142
marktsec @marktsec.bsky.social · 02/07/2026
🧵1/ An underground vendor selling code-signing certificates has revised its offering following Microsoft's recent reputation changes. The update suggests certificate possession alone is no longer sufficient to reliably bypass SmartScreen. #ThreatIntel #infosec
110
marktsec @marktsec.bsky.social · 01/07/2026
🧵 1/ A newly advertised ransomware operation, SevyWare RaaS, is promoting an unusual addition to its affiliate offering: "Violence as a Service." #ThreatIntel #Ransomware
111
marktsec @marktsec.bsky.social · 30/06/2026
🧵1/ Since its public debut in early June, the emerging VOLTA MaaS stealer has maintained a rapid development cadence, with 6 public updates released in less than a month. Below is a timeline of its development 👇 #ThreatIntel #infosec
121
marktsec @marktsec.bsky.social · 29/06/2026
🧵1/ The developers behind the Stealc malware have announced the sale of the complete Stealc v2 source code ahead of the planned v3 release. According to the advertisement, only two copies of the source code will be sold for $60,000 each. #ThreatIntel #Malware #secops
145
marktsec @marktsec.bsky.social · 28/06/2026
🧵1/ A new update to the ErrTraffic ClickFix framework was recently advertised on a Russian-language cybercrime forum. The release focuses less on new delivery techniques and more on scaling affiliate operations. #ThreatIntel #ClickFix #infosec
154
marktsec @marktsec.bsky.social · 28/06/2026
When Three Threats Meet One Inbox Against Japan ransom-isac.com/blog/three-t...
ransom-isac.com
When Three Threats Meet One Inbox Against Japan
Three unrelated Chinese-nexus operators — CoGUI email phishing, the Smishing Triad SMS/iMessage ecosystem, and MirrorFace espionage — converge on Japanese inboxes simultaneously, producing a single-ca...
000
marktsec @marktsec.bsky.social · 18/06/2026
Someone's Hands Are on Your Keyboard Then Your Whole Network. Courtesy of ClickFix, Potemkin, RMMProject and EtherRAT www.huntress.com/blog/potemki...
huntress.com
Potemkin Loader & RMMProject The Anatomy of a ClickFix Attack | Huntress
A ClickFix infection drops Potemkin loader and RMMProject RAT, leading to browser theft, hidden remote desktop, and lateral movement across over 11 hosts.
010
marktsec @marktsec.bsky.social · 18/06/2026
FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.
A newly discovered data leak dubbed "FortiBleed" has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide.
000
marktsec @marktsec.bsky.social · 15/06/2026
APT28, an evolution of tradecraft blog.sekoia.io/apt28-an-evo...
blog.sekoia.io
APT28, an evolution of tradecraft
Context Sekoia’s Threat Detection & Research (TDR) team has been tracking APT28 for several years. The intrusion set, also known as Fancy Bear, Forest Blizzard, Sofacy, Pawn Storm or Sednit and public...
000
marktsec @marktsec.bsky.social · 14/06/2026
My Agentic Trust Issues: From Prompt Injection to Supply-Chain Compromise on gemini-cli www.pillar.security/blog/my-agen...
pillar.security
My Agentic Trust Issues: From Prompt Injection to Supply-Chain Compromise on gemini-cli
010
marktsec @marktsec.bsky.social · 10/06/2026
Nightmare-Eclipse is back. RoguePlanet Windows Defender Vulnerability github.com/MSNightmare/...
github.com
GitHub - MSNightmare/RoguePlanet: RoguePlanet Windows Defender Vulnerability
RoguePlanet Windows Defender Vulnerability. Contribute to MSNightmare/RoguePlanet development by creating an account on GitHub.
011
marktsec @marktsec.bsky.social · 09/06/2026
Enter the WasmForge: Compiling Sliver into WebAssembly www.praetorian.com/blog/wasmfor...
praetorian.com
Enter the WasmForge: Compiling Sliver into WebAssembly
Expose how compiling Sliver into WebAssembly beats EDR: WasmForge produces opsec-safe binaries with zero changes to the tool source.
000
marktsec @marktsec.bsky.social · 03/06/2026
TierOne forum has moved to a new onion domain. The old site now points users to the replacement address, but the new service is currently throwing an Internal Server Error. #OSINT #ThreatIntel #DarkWeb
100
marktsec @marktsec.bsky.social · 28/05/2026
The Gentlemen Leak Analysis (Part 2) — JA456 Follow-on ransom-isac.org/blog/the-gen...
ransom-isac.org
The Gentlemen Leak Analysis (Part 2) — JA456 Follow-on
Analysis of JA456, a follow-on package to the original Gentlemen Leaks that exposes operator-side artifacts — MEGA session history, a Synology NAS shadow dump, and wipe-in-progress screenshots — yield...
