Sign in

Sekoia

@sekoia.com
469 followers 38 following 166 posts

Sekoia is the European cybersecurity company building the Cyber Operations Platform for the AI era.

PostsRepliesMedia
Sekoia @sekoia.com · 01/10/2026
Sekoia #TDR team traces how the operation reached cloud and SaaS environments, then turned trusted access into money. Written with @BeazleySecurity, the report also draws on first-hand incident response from a zero-day Oracle PeopleSoft compromise.
120
Sekoia @sekoia.com · 01/10/2026
What makes #ShinyHunters hard to stop? Well… the name can survive the people using it. Since 2020, changing operators have used the name to steal data and run extortion schemes. www.sekoia.com/blog/gotta-b...
121
Sekoia @sekoia.com · 21/09/2026
TDR analysts uncovered #Exvicy, an emerging #ClickFix MaaS sold on Exploit.IN since May 2026. We assess with high confidence that Exvicy is a copycat of #ErrTraffic, reusing its injected JavaScript, ClickFix HTML, and C2 communication logic. buff.ly/nKNSjMy
101
Sekoia @sekoia.com · 07/09/2026
The research maps the institutions responsible for North Korea’s cyber offensive operations, including recent reorganizations and the intrusion sets operating under them.
110
Sekoia @sekoia.com · 07/09/2026
North Korea’s cyber program was built to serve two purposes: intelligence collection and revenue generation. A new joint report from Sekoia #TDR and @KudelskiSec examines how that system is organized. buff.ly/vmqOr9d
223
Sekoia @sekoia.com · 01/07/2026
Don’t Eat The #ChocoPoCs! How Vulnerability Researchers Were Repeatedly Targeted By Trojanised Exploits www.sekoia.com/blog/dont-ea... Discover our joint threat intelligence report with @YesWeHack.
100
Sekoia @sekoia.com · 26/06/2026
Our latest Threat Intelligence report dives deep into ADINT (Advertisement-based Intelligence) to expose how private companies weaponise AdTech mechanisms to harvest intelligence data, fueling the surveillance solutions they sell. www.sekoia.com/blog/sold-to...
123
Sekoia @sekoia.com · 16/06/2026
Our forensic analysis of compromised WordPress servers helped us to cluster ErrTraffic and map affiliates' TTPs and backdoors. We notably identified two distinct clusters: "Analytics" operated by a single threat actor, and "Beer" likely operated by LenAI for affiliates.
111
Sekoia @sekoia.com · 16/06/2026
#TDR analysts published a new report detailing #ErrTraffic, a widespread #ClickFix malware distribution framework. ErrTraffic injects malicious JavaScript into compromised WordPress and malicious sites to serve ClickFix lures. blog.sekoia.io/unveiling-er...
243
Sekoia @sekoia.com · 11/06/2026
🇷🇺 Sekoia #TDR team has just released a comprehensive analysis of how #APT28's arsenal has evolved, from its early to its current operations. blog.sekoia.io/apt28-an-evo...
132
Sekoia @sekoia.com · 08/06/2026
The second and third parts of our investigation into the #Gamaredon, the cyberespionage group operated by the Russian #FSB, are live! 🪆Part 2 — The loaders buff.ly/bBYZSKa 🪆Part 3 — The stealer & full infrastructure buff.ly/74WHuPd #CTI #TDR #Sekoia
011
Sekoia @sekoia.com · 01/06/2026
Russia's #FSB-linked #Gamaredon has been hammering Ukraine's government, military & critical infrastructure for over a decade. We went behind the scenes. Tracked their infrastructure. Recovered artefacts from compromised machines. Here's what we found 🧵 buff.ly/6hR2IMj
241
Sekoia @sekoia.com · 08/04/2026
The EvilTokens PhaaS runs via fully featured Telegram bots and continuously enhances its phishing kit with new capabilities.
100
Sekoia @sekoia.com · 08/04/2026
Part 2 of our #EvilTokens analysis is live. TDR analysts uncovered the AI-augmented features that automate and scale #BEC workflows, marking a breakthrough in the #PhaaS ecosystem. blog.sekoia.io/eviltokens-a...
120
Sekoia @sekoia.com · 30/03/2026
Active since late February 2026 and rapidly adopted by cybercriminals, TDR analysts believe EvilTokens will become a serious competitor in the phishing and BEC landscape.
100
Sekoia @sekoia.com · 30/03/2026
#TDR analysts uncovered an emerging Phishing-as-a-Service (#PhaaS) platform called #EvilTokens, which offers device code phishing pages and AI-augmented features to automate and scale #BEC workflows. ⬇️ blog.sekoia.io/new-widespre...
