Sign in

Sekoia

@sekoia.com
468 followers 38 following 164 posts

Sekoia is the European cybersecurity company building the Cyber Operations Platform for the AI era.

PostsRepliesMedia
Sekoia @sekoia.com · 21/09/2026
As usual, IoCs are available in our Community GitHub repository: buff.ly/5CISNsZ
000
Sekoia @sekoia.com · 21/09/2026
Exvicy is already widespread in the wild. We identified dozens of active administration panels and more than 100 C2 servers. Its monthly price also jumped from $1,200 to $2,000 in mid-August 2026.
100
Sekoia @sekoia.com · 21/09/2026
Exvicy reuses ErrTraffic's obfuscated JavaScript, ClickFix HTML, FNV-1a hashing and C2 actions. The main advertised change is the use of Win+R instead of Win+X for the ClickFix command.
100
Sekoia @sekoia.com · 21/09/2026
Exvicy's affiliates compromise WordPress sites to display a fake Cloudflare Turnstile CAPTCHA in a fullscreen iframe. Victims are told to press Win+R, Ctrl+V, and Enter, executing Base64-encoded PowerShell that drops malware.
100
Sekoia @sekoia.com · 21/09/2026
TDR analysts uncovered #Exvicy, an emerging #ClickFix MaaS sold on Exploit.IN since May 2026. We assess with high confidence that Exvicy is a copycat of #ErrTraffic, reusing its injected JavaScript, ClickFix HTML, and C2 communication logic. buff.ly/nKNSjMy
101
Sekoia @sekoia.com · 07/09/2026
IT workers operating under false identities are part of this model too, functioning as a revenue channel and an insider threat. Read the full report, Beyond Lazarus: Organization of DPRK Cyber Capabilities buff.ly/vmqOr9d
001
Sekoia @sekoia.com · 07/09/2026
One finding runs throughout the research: espionage and revenue generation are closely linked. Access obtained for financial gain can be reused for intelligence collection. Shared infrastructure can support both missions.
100
Sekoia @sekoia.com · 07/09/2026
The analysis also covers the wider support structure behind North Korea’s cyber operations. Academic institutions train operators and provide cover. Front companies act as proxies across several regions. Criminal networks support fund movements.
100
Sekoia @sekoia.com · 07/09/2026
By cross-referencing multiple taxonomies, the report breaks down the former Lazarus umbrella into six distinct sub-clusters. This provides a clearer view of who is operating and how.
100
Sekoia @sekoia.com · 07/09/2026
It also addresses a persistent challenge in threat intelligence: cluster deconfliction. Aliases multiply. Boundaries shift between vendors. Different names can hide the same activity.
100
Sekoia @sekoia.com · 07/09/2026
The research maps the institutions responsible for North Korea’s cyber offensive operations, including recent reorganizations and the intrusion sets operating under them.
110
Sekoia @sekoia.com · 07/09/2026
North Korea’s cyber program was built to serve two purposes: intelligence collection and revenue generation. A new joint report from Sekoia #TDR and @KudelskiSec examines how that system is organized. buff.ly/vmqOr9d
223
Sekoia @sekoia.com · 01/07/2026
- An Ongoing threat: The campaign's structure and persistence indicate a broader, long-term operation aiming directly at cyber defenders rather than an isolated, one-shot attack.
000
Sekoia @sekoia.com · 01/07/2026
- Targeted Action & Persistence: While the malicious PyPI packages were immediately reported and removed, our analysis shows that parts of the core Command & Control (C2) infrastructure remain active.
100
Sekoia @sekoia.com · 01/07/2026
- Infrastructure Uncovered: We mapped out a cluster of malicious GitHub repositories and backdoored Python (PyPI) specifically crafted to target the security community.
100
Sekoia @sekoia.com · 01/07/2026
Recognising critical anomalies in the code and its malicious imports, the YesWeHack team joined forces with Sekoia’s threat intelligence experts to run a deep-dive investigation. The outcome of this collective defence effort:
120
Sekoia @sekoia.com · 01/07/2026
It started when a suspicious GitHub repository, disguised as a harmless Proof of Concept (PoC) for a Nuclei template, was flagged.
