Sign in

thehappydinoa

@thehappydinoa.dev
76 followers 261 following 7 posts

aka Aidan | Security Researcher, Developer, and Collaborator at @censysio | Opinions are my own

PostsRepliesMedia
Reposted by thehappydinoa
Censys @censys.bsky.social · 25/08/2026
ERMAC and HookBot are tracked as two families. Censys ARC researcher @thehappydinoa.dev read the leaked source and found one code base, where a single constant decides which name the panel shows. Also in the post: which detection artifacts survive a rebrand, and which do not. bit.ly/46lP3Ao
012
Reposted by thehappydinoa
Censys @censys.bsky.social · 03/08/2026
New research from @thehappydinoa.dev identifies a threat actor running 100+ DarkSword panels. Censys ARC has now observed at least 7 (likely 8) unrelated crews using the leaked iOS exploit chain. bit.ly/4fMX71w #CensysARC
bit.ly
DarkSword's Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster - Censys
Censys ARC noticed a recent spike in DarkSword hosts and web properties. Here are the IOCs and pivots you need to track the growing threat.
011
thehappydinoa @thehappydinoa.dev · 03/08/2026
new writeup: the latest DarkSword operator, chinese-speaking, well over a hundred panels found the whole thing off one http body hash. six panels, two totally different codebases, same guy we're at 7-8 unrelated crews running this leaked ios chain now censys.com/blog/darkswo... #darksword
censys.com
DarkSword's Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster - Censys
Censys ARC noticed a recent spike in DarkSword hosts and web properties. Here are the IOCs and pivots you need to track the growing threat.
001
Reposted by thehappydinoa
Martijn Grooten @martijngrooten.bsky.social · 26/06/2026
I don't talk a lot about work here, but I looked into a phishing campaign that targeted a Belarusian opposition politician and then turned out to also impersonate at least three popular Ukrainian portals (it was also my first blog post for Censys) censys.com/blog/unc1151...
censys.com
UNC1151 Phishing Email Targeting Belarusian Politician Points to Multi-National Campaign - Censys
New Censys ARC research discovers that UNC1151's phishing email to a Belarusian politician is linked to a much broader campaign.
095
thehappydinoa @thehappydinoa.dev · 12/02/2026
Odyssey Stealer isn't a solo operation. It's a macOS MaaS platform where affiliates rent C2 access to steal crypto. New research: payload analysis, 10 C2s mapped, and the AMOS → Poseidon → Odyssey lineage traced. censys.com/blog/odyssey... #macOS #Malware #OdysseyStealer
censys.com
Odyssey Stealer: Inside a macOS Crypto-Stealing Operation
Odyssey is a macOS stealer focused on crypto theft. Learn how it works, the risks it poses, and how to defend against it.
020
Reposted by thehappydinoa
Zakir Durumeric @zakird.com · 27/11/2024
We released Censeye today, an open source CLI tool that makes it dramatically easier to pivot and find related assets when threat hunting on Censys instead of manually checking for potential identifying characteristics like an SSH host key. github.com/Censys-Resea...
22814