Sign in

Sekoia

@sekoia.com
468 followers 38 following 164 posts

Sekoia is the European cybersecurity company building the Cyber Operations Platform for the AI era.

PostsRepliesMedia
Sekoia @sekoia.com · 21/09/2026
TDR analysts uncovered #Exvicy, an emerging #ClickFix MaaS sold on Exploit.IN since May 2026. We assess with high confidence that Exvicy is a copycat of #ErrTraffic, reusing its injected JavaScript, ClickFix HTML, and C2 communication logic. buff.ly/nKNSjMy
101
Sekoia @sekoia.com · 07/09/2026
North Korea’s cyber program was built to serve two purposes: intelligence collection and revenue generation. A new joint report from Sekoia #TDR and @KudelskiSec examines how that system is organized. buff.ly/vmqOr9d
223
Sekoia @sekoia.com · 01/07/2026
Don’t Eat The #ChocoPoCs! How Vulnerability Researchers Were Repeatedly Targeted By Trojanised Exploits www.sekoia.com/blog/dont-ea... Discover our joint threat intelligence report with @YesWeHack.
100
Sekoia @sekoia.com · 26/06/2026
Our latest Threat Intelligence report dives deep into ADINT (Advertisement-based Intelligence) to expose how private companies weaponise AdTech mechanisms to harvest intelligence data, fueling the surveillance solutions they sell. www.sekoia.com/blog/sold-to...
123
Sekoia @sekoia.com · 16/06/2026
#TDR analysts published a new report detailing #ErrTraffic, a widespread #ClickFix malware distribution framework. ErrTraffic injects malicious JavaScript into compromised WordPress and malicious sites to serve ClickFix lures. blog.sekoia.io/unveiling-er...
243
Sekoia @sekoia.com · 11/06/2026
🇷🇺 Sekoia #TDR team has just released a comprehensive analysis of how #APT28's arsenal has evolved, from its early to its current operations. blog.sekoia.io/apt28-an-evo...
132
Sekoia @sekoia.com · 08/06/2026
The second and third parts of our investigation into the #Gamaredon, the cyberespionage group operated by the Russian #FSB, are live! 🪆Part 2 — The loaders buff.ly/bBYZSKa 🪆Part 3 — The stealer & full infrastructure buff.ly/74WHuPd #CTI #TDR #Sekoia
011
Sekoia @sekoia.com · 01/06/2026
Russia's #FSB-linked #Gamaredon has been hammering Ukraine's government, military & critical infrastructure for over a decade. We went behind the scenes. Tracked their infrastructure. Recovered artefacts from compromised machines. Here's what we found 🧵 buff.ly/6hR2IMj
241
Sekoia @sekoia.com · 08/04/2026
Part 2 of our #EvilTokens analysis is live. TDR analysts uncovered the AI-augmented features that automate and scale #BEC workflows, marking a breakthrough in the #PhaaS ecosystem. blog.sekoia.io/eviltokens-a...
120
Sekoia @sekoia.com · 30/03/2026
#TDR analysts uncovered an emerging Phishing-as-a-Service (#PhaaS) platform called #EvilTokens, which offers device code phishing pages and AI-augmented features to automate and scale #BEC workflows. ⬇️ blog.sekoia.io/new-widespre...
100
Sekoia @sekoia.com · 25/03/2026
#SilverFox is a China-based intrusion set operating on a unique "dual-track" model. While often tracked for their APT-style espionage, our telemetry shows they continuously run broad, opportunistic cybercrime campaigns targeting entities across South Asia. blog.sekoia.io/silver-fox-t...
212
Sekoia @sekoia.com · 12/02/2026
#OysterLoader (aka #Broomstick or #Cleanup) is not just another downloader. Often serving as a precursor to #Rhysida #ransomware campaigns or distributing commodity malware such as #Vidar, this threat has evolved significantly as we enter 2026. blog.sekoia.io/oysterloader... #Reverse
223
Sekoia @sekoia.com · 29/01/2026
#TDR analysts deep dived into a widespread malicious JavaScript framework injected into 3,800+ WordPress sites to distribute #NetSupport RAT via the #ClickFix social engineering tactic. blog.sekoia.io/meet-iclickf...