100
Sekoia @sekoia.com · 01/07/2026
Don’t Eat The #ChocoPoCs! How Vulnerability Researchers Were Repeatedly Targeted By Trojanised Exploits www.sekoia.com/blog/dont-ea... Discover our joint threat intelligence report with @YesWeHack.
100
Sekoia @sekoia.com · 26/06/2026
As the threat landscape expands beyond traditional network perimeters, understanding the security risks of the AdTech ecosystem is becoming critical for enterprise defence.
000
Sekoia @sekoia.com · 26/06/2026
- Ultimately, ADINT can be leveraged as a zero-click intrusion vector through code injection within the ad content, exploiting software vulnerabilities to deploy spyware.
100
Sekoia @sekoia.com · 26/06/2026
- ADINT can be used for group-level profiling, identification of geolocation patterns or highly targeted near real-time geolocation tracking.
100
Sekoia @sekoia.com · 26/06/2026
Key insights from the report: - ADINT can be defined as the weaponisation of legitimate AdTech mechanisms, notably the real-time bidding process and third-party SDKs, to collect, correlate, and operationalise large-scale data for intelligence purposes.
100
Sekoia @sekoia.com · 26/06/2026
Online advertising is no longer just a tool for marketers, it has become a sophisticated vector for surveillance and cyber espionage.
100
Sekoia @sekoia.com · 26/06/2026
Our latest Threat Intelligence report dives deep into ADINT (Advertisement-based Intelligence) to expose how private companies weaponise AdTech mechanisms to harvest intelligence data, fueling the surveillance solutions they sell. www.sekoia.com/blog/sold-to...
123
Sekoia @sekoia.com · 16/06/2026
This blog post details the ErrTraffic threat and its associated ecosystem, highlighting three specific campaigns and their operators’ arsenal. Finally, it provides several analytical hypotheses regarding the MaaS operations and the organisation of these affiliate groups.
010
Sekoia @sekoia.com · 16/06/2026
Our forensic analysis of compromised WordPress servers helped us to cluster ErrTraffic and map affiliates' TTPs and backdoors. We notably identified two distinct clusters: "Analytics" operated by a single threat actor, and "Beer" likely operated by LenAI for affiliates.
111
Sekoia @sekoia.com · 16/06/2026
The ErrTraffic MaaS offering includes: - The EtherHiding technique to retrieve the C2 from Polygon smart contracts - A Traffic Distribution System (TDS) to filter unwanted traffic - Various ClickFix lures LenAI, the operator behind ErrTraffic, sells subscriptions for $380/month
110
Sekoia @sekoia.com · 16/06/2026
#TDR analysts published a new report detailing #ErrTraffic, a widespread #ClickFix malware distribution framework. ErrTraffic injects malicious JavaScript into compromised WordPress and malicious sites to serve ClickFix lures. blog.sekoia.io/unveiling-er...
243
Sekoia @sekoia.com · 11/06/2026
This report is part of a broader coordinated effort, conducted since 2025 in collaboration with foreign and domestic law enforcement and government agencies, including the FBI, to limit APT28's activities and constrain GRU cyber operations.
000
Sekoia @sekoia.com · 11/06/2026
- Return of custom implants: Deploying stealthy, modular toolsets (like Phantom Net Voxel) controlled via cloud infrastructures. - Delegating logic to AI: Experimenting with malware (like LameHug) that queries an LLM on the fly to generate attack commands.
100
Sekoia @sekoia.com · 11/06/2026
Here are the three major shifts defining APT28's modern operations: - Infrastructure moved to the edge: Compromising SOHO devices and abusing cloud services to mask traffic.
100
Sekoia @sekoia.com · 11/06/2026
🇷🇺 Sekoia #TDR team has just released a comprehensive analysis of how #APT28's arsenal has evolved, from its early to its current operations. blog.sekoia.io/apt28-an-evo...
