Sign in

Ole Villadsen

@olevilladsen.bsky.social
241 followers 200 following 7 posts

Threat researcher @ Proofpoint. Formerly IBM X-Force, CMU, US Government, US Navy. Views are my own.

PostsRepliesMedia
Reposted by Ole Villadsen
James Reddick @jreddjourno.bsky.social · 16/04/2026
New @therecordmedia.bsky.social Thanks to @olevilladsen.bsky.social for chatting about Proofpoint's interesting new research into what happens after cybercriminals break into the systems of companies in the cargo industry therecord.media/cargo-thievi...
therecord.media
Cargo thieving hackers running sophisticated remote access campaigns, researchers find
Losses from cargo theft in North America rose to $6.6 billion in 2025, driven largely by digital attacks, according to the fleet management company Geotab.
011
Ole Villadsen @olevilladsen.bsky.social · 03/11/2025
Threat actors are teaming up with organized crime to target truckers — stealing identities, placing fraudulent bids on freight, and making off with the cargo. Their entry point? Emails with links delivering Remote Monitoring and Management (RMM) tools. Together with @selenalarson.bsky.social :
proofpoint.com
Remote access, real cargo: cybercriminals targeting trucking and logistics | Proofpoint US
Key findings  Cybercriminals are compromising trucking and freight companies in elaborate attack chains to steal cargo freight.  Cargo theft is a multi-million-dollar criminal
12919
Reposted by Ole Villadsen
ThreatInsight @threatinsight.proofpoint.com · 24/07/2025
🚨 Job seekers, watch out! 🚨 Proofpoint found threat actors targeting job seekers to distribute remote management tools that can lead to data or financial theft, or potentially to install follow-on malware like ransomware.
132
Reposted by Ole Villadsen
ThreatInsight @threatinsight.proofpoint.com · 22/05/2025
Today, Proofpoint joins the cybersecurity community and the U.S. and international law enforcement in celebrating the disruption of #DanaBot, a malware-as-a-service used by sophisticated cybercriminals since 2018. brnw.ch/21wSRiZ
brnw.ch
A Brief History of DanaBot, Longtime Ecrime Juggernaut Disrupted by Operation Endgame | Proofpoint US
Key Findings: Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on
151
Reposted by Ole Villadsen
Kostas @kostastsale.bsky.social · 13/03/2025
Thanks for the shoutout and for recognizing our work at DFIR Report in tracking these threats! 🔗Read the article here: www.proofpoint.com/us/blog/thre...
proofpoint.com
Remote Monitoring and Management (RMM) Tooling Increasingly an Attacker’s First Choice | Proofpoint US
Key findings    More threat actors are using legitimate remote monitoring and management (RMM) tools as a first-stage payload in email campaigns.  RMMs can be used for
081
Reposted by Ole Villadsen
ThreatInsight @threatinsight.proofpoint.com · 11/03/2025
New cyber threat research from Proofpoint highlights how attackers are adapting to law enforcement disruptions, leveraging trusted software to evade detection and compromise systems. This blog details our team's findings: www.proofpoint.com/us/blog/thre.... #malware #ransomware #dataloss
brnw.ch
Remote Monitoring and Management (RMM) Tooling Increasingly an Attacker’s First Choice | Proofpoint US
Key findings    More threat actors are using legitimate remote monitoring and management (RMM) tools as a first-stage payload in email campaigns.  RMMs can be used for
051
Reposted by Ole Villadsen
Nick Attfield @nickattfield.bsky.social · 17/12/2024
Dropping some new research on TA397/Bitter 🚨 Hidden in Plain Sight | TA397’s New Attack Chain Delivers Espionage RATs Report: www.proofpoint.com/us/blog/thre...
proofpoint.com
Hidden in Plain Sight: TA397’s New Attack Chain Delivers Espionage RATs | Proofpoint US
Key findings  Proofpoint observed advanced persistent threat (APT) TA397 targeting a Turkish defense sector organization with a lure about public infrastructure projects in Madagascar.   The attack...
21613
Reposted by Ole Villadsen
ThreatInsight @threatinsight.proofpoint.com · 12/12/2024
In December 11 and 12, 2024, a spearphishing campaign targeted at least 20 Autonomous System (AS) owners, predominantly Internet Service Providers (ISPs), and purported to come from the Network Operations Center (NOC) of a prominent European ISP. 🧵⤵️
11610
Reposted by Ole Villadsen
Brad @malware-traffic-analysis.net · 05/12/2024
2024-12-04 (Wednesday): #AgentTesla variant using #FTP for data exfiltration. A sanitized copy of the email distributing the malware, a #pcap from an infection run, the associated malware samples, and a list of indicators are available at www.malware-traffic-analysis.net/2024/12/04/i...
Screenshot of the email showing a TAR archive as an email attachment.The TAR archive and its content, a Windows EXE file for AgentTeslaAn update to the Windows registry showing the malware persistent on an infected Windows host.Traffic from an infection filtered in Wireshark to show the FTP data exfiltration traffic.