222
Sekoia @sekoia.com · 14/01/2026
🐧 Leveraging #Landlock Telemetry for #Linux Detection Engineering Sekoia #TDR explores how Linux Landlock telemetry can be leveraged to build high-fidelity, low-noise detections by observing sandbox policy violations. blog.sekoia.io/leveraging-l...
112
Sekoia @sekoia.com · 15/12/2025
🎅 Check out the first three episodes of our special Advent of Configuration Extraction Part 1: buff.ly/mpEzALh Part 2: buff.ly/agWWCnp Part3: buff.ly/Crz8rDh 🎄 Last part following Monday! 🎄
101
Sekoia @sekoia.com · 04/12/2025
🇷🇺 French NGO Reporters Without Borders targeted by #Calisto in recent campaign Sekoia #TDR analysed a recent #Calisto (aka #ColdRiver #Star Blizzard) spear-phishing campaign aimed at Reporters sans frontières and other #Ukraine-supporting organisations. blog.sekoia.io/ngo-reporter...
154
Reposted by Sekoia
Hervé Schauer @herve-schauer.bsky.social · 08/11/2025
Histoire et dissection du 𝑚𝑎𝑙𝑤𝑎𝑟𝑒 ou chargeur malveillant 🇷🇺 #Latrodectus par Pierre Le Bourhis @sekoia.io à #UYBHYS25 @uybhys.bsky.social
152
Sekoia @sekoia.com · 06/11/2025
#TDR analysts dig into a modus operandi targeting the hospitality industry and the related cybercrime ecosystem that facilitates #phishing and #fraud campaigns. blog.sekoia.io/phishing-cam...
153
Sekoia @sekoia.com · 23/10/2025
Discover how #TransparentTribe (#APT36) uses a disguised DESKTOP dropper to deploy #DeskRAT, a Golang RAT, on BOSS Linux endpoints in India. Our Sekoia #TDR report breaks down the full infection chain and stealthy WebSocket C2 communications . Read more 👉 blog.sekoia.io/transparentt...
011
Sekoia @sekoia.com · 21/10/2025
Our latest technical deep-dive unravels the mystery behind the opaque numeric codes (16, 272, 33554432, etc.) you see in #Microsoft365 audit logs. blog.sekoia.io/userauthenti...
210
Sekoia @sekoia.com · 14/10/2025
After our initial #PolarEdge #botnet write-up, we’re happy to announce the second part: “Defrosting PolarEdge’s Backdoor,” a full technical deep-dive into its TLS-based implant. blog.sekoia.io/polaredge-ba...
123
Reposted by Sekoia
Nicolas Caproni @caproni.fr · 06/10/2025
Je recherche un Threat Researcher pour l’équipe TDR de @sekoia.io ! Vous aimez faire des règles #Sigma et #Yara ? Vous adorez pivoter et traquer les infrastructures (C2) d’attaques des cybercriminels ? Alors cette offre d’emploi est faite pour vous ! www.welcometothejungle.com/en/companies...
welcometothejungle.com
Technical Threat Researcher – Sekoia.io – Permanent contract – Fully-remote
Sekoia.io is looking for a Technical Threat Researcher!
021
Sekoia @sekoia.com · 02/10/2025
📱 Silent Smishing: The Hidden Abuse of Cellular Router APIs Our latest #CTI investigation from Sekoia #TDR team uncovers a novel #smishing vector abusing Milesight industrial cellular router APIs to send phishing #SMS at scale. blog.sekoia.io/silent-smish...
164
Sekoia @sekoia.com · 16/09/2025
🐻 #APT28 – Operation Phantom Net Voxel: deep-dive into the latest spear-phishing campaign targeting Ukrainian military administrative staff. blog.sekoia.io/apt28-operat...
122
Sekoia @sekoia.com · 02/09/2025
[Threat investigation alert 🚨] Predators for Hire: A Global Overview of Commercial Surveillance Vendors ➡️ blog.sekoia.io/predators-fo...
124
Sekoia @sekoia.com · 21/07/2025
🔥 Hot summer, sizzling crypto... and scammers turning up the heat 🔥 Back in March, Sekoia #TDR team published a deep-dive report on a #Lazarus cluster we dubbed #ClickFake Interview, leveraging the #ClickFix technique in their #ContagiousInterview campaign.