132
Sekoia @sekoia.com · 08/06/2026
The second and third parts of our investigation into the #Gamaredon, the cyberespionage group operated by the Russian #FSB, are live! 🪆Part 2 — The loaders buff.ly/bBYZSKa 🪆Part 3 — The stealer & full infrastructure buff.ly/74WHuPd #CTI #TDR #Sekoia
011
Sekoia @sekoia.com · 01/06/2026
📄 Part 1 — Initial access & the worm → buff.ly/6hR2IMj 🔜 Part 2 — The loaders (Wednesday) 🔜 Part 3 — The stealer & full infrastructure (Thursday)
020
Sekoia @sekoia.com · 01/06/2026
The result: the most complete picture of Gamaredon's current operations to date. A massive campaign. Still running. Right now. We're releasing a 3-part investigation this week — starting today with Part 1: Initial access & the worm.
111
Sekoia @sekoia.com · 01/06/2026
Russia's #FSB-linked #Gamaredon has been hammering Ukraine's government, military & critical infrastructure for over a decade. We went behind the scenes. Tracked their infrastructure. Recovered artefacts from compromised machines. Here's what we found 🧵 buff.ly/6hR2IMj
241
Sekoia @sekoia.com · 08/04/2026
Part 1 of our technical deep dive into EvilTokens: blog.sekoia.io/new-widespre...
000
Sekoia @sekoia.com · 08/04/2026
We assess that EvilTokens is the first PhaaS to offer #AI-augmented post-compromise tooling, representing a significant shift in the BEC ecosystem by making advanced, victim-tailored fraud capabilities accessible to a broad audience of financially-motivated threat actors.
100
Sekoia @sekoia.com · 08/04/2026
TDR analysts gained access to the #EvilTokens backend JavaScript and implemented device code phishing functions and token weaponisation. This script also includes #LLM #prompts to analyse large volumes of emails, construct BEC attack scenarios, and draft targeted #BEC emails.
101
Sekoia @sekoia.com · 08/04/2026
The EvilTokens PhaaS runs via fully featured Telegram bots and continuously enhances its phishing kit with new capabilities.
100
Sekoia @sekoia.com · 08/04/2026
Part 2 of our #EvilTokens analysis is live. TDR analysts uncovered the AI-augmented features that automate and scale #BEC workflows, marking a breakthrough in the #PhaaS ecosystem. blog.sekoia.io/eviltokens-a...
120
Sekoia @sekoia.com · 30/03/2026
As usual, IoCs are available in our Community GitHub repository: github.com/SEKOIA-IO/Co...
011
Sekoia @sekoia.com · 30/03/2026
Our report offers a technical analysis of the EvilTokens kit, its delivery campaigns, and the adversary's infrastructure.
100
Sekoia @sekoia.com · 30/03/2026
Active since late February 2026 and rapidly adopted by cybercriminals, TDR analysts believe EvilTokens will become a serious competitor in the phishing and BEC landscape.
100
Sekoia @sekoia.com · 30/03/2026
EvilTokens device code phishing pages allows attackers to capture Microsoft refresh and access token, weaponise them, harvest victims' mailbox, and automatically craft BEC emails using AI.
100
Sekoia @sekoia.com · 30/03/2026
#TDR analysts uncovered an emerging Phishing-as-a-Service (#PhaaS) platform called #EvilTokens, which offers device code phishing pages and AI-augmented features to automate and scale #BEC workflows. ⬇️ blog.sekoia.io/new-widespre...
100
Sekoia @sekoia.com · 25/03/2026
Agile and persistent, Silver Fox successfully blends into the noise of traditional cybercrime while maintaining the capacity for advanced intelligence collection.
010
Sekoia @sekoia.com · 25/03/2026
🛠️ RMM Abuse: Transitioned from deploying #ValleyRAT via malicious PDFs to abusing Chinese #RMM tools. 🐍 Custom Payloads: Recently observed dropping a custom Python-based stealer embedded in a Python installer.
110
Sekoia @sekoia.com · 25/03/2026
Key findings: 🎣 Deceptive Lures: Consistently impersonates national taxation authorities or uses fake payroll documents to trick victims into executing payloads. 🌊 3-Wave Arsenal Evolution: Between 2025 and 2026, their attack chains shifted significantly to evade detection.
100
Sekoia @sekoia.com · 25/03/2026
In this deep-dive analysis, our Threat Detection & Research (#TDR) team unmasks their massive 2025-2026 campaign and rapidly evolving infection chains.
100