Sign in

Arda Büyükkaya

@whichbufferarda.bsky.social
150 followers 340 following 43 posts

Cyber Threat Intelligence Analyst at Rabobank. (All opinions expressed here are mine only). #cybersecurity

PostsRepliesMedia
Arda Büyükkaya @whichbufferarda.bsky.social · 22/05/2025
🇨🇳 UNC5221 China-Nexus Threat Actor Actively Exploiting Ivanti EPMM (CVE-2025-4428).Targets critical networks like US airports and Telecommunications companies in EU. Exfiltrating sensitive data from managed mobile devices. #cyber Here is the full report: blog.eclecticiq.com/china-nexus-...
141
Arda Büyükkaya @whichbufferarda.bsky.social · 02/05/2025
🎉 Happy to share that my talk has been accepted at Virus Bulletin! I’ll be presenting in 🇩🇪 Berlin on Friday, September 26 at VB2025: Details: www.virusbulletin.com/conference/v... See you there! #vbconference #VB2025
052
Arda Büyükkaya @whichbufferarda.bsky.social · 01/05/2025
Microsoft Teams appears to have been used as part of the cyber kill chain in the Co-Op hack. I've recently seen similar tactics, where threat actors employed voice phishing via Teams calls. It’s a threat worth watching.
000
Arda Büyükkaya @whichbufferarda.bsky.social · 25/04/2025
🚨 Erlang SSH RCE (CVE-2025-32433) is a significant supply chain risks to ICS and OT devices, particularly critical networking equipment like routers, switches, and smart sensors. The public availability of a POC makes this vulnerability especially concerning, as it is straightforward to exploit.
011
Arda Büyükkaya @whichbufferarda.bsky.social · 23/04/2025
Since April 15, 2025, BreachForums 2 was offline. Admin “Normal” confirmed its return at breached[.]fi, with no prior data restored. The new site faces skepticism, with some calling it a potential honeypot, likely pushing threat actors toward other platforms.
033
Arda Büyükkaya @whichbufferarda.bsky.social · 23/04/2025
Sri Lanka’s Foreign Ministry hit by phishing email posing as peacekeeper notice sent from Pakistan’s Naval Uni (likely breached) “pro-rector.admin@bahria.edu.pk.” Malicious link led to fake Gmail login via Railway-hosted page "gs23-production.up.railway[.]app", stealing user credentials and OTPs.
000
Arda Büyükkaya @whichbufferarda.bsky.social · 18/04/2025
Telephone-oriented attack delivery (TOAD) should be part of your threat model. We're seeing a rise in phishing where real human voices trick IT admins or helpdesks. Threat actors even run affiliate programs, paying people to guide victims into RMM installs or password reset.
054
Arda Büyükkaya @whichbufferarda.bsky.social · 13/04/2025
Ransomware brands come and go, but affiliates stay active, favoring repeatable/high-ROI tradecrafts. Many work with multiple RaaS crews at once. Their playbooks aren’t static, affiliates adapt to tech shifts like cloud adoption. Focus on affiliate behavior and hunt the tradecraft. #Ransomware
021
Arda Büyükkaya @whichbufferarda.bsky.social · 01/03/2025
🎙️ Honored to be speaking at FIRST 🇳🇱 🇪🇺 Amsterdam Technical Colloquium on March 27 (Day 2) about Scattered Spider’s Cloud Tactics and the Ransomware Deployment Life Cycle!. If you’re attending, let’s connect—DMs are open :) #FIRSTAMS2025 #CyberSecurity @firstdotorg.bsky.social
100
Arda Büyükkaya @whichbufferarda.bsky.social · 12/02/2025
I'm incredibly honored to have my threat research on Sandworm APT featured in WIRED Magazine. I'm excited about what's ahead as I continue contributing to the cybersecurity community with actionable intelligence! www.wired.com/story/russia...
120
