Sign in

Mark Kelly

@mkyo.bsky.social
548 followers 173 following 48 posts

🇨🇳 Threat Research at Proofpoint

PostsRepliesMedia
Reposted by Mark Kelly
Alex Engler @alexengler.bsky.social · 01/10/2026
The attackers posed as former OSTP official Lynne Parker with a believable email about a new AI policy center, which was apparently oriented towards U.S. AI policymakers - be careful out there! Thanks to @proofpoint.com for the thorough technical investigation www.proofpoint.com/us/blog/thre...
proofpoint.com
Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles | Proofpoint US
Key Findings In July 2026, a China-aligned threat actor Proofpoint tracks as TA419 conducted multiple credential phishing campaigns impersonating prominent economists and artificial
042
Reposted by Mark Kelly
Alex Engler @alexengler.bsky.social · 01/10/2026
Totally surreal to announce I've been targeted by my first China-aligned threat actor, as an AI policy leader. Sometimes little moments of recognition like this really make you feel like you've made it www.reuters.com/legal/govern...
1113
Mark Kelly @mkyo.bsky.social · 01/10/2026
🚨 New @threatinsight.proofpoint.com blog covering a 🇨🇳- aligned threat actor targeting US AI policy circles in spear phishing campaigns in recent months: www.proofpoint.com/us/blog/thre...
proofpoint.com
Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles | Proofpoint US
Key Findings In July 2026, a China-aligned threat actor Proofpoint tracks as TA419 conducted multiple credential phishing campaigns impersonating prominent economists and artificial
2106
Reposted by Mark Kelly
Alex Lanstein @lanstein.bsky.social · 30/09/2026
great work by Eamon to tell the story of run-of-the-mill chinese espionage against the federal reserve. a decade of effort to gather information that is useful, but usually not anything even close to "top secret".
112
Reposted by Mark Kelly
Horkos @wylienewmark.bsky.social · 25/09/2026
Absolutely mandatory reading. The single best analysis I’ve seen on Iranian CNA trends post-2/28, in terms of both accuracy and assessment.
2186
Reposted by Mark Kelly
Saher @saffronsec.bsky.social · 24/09/2026
Excited to publish my first @bindinghook.bsky.social piece on challenging assumptions of how Iranian cyber ops function in wartime & the discrepancy between capability/intent signals from peacetime. What does the evidence say on how cyber/kinetic interact in conflict? bindinghook.com/what-does-th...
bindinghook.com
What does the Iran war tell us about the relationship between cyber and kinetic conflict?
The predicted wave of Iranian cyber retaliation never came
22215
Reposted by Mark Kelly
Binding Hook @bindinghook.bsky.social · 24/09/2026
'The damage was likely negligible; the effect was psychological, not operational.’ Read more from @saffronsec.bsky.social on Iran’s wartime cyber operations: bindinghook.com/what-does-th...
bindinghook.com
What does the Iran war tell us about the relationship between cyber and kinetic conflict?
The predicted wave of Iranian cyber retaliation never came
074
Reposted by Mark Kelly
Wesley Shields @wxs.bsky.social · 09/09/2026
Nice work on this! It cost me a bit of my sanity last week but was definitely interesting to see.
132
Reposted by Mark Kelly
Saher @saffronsec.bsky.social · 09/09/2026
Exploits, zero-days, robots, oh my! New research from @threatinsight.proofpoint.com on multiple China-aligned actors using an exploit chain with Chrome (patch-gap) and Windows zero-days and indicators of AI-assisted development. Meet BlueMoon exploit kit: www.proofpoint.com/us/blog/thre...
proofpoint.com
Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days | Proofpoint US
Analyst note: Proofpoint uses the UNK_ designator to define clusters of activity that are still developing and have not been observed for long enough to receive a numerical TA designation.
185
Mark Kelly @mkyo.bsky.social · 09/09/2026
🚨🌙 Today we are releasing a new @threatinsight blog on BlueMoon, an exploit kit that chained “patch-gap” Chrome zero-days with a Windows zero-day and had indicators of AI-assisted development. It was used by at least four espionage-motivated threat actors since late August.
