Matt Johansen @mattjay.com · 23/10/2025The criminal information doc is light on specifics - doesn't name the victim companies or detail nature of stolen trade secrets. But does list all the watches the FBI collected from him... We can connect some dots based on what they do as a company. 120
Matt Johansen @mattjay.com · 23/10/2025Worth noting that this comes on heels of recent internal Trenchant investigation into leaked hacking tools. Not yet clear if the two incidents are connected. 110
Matt Johansen @mattjay.com · 23/10/2025Timeline: Williams allegedly stole 7 trade secrets between Apr '22-Jun '25, and an 8th between Jun-Aug '25. He was Trenchant's GM from Oct '24 until Aug '25, operating out of DC. 120
Matt Johansen @mattjay.com · 23/10/2025Former L3Harris/Trenchant GM Peter Williams charged with stealing trade secrets. DOJ claims he made $1.3M from the sale. 120
Matt Johansen @mattjay.com · 23/10/2025Woah. Trenchant, who develops zero-days and surveillance tools for Five Eyes intelligence agencies (US, UK, Canada, Australia, and New Zealand). Has had an insider accused of selling secrets to Russia. 3167
Matt Johansen @mattjay.com · 29/09/2025Funnily enough, I was looking for Medusa stuff while writing this thread, and CISA's advisory on how to protect yourself from them is the top search result. While this is all good advice, it wouldn't have done much to stop this type of attack. Hacks are just logins in 2025. 130
Matt Johansen @mattjay.com · 29/09/2025Group referenced previous "successful" insider compromises at UK healthcare and US emergency services orgs. Claims align with known Medusa TTPs focusing on high-value targets. 140
Matt Johansen @mattjay.com · 29/09/2025When reporter delayed, group pivoted to aggressive MFA bombing - continuously triggering 2FA notifications hoping for accidental approval. Same technique used in 2022 Uber compromise. 160
Matt Johansen @mattjay.com · 29/09/2025They requested specific network reconnaissance via command line queries, demonstrated knowledge of BBC's IT infrastructure, and offered "trust payment" of 0.5 BTC as deposit. 150
Matt Johansen @mattjay.com · 29/09/2025Threat actor claimed to be a "reach out manager" for Medusa - a Ransomware-as-a-Service operation believed to operate from Russia/CIS region. Group has hit 300+ victims in past 4 years per US cyber authorities. (img: TheHackerNews) 150
Matt Johansen @mattjay.com · 29/09/2025Initial contact came to @JoeTidy via Signal from "Syndicate" offering 15% of potential ransom payment for access to BBC systems. Offer later increased to 25% of what they claimed would be "1% of BBC's total revenue." 260
Matt Johansen @mattjay.com · 29/09/2025This BBC reporter was offered 25% of a ransom payout if he gave hackers access to the corporate network. He played along so we got a look inside their tactic here: 26025
Matt Johansen @mattjay.com · 05/08/2025Panel on bootstrapping vs. VC money. @haroonmeer.canary.love : “With bootstrapping you need to be careful to not be timid when it’s time to be bold” Just great life advice in general. Will remember this quote forever. Oh and @hdm.io and @andrewmorr.is are cool too. 030
Matt Johansen @mattjay.com · 25/07/2025Not just 4chan trolls. 404media decompiled the app and found the URLs in question in code. Not public anymore, but verified they are there. Original article: www.404media.co/wome... 280
Matt Johansen @mattjay.com · 25/07/2025"No authentication, no nothing. It's a public bucket" This is why security and privacy pros hate these ID verification laws that require drivers license uploads - these apps just can't keep this stuff secure. 271
Matt Johansen @mattjay.com · 25/07/2025They found the database exposed on Google's Firebase. The app is meant to be basically the "are we dating the same man?" Facebook group in a dating app. In order to verify that the users are women, they ask for photos and driver's licenses. 130
Matt Johansen @mattjay.com · 25/07/2025That viral women's only dating app 'Tea' was hacked by some 4chan users. They didn't phish, social engineer, or use some crazy hacker technique either - the database was just public 4104
Matt Johansen @mattjay.com · 17/07/2025Someone can buy this extension that is tied to tons of peole's salesforce account and just ...get access to all that info. (h/t @johntuckner.me) 182
Matt Johansen @mattjay.com · 15/07/2025If I was a bad guy who was looking for memory vulns, I'd be ALL OVER these new hotness web browsers. (Comet, Arc, etc.) Market share is small but much more valuable targets. - Teams behind them way smaller than ...Google 2112
Matt Johansen @mattjay.com · 11/07/2025Wild trend this week of legitimate apps and extensions turning into malware. youtu.be/o9XBXeX0_5E 032
Matt Johansen @mattjay.com · 10/07/2025I just can't believe how successful ClickFix campaigns are right now. And now FileFix on top of it... 170
Matt Johansen @mattjay.com · 06/07/2025Which Windows drivers keep Microsoft’s security engineers busiest - and which ones do attackers actually exploit? Artem Baranov did the dang math. He scraped every CVE bulletin from Jan 2022 through May 2025 and built a clean data set of kernel-mode driver patches. 1111
Matt Johansen @mattjay.com · 03/07/2025The data exfiltration: Keychain creds, browser data, Telegram chats, then push over WebSockets - encrypted channel, tricky for network sensors that ignore non-HTTP(S) traffic 110
Matt Johansen @mattjay.com · 03/07/2025Nasty little persistence trick - malware revives itself when killed. It intercepts `SIGINT` / `SIGTERM`, then rewrites LaunchAgents on shutdown. "any user-initiated termination of the malware results in the deployment of the core components, making the code resilient to basic defensive actions." 110
