Sign in

marktsec

@marktsec.bsky.social
108 followers 15 following 717 posts

💫Threat Intel💫 Automation💫 Threat Analysis 💫OSINT💫 Testing 💫Network Security💫 github.com/marktsec

PostsRepliesMedia
marktsec @marktsec.bsky.social · 09/10/2026
AutoLogin - Phishing Automation Framework Update: Google AutoLogin v2 Phishing kits are becoming automation frameworks #ThreatIntel
110
marktsec @marktsec.bsky.social · 21/09/2026
AI infrastructure is becoming another underground service. A new marketplace advertises one API key for multiple LLMs, plus custom "uncensored coder" models targeting reverse engineering, malware, exploits and automation.
242
marktsec @marktsec.bsky.social · 20/09/2026
010
marktsec @marktsec.bsky.social · 20/09/2026
ShinyHunters reportedly breached and defaced Cl0p's leak site and is now publicly demanding payment from the operators. A new DLS update gives Cl0p 66 hours and threatens to expose alleged payment information from previous victims.
122
marktsec @marktsec.bsky.social · 19/09/2026
ICMacOS isn't just targeting browser credentials. Its latest "Dev Secrets" module advertises collection across: .env, SSH, Git, AWS, GCP, Docker, Kubernetes, Terraform, npm, databases It also tracks Keychain-related sources separately.
131
marktsec @marktsec.bsky.social · 19/09/2026
ICMacOS is building a MaaS offering around macOS malware. The stealer claims support for macOS 10.12+ across Intel and Apple Silicon. Its panel adds build/log analytics, custom VPS integration and Telegram alerts for incoming logs.
262
marktsec @marktsec.bsky.social · 12/09/2026
1/ A new Dark Project ransomware affiliate program is advertising a Go-based locker targeting Windows, UNIX, ESXi, NAS and BSD environments. The program also offers a separate "data ransom" model with a 90/10 affiliate split. #ThreatIntel
111
marktsec @marktsec.bsky.social · 04/09/2026
Detection evasion is being sold as a service. A new underground service advertises EXE "crypting" with: - SmartScreen bypass - Defender bypass - EDR bypass - EXE/DLL sideloading - ClickFix support - Custom stubs They claim to process RATs, stealers and other files.
111
marktsec @marktsec.bsky.social · 28/08/2026
Hyflock RaaS is building an AI-powered C2 The ransomware group claims its new custom C2 uses an LLM agent to operate the platform and interact with custom modules.
123
marktsec @marktsec.bsky.social · 21/08/2026
🧵 1/ A newly advertised Windows remote administration tool, Hydra Remote, combines HVNC with browser-session cloning and credential recovery. The most interesting capability: cloning existing browser profiles into a hidden session. #ThreatIntel
141
marktsec @marktsec.bsky.social · 15/08/2026
🧵1/ Volta Stealer v2.0 released, and the update is focused heavily on scaling operations. The new release adds major changes to its delivery infrastructure, data collection, filtering and operator workflow. Here are some of the more interesting changes: #ThreatIntel
120
marktsec @marktsec.bsky.social · 15/08/2026
2/ Remus claims extensive collection capabilities: - 21 browsers - 181 Chrome wallet extensions - 43 password managers - 38 applications - Browser history - Cards + CVV - Important files, seed phrases & private keys - Mozilla extensions and wallets
100
marktsec @marktsec.bsky.social · 15/08/2026
🧵 1/ A relatively new MaaS stealer called Remus is positioning itself as more than another credential stealer. Its standout feature isn't just what it collects, but how it measures whether the collection actually succeeded. #ThreatIntel
120
marktsec @marktsec.bsky.social · 14/08/2026
🧵 1/ A new wave of ransomware brands is emerging, but the interesting part isn't the encryption. Across recent RaaS programs, operators are competing on operational capabilities and victim pressure, not just lockers. #ThreatIntel #Ransomware
164
marktsec @marktsec.bsky.social · 08/08/2026
1/ 🧵 A new Bee Stealer v2.1 update introduces an interesting feature: an AI-generated profile of the victim. Instead of simply collecting credentials, the stealer reportedly feeds parts of the stolen log to an AI model to generate a summary of the victim. #ThreatIntel
122
marktsec @marktsec.bsky.social · 08/08/2026
5/ Another interesting feature is automated log marking. Operators can define domains associated with banks, exchanges, gaming, email and other services, allowing potentially valuable logs to be highlighted automatically.