Arda Büyükkaya @whichbufferarda.bsky.social · 11/02/2025
🚨 EclecticIQ analysts uncovered a Sandworm #cyber espionage campaign targeting Ukrainian Windows users. Attackers used trojanized #Microsoft KMS activation tools to deploy the BACKORDER loader and Dark Crystal RAT, enabling data theft and espionage. blog.eclecticiq.com/sandworm-apt...
132
Arda Büyükkaya @whichbufferarda.bsky.social · 07/02/2025
Attacker compromised email account from mx[.]jurimex[.]ua to deliver phishing email. Email contains malicious URL abuse infrastructure from drive[.]legalaid[.]gov[.]ua, owned by Ukraine's Coordination Centre for Legal Aid Provision that was abused to deliver RAR file contains #SmokeLoader malware.
100
Arda Büyükkaya @whichbufferarda.bsky.social · 07/02/2025
🚨 Targeted #phishing attacks on Ukrainian 🇺🇦 gov! Emails from moulmg@meta[.]ua & info@betta[.]com[.]ua deliver malicious 7ZIP files exploiting CVE-2025-0411 to drop #SmokeLoader. Notably, the meta[.]ua mail service has been previously abused by #APT28 (GRU) for #cyber operations.
110
Arda Büyükkaya @whichbufferarda.bsky.social · 28/01/2025
It was an honor to speak at the SANS CTI Summit today. Such a fantastic event filled with great networking opportunities and insights from the rock stars of the infosec industry! @likethecoins.bsky.social
130
Arda Büyükkaya @whichbufferarda.bsky.social · 23/01/2025
🇳🇱 ✈️ 🇺🇸 Dear all, From January 27-28, I’ll be attending the SANS Cyber Threat Intelligence Summit in Alexandria, VA. If you’re attending the summit, let’s connect my DMs are open! Looking forward to seeing you in Alexandria! #SANS #cybersecuirty
020
Arda Büyükkaya @whichbufferarda.bsky.social · 05/12/2024
SHA-256: 6dd97f5ac9f05bfe3b810ac08f4fe0377933d54a4ab64158d4e40f94feab2cf0 -> bb.ps1 fe08a5e0fb220232e70a4da3378162608a7fe0655bf999685d441e89d68a454a -> trigger Additional IOCs from BAT file: 154[.]12[.]242[.]190 38[.]242[.]143[.]200 144[.]126[.]146[.]201 31[.]220[.]97[.]187 154[.]38[.]179[.]250
010
Arda Büyükkaya @whichbufferarda.bsky.social · 05/12/2024
After further investigation, I found the threat actor who very likely compromised that legitimate VICIdial server, it was 158.220.106[.]204 - liceba[.]store, also delivering an Powershell RDP backdoor with an interesting file path named "UP".
100
Arda Büyükkaya @whichbufferarda.bsky.social · 05/12/2024
Threat actors exploits GlobalProtect (CVE-2024-3400) to deliver the Sliver C2 malware (up.js) by leveraging the compromised VICIdial server, threat actor likely exploited the (CVE-2024-8504) to store their payloads on legitimate server (104.131.69[.]106/vicidial/up.js).
100
Arda Büyükkaya @whichbufferarda.bsky.social · 22/11/2024
Critical energy infrastructure, including power grids, gas pipelines, and energy companies in Ukraine, the US, and Europe (especially the UK and Germany), is highly likely a target of Russia’s cyber sabotage unit Sandworm (APT44). www.politico.eu/article/russ...
010
Arda Büyükkaya @whichbufferarda.bsky.social · 22/11/2024
After using some cool network pivoting tricks and a zero-day privilege escalation, the threat actor leveraged noisy reg.exe to dump SAM credentials and PowerShell to compress the results.
100
Arda Büyükkaya @whichbufferarda.bsky.social · 20/11/2024
🕷 🕸 The FBI has linked Tyler Robert Buchanan, aka "bobsagetfaget," to Scattered Spider’s credential theft campaigns. Key evidence includes phishing domains like tmobiie[.]us, registered via NameCheap with the email lululongstaffihw98@gmail.com under the username "bobsagetfaget."
010