Matt Johansen @mattjay.com · 03/07/2025Stage-2 drops two binaries in /private/var/tmp • `a` (C++) - kicks off data-stealing chain • `installer` (Nim) - sets up persistence via signal handlers so killing the process re-installs the backdoor on reboot. 100
Matt Johansen @mattjay.com · 03/07/2025That script (`zoom_sdk_support.scpt`) hides *10,000 blank lines* scroll forever, never see the payload. The last 3 lines fetch stage-2 from `support.us05web-zoom[.]forum` (notice the look-alike Zoom domain) 100
Matt Johansen @mattjay.com · 03/07/2025The attacker pretends to be a trusted contact → DM on Telegram → Calendly invite → follow-up email with a Zoom link that tells victims to “run this update script.” It's been hyper successful and catching founders/devs off-guard 100
Matt Johansen @mattjay.com · 03/07/2025🚨 New macOS backdoor alert: North-Korean hackers are disguising a Zoom update that drops malware built to hijack laptops and steal data & passwords. If you or your devs run macOS, keep scrolling.👇 286
Matt Johansen @mattjay.com · 02/07/2025One of the wilder revelations in this report for me: They're hiring facilitators that are managing the scheme in the US. They also: - Create a bank account for the North Korean, or lend their own account to the worker - Purchase mobile phone numbers or SIM cards 100
Matt Johansen @mattjay.com · 02/07/2025But they create a big digital footprint and work history. This helps with legitimacy and some light background checks. A bunch of them have GitHub profiles full of activity and badges. 100
Matt Johansen @mattjay.com · 02/07/2025They've gotten real good at making fake profiles, pictures, resumes on LinkedIn and even boosting their resumes. This is the heaviest use of AI we've seen. 100
Matt Johansen @mattjay.com · 02/07/2025"To evade detection, these workers use VPNs, virtual private servers (VPSs), and proxy services as well as RMM tools to connect to a device housed at a facilitator’s laptop farm located in the country of the job." 100
Matt Johansen @mattjay.com · 02/07/2025Even the DoJ just put out how they're busting these laptop farms facilitating these remote workers access to US companies. 29 houses raided recently 100
Matt Johansen @mattjay.com · 02/07/2025A lot of people are waiting for the "super AI malware hacking machine!" to drop, but really it's just how everyone is using AI. Either way, it's been hyper successful for them. Hundreds of companies have hired these spies unwittingly. 110
Matt Johansen @mattjay.com · 02/07/2025Microsoft just put out a detailed threat intel report on North Korean threat actors who keep getting hired for remote jobs at US companies. They also outline how they're using AI to level up. Here's some highlights: 193
Matt Johansen @mattjay.com · 01/07/2025Been reading more and more about governments hacking their own citizens with spyware. They seem to be finding any excuse - journalists. politically active people. social media posts. Whatever they want. Then they do it with zero click 0days silently. Wild. youtu.be/zqY2A112bAQ 1132
Matt Johansen @mattjay.com · 25/06/2025I dove deeper into that AI Agent becoming #1 on the HackerOne leaderboard. youtu.be/lC2Ornloj24 110
Matt Johansen @mattjay.com · 22/06/2025Sunday scaries big time when I’m leaving this to go back to reality. 2380
Matt Johansen @mattjay.com · 17/06/2025 Data at risk includes sensitive labor organizing info and union complaints. Over 50 House Democrats from Congressional Labor Caucus expressed concerns about worker data exposure risks. 133
Matt Johansen @mattjay.com · 17/06/2025The alleged extraction code was hosted on Microsoft-owned GitHub. Rep. Lynch specifically wants details about attempts to "conceal activities, obstruct oversight, and shield from accountability." 144
Matt Johansen @mattjay.com · 17/06/2025Key context: This follows whistleblower Daniel Berulis's disclosure about ~10GB of data exfiltrated from NLRB's NxGen system. DOGE engineer Jordan Wick's repo "NxGenBdoorExtract" was made private before investigation. 175
Matt Johansen @mattjay.com · 17/06/2025Breaking: House Oversight's top Dem Rep. Lynch requests Microsoft provide info on DOGE staffer's GitHub repo. It allegedly contains code to extract data from the NLRB's case management system. 23412
Matt Johansen @mattjay.com · 13/06/2025This fits a pattern: Major supply chain attacks hit Clorox (2023, $356M impact), Sysco (2024, data leak), JBS Foods (2021, $11M ransom). Targeting distributors maximizes downstream impact. 100
Matt Johansen @mattjay.com · 13/06/2025Market impact: UNFI stock was down 9% after 8-K filing mentioned ongoing disruptions. Critical infrastructure implications too - UNFI serves hospitals, schools, SNAP retailers. (It's now down over 20% the last 5 days) 100
Matt Johansen @mattjay.com · 13/06/2025Whole Foods already seeing impacts: Reports of empty freezers, delayed deliveries across multiple states. While they have regional DCs, most center-store items flow through UNFI. (Still nobody wants Keto bread...) 100
Matt Johansen @mattjay.com · 13/06/2025UNFI is North America's largest grocery wholesaler ($31B in sales). Whole Foods represents >10% of their business. Manual operations now in place at distribution centers. Who remembers when DEFCON hotel got hacked and they had to break out the *cachunk* credit card carbon paper machines? 100
Matt Johansen @mattjay.com · 13/06/2025UNFI (major distributor for Whole Foods + 30k grocery stores) hit with cyber incident. Critical systems offline since June 5. Significant supply chain disruptions ongoing. Heres what we know. 🧵 272