111
Sekoia @sekoia.com · 08/07/2025
A few weeks ago, we published our global analysis of Adversary-in-the-Middle #phishing threats, providing actionable intelligence on multiple #AitM phishing kits. This report includes 11 sheets covering the most widespread #AitM phishing kits as of Q1 2025.
152
Sekoia @sekoia.com · 11/06/2025
📝 Our latest #TDR report delivers an in-depth analysis of Adversary-in-the-Middle (#AitM) #phishing threats - targeting Microsoft 365 and Google accounts - and their ecosystem. This report shares actionable intelligence to help analysts detect and investigate AitM phishing.
1107
Sekoia @sekoia.com · 27/05/2025
🧀 The Sharp Taste of #Mimo’lette: Analyzing Mimo’s Latest Campaign targeting #Craft CMS blog.sekoia.io/the-sharp-ta...
blog.sekoia.io
The Sharp Taste of Mimo'lette: Analyzing Mimo’s Latest Campaign targeting Craft CMS
Analysis of the CVE-2025-32432 compromise chain by Mimo: exploitation, loader, crypto miner, proxyware, and detection opportunities.
031
Sekoia @sekoia.com · 22/05/2025
🪤 Sekoia #TDR's new exclusive research uncovers the #ViciousTrap, a honeypot network deployed on compromised edge devices. blog.sekoia.io/vicioustrap-...
blog.sekoia.io
ViciousTrap - Infiltrate, Control, Lure: Turning edge devices into honeypots en masse.
Discover ViciousTrap, a newly identified threat who turning edge devices into honeypots en masse targeting
042
Sekoia @sekoia.com · 23/04/2025
Our new report describes one of the latest observed infection chains (delivering #AsyncRAT) relying on the #Cloudflare tunnel infrastructure and the attacker’s #TTPs with a principal focus on detection opportunities. blog.sekoia.io/detecting-mu...
021
Sekoia @sekoia.com · 16/04/2025
Since the apparition of the #Interlock ransomware, the Sekoia #TDR team observed its operators evolving, improving their toolset (#LummaStealer and #BerserkStealer), and leveraging new techniques such as #ClickFix to deploy the ransomware payload. blog.sekoia.io/interlock-ra...
025
Sekoia @sekoia.com · 09/04/2025
🎉 It's not about a CTI investigation or a Detection Engineering topic, but today we are happy to announce that Sekoia.io has raised €26m! www.sekoia.io/en/presse/se...
031
Sekoia @sekoia.com · 31/03/2025
🇰🇵 Sekoia #TDR team investigated a malicious campaign that employs fake job interview websites to deliver backdoors on Windows and macOS - #GolangGhost using #ClickFix tactic. Dubbed #ClickFake Interview, this campaign has been attributed to #Lazarus APT blog.sekoia.io/clickfake-in...
052
Reposted by Sekoia
Sekoia @sekoia.com · 19/03/2025
TDR analysts published an analysis of the new #ClearFake variant that relies on compromised websites injected with the malicious JavaScript framework, the #EtherHiding technique, and the #ClickFix social engineering tactic. buff.ly/vbiVbsN
blog.sekoia.io
ClearFake’s New Widespread Variant: Increased Web3 Exploitation for Malware Delivery
ClearFake spreads malware via compromised websites, using fake CAPTCHAs, JavaScript injections, and drive-by downloads.
153
Sekoia @sekoia.com · 19/03/2025
TDR analysts published an analysis of the new #ClearFake variant that relies on compromised websites injected with the malicious JavaScript framework, the #EtherHiding technique, and the #ClickFix social engineering tactic. buff.ly/vbiVbsN
blog.sekoia.io
ClearFake’s New Widespread Variant: Increased Web3 Exploitation for Malware Delivery
ClearFake spreads malware via compromised websites, using fake CAPTCHAs, JavaScript injections, and drive-by downloads.
