Sign in

Rony

@r0ny.bsky.social
126 followers 106 following 40 posts

Threat Intelligence Analyst

PostsRepliesMedia
Reposted by Rony
mad5quirrel.bsky.social @mad5quirrel.bsky.social · 02/03/2026
Reverse engineers often spend significant time deciphering third-party libraries within firmware. My talk, scheduled for Friday at 5 PM at Reverse, introduces SightHouse, an open-source initiative aimed at automatically identifying third-party functions to enhance analysis efficiency.
044
Reposted by Rony
Max 'Libra' Kersten @maxkersten.nl · 01/07/2025
Ghidra, scripting, LLM, automagic automation. That should grab the attention for this thread. If you want to read the complete blog, you can do so here: www.trellix.com/blogs/resear... 1/n
A side by side comparison of the original output by Ghidra, and the LLM enriched output.
195
Reposted by Rony
aptwhatnow.bsky.social @aptwhatnow.bsky.social · 14/05/2025
Many many folks in this effort over the years. Thankful for everyone and hope its of use.
1168
Reposted by Rony
Natto Thoughts @nattothoughts.bsky.social · 14/05/2025
The Natto Team continues finding stories of Chinese hackers fascinating as they reveal the motivations behind cyber operations and the evolution of China's information security industry. nattothoughts.substack.com/p/stories-of...
nattothoughts.substack.com
From the World of “Hacker X Files” to the Whitewashed Business Sphere
Jiang Jintao’s journey from hacker to infosec entrepreneur illustrates the blend of ambition, skill, and changes in China's cybersecurity industry
055
Reposted by Rony
Cipher Tech Solutions @ciphertech.bsky.social · 12/05/2025
The May release for ACCE includes updates and support including #AurotunStealer #rutserv #PupkinStealer #PE32Ransomware #Interlock www.ciphertechsolutions.com/acce-release...
ciphertechsolutions.com
ACCE Release Notes v2.9.20250508 – Cipher Tech Solutions, Inc.
011
Rony @r0ny.bsky.social · 30/04/2025
France just called out GRU Unit 20728 (166th Research Information Centre), posted up in Rostov-on-Don, for cyberattacks. Kremlin got new ops on the board. www.diplomatie.gouv.fr/en/country-f... @wylienewmark.bsky.social
diplomatie.gouv.fr
Russia – Attribution of cyber attacks on France to the Russian military intelligence service (APT28) (29.04.25)
France condemns in the strongest terms the use by Russia's military intelligence service (GRU) of the APT28 attack group, at the origin of several (…)
063
Reposted by Rony
Andrew Morris @andrewmorr.is · 21/04/2025
Yall are beyond not ready about the shit we're cooking up with @censys.bsky.social and @greynoise.io powers combined censys.com/blog/hunting...
censys.com
Hunting Botnets With CursorAI, GreyNoise, Censys, and Censeye
Threat hunting is made easier and simpler by combining the power of Censys, GreyNoise, CursorAI, and Censeye.
0258
Rony @r0ny.bsky.social · 15/04/2025
I'm always a big fan of @agreenberg.bsky.social's writing, but I don't see a clear reason to believe these six stories are connected to "lesser-known hacker groups."
000
Rony @r0ny.bsky.social · 09/04/2025
S02E01: Smoked Customers operation-endgame.com
000
Rony @r0ny.bsky.social · 09/04/2025
It's here! S02E01: Smoked customers
000
Rony @r0ny.bsky.social · 08/04/2025
Tick Tock ⏰
010
Reposted by Rony
Binary Ninja @binary.ninja · 07/04/2025
Kyle's talk at Insomni'Hack is live! youtu.be/I0PoE0IdtmE?... Check it out if you're interested in a slice of modern program analysis and try the latest version of Tanto as well, in the plugin manager or at github.com/Vector35/tanto
youtu.be
"A Slice Of" Modern Program Analysis - Kyle Martin
0116
Rony @r0ny.bsky.social · 30/03/2025
Cool stuff. Kudos to whoever at Censys wrote this. I researched the ORB network myself but lack access to historical data. Thanks for providing historical visibility. censys.com/junos-and-re...
censys.com
JunOS and RedPenguin
055
Rony @r0ny.bsky.social · 28/03/2025
Bring Back RiskIQ!