110
marktsec @marktsec.bsky.social · 08/08/2026
4/ The infrastructure is also built for scale: - Parallel log receiving - Multiple gateways - Automatic failover - Real-time log processing - Storage designed for millions of logs
110
marktsec @marktsec.bsky.social · 08/08/2026
3/ One detail caught my attention: Data is reportedly sent to the server in chunks, while much of the decryption and processing happens server-side. This minimizes the amount of heavy processing performed by the build itself.
110
marktsec @marktsec.bsky.social · 08/08/2026
2/ WARDEN claims support for 360+ targets across 13 categories, including browsers, crypto apps, messengers, email, VPN, RDP/VNC, cloud and password managers. It also supports custom file and registry collection.
110
marktsec @marktsec.bsky.social · 08/08/2026
1/ 🧵 A relatively new infostealer called WARDEN is being advertised with an interesting architecture. Rather than focusing only on collecting credentials, the project appears designed as a large-scale data collection and processing platform. #ThreatIntel
121
marktsec @marktsec.bsky.social · 31/07/2026
4/5 A recent v3.1.0 update continues this trend by improving operational scalability rather than adding new collection features: - ~2× faster log processing - Bulk log management - Dashboard enhancements - Improved proxy automation - Expanded Telegram integration
110
marktsec @marktsec.bsky.social · 31/07/2026
2/5 Instead of focusing solely on stealing data, Stealc v3 introduces platform-level improvements: - Docker-based deployment - One-command installation - Integrated builder - Automated proxy deployment - In-panel updatesIt increasingly resembles a commercial SaaS product.
110
marktsec @marktsec.bsky.social · 31/07/2026
🧵1/5 The developers behind Stealc have released Stealc v3, a major redesign that shifts the project beyond a traditional stealer. The most notable changes aren't new collection capabilities, they're improvements to deployment, scalability and operator experience. #ThreatIntel
111
marktsec @marktsec.bsky.social · 25/07/2026
🧵1/ The Gentlemen RaaS operators have announced several updates for affiliates, but two additions stand out: Active Directory credential harvesting and an AI-assisted data analysis service designed to support ransom negotiations.#ThreatIntel #Ransomware #RaaS
121
marktsec @marktsec.bsky.social · 25/07/2026
🧵1/ A recently advertised phishing framework "AutoLogin Phishing kit" suggests phishing tooling is evolving beyond static login pages. The project is marketed as a browser automation platform using real Chrome instances to interact with legitimate login flows. #ThreatIntel
121
marktsec @marktsec.bsky.social · 17/07/2026
🧵1/ A custom ransomware project was recently advertised on cybercrime forum, and its feature list provides an interesting snapshot of what operators now market as a "premium" ransomware offering. #ThreatIntel #Ransomware
142
marktsec @marktsec.bsky.social · 02/07/2026
🧵1/ An underground vendor selling code-signing certificates has revised its offering following Microsoft's recent reputation changes. The update suggests certificate possession alone is no longer sufficient to reliably bypass SmartScreen. #ThreatIntel #infosec
110
marktsec @marktsec.bsky.social · 01/07/2026
🧵 1/ A newly advertised ransomware operation, SevyWare RaaS, is promoting an unusual addition to its affiliate offering: "Violence as a Service." #ThreatIntel #Ransomware
111
marktsec @marktsec.bsky.social · 30/06/2026
🧵1/ Since its public debut in early June, the emerging VOLTA MaaS stealer has maintained a rapid development cadence, with 6 public updates released in less than a month. Below is a timeline of its development 👇 #ThreatIntel #infosec
121
marktsec @marktsec.bsky.social · 29/06/2026
🧵1/ The developers behind the Stealc malware have announced the sale of the complete Stealc v2 source code ahead of the planned v3 release. According to the advertisement, only two copies of the source code will be sold for $60,000 each. #ThreatIntel #Malware #secops
145
marktsec @marktsec.bsky.social · 28/06/2026
3/ One feature stands out: payloads are now retrieved dynamically from an operator-controlled URL instead of being statically stored in the panel. This allows rapid payload rotation without rebuilding delivery infrastructure, making campaigns more flexible and resilient.