153
Sekoia @sekoia.com · 10/03/2025
The conclusion (part three) of our series on #DetectionEngineering is finally here! buff.ly/dijB0fy
031
Sekoia @sekoia.com · 25/02/2025
Using our #honeypots, we uncovered an unreported #botnet that has been operational since at least the end of November 2023. This #PolarEdge botnet has been focusing on #edge devices, particularly those made by #Cisco, #Asus, #QNAP, and #Synology. buff.ly/4ibOEo8
053
Sekoia @sekoia.com · 24/02/2025
Cyber threats impacting the financial sector: focus on the main actors We're thrilled to announce the release of the latest strategic report by Sekoia #TDR. This analysis highlights key cyber threats to the #financial sector in 2024. buff.ly/3D3IZl7
052
Sekoia @sekoia.com · 17/02/2025
🐭 RATatouille: Cooking Up Chaos in the I2P Kitchen 🔍 Our Threat Detection & Research (TDR) team has been analyzing a sophisticated new malware, #I2PRAT, featured in our latest FLINT report- now available in our blog! buff.ly/3WVWpqe
141
Sekoia @sekoia.com · 17/02/2025
🐭 RATatouille: Cooking Up Chaos in the I2P Kitchen 🔍 Our Threat Detection & Research (TDR) team has been analyzing a sophisticated new malware, #I2PRAT, featured in our latest FLINT report- now available in our blog! buff.ly/3WVWpqe
100
Sekoia @sekoia.com · 17/02/2025
🐭 RATatouille: Cooking Up Chaos in the I2P Kitchen 🔍 Our Threat Detection & Research (TDR) team has been analyzing a sophisticated new malware, #I2PRAT, featured in our latest FLINT report- now available in our blog! buff.ly/3WVWpqe
100
Sekoia @sekoia.com · 04/02/2025
🔍 Large-scale detection engineering: part two! 🚀 In this article, we explore an innovative approach that transforms the execution of automated actions via CI/CD pipelines, enabling effective scaling and alignment with developer and DevOps practices.
buff.ly
Detection engineering at scale: one step closer (part two)
Discover the power of detection engineering and how it can help scale your cybersecurity projects efficiently.
031
Reposted by Sekoia
Nicolas Caproni @caproni.fr · 29/01/2025
🚨To strengthen the #investigation and #detection capabilities of the Sekoia.io Threat Detection & Research (TDR) team, we are looking for a Senior Technical Threat Researcher! www.welcometothejungle.com/fr/companies... #CTI #DetectionEngineering
welcometothejungle.com
Sr Technical Threat Researcher - Sekoia.io - CDI - Télétravail total
Sekoia.io recrute un(e) Sr Technical Threat Researcher !
054
Sekoia @sekoia.com · 22/01/2025
TDR analysts analysed the supply chain attack targeting Chrome browser extensions, which potentially affected hundreds of thousands of end users in December 2024. buff.ly/4auQ0HN
184
Reposted by Sekoia
crep1x @crep1x.bsky.social · 20/01/2025
Around 1,000 malicious domains are hosting webpages impersonating Reddit and WeTransfer, redirecting users to download password-protected archives These archives contain an AutoIT dropper, we internally named #SelfAU3 Dropper at @sekoia.io, which executes #Lumma Stealer IoCs ⬇️
296
Sekoia @sekoia.com · 16/01/2025
🔍 TDR analysts discovered a new Adversary-in-the-Middle (#AiTM) #phishing kit, specifically targeting Microsoft 365 accounts and circumventing 2-step verification: Sneaky 2FA blog.sekoia.io/sneaky-2fa-exposing-… #detection #sneaky2fa
blog.sekoia.io
Sneaky 2FA: exposing a new AiTM Phishing-as-a-Service
In this blog post, learn about Sneaky 2FA, a new Adversary-in-the-Middle (AiTM) phishing kit targeting Microsoft 365 accounts.
153
Sekoia @sekoia.com · 13/01/2025
🇷🇺 #DoubleTap Campaign: #Russia-nexus APT possibly related to #APT28 conducts cyber espionage on Central Asia and Kazakhstan diplomatic relations buff.ly/3WEwPG7
175
Sekoia @sekoia.com · 09/01/2025
A look back at #PlugX #worm “sovereign disinfection” campaign
blog.sekoia.io
PlugX worm disinfection campaign feedbacks
Discover how we successfully disinfected thousands of computers infected with the PlugX worm using two remote disinfection methods.
043
Reposted by Sekoia
Sekoia @sekoia.com · 19/12/2024
Please Santa please, gimme some #YARA 🎅🎄 This blog post on our use of #YARA rules is also an opportunity for us to announce the release of hundreds of our #YARA rules on GitHub, which are now directly integrated into VirusTotal for detection. blog.sekoia.io/happy-yara-christmas
131