175
Reposted by Mark Kelly
Greg Lesnewich @greg-l.bsky.social · 29/07/2026
It was truly a wild ride to find this the day before such a big release. And the effort to get it out to the world in less than a week was astonishing Good shit @saffronsec.bsky.social @mkyo.bsky.social @konstantinklinger.bsky.social @nickattfield.bsky.social TREE FOREVER
181
Reposted by Mark Kelly
Greg Lesnewich @greg-l.bsky.social · 29/07/2026
So remember last week when we said we hadn’t see TA488/Laundry Bear/Void since Feb? Well... We kinda lied Day before the release, we found em throwing a half click against Outlook to install one of the coolest implants we’ve ever examined: OWAReaper www.proofpoint.com/us/blog/thre...
proofpoint.com
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
22415
Mark Kelly @mkyo.bsky.social · 23/07/2026
Come read TWO @threatinsight.proofpoint.com blogs on Russia state-aligned threat actors doing some funky exploitation over email 🔥 with accompanying NSA/FBI reporting 👾
031
Reposted by Mark Kelly
ThreatInsight @threatinsight.proofpoint.com · 23/07/2026
Our researchers discovered that a Russia-aligned threat actor was exploiting a previously unknown (zero-day) vulnerability against Zimbra mailservers. We alerted government partners, with whom we have collaborated on further discovery. Blog: www.proofpoint.com/us/blog/thre...
265
Reposted by Mark Kelly
Saher @saffronsec.bsky.social · 23/07/2026
Most exciting @threatinsight.proofpoint.com drop yet - in collaboration with NSA - and the product of @greg-l.bsky.social's blood, sweat, and tears. Research into two Russian actors throwing half-click exploits against mailservers. Part 1 on TA488 / Void Blizzard www.proofpoint.com/us/blog/thre...
proofpoint.com
TA488 Targets Zimbra Mailservers with Half-Click Exploits | Proofpoint US
Proofpoint is releasing this report in coordination with NSA and FBI’s JSAC reporting about TA488/Void Blizzard, which can be found here. This is part 1 of a 2-part blog series Proofpoint is
21815
Reposted by Mark Kelly
Saher @saffronsec.bsky.social · 07/07/2026
New research from @greg-l.bsky.social and @mkyo.bsky.social on a China-aligned actor exploiting n-day vulns in Roundcube to pop mailservers of North American universities. So reminder to protect & patch your mailserver, the edge device you forgot was an edge device www.proofpoint.com/us/blog/thre...
proofpoint.com
One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation | Proofpoint US
Analyst note: Proofpoint uses the UNK_ designator to define clusters of activity that are still developing and have not been observed for long enough to receive a numerical TA designation. Key
097
Reposted by Mark Kelly
ThreatInsight @threatinsight.proofpoint.com · 07/07/2026
🚨 New research: Proofpoint has identified a suspected China-aligned espionage cluster, UNK_MassTraction, exploiting multiple Roundcube n-day vulnerabilities to compromise mail servers at U.S. and Canadian universities. Analysis, infection chain & IOCs: www.proofpoint.com/us/blog/thre....
UNK_MassTraction infection chain.
157
Reposted by Mark Kelly
ThreatInsight @threatinsight.proofpoint.com · 09/06/2026
🚨 New threat research: Proofpoint identified a likely North Korea-aligned threat cluster, UNK_DeadDrop, targeting software developers through trusted development platforms and workflows. Read the blog: www.proofpoint.com/us/blog/thre....
proofpoint.com
Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency | Proofpoint US
By Saher Naumaan, Carlos Rubio, and the Proofpoint Threat Research Team Key Findings Between April and May 2026, Proofpoint Threat Research observed a likely North Korean threat actor
168
Reposted by Mark Kelly
Saher @saffronsec.bsky.social · 08/06/2026
New from @threatinsight.proofpoint.com! North Korean actor UNK_DeadDrop (possibly overlapping with Contagious Interview) conducts a high volume phishing campaign targeting developers with a new technique abusing VSIX extensions and new open source payload Overlord www.proofpoint.com/us/blog/thre...
proofpoint.com
Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency | Proofpoint US
By Saher Naumaan, Carlos Rubio, and the Proofpoint Threat Research Team Key Findings Between April and May 2026, Proofpoint Threat Research observed a likely North Korean threat actor
055
Reposted by Mark Kelly
John Scott-Railton @jsrailton.bsky.social · 28/04/2026
NEW: we caught 🇨🇳Chinese hackers... again. Twist: they're hacking journalists & activists, but we suspect they're private contractors. State repression... with a profit margin. Thread + how to protect yourself 1/ By my colleagues @citizenlab.ca + @icij.org citizenlab.ca/research/how...