020
Rony @r0ny.bsky.social · 21/03/2025
🚨 ALEART 🚨 #UAT-5918 is the new #Winnti! 😂
010
Rony @r0ny.bsky.social · 13/03/2025
The R&D team at JuniperNetworks released a detailed 35-page malware analysis report "The RedPenguin Malware Incident", covering the #TINYSHELL components used by #UNC3886, including the C2 protocol structure. supportportal.juniper.net/sfc/servlet.shepherd/document/download/069Dp00000FzdmIIAR
supportportal.juniper.net
031
Rony @r0ny.bsky.social · 05/03/2025
APT27 & i-soon hackers charged by DOJ—12 caught as the cats are out of the bag now. Yet APT27’s infra still purrs. Let’s see how they claw back from this! www.justice.gov/opa/pr/justi...
justice.gov
Justice Department Charges 12 Chinese Contract Hackers and Law Enforcement Officers in Global Computer Intrusion Campaigns
The Justice Department, FBI, Naval Criminal Investigative Service, and Departments of State and the Treasury announced today their coordinated efforts to disrupt and deter the malicious cyber activiti...
021
Rony @r0ny.bsky.social · 27/02/2025
Epic collab, UNC4899 🤝 UNC5267 FBI official advisory on Bybit crypto theft www.ic3.gov/PSA/2025/PSA...
ic3.gov
Internet Crime Complaint Center (IC3) | North Korea Responsible for $1.5 Billion Bybit Hack
020
Reposted by Rony
Rikmer @rikmer.bsky.social · 24/02/2025
@shodanhq.bsky.social Awesome! Shodan History is back in the UI. Nice!!! Thank you. But I have a question regarding trends.shodan.io. all trends I do are stopping at October 2024. Why? Please make them to the current data again. I love it and need it. :)
trends.shodan.io
Shodan
Shodan Trends - Discover how the Internet has changed over time.
044
Reposted by Rony
Dan Black @danwblack.bsky.social · 19/02/2025
Today, Google Threat Intelligence is alerting the community to increasing efforts from several Russia state-aligned threat actors (GRU, FSB, etc.) to compromise Signal Messenger accounts. cloud.google.com/blog/topics/...
cloud.google.com
Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger | Google Cloud Blog
Russia state-aligned threat actors target Signal Messenger accounts used by individuals of interest to Russia's intelligence services.
3165115
Reposted by Rony
geech @captaingee.ch · 15/02/2025
This latest blog from Cyfirma on Cl0p/Cleo exploitation is utter garbage, ignore it. LLM YARA rule (not even valid syntax), massively inflated statistics, and misleading IOCs and analysis. www.cyfirma.com/research/cl0...
cyfirma.com
CL0P Ransomware : Latest Attacks - CYFIRMA
INTRODUCTION The Cl0p group has been active since early 2019, leveraging vulnerabilities and exploits to encrypt files for ransom. The...
152
Rony @r0ny.bsky.social · 10/02/2025
Excited to receive the @abuse-ch.bsky.social& @spamhaus.bsky.social swag! 🎁 Thank you for sending this amazing package. It means a lot to be recognized as a Top Contributor in the fight against cybercrime. Looking forward to continuing our battle together! 💪 #StrengthINUnity
270
Reposted by Rony
IntelCorgi @intelcorgi.bsky.social · 06/02/2025
I miss the free version of riskIQ
052
Reposted by Rony
abuse-ch.bsky.social @abuse-ch.bsky.social · 06/02/2025
A BIG thank you to our top contributors🎖️for sharing valuable technical cyber threat intelligence on our platforms over the past year. 🙏 Your efforts had a significant impact on cyber security, making the internet a safer place👏💪🛡️ A nice surprise is coming your way! 🎁 👀👇
051
Rony @r0ny.bsky.social · 31/01/2025
#CMS8000 backdoor Hardcoded IP: 202.114.4[.]119 (h/t @craiu.bsky.social) registered to Tsinghua University 👀 VT link: www.virustotal.com/gui/file/4e4... 📝 www.cisa.gov/sites/defaul...
cisa.gov
020
Rony @r0ny.bsky.social · 29/01/2025
The blog feels like a retro FLARE blog from the good old FireEye days! Shout out to Nino Isakovic, @qutluch.bsky.social and @lukejenx.bsky.social cloud.google.com/blog/topics/...
cloud.google.com
ScatterBrain: Unmasking the Shadow of PoisonPlug's Obfuscator | Google Cloud Blog
We been tracking multiple espionage operations conducted by China-nexus actors utilizing POISONPLUG.SHADOW malware.
