Sign in

pdub5.bsky.social

@pdub5.bsky.social
28 followers 33 following 8 posts
PostsRepliesMedia
pdub5.bsky.social @pdub5.bsky.social · 26/06/2026
Completely forgot to post this here last week. 😅 🚨Our latest research into a sophisticated PRC-nexus campaign! The threat actor is pursuing defense intelligence on AI, UVS, offensive cyber, medical research, and geo-strategic policy 🧑‍💻💉🌏. Read the full report here: cloud.google.com/blog/topics/...
cloud.google.com
Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research | Google Cloud Blog
UNC6508 leveraged Google Workspace compliance rules and REDCap vulnerabilities for intelligence collection.
021
Reposted by @pdub5.bsky.social
CYBERWARCON @cyberwarcon.bsky.social · 12/11/2025
CYBERWARCON is ONE WEEK AWAY! 💣💥💻 ✉️ Check out our website to view the agenda and plan your day, read more about our speakers, or buy a last minute ticket! We can't wait to see everyone in Arlington, VA on November 19th! www.cyberwarcon.com
043
pdub5.bsky.social @pdub5.bsky.social · 10/11/2025
I couldn't have asked for a better venue than #RooCon25 🇦🇺 for my first Cyber Threat Intel talk! It was an amazing and surreal experience. A huge thanks to the organizers for having me and another thanks to everyone that attended!
010
Reposted by @pdub5.bsky.social
CYBERWARCON @cyberwarcon.bsky.social · 05/11/2025
Meet our speaker Patrick Whitsell! Patrick has expertise in monitoring and defending against cyber espionage threat actors. His talk, "Cyber(trade)war: Paradigm Shift in Economic Espionage", will cover the shift in PRC state-sponsored cyber espionage. Learn more! www.cyberwarcon.com
043
pdub5.bsky.social @pdub5.bsky.social · 21/10/2025
Yes, no, maybe robot?? Which is it @wxs.bsky.social!? 🤖
100
pdub5.bsky.social @pdub5.bsky.social · 09/10/2025
I'm super excited to be speaking at @cyberwarcon.bsky.social this year! The lineup looks amazing, as always. including a keynote with Dimitri Alperovitch. 🤯 Check out the full agenda here! cyberwarcon.com/agenda-25
010
pdub5.bsky.social @pdub5.bsky.social · 09/09/2025
Join @austinlarsen.me and me next Tuesday for a deep-dive into PRC-nexus threat actor capabilities! Learn about advanced social engineering tactics, novel malware delivery, and strategies to defend your organization. www.brighttalk.com/webcast/7451...
011
pdub5.bsky.social @pdub5.bsky.social · 25/08/2025
New GTIG blog just dropped! 🥸🇨🇳🌐💼 ”Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats"! We're analyzing an operation that has it all; AitM, social engineering, signed malware, and more! Get the full breakdown here: cloud.google.com/blog/topics/...
cloud.google.com
PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats | Google Cloud Blog
A social engineering campaign leveraging signed malware, evasive tactics, and captive portal hijacking.
020
Reposted by @pdub5.bsky.social
Wesley Shields @wxs.bsky.social · 18/06/2025
So @gabagool.ing (who will henceforth be referred to as "gabbot") and I wrote some stuff on some ASP phishing campaigns: cloud.google.com/blog/topics/... Citizen Lab worked closely with one of the targets and shared their work on it also: citizenlab.ca/2025/06/russ...
cloud.google.com
What’s in an ASP? Creative Phishing Attack on Prominent Academics and Critics of Russia | Google Cloud Blog
A Russia-sponsored threat actor is impersonating the U.S. Department of State, and using phishing to gain access to email accounts.
0107
Reposted by @pdub5.bsky.social
Wesley Shields @wxs.bsky.social · 07/05/2025
I wrote some details on LOSTKEYS: malware which we directly attribute to COLDRIVER. They don't deploy it often, but we have seen it a few times and want to make people aware of it. cloud.google.com/blog/topics/...
cloud.google.com
COLDRIVER Using New Malware To Steal Documents From Western Targets and NGOs | Google Cloud Blog
Russian government-backed group COLDRIVER is using LOSTKEYS malware to steal files and system information from NGOs and western targets.
11714
pdub5.bsky.social @pdub5.bsky.social · 28/05/2025
🚨 Heads up! 🚨 APT41 is using Google Calendar 🗓️ as their latest C2 trick. GTIG just pulled back the curtain 🎭 on the TOUGHPROGRESS malware campaign and how we shut it down 💪. Dive into the details here: 🚀https://cloud.google.com/blog/topics/threat-intelligence/apt41-innovative-tactics
184