110
marktsec @marktsec.bsky.social · 28/06/2026
2/ Key additions advertised by the developer: • Dynamic payload retrieval from external URLs • Country & referrer-based delivery rules • Per-affiliate campaign management • Queueing for multiple customer campaigns • Database optimizations for high-volume operations
110
marktsec @marktsec.bsky.social · 28/06/2026
🧵1/ A new update to the ErrTraffic ClickFix framework was recently advertised on a Russian-language cybercrime forum. The release focuses less on new delivery techniques and more on scaling affiliate operations. #ThreatIntel #ClickFix #infosec
154
marktsec @marktsec.bsky.social · 03/06/2026
Update: TierOne is back online.
000
marktsec @marktsec.bsky.social · 03/06/2026
TierOne forum has moved to a new onion domain. The old site now points users to the replacement address, but the new service is currently throwing an Internal Server Error. #OSINT #ThreatIntel #DarkWeb
100
marktsec @marktsec.bsky.social · 12/05/2026
🚨 Storm Stealer operators announced a major feature update focused on Google’s DBSC protections. The group claims to have developed a “DBSC cookie bypass” module targeting Chrome 147 on Windows. #ThreatIntel #Infostealer #CyberSecurity
100
marktsec @marktsec.bsky.social · 06/04/2026
Baphomet: Tooling KslDump / KslKatzBOF leverages a Microsoft-signed Defender driver (KslD.sys) Microsoft patched the active driver, yet left a vulnerable version accessible locally #ThreatIntel #infosec
100
marktsec @marktsec.bsky.social · 07/03/2026
New Atroposia infostealer + remote admin toolkit: • Encrypted C2 with unique/native stubs (C++/Rust) • Persistence + automatic UAC bypass + anti-VM evasion • HVNC + Hidden RDP for invisible remote sessions • Stealer/Grabber + Chromium/Gecko credential recovery #ThreatIntel #infosec
100
marktsec @marktsec.bsky.social · 19/02/2026
A shared RaaS affiliate blacklist attributed to Nova, Qilin and DragonForce suggests emerging cartel-style governance in the ransomware ecosystem. Violators get 24h to resolve disputes or face platform wide bans #ThreatIntel #infosec
000
marktsec @marktsec.bsky.social · 13/02/2026
Aura Stealer update: Shift to native x64 builds, citing better crypter support, reduced WoW64 visibility, and improved evasion via direct kernel calls. They claim successful tests with low detection rates. #ThreatIntel
000
marktsec @marktsec.bsky.social · 12/02/2026
A new update of “Solana Drainer 2.0”: advertising multi-wallet draining, Phantom targeting, and signature-based asset theft across up to 100 tokens at once. Claims include bypasses for wallet protections and abuse of in-app browsers (X/Discord). #ThreatIntel
000
marktsec @marktsec.bsky.social · 02/02/2026
CloudFlare Captcha ClickFix update: A fake Cloudflare CAPTCHA stage to their flow. The “verification” only succeeds after the victim runs the delivered file. #threatintel #infosec
000
marktsec @marktsec.bsky.social · 02/02/2026
Void Stealer v1.3 update: Stronger obfuscation (RC4-encrypted strings) and a more capable backend API for build creation and large-scale log searching (cookies, creds, victim profiling). #threatintel #infostealer
000
marktsec @marktsec.bsky.social · 02/02/2026
Aura Stealer v1.6.0 update: Improved decryption for Chromium 144+, dynamic selection between separate decryptors for pre/post-144 builds, expanded CIS language/geo checks, and a fix to WinAPI name hashing that previously left strings exposed. #infosec #ThreatIntel
000
marktsec @marktsec.bsky.social · 28/01/2026
000
marktsec @marktsec.bsky.social · 28/01/2026
RAMP forum has been seized
100
marktsec @marktsec.bsky.social · 14/01/2026
Matanbuchus added new DLL sideloading techniques after older ones started getting flagged by some EDRs.
000
marktsec @marktsec.bsky.social · 14/01/2026
🚨 “Orion Leaks” which positioning itself as a Data Leaks & Exposures hub for confidential breaches, so far, every link to "leaked" datasets redirects to a LockBit DLS.
000
marktsec @marktsec.bsky.social · 14/01/2026
Operation Endgame S03E02 - INTERLUDE
000
marktsec @marktsec.bsky.social · 07/01/2026
123 stealer: stealer-as-a-service: C++ build (~700KB, x64), targets default browsers, files & extensions, customizable file grabber, Telegram exfil. #ThreatIntel #infosec
000