Sign in

Stephen Hilt

@sjhilt.hilt.zip
729 followers 402 following 197 posts

Threat Researcher @ TrendAI (Trend Micro), waffle maker, and dad. My statements and opinions are my own and do not reflect my company.

PostsRepliesMedia
Stephen Hilt @sjhilt.hilt.zip · 02/09/2026
We mapped the criminal economy targeting critical infrastructure. 3,178 leak-site listings, victims up 48%, manufacturing 78% of the cases. www.trendaisecurity.com/en-us/resour...
trendaisecurity.com
Mapping the Criminal Economy Targeting Critical Infrastructure | TrendAI (US)
TrendAI™ Research went inside the forums, marketplaces, and Telegram channels where access to factories, utilities, and energy firms is bought, sold, and weaponized. Combing through two years’ worth o...
000
Stephen Hilt @sjhilt.hilt.zip · 08/08/2026
Numaan Huq and I presented this research at DEF CON. We looked at thousands of internet-exposed ICS and building automation systems near U.S. data centers, including systems tied to power and cooling. Full research: www.trendaisecurity.com/en/resources...
trendaisecurity.com
An Invisible Attack Surface: Thousands of Industrial Control Systems Exposed Near Data Centers | TrendAI
TrendAI™ Research's investigation of ICS protocols near U.S. data centers uncovered thousands of vulnerable devices controlling critical cooling, power, and environmental infrastructure. These systems...
010
Stephen Hilt @sjhilt.hilt.zip · 04/08/2026
Tycoon2FA was one of the most prolific phishing kits targeting Microsoft 365. Our latest publication details how TrendAI intelligence supported law enforcement in identifying leading to the arrest of its operators. www.trendaisecurity.com/en-us/resour...
trendaisecurity.com
TrendAI™ Intelligence Aids Law Enforcement Arrest of Tycoon 2FA Operators
The Singapore Police Force (SPF), working closely with Pakistan's National Cyber Crime Investigation Agency (NCCIA) and INTERPOL has arrested two individuals linked to Tycoon2FA, a phishing operation ...
000
Stephen Hilt @sjhilt.hilt.zip · 29/07/2026
The team at TrendAI published our 2026 H1 APT Report on how APT groups are weaponizing trust in the age of AI. AI isn't replacing APT tradecraft. It's helping scale what already works. Full report: documents.trendmicro.com/assets/pdf/A...
documents.trendmicro.com
010
Stephen Hilt @sjhilt.hilt.zip · 23/07/2026
Kratos (rebranded Sneaky2FA) is down. BKA/ZIT + US authorities took out 200+ servers, Indonesia arrested the developer. AiTM kit rented to 1,800+ subscribers running ~15K phishing campaigns/month against MS365 accounts. We fed intel since 2025. www.trendmicro.com/en_us/resear...
trendmicro.com
Law Enforcement Takes Down Kratos/Sneaky2FA Phishing Service, With an Assist From TrendAI™
Kratos, the phishing-as-a-Service (PhaaS) platform behind a large share of recent Microsoft 365 credential theft, has been taken offline by the BKA and ZIT in an operation dubbed Olympus Blade.
000
Stephen Hilt @sjhilt.hilt.zip · 14/07/2026
How much can one threat actor accomplish with AI? This research from my colleagues at TrendAI explores how the operator behind "Patriot Bait" used AI to help deploy C2 infrastructure. www.trendmicro.com/en_us/resear...
trendmicro.com
Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet
TrendAI™ Research analyzed over 200 Gemini CLI session logs showing how a Russian-speaking threat actor used AI to run a live botnet, finishing a full C&C migration in six minutes while doing just 11%...