315581
Reposted by Mark Kelly
The Citizen Lab @citizenlab.ca · 23/04/2026
🚨New research reveals how two sophisticated surveillance actors exploited the global telecom ecosystem and, for the first time, directly links combined 3G and 4G network attacks to mobile operator infrastructure. citizenlab.ca/research/unc...
citizenlab.ca
Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors
Our investigation uncovers two sophisticated telecom surveillance campaigns and, for the first time, links real-world attack traffic to mobile operator signalling infrastructure. The findings expose h...
12923
Reposted by Mark Kelly
ThreatInsight @threatinsight.proofpoint.com · 01/04/2026
After a lull in activity targeting Europe from mid-2023 to mid-2025, the China-aligned espionage actor #TA416 (RedDelta, Vertigo Panda, Red Lich) has resumed targeting European government and diplomatic entities, with a recent expansion to the Middle East. brnw.ch/21x1f0j
brnw.ch
I’d come running back to EU again: TA416 resumes European government espionage campaigns | Proofpoint US
Key findings From mid-2025 onwards, the China-aligned threat actor TA416 resumed observed targeting of European government and diplomatic organizations following a period of reduced EU-
153
Reposted by Mark Kelly
ThreatInsight @threatinsight.proofpoint.com · 27/03/2026
Proofpoint has directly observed a targeted email campaign that delivers DarkSword RCE, and we attribute the messages to Russian FSB threat actor TA446 with high confidence. 🧵
11713
Reposted by Mark Kelly
ThreatInsight @threatinsight.proofpoint.com · 11/03/2026
Conflict in Iran is accelerating cyber espionage across the Middle East. Since the start of Operation Epic Fury on February 28, 2026, Proofpoint researchers have observed heightened cyber activity against Middle East targets tied to the war. Details: brnw.ch/21x0EJi.
brnw.ch
Iran conflict drives heightened espionage activity against Middle East targets | Proofpoint US
Analyst note: Proofpoint uses the UNK_ designator to define clusters of activity that are still developing and have not been observed for long enough to receive a numerical TA designation.
124
Reposted by Mark Kelly
PIVOTcon @pivotcon.bsky.social · 10/03/2026
📣 #PIVOTcon26 Agenda is here 🤟 We are thrilled to announce the lineup for this year's edition! 2⃣ days and 19 talks from leading #ThreatResearch experts. The agenda link is in the first comment👇, and the talks and speakers are in the thread.🧵 #CTI #ThreatIntel 1/15
11610
Reposted by Mark Kelly
The Banshee Queen 👑 @cyberoverdrive.bsky.social · 29/01/2026
One of the fastest ways to trigger me in a work context these days is to whisper "Mustang Panda". Instant menty b ✨
121
Reposted by Mark Kelly
ThreatInsight @threatinsight.proofpoint.com · 28/01/2026
In addition to espionage threat actors, financially motivated cybercriminals have been exploiting the WinRAR vulnerability CVE-2025-8088. The highly effective ecrime actor, typically seen distributing Koi Stealer/Koi Loader (TA4561), was observed doing so in Fall 2025. Details. ⤵️
133
Reposted by Mark Kelly
ThreatInsight @threatinsight.proofpoint.com · 28/01/2026
Alongside this activity recently highlighted by Google (cloud.google.com/blog/topics/...), Proofpoint threat researchers have observed additional exploitation of WinRAR vulnerability CVE-2025-8088 by state‑aligned groups linked to China and the DPRK.
121
Mark Kelly @mkyo.bsky.social · 18/12/2025
New espionage/e-crime crossover blog from the team on the continued rise of device code phishing by state-aligned and financially motivated groups.
162
Mark Kelly @mkyo.bsky.social · 06/12/2025
A study in the evolution of SVR cyberespionage tradecraft
0224
Reposted by Mark Kelly
Volexity @volexity.com · 04/12/2025
@volexity.com tracks a variety of threat actors abusing Device Code & OAuth authentication workflows to phish credentials, which continue to see success due to creative social engineering. Our latest blog post details Russian threat actor UTA0355’s campaigns impersonating European security events.
volexity.com
Dangerous Invitations: Russian Threat Actor Spoofs European Security Events in Targeted Phishing Attacks
In early 2025, Volexity published two blog posts detailing a new trend among Russian threat actors targeting organizations through the abuse of Microsoft 365 OAuth and Device Code authentication workf...