000
marktsec @marktsec.bsky.social · 20/05/2026
Weaponizing a signed lenovo kernel driver to terminate any process — including EDR/AV protected processes. github.com/redteamfortr...
github.com
GitHub - redteamfortress/PhantomKiller: Another BYOVD process killer. works on all EDR's. fully signed.
Another BYOVD process killer. works on all EDR's. fully signed. - redteamfortress/PhantomKiller
100
marktsec @marktsec.bsky.social · 16/05/2026
Gamaredon’s infection chain: Spoofed emails, GammaDrop and GammaLoad harfanglab.io/insidethelab...
harfanglab.io
Gamaredon's infection chain: Spoofed emails, GammaDrop and GammaLoad
Identifier: TRR260501. Summary Investigating Gamaredon’s abuse of CVE-2025-8088, we identified a dozen waves of spearphishing emails against Ukrainian state institutions in a campaign that is still ac...
000
marktsec @marktsec.bsky.social · 15/05/2026
The Gentlemen Ransomware Group — Leak Analysis ransom-isac.org/blog/the-gen...
ransom-isac.org
The Gentlemen Ransomware Group — Leak Analysis
A 120-minute technical intelligence whitepaper analysing the leaked Rocket.Chat corpus of The Gentlemen RaaS — 3,366 messages, 66 confirmed victims, custom G-BOT C2, Fortinet exploitation, AI-assisted...
010
marktsec @marktsec.bsky.social · 12/05/2026
🚨 Storm Stealer operators announced a major feature update focused on Google’s DBSC protections. The group claims to have developed a “DBSC cookie bypass” module targeting Chrome 147 on Windows. #ThreatIntel #Infostealer #CyberSecurity
100
marktsec @marktsec.bsky.social · 04/05/2026
This article walks through three authentication paths that impacket-net supports NTLM hash (Pass-the-Hash), Kerberos ticket, and AES key. www.hackingarticles.in/impacket-for...
hackingarticles.in
Impacket for Pentester: Net
Master impacket-net to enumerate & manage Active Directory using NTLM hash, Kerberos ticket, or AES key auth.
000
marktsec @marktsec.bsky.social · 04/05/2026
Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks
A new disclosed cPanel flaw tracked as CVE-2026-41940 is being mass-exploited to breach websites and encrypt data in "Sorry" ransomware attacks.
010
marktsec @marktsec.bsky.social · 30/04/2026
EasterBunny, APT29's sophisticated malware github.com/blackorbird/...
github.com
000
marktsec @marktsec.bsky.social · 26/04/2026
The first publicly available decryption method for The Gentlemen ransomware. github.com/Bedrock-Safe...
github.com
GitHub - Bedrock-Safeguard/gentlemen-decryptor: First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extraction. 35/35 file...
First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extraction. 35/35 files decrypted. Research by Bedrock Safeguard In...
000
marktsec @marktsec.bsky.social · 20/04/2026
Operation GhostMail: Russian APT exploits Zimbra Webmail to Target Ukraine State Agency www.seqrite.com/blog/operati...
seqrite.com
Operation GhostMail: Russian APT Exploits Zimbra XSS to Target Ukraine Government
Operation GhostMail uncovers a Russian APT campaign exploiting a Zimbra XSS vulnerability (CVE-2025-66376) to target a Ukrainian government agency via phishing emails and browser-based data exfiltrati...
000
marktsec @marktsec.bsky.social · 17/04/2026
RedSun: How Windows Defender's Remediation Became a SYSTEM File Write nefariousplan.com/posts/redsun...
nefariousplan.com
RedSun: How Windows Defender's Remediation Became a SYSTEM File Write — nefariousplan.com
A technical teardown of the RedSun zero-day — the second Defender escalation in two weeks from the same researcher — grounded in the actual source code.
010
marktsec @marktsec.bsky.social · 16/04/2026
The Red Sun vulnerability repository github.com/Nightmare-Ec...
github.com
GitHub - Nightmare-Eclipse/RedSun: The Red Sun vulnerability repository
The Red Sun vulnerability repository. Contribute to Nightmare-Eclipse/RedSun development by creating an account on GitHub.
010
marktsec @marktsec.bsky.social · 09/04/2026
You’re Driving Me Crazy: Analysing and Detecting BYOVD ransom-isac.com/blog/analysi...
ransom-isac.com
You’re Driving Me Crazy: Analysing and Detecting BYOVD
A deep-dive technical reference for SOC teams and threat hunters covering BYOVD attack analysis and detection.
010
marktsec @marktsec.bsky.social · 08/04/2026
A DNS setting change on a single router can quietly reroute an entire network’s authentication traffic. www.lumen.com/blog-and-new...
lumen.com
Frostarmada forest blizzard dns hijacking
A DNS setting change on a single router can quietly reroute an entire network’s authentication traffic. In FrostArmada, Lumen observed Forest Blizzard using that technique ...
000