000
Stephen Hilt @sjhilt.hilt.zip · 04/06/2026
Healthcare data is not just stolen. It is traded, resold, and monetized across a complex criminal ecosystem. Our latest research explores the underground economy fueling healthcare cybercrime. www.trendaisecurity.com/en-us/resour...
trendaisecurity.com
The Cybercriminal Underground: Mapping the Healthcare Data Economy | TrendAI (US)
A look inside an industrialized economy where stolen healthcare data is bought, sold, and weaponized, from ransomware breaches to broker access and fake medical documents fueling an expanding criminal...
000
Stephen Hilt @sjhilt.hilt.zip · 05/05/2026
Did a rewrite of #GasPot over the last few months to make it better. I also wrote an HMI to test it out and fix some of my bugs where things were not looking too realistic and it took me mapping it to a HMI. github.com/sjhilt/GasPo...
github.com
GitHub - sjhilt/GasPot: GasPot Released at Blackhat 2015
GasPot Released at Blackhat 2015. Contribute to sjhilt/GasPot development by creating an account on GitHub.
000
Stephen Hilt @sjhilt.hilt.zip · 05/05/2026
New research: 3,627 DICOM medical imaging servers exposed online, 99.56% with no authentication, only 0.14% encrypted. Patient data at serious risk. www.trendmicro.com/vinfo/us/sec...
trendmicro.com
A Hidden Vulnerability in Healthcare: Exposed DICOM Servers and the Risk to Patient Data
Analysis from TrendAI™ Research found that thousands of DICOM medical imaging servers worldwide are exposed online without basic security measures, leaving sensitive patient data and healthcare operat...
000
Stephen Hilt @sjhilt.hilt.zip · 30/04/2026
Strong research from my co-workers at TrendAI on “Inside Shadow Earth-053.” A sharp look at how modern threat actors abuse trusted systems and workflows to evade detection. www.trendmicro.com/en_us/resear...
trendmicro.com
Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia
A China-aligned threat group is exploiting unpatched Microsoft Exchange vulnerabilities to conduct cyberespionage against government and critical infrastructure targets across Asia and beyond.
010
Stephen Hilt @sjhilt.hilt.zip · 22/04/2026
New TrendAI™ research: Void Dokkaebi uses fake job interviews to lure devs into cloning malicious repos. - Job lures as entry - Dev workflows exploited - Risk to pipelines www.trendmicro.com/en_us/resear...
trendmicro.com
Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories
Our research on Void Dokkaebi’s operations uncovered a campaign that turns infected developer repositories into malware delivery channels. By spreading through trusted workflows, organizational codeba...
020
Stephen Hilt @sjhilt.hilt.zip · 16/04/2026
Cyber threats are evolving fast and so is the playbook to stop them. The latest APT report from TrendAI team highlights a clear shift toward proactive security, smarter use of AI, and more coordinated threat actors. Worth a read: www.trendmicro.com/vinfo/us/sec...
trendmicro.com
2025 APT Report: Staying Ahead of the Modern Threat Landscape
AI‑enabled APTs are accelerating attacks, shrinking response windows, and raising the stakes. This report reveals what’s changed and how to defend against it.
010
Stephen Hilt @sjhilt.hilt.zip · 28/03/2026
Because this treatment is a crime The working people fuel the engine While you yank the chain We fight the wars and build buildings For someone else’s gains youtu.be/5BRHuiRyVEE?si=5ylU9Ps1fDq…
youtu.be
Dropkick Murphys "Who'll Stand With Us?" Music Video
Dropkick Murphys music video for "Who'll Stand With Us?" from the album 'For The People' now streaming, out on CD/LP October 10.Preorder Vinyl & CD: https://...
110
Stephen Hilt @sjhilt.hilt.zip · 06/03/2026
Again fuck this place youtu.be/eF_xzJ6-Ow4?si=XbFXjZvlmkI…
youtu.be
Hero Of War
Provided to YouTube by Universal Music GroupHero Of War · Rise AgainstAppeal To Reason℗ 2008 UMG Recordings, Inc.Released on: 2008-01-01Engineer, Producer, S...