0108
Reposted by Mark Kelly
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 04/12/2025
1/ Today we release a new report exposing previously undisclosed entities connected to the wider #Intellexa ecosystem as well as newly identified activity clusters in Iraq and indications of activity in Pakistan: www.recordedfuture.com/research/int...
recordedfuture.com
Intellexa’s Global Corporate Web
22618
Reposted by Mark Kelly
Saher @saffronsec.bsky.social · 05/11/2025
New Iran drop from me tracking an attribution nightmare - UNK_SmudgedSerpent! A little Charming, a little Muddy, and a lot C5. Targeting policy experts with benign conversation starters, health-themed infra, OnlyOffice spoofs, and RMMs. Check out the full story www.proofpoint.com/us/blog/thre...
proofpoint.com
Crossed wires: a case study of Iranian espionage and attribution | Proofpoint US
Proofpoint would like to thank Josh Miller for his initial research on UNK_SmudgedSerpent and contribution to this report.  Key findings  Between June and August 2025,
21812
Reposted by Mark Kelly
ThreatInsight @threatinsight.proofpoint.com · 23/10/2025
Proofpoint threat researchers have designed an open-source tool—named PDF Object Hashing—to track and detect the unique characteristics of PDFs used by threat actors... similar to a digital fingerprint. 🫆 We use this tool internally to help track multiple threat actors with high confidence.
1188
Reposted by Mark Kelly
PIVOTcon @pivotcon.bsky.social · 02/10/2025
📣 🔥 🛋️ SAVE THE DATE 🛋️ 🔥 📣 The next #PIVOTcon will be on 6-8 May 2026, in Malaga, ES!!! You favorite ;) #ThreatResearch conference is coming back and we are planning to bring you the usual experience and content of utmost quality. Follow us + #StayTuned for more info #CTI #ThreatIntel #PIVOTcon26
01710
Mark Kelly @mkyo.bsky.social · 04/10/2025
Good piece covering a big burst of TA416 activity targeting European governments last week!
042
Reposted by Mark Kelly
The Banshee Queen 👑 @cyberoverdrive.bsky.social · 24/09/2025
First public report at Recorded Future by yours truly is out! RedNovember (formerly TAG-100, a.k.a. Storm-2077) is a Chinese state-sponsored threat group focused on intelligence collection, especially on flashpoint issues of strategic interest to China. www.recordedfuture.com/research/red...
recordedfuture.com
RedNovember Targets Government, Defense, and Technology Organizations
RedNovember, a likely Chinese state-sponsored cyber-espionage group, has targeted global government, defense, and tech sectors using advanced tools like Pantegana and Cobalt Strike. Discover the lates...
22414
Reposted by Mark Kelly
ThreatInsight @threatinsight.proofpoint.com · 18/09/2025
Proofpoint threat researchers have published new research identifying a new cyber-espionage campaign by #TA415 (#APT41), a China-aligned threat actor, exploiting growing uncertainty in U.S.-China economic relations. Blog: www.proofpoint.com/us/blog/thre....
proofpoint.com
Going Underground: China-aligned TA415 Conducts U.S.-China Economic Relations Targeting Using VS Code Remote Tunnels | Proofpoint US
What happened  Throughout July and August 2025, TA415 conducted spearphishing campaigns targeting United States government, think tank, and academic organizations utilizing U.S.-China
153
Mark Kelly @mkyo.bsky.social · 16/09/2025
🚨🇨🇳💰 New @threatinsight.proofpoint.com blog on TA415 (aka APT41) economy and trade-themed spearphishing against US govt, think tanks & academia. The campaigns used U.S.-China economic lures and spoofed the Chair of the House Select Committee on CCP competition + the US-China Business Council.
131
Mark Kelly @mkyo.bsky.social · 11/09/2025
It is time the Mustang Panda moniker went the way of Winnti Group ☠️
150
Reposted by Mark Kelly
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 05/08/2025
1/ We've just released a new report uncovering new infrastructure tied to multiple activity clusters linked to the Israeli spyware vendor #Candiru across several countries. Full report: www.recordedfuture.com/research/tra...
recordedfuture.com
Tracking Candiru’s DevilsTongue Spyware in Multiple Countries
Recorded Future's Insikt Group uncovers active infrastructure linked to Candiru’s DevilsTongue spyware across multiple countries. Discover how this stealthy spyware targets high-value individuals and ...
