Sign in

Nick Attfield

@nickattfield.bsky.social
124 followers 176 following 5 posts

Threat Research @ Proofpoint | Views are my own.

PostsRepliesMedia
Reposted by Nick Attfield
Greg Lesnewich @greg-l.bsky.social · 29/07/2026
So remember last week when we said we hadn’t see TA488/Laundry Bear/Void since Feb? Well... We kinda lied Day before the release, we found em throwing a half click against Outlook to install one of the coolest implants we’ve ever examined: OWAReaper www.proofpoint.com/us/blog/thre...
proofpoint.com
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
22414
Reposted by Nick Attfield
ThreatInsight @threatinsight.proofpoint.com · 23/07/2026
Our researchers discovered that a Russia-aligned threat actor was exploiting a previously unknown (zero-day) vulnerability against Zimbra mailservers. We alerted government partners, with whom we have collaborated on further discovery. Blog: www.proofpoint.com/us/blog/thre...
265
Reposted by Nick Attfield
ThreatInsight @threatinsight.proofpoint.com · 07/07/2026
🚨 New research: Proofpoint has identified a suspected China-aligned espionage cluster, UNK_MassTraction, exploiting multiple Roundcube n-day vulnerabilities to compromise mail servers at U.S. and Canadian universities. Analysis, infection chain & IOCs: www.proofpoint.com/us/blog/thre....
UNK_MassTraction infection chain.
157
Reposted by Nick Attfield
ThreatInsight @threatinsight.proofpoint.com · 27/03/2026
Proofpoint has directly observed a targeted email campaign that delivers DarkSword RCE, and we attribute the messages to Russian FSB threat actor TA446 with high confidence. 🧵
11713
Reposted by Nick Attfield
ThreatInsight @threatinsight.proofpoint.com · 20/03/2026
Proofpoint identified a targeted campaign against operations personnel at energy firms linked to projects in Pakistan. The messages were sent on 18 March 2026, and mimicked invitations to the upcoming Pakistan Energy Exhibition & Conference (PEEC). We track the activity as UNK_VaporVibes. 1/8
196
Reposted by Nick Attfield
ThreatInsight @threatinsight.proofpoint.com · 11/03/2026
Conflict in Iran is accelerating cyber espionage across the Middle East. Since the start of Operation Epic Fury on February 28, 2026, Proofpoint researchers have observed heightened cyber activity against Middle East targets tied to the war. Details: brnw.ch/21x0EJi.
brnw.ch
Iran conflict drives heightened espionage activity against Middle East targets | Proofpoint US
Analyst note: Proofpoint uses the UNK_ designator to define clusters of activity that are still developing and have not been observed for long enough to receive a numerical TA designation.
124
Reposted by Nick Attfield
Saher @saffronsec.bsky.social · 05/11/2025
New Iran drop from me tracking an attribution nightmare - UNK_SmudgedSerpent! A little Charming, a little Muddy, and a lot C5. Targeting policy experts with benign conversation starters, health-themed infra, OnlyOffice spoofs, and RMMs. Check out the full story www.proofpoint.com/us/blog/thre...
proofpoint.com
Crossed wires: a case study of Iranian espionage and attribution | Proofpoint US
Proofpoint would like to thank Josh Miller for his initial research on UNK_SmudgedSerpent and contribution to this report.  Key findings  Between June and August 2025,
21812
Reposted by Nick Attfield
StrikeReady Labs @strikereadylabs.com · 19/08/2025
A South Asian APT has been persistently targeting Sri Lanka, Bangladesh, Pakistan, and Turkey. This post walks through how to pivot from the well-publicized phishing infrastructure to expose APK tooling that compromised members of the military of Asian countries. strikeready.com/blog/apt-and...
strikeready.com
APT: Android, Phishing, microsoft
A South Asian APT has been persistently targeting Sri Lanka, Bangladesh, Pakistan, and Turkey. This post walks through infrastructure and malware pivots to expose novel tooling that compromised the p...
043
Reposted by Nick Attfield
AJ Vicens @ajvicens.bsky.social · 16/07/2025
New: A handful of Chinese-linked cyber espionage groups are stepping up targeting of Taiwanese semiconductor companies, per new analysis from @proofpoint.com. Campaigns include targeting of financial analysts focused on the sector as well: www.reuters.com/sustainabili...
reuters.com
Exclusive: China-linked hackers target Taiwan's chip industry with increasing attacks, researchers say
Chinese-linked hackers are targeting the Taiwanese semiconductor industry and investment analysts as part of a string of cyber espionage campaigns, researchers said on Wednesday.
1159
Reposted by Nick Attfield
ThreatInsight @threatinsight.proofpoint.com · 04/06/2025