000
Stephen Hilt @sjhilt.hilt.zip · 04/03/2026
The global disruption of Tycoon 2FA, a phishing-as-a-service platform built to bypass MFA using adversary-in-the-middle techniques. Proud TrendAI to have worked with partners across industry and Law enforcement to help dismantle this operation. www.trendmicro.com/en_us/resear...
trendmicro.com
Europol, Microsoft, TrendAI™, and Collaborators Halt Tycoon 2FA Operations
Tycoon 2FA was dismantled this week by law enforcement and industry partners including TrendAI™. The phishing-as-a-service platform offered MFA bypass services using adversary-in-the-middle (AitM) pro...
010
Stephen Hilt @sjhilt.hilt.zip · 23/02/2026
TrendAI show how AI compresses target profiling from days to minutes using public data, including professional profiles. That shift makes tailored attacks easier to scale and harder to spot. www.trendmicro.com/vinfo/us/sec...
trendmicro.com
From LinkedIn to Tailored Attack in 30 Minutes: How AI Accelerates Target Profiling for Cybercrime
The industrialization of AI-driven OSINT has transformed individual digital footprints into machine-readable intelligence at scale, enabling attackers to operationalize personalized reconnaissance at ...
000
Stephen Hilt @sjhilt.hilt.zip · 17/02/2026
Attackers are abusing Atlassian Jira Cloud to launch spam campaigns and bypass email defenses by leveraging trusted SaaS notifications. Worth a read from TrendAI Research: www.trendmicro.com/en_us/resear...
trendmicro.com
Spam Campaign Abuses Atlassian Jira, Targets Government and Corporate Entities
We uncover how a campaign used Atlassian Jira Cloud to launch automated and targeted spam campaigns, exploiting trusted SaaS workflows to bypass security controls.
010
Stephen Hilt @sjhilt.hilt.zip · 12/02/2026
Just published a piece on how TrendAI uses a structured, evidence-based approach to threat attribution instead of speculation, and why this matters for better investigations. www.trendmicro.com/vinfo/us/sec...
trendmicro.com
Threat Attribution Framework: How TrendAI™ Applies Structure Over Speculation
TrendAI™ brings structure and discipline to threat attribution, helping security leaders and teams make informed decisions about cyber risk, incident response, and overall defensive posture.
010
Stephen Hilt @sjhilt.hilt.zip · 10/02/2026
We are hiring a Senior Threat Researcher for the Forward Looking Threat Research team at TrendAI. Remote in US Eastern and Central time zones prefered. Job is to research financial threats, attacker tooling, and new techniques. Details: trendmicro.wd3.myworkdayjobs.com/External/job...
trendmicro.wd3.myworkdayjobs.com
Senior Threat Researcher, FTR
Trend Micro, a global cybersecurity leader, helps make the world safe for exchanging digital information across enterprises, governments, and consumers. Fueled by decades of security expertise, global...
000
Stephen Hilt @sjhilt.hilt.zip · 25/01/2026
Fuck this place open.spotify.com/track/01ao83...
open.spotify.com
We Called It America
020
Stephen Hilt @sjhilt.hilt.zip · 11/12/2025
New research details SHADOW-VOID-042, a targeted spear phishing campaign abusing Trend Micro themed lures against multiple industries. Early detection prevented payload execution. Full analysis here: www.trendmicro.com/en_us/research/2…
trendmicro.com
SHADOW-VOID-042 Targets Multiple Industries with Void Rabisu-like Tactics
010
Stephen Hilt @sjhilt.hilt.zip · 09/12/2025
Is the era of “Cybercrime-as-a-Service” is ending? In our new report we show how agentic AI could transform cybercriminals from service-buyers into autonomous operators, enabling scalable, adaptive, and near-self driving attacks. www.trendmicro.com/vinfo/us/sec... #Cybersecurity #AIThreats
trendmicro.com
The Next Phase of Cybercrime: Agentic AI and the Shift to Autonomous Criminal Operations
We dive into the transformation from “Cybercrime-as-a-Service“ to “Cybercrime-as-a-Sidekick“, which fundamentally alters the operational dynamics of criminal enterprises.