11212
Mark Kelly @mkyo.bsky.social · 16/07/2025
🚨🆕🐟🍟 New blog from me and the amazing @threatinsight.proofpoint.com team covering recent activity by multiple China-aligned threat actors targeting semiconductor companies in Taiwan over the past few months: www.proofpoint.com/us/blog/thre...
proofpoint.com
Phish and Chips: China-Aligned Espionage Actors Ramp Up Taiwan Semiconductor Industry Targeting  | Proofpoint US
Key findings  Between March and June 2025, Proofpoint Threat Research observed three Chinese state-sponsored threat actors conduct targeted phishing campaigns against the Taiwanese
053
Reposted by Mark Kelly
AJ Vicens @ajvicens.bsky.social · 16/07/2025
New: A handful of Chinese-linked cyber espionage groups are stepping up targeting of Taiwanese semiconductor companies, per new analysis from @proofpoint.com. Campaigns include targeting of financial analysts focused on the sector as well: www.reuters.com/sustainabili...
reuters.com
Exclusive: China-linked hackers target Taiwan's chip industry with increasing attacks, researchers say
Chinese-linked hackers are targeting the Taiwanese semiconductor industry and investment analysts as part of a string of cyber espionage campaigns, researchers said on Wednesday.
1159
Reposted by Mark Kelly
Saher @saffronsec.bsky.social · 01/07/2025
New DISCARDED podcast drop! Join @greg-l.bsky.social and me as we talk about our fave North Korean groups, DPRK as the neglected child, TA406 and the Russian connection, and finally, the dreaded but pervasive IT worker problem podcasts.apple.com/us/podcast/c... open.spotify.com/episode/01d1...
podcasts.apple.com
Comic Sans and Cybercrime: Inside North Korea’s Global Cyber Playbook
Podcast Episode · DISCARDED: Tales From the Threat Research Trenches · 07/01/2025 · 53m
184
Reposted by Mark Kelly
Greg Lesnewich @greg-l.bsky.social · 30/06/2025
Fun crossover blog about TA829 (RomCom) & TransferLoader with my ecrime pals @selenalarson.bsky.social it’s got it all: 🛰️ Popped routers for sending phish 📊 ACH on attribution 👾 custom protocols 👽 cool malware 🕵️ crime 🎯 espionage ❔many unanswered questions www.proofpoint.com/us/blog/thre...
proofpoint.com
10 Things I Hate About Attribution: RomCom vs. TransferLoader | Proofpoint US
Threat Research would like to acknowledge and thank the Paranoids, Spur, and Pim Trouerbach for their collaboration to identify, track, and disrupt this activity.  Key takeaways
01712
Reposted by Mark Kelly
Calwarez @calwarez.bsky.social · 20/06/2025
🚨 We’re hiring at Recorded Future’s Insikt Group Two senior analyst roles are open right now. Both focus on tracking nation-state threats. 🧵
163
Reposted by Mark Kelly
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 12/06/2025
Today we’re publishing new findings on Predator spyware, still active despite global sanctions, now with a new client and ties to a Czech entity. Here’s what we found 🧵 www.recordedfuture.com/research/pre...
recordedfuture.com
Predator Spyware Resurgence: Insikt Group Exposes New Global Infrastructure
Despite sanctions and global scrutiny, Predator spyware operations persist. Insikt Group reveals new infrastructure links in Mozambique, Africa, and Europe, highlighting ongoing threats to civil socie...
11912
Reposted by Mark Kelly
Nick Attfield @nickattfield.bsky.social · 04/06/2025
Dropping some joint research today with Threatray on TA397/Bitter 🔍 We dive into the confluence of signals that led us to our attribution of the threat actor 🎯 Shoutout to @konstantinklinger.bsky.social and Threatray for collaborating on this research. www.proofpoint.com/us/blog/thre...
proofpoint.com
The Bitter End: Unraveling Eight Years of Espionage Antics—Part One | Proofpoint US
This is a two-part blog series, detailing research undertaken in collaboration with Threatray. Part two of this blog series can be found on their website here.  Analyst note: Throughout
0118
Reposted by Mark Kelly
Saher @saffronsec.bsky.social · 04/06/2025
From phishes to hands-on-keyboard commands 🔥 new @proofpoint.bsky.social research from @nickattfield.bsky.social and @konstantinklinger.bsky.social on Indian state-sponsored actor TA397 (Bitter) with a great story on the steps to technical and political attribution www.proofpoint.com/us/blog/thre...
proofpoint.com
The Bitter End: Unraveling Eight Years of Espionage Antics—Part One | Proofpoint US
This is a two-part blog series, detailing research undertaken in collaboration with Threatray. Part two of this blog series can be found on their website here.  Analyst note: Throughout
0102
Reposted by Mark Kelly
Greg Lesnewich @greg-l.bsky.social · 21/05/2025
Is the era of the “named actor” done? As the OG adversary sets diverge, get promoted, or move on actors dispersing across the kill chain based on specialized skills increases (ORBs, criminal underground) AND the CTI models maturing… APTs ⬇️⬇️ UNCs ⬆️⬆️
7278