Just published: A two-part blog series in collaboration with @threatray.bsky.social, which aims to substantiate the claim that #TA397 (Bitter) is an espionage-focused, state-backed threat actor with interests aligned to the Indian state. Part 1: brnw.ch/21wT9A5 Part 2: brnw.ch/21wT9Ad.
brnw.ch
The Bitter End: Unraveling Eight Years of Espionage Antics—Part One | Proofpoint US
This is a two-part blog series, detailing research undertaken in collaboration with Threatray. Part two of this blog series can be found on their website here.  Analyst note: Throughout
132
Nick Attfield @nickattfield.bsky.social · 04/06/2025
Dropping some joint research today with Threatray on TA397/Bitter 🔍 We dive into the confluence of signals that led us to our attribution of the threat actor 🎯 Shoutout to @konstantinklinger.bsky.social and Threatray for collaborating on this research. www.proofpoint.com/us/blog/thre...
proofpoint.com
The Bitter End: Unraveling Eight Years of Espionage Antics—Part One | Proofpoint US
This is a two-part blog series, detailing research undertaken in collaboration with Threatray. Part two of this blog series can be found on their website here.  Analyst note: Throughout
0118
Reposted by Nick Attfield
Greg Lesnewich @greg-l.bsky.social · 21/05/2025
Is the era of the “named actor” done? As the OG adversary sets diverge, get promoted, or move on actors dispersing across the kill chain based on specialized skills increases (ORBs, criminal underground) AND the CTI models maturing… APTs ⬇️⬇️ UNCs ⬆️⬆️
7278
Reposted by Nick Attfield
Saher @saffronsec.bsky.social · 13/05/2025
@greg-l.bsky.social drops knowledge on TA406 (Konni) as North Korea shows new interest in Ukraine, likely to keep tabs on the progress of the war and Russia's ability to keep pace on the battlefield www.proofpoint.com/us/blog/thre...
proofpoint.com
TA406 Pivots to the Front | Proofpoint US
What happened  In February 2025, TA406 began targeting government entities in Ukraine, delivering both credential harvesting and malware in its phishing campaigns. The aim of these
11513
Reposted by Nick Attfield
BogeyBackdoor @bogeybackdoor.bsky.social · 04/03/2025
Introducing #UNK_CraftyCamel! Leveraged Trusted Business Relationship? ✅ Low Volume, highly targeted? ✅ Interesting technique? ✅ Overlaps with other IRGC clusters? ✅ Bonus: Infrastructure still up to watch how they respond to the blog? ✅ www.proofpoint.com/us/blog/thre...
proofpoint.com
Call It What You Want: Threat Actor Delivers Highly Targeted Multistage Polyglot Malware | Proofpoint US
Key findings  Proofpoint researchers identified a highly targeted email-based campaign targeting fewer than five Proofpoint customers in the United Arab Emirates with a distinct
075
Nick Attfield @nickattfield.bsky.social · 17/12/2024
Dropping some new research on TA397/Bitter 🚨 Hidden in Plain Sight | TA397’s New Attack Chain Delivers Espionage RATs Report: www.proofpoint.com/us/blog/thre...
proofpoint.com
Hidden in Plain Sight: TA397’s New Attack Chain Delivers Espionage RATs | Proofpoint US
Key findings  Proofpoint observed advanced persistent threat (APT) TA397 targeting a Turkish defense sector organization with a lure about public infrastructure projects in Madagascar.   The attack...
21613
Reposted by Nick Attfield
ThreatInsight @threatinsight.proofpoint.com · 12/12/2024
In December 11 and 12, 2024, a spearphishing campaign targeted at least 20 Autonomous System (AS) owners, predominantly Internet Service Providers (ISPs), and purported to come from the Network Operations Center (NOC) of a prominent European ISP. 🧵⤵️
11610
Nick Attfield @nickattfield.bsky.social · 19/11/2024
I’m a little excited for this one
media.tenor.com
a man in a suit and tie says oh my god okay it 's happening ..
ALT: a man in a suit and tie says oh my god okay it 's happening ..
010
Reposted by Nick Attfield
PIVOTcon @pivotcon.bsky.social · 19/11/2024
#PIVOTcon25 registration is now OPEN 🤟📥📥📥 pivotcon.org #CTI #ThreatResearch #ThreatIntel Please read carefully the whole 🧵 for the rules about invite -> registration (1/5)
media.tenor.com
two men are standing next to each other with the words " we open it up " on the screen
ALT: two men are standing next to each other with the words " we open it up " on the screen
24222
Reposted by Nick Attfield
Catalin Cimpanu @campuscodi.risky.biz · 12/11/2024
Wait... did a Chinese security vendor just publish research on a suspected Chinese APT backdoor? 🙃 I need your thoughts here @jags.bsky.social blog.xlab.qianxin.com/analysis_of_...
blog.xlab.qianxin.com
New Zero-Detection Variant of Melofee Backdoor from Winnti Strikes RHEL 7.9
Background On July 27, 2024, XLab's Cyber Threat Insight and Analysis System(CTIA) detected an ELF file named pskt from IP address 45.92.156.166. Currently undetected on VirusTotal, the file trigger...
1258