Sign in

Daniel Lunghi

@thehellu.bsky.social
170 followers 89 following 10 posts

Threat researcher at Trend Micro mostly focused on APT

PostsRepliesMedia
Daniel Lunghi @thehellu.bsky.social · 30/04/2026
We investigated a China-aligned #APT that targeted multiple governments and companies with government contracts in Asia. In half of the targets we found a second group with different malware toolkit but sharing the infection vector and some post-exploitation tools. www.trendmicro.com/en_us/resear...
031
Daniel Lunghi @thehellu.bsky.social · 17/04/2026
This is also our first edition of annual APT landscape report :)
020
Reposted by Daniel Lunghi
Feike Hacquebord @feikeh.bsky.social · 12/02/2026
TrendAI formalizes threat attribution as a structured, repeatable discipline by combining standardized evidence scoring, relationship mapping, and bias testing, with a temporary stage that separates clustering from final naming. Article on how we attribute: www.trendmicro.com/vinfo/us/sec...
trendmicro.com
Threat Attribution Framework: How TrendAI™ Applies Structure Over Speculation
TrendAI™ brings structure and discipline to threat attribution, helping security leaders and teams make informed decisions about cyber risk, incident response, and overall defensive posture.
021
Daniel Lunghi @thehellu.bsky.social · 11/12/2025
We investigated an #APT with links to Void Rabisu (Romcom) that used Trend Micro updates as a lure in a recent campaign involving vulnerability exploitation. There were at least 4 stages before the final payload, some of them being tailored to the targeted machine www.trendmicro.com/en_us/resear...
spear phishing email using Trend Micro updates as a luretargeted industriescomparison between this intrusion set and Void RabisuWebsite mimicking Trend Micro graphical design
011
Daniel Lunghi @thehellu.bsky.social · 22/10/2025
We saw Earth Estries, an advanced #APT intrusion set, sharing its access to Earth Naga (Flax Typhoon). We introduce the term "Premier Pass" to describe this behavior, and propose a four-tier classification framework for collaboration types among advanced groups www.trendmicro.com/en_us/resear...
Earth Estries and Earth Naga malware linksList of Earth Estries and Earth Naga targets, classified by targeted industry and locationCollaboration types and the related MITRE tactic stage where such collaboration occursEarth Estries and Earth Naga malware toolkits
22014
Daniel Lunghi @thehellu.bsky.social · 20/02/2025
We released a report on an updated version of #Shadowpad including anti-debugging features and new configuration structure, that in some cases deploy a custom ransomware family. We have mainly seen the manufacturing industry being targeted in Europe and Asia www.trendmicro.com/fr_fr/resear... #APT
152
Daniel Lunghi @thehellu.bsky.social · 29/01/2025
Intelligence Online links the MOONSHINE framework that we discussed in our Earth Minotaur report (www.trendmicro.com/en_us/resear...) to a Chinese company www.intelligenceonline.com/surveillance... (article is free but needs registration to access it). Happy new year UPSEC ! 😘
intelligenceonline.com
China : Chinese firm behind hacking operations against Uyghurs and Tibetans unveiled
Intelligence Online has established a link between a Chinese public security ministry contractor and recent IT hacking operations carried out in China and abroad against the two minorities, reviled
1811
Reposted by Daniel Lunghi
Feike Hacquebord @feikeh.bsky.social · 17/12/2024
Since Aug 2024 Earth Koshchei (APT29, Midnight Blizzard) used 193 RDP relays and 34 rogue backends against military, MFAs and others. The campaign peak was likely preceded by barely audible campaigns that ended with a bang in Oct 2024. Details and indicators here: www.trendmicro.com/en_us/resear...
trendmicro.com
Earth Koshchei Coopts Red Team Tools in Complex RDP Attacks
087
Daniel Lunghi @thehellu.bsky.social · 05/12/2024
Our latest report presents Earth Minotaur, a threat actor targeting Tibetans and Uyghurs using Moonshine, an exploitation framework for Android apps described in 2019 by @citizenlab.ca leveraging vulnerabilities in applications embedding old versions of Chromium trendmicro.com/en_us/resear...
Attack chain showing attacker generating link on Moonshine, then sending it through targeted application to the victim, which after clicking the links gets compromised and delivered the DarkNimbus backdoorValidation flow that fingerprints the target by looking at user agent and delivering the proper exploitmultiple Chrome vulnerabilities exploited in the third-party applicationsList of Android applications being targeted
Most are very popular in South East Asia
0127