100
Sekoia @sekoia.com · 25/03/2026
Key findings: 🎣 Deceptive Lures: Consistently impersonates national taxation authorities or uses fake payroll documents to trick victims into executing payloads. 🌊 3-Wave Arsenal Evolution: Between 2025 and 2026, their attack chains shifted significantly to evade detection.
100
Sekoia @sekoia.com · 25/03/2026
In this deep-dive analysis, our Threat Detection & Research (#TDR) team unmasks their massive 2025-2026 campaign and rapidly evolving infection chains.
100
Sekoia @sekoia.com · 25/03/2026
#SilverFox is a China-based intrusion set operating on a unique "dual-track" model. While often tracked for their APT-style espionage, our telemetry shows they continuously run broad, opportunistic cybercrime campaigns targeting entities across South Asia. blog.sekoia.io/silver-fox-t...
212
Sekoia @sekoia.com · 12/02/2026
🎭 Advanced Evasion: Packed with TextShell for enhanced obfuscation (custom LZMA); utilizes API "hammering" and anti-debug traps to bypass detection and delay manual analysis.
110
Sekoia @sekoia.com · 12/02/2026
#OysterLoader (aka #Broomstick or #Cleanup) is not just another downloader. Often serving as a precursor to #Rhysida #ransomware campaigns or distributing commodity malware such as #Vidar, this threat has evolved significantly as we enter 2026. blog.sekoia.io/oysterloader... #Reverse
223
Sekoia @sekoia.com · 29/01/2026
The attacker is abusing the open-source URL shortener YOURLS as a Traffic Distribution System (TDS), filtering visitors by device type and protecting their infrastructure. To our knowledge, this is the first time cybercriminals have used YOURLS as a TDS.
110
Sekoia @sekoia.com · 29/01/2026
We named the framework "IClickFix" after its characteristic HTML the tag "ic-tracker-js". In November 2025, we unveiled IClickFix via an internal tool detecting watering hole attacks and YARA rules tuned to identify ClickFix pages.
110
Sekoia @sekoia.com · 29/01/2026
#TDR analysts deep dived into a widespread malicious JavaScript framework injected into 3,800+ WordPress sites to distribute #NetSupport RAT via the #ClickFix social engineering tactic. blog.sekoia.io/meet-iclickf...
222
Sekoia @sekoia.com · 14/01/2026
🐧 Leveraging #Landlock Telemetry for #Linux Detection Engineering Sekoia #TDR explores how Linux Landlock telemetry can be leveraged to build high-fidelity, low-noise detections by observing sandbox policy violations. blog.sekoia.io/leveraging-l...
112
Sekoia @sekoia.com · 15/12/2025
In the third part of our series “Advent of Configuration Extraction”, we dissect #SNOWLIGHT, a lightweight ELF downloader designed to retrieve and execute a remote payload on #Linux systems. buff.ly/Crz8rDh
000
Sekoia @sekoia.com · 15/12/2025
In the second part, we unwrap #QuasarRAT, a popular .NET remote access trojan, and show how to extract its encrypted configuration out of the binary. buff.ly/agWWCnp
100
Sekoia @sekoia.com · 15/12/2025
The first part introduces #Assemblyline, the analysis pipeline used by #TDR and more specifically, the configextractor service. buff.ly/mpEzALh
100
Sekoia @sekoia.com · 15/12/2025
🎅 Check out the first three episodes of our special Advent of Configuration Extraction Part 1: buff.ly/mpEzALh Part 2: buff.ly/agWWCnp Part3: buff.ly/Crz8rDh 🎄 Last part following Monday! 🎄
101
Sekoia @sekoia.com · 04/12/2025
🇷🇺 French NGO Reporters Without Borders targeted by #Calisto in recent campaign Sekoia #TDR analysed a recent #Calisto (aka #ColdRiver #Star Blizzard) spear-phishing campaign aimed at Reporters sans frontières and other #Ukraine-supporting organisations. blog.sekoia.io/ngo-reporter...
154
Sekoia @sekoia.com · 06/11/2025
Our blog post provides an overview of the services facilitating this modus operandi and the market for infostealer logs tied to booking platforms, including underground activities around Booking[.]com data on Russian-speaking cybercrime forums.
010
Sekoia @sekoia.com · 06/11/2025
In this report, we analysed a widespread, persistent campaign distributing the PureRAT malware via the #ClickFix social engineering tactic and emails impersonating Booking[.]com. We also detailed the fraud scheme targeting hotel customers.
110
Sekoia @sekoia.com · 06/11/2025
#TDR analysts dig into a modus operandi targeting the hospitality industry and the related cybercrime ecosystem that facilitates #phishing and #fraud campaigns. blog.sekoia.io/phishing-cam...