030
Stephen Hilt @sjhilt.hilt.zip · 16/11/2025
I have spent two weeks, trying to get rid of streaming audio, and all I learned was my local rock station is repetitive, sucks and I remember why I went to streaming.
010
Reposted by Stephen Hilt
Zack Whittaker @zackwhittaker.com · 06/11/2025
When I recently told an executive about the North Korean remote workers' scheme, he almost shit his pants. Known as a triple threat, North Koreans gain real jobs at Western firms, earn a wage, then steal data and extort them when they get caught. All to make the regime money for nuclear weapons.
this.weekinsecurity.com
Thousands of North Koreans have secretly infiltrated US and European companies as remote IT workers
North Korea's secret remote workers are a major threat facing U.S. and European businesses today, taking jobs in Fortune 100 and smaller companies alike. Here's how to recognize and combat the threat.
1136
Stephen Hilt @sjhilt.hilt.zip · 04/11/2025
The Birria trend can stop.. it’s like Cincinnati chili it’s not good.
000
Reposted by Stephen Hilt
Johnny Xmas @j0hnnyxm4s.johnnyxmas.net · 26/10/2025
I fixed the MCP server from the Kali repo so it's no longer openly hosting an authentication-free instance of Kali for everyone on your network to freely enjoy like your favorite PornHub category github.com/johnnyxmas/M...
github.com
GitHub - johnnyxmas/MCP-Kali-Server: MCP configuration to connect AI agent to a Linux machine.
MCP configuration to connect AI agent to a Linux machine. - johnnyxmas/MCP-Kali-Server
063
Stephen Hilt @sjhilt.hilt.zip · 26/10/2025
spotify.link/D42xc6izLXb
spotify.link
Another F.U. Song
010
Stephen Hilt @sjhilt.hilt.zip · 24/10/2025
With everyone bailing on a specific streaming service lately I started digging into the airwaves around us and found some cool projects that let you actually decode and listen to HD Radio, but none of the UIs were working. Made my own, also fallback uses analog Radio. github.com/sjhilt/SDR-B...
010
Stephen Hilt @sjhilt.hilt.zip · 22/10/2025
spotify.link/TOXKwfTYEXb
spotify.link
Fearless
PRESIDENT · Fearless · Song · 2025
000
Stephen Hilt @sjhilt.hilt.zip · 11/10/2025
I was one of the 4,000 killed in Chicago, ded.
010
Stephen Hilt @sjhilt.hilt.zip · 01/10/2025
I hate when my candy comes with instructions
010
Stephen Hilt @sjhilt.hilt.zip · 04/09/2025
open.spotify.com/track/0ypg59NyOVCp…
open.spotify.com
Every Day Is Exactly The Same
Nine Inch Nails · With Teeth · Song · 2005
000
Stephen Hilt @sjhilt.hilt.zip · 27/08/2025
As part of a Trend Micro exercise, I helped show how quickly scammers can piece together your life: tagged photos, Strava runs, the street outside your home—in minutes. If we can do it, real criminals can too. metro.co.uk/2025/08/23/scammers-found-home-address-minutes-terrifyingly-easy-23966712/
011
Stephen Hilt @sjhilt.hilt.zip · 09/08/2025
It’s only the end of the world again… open.spotify.com/track/1sYpfdQKtB8U…
open.spotify.com
Endsmouth
Agents Of Oblivion · Agents of Oblivion · Song · 2000
000
Reposted by Stephen Hilt
JoshCorman @joshcorman.bsky.social · 02/08/2025
Oh! Today marks 12 yrs since I launched @iamthecavalry at @BSidesLV w/ @c7five Join Mon-Wed or stream bsideslv.org/schedule#IATC
bsideslv.org
- BSides Las Vegas
BSides Las Vegas is a nonprofit organization formed to stimulate the Information Security industry and community.