1124
Reposted by Rony
Rony @r0ny.bsky.social · 27/01/2025
⚖️EU sanctions three Russian GRU Unit 29155 officers for cyberattacks against Estonia in 2020. www.consilium.europa.eu/en/press/pre... Individuals Sanctioned: 1️⃣Nikolay Alexandrovich KORCHAGIN 2️⃣Vitaly SHEVCHENKO 🆕 3️⃣Yuriy Fedorovich DENISOV 📎 eur-lex.europa.eu/legal-conten...
consilium.europa.eu
Cyber-attacks: three individuals added to EU sanctions list for malicious cyber activities against Estonia
The Council imposed restrictive measures on three individuals involved in cyber-attacks against Estonia.
001
Rony @r0ny.bsky.social · 27/01/2025
⚖️EU sanctions three Russian GRU Unit 29155 officers for cyberattacks against Estonia in 2020. www.consilium.europa.eu/en/press/pre... Individuals Sanctioned: 1️⃣Nikolay Alexandrovich KORCHAGIN 2️⃣Vitaly SHEVCHENKO 🆕 3️⃣Yuriy Fedorovich DENISOV 📎 eur-lex.europa.eu/legal-conten...
consilium.europa.eu
Cyber-attacks: three individuals added to EU sanctions list for malicious cyber activities against Estonia
The Council imposed restrictive measures on three individuals involved in cyber-attacks against Estonia.
001
Reposted by Rony
Wesley Shields @wxs.bsky.social · 24/12/2024
Spent a bit of time adding some new features to “yr fmt” that I suspect will be well liked and very useful if you write a lot of rules and like consistency. I have the gist of it but am stumbling over some rust intricacies for the first time. Maybe by the end of the year I’ll have it done.
032
Rony @r0ny.bsky.social · 19/12/2024
Just read this @sekoia.io's blog, and wow, it's a cool deep dive into how they use YARA internally! They go deep into metadata which you don't hear much about. Good stuff if you're into the nitty-gritty of YARA. blog.sekoia.io/happy-yara-c... #yara #threatintelligence
blog.sekoia.io
Happy YARA Christmas!
Discover daily YARA usage at Sekoia.io TDR. Learn how YARA rules identify threats and aid in investigations and DFIR engagements.
080
Rony @r0ny.bsky.social · 17/12/2024
A new #yara-x release is out with some small improvements and bugfix. github.com/VirusTotal/y...
github.com
Release v0.12.0 · VirusTotal/yara-x
The macho module now parses and exposesLC_LINKER_OPTION commands (#256). Raise warning with some patterns that have too many 2-byte atoms and are potentially slow (#264). Extract more information ...
174
Rony @r0ny.bsky.social · 17/12/2024
Russia’s cyber warfare evolved with #SecretBlizzard (APT) repurposing tools from other groups (Storm-1837 & Storm-1919) for targeted operations. The analysis details ongoing attacks on Ukraine, showcasing the group’s resource-sharing strategy and growing sophistication. tinyurl.com/4kzn3zcv
microsoft.com
Frequent freeloader part II: Russian actor Secret Blizzard using tools of other groups to attack Ukraine | Microsoft Security Blog
Since January 2024, Microsoft has observed Secret Blizzard using the tools or infrastructure of other threat groups to attack targets in Ukraine and download its custom backdoors Tavdig and KazuarV2.