174
Reposted by Ole Villadsen
abuse-ch.bsky.social @abuse-ch.bsky.social · 04/12/2024
#BumbleBee malspam using Cisco AnyConnect as a lure. It contains a PDF with a link to a fake AnyConnect installer that opens AnyConnect on the Microsoft App Store to mask the BumbleBee infection 🔥 Payload delivery URLs: 🌐 urlhaus.abuse.ch/host/95.164.... Payload: 📄 bazaar.abuse.ch/sample/b8794...
Malicious BumbleBee PDF using Cisco AnyConnect as a lureMalicious download page using Cisco AnyConnect as a lure to infect users with BumbleBee malware
052
Reposted by Ole Villadsen
Cryptolaemus @cryptolaemus.bsky.social · 03/12/2024
#BruteRatel - #Latrodectus - url > .js > .msi > .dll wscript.exe Document-v15-51-07.js msiexec.exe /I C:\Users\Admin\AppData\Local\Temp\fes.msi rundll32.exe C:\Users\Admin\AppData\Roaming\avutil.dll, DLLMain (1/3)👇 IOC's github.com/pr0xylife/La...
1208
Reposted by Ole Villadsen
blackorbird @blackorbird.bsky.social · 27/11/2024
I really like the freedom of BlueSky's API and hope it can be maintained. I will use the API to push more IOCs.
011
Reposted by Ole Villadsen
Greg Lesnewich @greg-l.bsky.social · 25/11/2024
T-Minus 37 days til the next season of #100DaysofYARA kicks off!! Who’s excited and what will you be working on? I can’t believe it but I’m excited to write rules for JavaScript 😬😵‍💫 But also get to show off the new macho module from the one and only @jacoblatonis.me
063
Reposted by Ole Villadsen
Brad @malware-traffic-analysis.net · 22/11/2024
2024-11-22 (Friday) #XLoader / #Formbook: I've been fired by my non-existent HR department. At least I got a "salary-receipt.exe" bazaar.abuse.ch/sample/003b5... Tria.ge and Any.Run don't identify the malware, but Joe Sandbox does: www.joesandbox.com/analysis/156... Also runs in my lab just fine
Screenshot of malicious spam (malspam) with malware file attachment.Traffic from the XLoader (Formbook) infection filtered in Wireshark.
21710
Ole Villadsen @olevilladsen.bsky.social · 22/11/2024
Welcome Brad! @malware-traffic.bsky.social
120
Reposted by Ole Villadsen
Joe Roosen @jroosen.bsky.social · 21/11/2024
Very interesting story which in my opinion that shows how the Chinese surveillance state is even "knocking off" on itself when it comes to IP/Data. This is some great research from SpyCloud Labs! Very proud of the Labs Research Team! www.wired.com/story/chines...
wired.com
China’s Surveillance State Is Selling Citizen Data as a Side Hustle
Chinese black market operators are openly recruiting government agency insiders, paying them for access to surveillance data and then reselling it online—no questions asked.
082
Ole Villadsen @olevilladsen.bsky.social · 18/11/2024
For visibility - x0rz now on Blue Sky, so happy :)
100
Reposted by Ole Villadsen
Tommy Madjar @ffforward.bsky.social · 18/11/2024
New blog drop with @selenalarson.bsky.social and the rest of the team. This one covers a lot of threats using the #ClickFix technique to lure targets to infect themselves by pasting malicious CMD/PS code. My "fave" is the chumbox #malvertising on major tech sites. www.proofpoint.com/us/blog/thre...
0104
Reposted by Ole Villadsen
NOELREPORTS @noelreports.com · 17/11/2024
Reuters also confirms the story about Biden allowing Ukraine to use US arms to strike inside Russia, citing three sources familiar with the matter. Ukraine plans to conduct its first long-range attacks in the coming days. www.reuters.com/world/biden-...
2980392
Reposted by Ole Villadsen
Nathan McNulty @nathanmcnulty.com · 17/11/2024
Almost embarrassed to post this, but I've always used Fiddler or Burp for capturing things like this... I didn't have admin rights and was trying to capture network traffic from a pop-up, so Dev Tools wasn't working Apparently this is built into Chrome/Edge! So cool :) edge://net-export/
1518645
Ole Villadsen @olevilladsen.bsky.social · 17/11/2024
Two great easy-to-use tools to find new follows - both worked great.
020
Reposted by Ole Villadsen
Myrtus @malwareindepth.com · 16/11/2024
Smokeloader keeps crawling its way back into the limelight. If you want a primer on it, I gave a public talk on it 2 years ago www.youtube.com/watch?v=O69e...
youtube.com
Smokeloader: The Pandora’s box of tricks, payloads and anti-analysis - BSides Portland 2022
YouTube video by BSides Portland
1249
Reposted by Ole Villadsen
Christopher Glyer @cglyer.bsky.social · 06/07/2023
IMO: Storm-0875 (overlaps UNC3944/Scattered Spider) is the most dangerous financial threat actor right now Some recent developments: 1. Now deploying ransomware (had been extorting orgs before) 2. In last few months targeting large/well known enterprises (not just telcos/help desk/crypto orgs)
185