153
Sekoia @sekoia.com · 23/10/2025
Discover how #TransparentTribe (#APT36) uses a disguised DESKTOP dropper to deploy #DeskRAT, a Golang RAT, on BOSS Linux endpoints in India. Our Sekoia #TDR report breaks down the full infection chain and stealthy WebSocket C2 communications . Read more 👉 blog.sekoia.io/transparentt...
011
Sekoia @sekoia.com · 21/10/2025
Our latest technical deep-dive unravels the mystery behind the opaque numeric codes (16, 272, 33554432, etc.) you see in #Microsoft365 audit logs. blog.sekoia.io/userauthenti...
210
Sekoia @sekoia.com · 14/10/2025
After our initial #PolarEdge #botnet write-up, we’re happy to announce the second part: “Defrosting PolarEdge’s Backdoor,” a full technical deep-dive into its TLS-based implant. blog.sekoia.io/polaredge-ba...
123
Sekoia @sekoia.com · 02/10/2025
Key takeaways: ✉️ API exploitation: attackers leverage an exposed /cgi endpoint to push malicious SMS without authentication 🌐 Scale of exposure: over 18,000 routers accessible on the internet; 572 confirmed vulnerable
111
Sekoia @sekoia.com · 02/10/2025
📱 Silent Smishing: The Hidden Abuse of Cellular Router APIs Our latest #CTI investigation from Sekoia #TDR team uncovers a novel #smishing vector abusing Milesight industrial cellular router APIs to send phishing #SMS at scale. blog.sekoia.io/silent-smish...
164
Sekoia @sekoia.com · 16/09/2025
🌐 As usual, APT28 uses legitimate third-party services in its execution chain, such as Koofr or icedrive, or more recently Filen. 🎯 The campaign’s goal is to gather cyber intelligence on frontline combatants by targeting administrative and logistics personnel.
100
Sekoia @sekoia.com · 16/09/2025
📃 APT28 distributed weaponised Office documents masquerading as Ukrainian military admin forms to harvest cyber-military intelligence. 🕷️ Attackers deploy a custom backdoor dubbed BeardShell using a modified Covenant Grunt stager.
110
Sekoia @sekoia.com · 16/09/2025
🐻 #APT28 – Operation Phantom Net Voxel: deep-dive into the latest spear-phishing campaign targeting Ukrainian military administrative staff. blog.sekoia.io/apt28-operat...
122
Sekoia @sekoia.com · 02/09/2025
[Threat investigation alert 🚨] Predators for Hire: A Global Overview of Commercial Surveillance Vendors ➡️ blog.sekoia.io/predators-fo...
124
Sekoia @sekoia.com · 21/07/2025
No OS left behind. It happily infects Windows, macOS, and Linux systems. Unlike before, they're not impersonating a real crypto company. Instead, they have built a completely #fake brand from scratch: waventic[.]com.
100
Sekoia @sekoia.com · 21/07/2025
🔥 Hot summer, sizzling crypto... and scammers turning up the heat 🔥 Back in March, Sekoia #TDR team published a deep-dive report on a #Lazarus cluster we dubbed #ClickFake Interview, leveraging the #ClickFix technique in their #ContagiousInterview campaign.
111
Sekoia @sekoia.com · 08/07/2025
These sheets aim to assist SOC analysts in detecting and investigating #AitM #phishing compromises by offering context, technical details, infrastructure overview, detection opportunities, and more. All are available in the PDF report and our Community GitHub.
112
Sekoia @sekoia.com · 08/07/2025
A few weeks ago, we published our global analysis of Adversary-in-the-Middle #phishing threats, providing actionable intelligence on multiple #AitM phishing kits. This report includes 11 sheets covering the most widespread #AitM phishing kits as of Q1 2025.
152
Sekoia @sekoia.com · 11/06/2025
🕵️ We also highlight multiple detection opportunities for AitM attacks in Microsoft Entra environments. All technical details are available on our community GitHub: buff.ly/v5Y6amN
110
Sekoia @sekoia.com · 11/06/2025
🎣 Leveraging our telemetry and proactive hunting, we ranked the most widespread AitM phishing kits - #Tycoon2FA, #Storm1167, #NakedPages, #Sneaky2FA, and more. Additionally, the article includes summary sheets covering 11 AitM phishing kits.
100
Sekoia @sekoia.com · 11/06/2025
🔍 Phishing-as-a-Service (#PhaaS) is driving a wave of large-scale, sophisticated attacks against organisations. In our new blogpost, we provide an overview of the key techniques, tactics and social engineering schemes that cybercriminals use in AitM phishing attacks.
110
Sekoia @sekoia.com · 11/06/2025
📝 Our latest #TDR report delivers an in-depth analysis of Adversary-in-the-Middle (#AitM) #phishing threats - targeting Microsoft 365 and Google accounts - and their ecosystem. This report shares actionable intelligence to help analysts detect and investigate AitM phishing.
1107