010
Rony @r0ny.bsky.social · 10/12/2024
Two more suspected #Zloader HTTPS C2 server theartofshare./com (193.188.22.125:443) ~ 2024-11-12 checkpointone./world (147.45.79.30:443) ~ 2024-06-14 www.zscaler.com/blogs/securi...
zscaler.com
Inside Zloader’s Latest Trick: DNS Tunneling
Discover how Zloader 2.9.4.0 implemented a custom DNS tunneling protocol combined with TLS encryption to evade network detection.
030
Rony @r0ny.bsky.social · 04/12/2024
Secret Blizzard: the hand-me-down hacker collective! After using tools from Hazel Sandstorm & Storm-0473, they’re now remixing Storm-0156’s infrastructure for fresh espionage hits. Also, they've leveraged resources from at least 6 other threat actors in the past! 👀 www.microsoft.com/en-us/securi...
microsoft.com
Frequent freeloader part I: Secret Blizzard compromising Storm-0156 infrastructure for espionage | Microsoft Security Blog
Microsoft has observed Secret Blizzard compromising the infrastructure and backdoors of the Pakistan-based threat actor we track as Storm-0156 for espionage against the Afghanistan government and Indi...
200
Rony @r0ny.bsky.social · 30/11/2024
See you 🔜 Boris! ⚖️
000
Reposted by Rony
Horkos @wylienewmark.bsky.social · 22/11/2024
Close access technical operations are never going away; there’ll always be at least edge cases requiring physical proximity to target. But given the risks involved, pursuing remote means to achieve “close”-style tactics is likely a trend that has been ongoing but only just now coming into the light.
1294
Rony @r0ny.bsky.social · 21/11/2024
🚨 Microsoft’s Digital Crimes Unit takes aim at Storm-0867, the operator behind the #Caffeine Phishing-as-a-Service (PhaaS) platform ☕. A major crackdown on the cybercrime supply chain! blogs.microsoft.com/on-the-issue... 📜Unsealed court order: www.noticeofpleadings.com/fakeonnx/
blogs.microsoft.com
Targeting the cybercrime supply chain
Microsoft’s Digital Crimes Unit (DCU) has seized 256 fraudulent websites linked to ‘MRxC0DER’, who sold phishing kits under the brand names ‘ONNX’ and ‘Caffeine’. This takedown disrupts a significant ...
041
Reposted by Rony
Kyle Eaton @0xkyle.bsky.social · 19/11/2024
Yara rule to match concatenated zip files. I like this one (biased) because of how we are able to avoid matching nested zip files. More info: x.com/threatinsigh... #yara github.com/EmergingThre...
github.com
threatresearch/yara/zip_file.yara at master · EmergingThreats/threatresearch
I wanted to call this repo "Nuclear Football Codes". I was outvoted.. - EmergingThreats/threatresearch
2137
Reposted by Rony
Horkos @wylienewmark.bsky.social · 26/09/2024
ESET’s latest, a roundup on 2 years of Gamaredon/PRIMITIVE BEAR ops targeting Ukraine, is a banner example of how cyber operations are primarily used—and better suited—for intelligence collection. While the GRU is playing cyber soldier to avoid the front, FSB Center 18 is on that espionage grind.
welivesecurity.com
Cyberespionage the Gamaredon way: Analysis of toolset used to spy on Ukraine in 2022 and 2023
ESET Research has conducted a comprehensive technical analysis of Gamaredon’s toolset used to conduct its cyberespionage activities focused in Ukraine.
0115
Reposted by Rony
Daniel Gordon @validhorizon.bsky.social · 15/09/2024
For a great discussion about a couple North Korean threat actors, check out this podcast thecyberwire.com/podcasts/mic...
thecyberwire.com
Citrine and Onyx Sleet: An Inside Look at North Korean Threat Actors
In this episode of the Microsoft Threat Intelligence Podcast host Sherrod DeGrippo discusses North Korean threat actors with one of our Microsoft Threat Intelligence researchers and Greg Schloemer focusing on two prominent groups: Onyx Sleet and Storm 0530. Onyx Sleet is a long-standing espionage group known for targeting defense and energy sectors, particularly in the U.S. and India. However, they’ve diversified into ransomware, using tactics like malware downloaders, zero-day vulnerabilities, and a remote access Trojan called D-Track. The conversation also touches on the use of fake certificates and the group's involvement in the software supply chain space.
122