052
Stephen Hilt @sjhilt.hilt.zip · 20/07/2025
Time to go! My Nordic friends know what I’ve done. ;)
000
Stephen Hilt @sjhilt.hilt.zip · 19/07/2025
9 hour layover in AMS earlier… worth the trip outside as AMS has a great luggage storage system
000
Stephen Hilt @sjhilt.hilt.zip · 19/07/2025
open.spotify.com/track/1SlxMFZexm81…
open.spotify.com
Watch The World Burn
Falling In Reverse · Popular Monster · Song · 2024
000
Stephen Hilt @sjhilt.hilt.zip · 05/07/2025
Always a treat
000
Reposted by Stephen Hilt
Last Week Tonight with John Oliver @lastweektonight.com · 22/06/2025
Earlier today we taped tomorrow’s show, and we discussed the potential for the U.S. to bomb Iran. Since taping, the U.S. has carried out several bombings. We’ll have more to say in the future, but for now our piece on Trump and the Iran Deal can help explain what got us here. youtu.be/5xnZ_CeTqyM
youtu.be
Iran Deal: Last Week Tonight with John Oliver (HBO)
YouTube video by LastWeekTonight
381505378
Stephen Hilt @sjhilt.hilt.zip · 15/06/2025
Single mothers have both days.
000
Stephen Hilt @sjhilt.hilt.zip · 15/06/2025
Happy Father’s Day all you hackers
010
Stephen Hilt @sjhilt.hilt.zip · 08/06/2025
One day I will have don’t scrape peanut butter out of the bottom of the jar money. #lifegoals
020
Reposted by Stephen Hilt
Lisa Forte @lisaforte.bsky.social · 26/05/2025
🤣🤣🤣
524659
Stephen Hilt @sjhilt.hilt.zip · 24/05/2025
It’s Bush drinking a Busch while trimming a bush. Happy Memorial Day weekend everyone.
010
Stephen Hilt @sjhilt.hilt.zip · 11/05/2025
Sunday jam open.spotify.com/track/3BuLlji2QpVa…
open.spotify.com
Are You Going to See the Rose in the Vase, or the Dust on the Table
$uicideboy$ · New World Depression · Song · 2024
000
Stephen Hilt @sjhilt.hilt.zip · 10/05/2025
Friday night jams open.spotify.com/track/0kEZlJh4mK1Q…
open.spotify.com
Kill Yourself (Part III)
$uicideboy$ · My Liver Will Handle What My Heart Can't · Song · 2015
000
Stephen Hilt @sjhilt.hilt.zip · 24/04/2025
Trend Micro identifies North Korean APTs, including Lazarus Group, using Russian infrastructure (ASNs, VPS) to obfuscate financially driven cyber ops. Highlights evolution in TTPs and inter-state cybercrime dynamics. www.trendmicro.com/en_us/resear... #ThreatIntel #CyberOps
trendmicro.com
Russian Infrastructure Plays Crucial Role in North Korean Cybercrime Operations
0149
Stephen Hilt @sjhilt.hilt.zip · 20/04/2025
‘Cause nobody gives a fuck open.spotify.com/track/3uC4r2daXert…
open.spotify.com
Lithonia
Childish Gambino · Bando Stone and The New World · Song · 2024
000
Stephen Hilt @sjhilt.hilt.zip · 14/04/2025
Stealthy and persistent: #BPFdoor is back, slipping past defenses with almost no trace. Learn how this elusive Linux backdoor hides in plain sight and what it means for enterprise security. Full analysis by @TrendMicro: www.trendmicro.com/en_us/research/2…
trendmicro.com
BPFDoors Hidden Controller Used Against Asia, Middle East Targets
A controller linked to BPF backdoor can open a reverse shell, enabling deeper infiltration into compromised networks. Recent attacks have been observed targeting the telecommunications, finance, and retail sectors across South Korea, Hong Kong, Myanmar, Malaysia, and Egypt.
081