X_Hunt3r @x-hunt3r.bsky.social · 22/07/2026This is wild! openai.com/index/huggin...openai.comOpenAI and Hugging Face partner to address security incident during model evaluationOpenAI and Hugging Face share early findings from a security incident during AI model evaluation, highlighting advanced cyber capabilities and lessons for defenders. 000
Reposted by X_Hunt3rJulian-Ferdinand Vögele @julianferdinand.bsky.social · 01/07/2026Colleagues of mine at Insikt Group just released new research on the Iran-nexus cluster #TAG-182, deploying #MarkiRAT, a malware family previously observed in use by #FerociousKitten, for internal and external surveillance: www.recordedfuture.com/research/nex...recordedfuture.comIran-Nexus TAG-182 Disseminates MarkiRAT Surveillance ToolDiscover how Iranian-nexus threat cluster TAG-182 uses MarkiRAT malware and fake VPN/media apps to conduct cyber surveillance operations against domestic targets. 099
Reposted by X_Hunt3rJulian-Ferdinand Vögele @julianferdinand.bsky.social · 19/03/20261/ Today we’re publishing our annual malicious infrastructure report, providing a broad view of global threat infrastructure. This year, we significantly expanded coverage across malware families, threat categories, and deeper infrastructure insights: www.recordedfuture.com/research/202...recordedfuture.com2025 Year in Review: Malicious, InfrastructureExplore Insikt Group’s 2025 Malicious Infrastructure Report. Gain insights into Cobalt Strike, Vidar infostealers, and AI-driven threats to secure your 2026 strategy. 1910
Reposted by X_Hunt3rZack Whittaker @zackwhittaker.com · 11/02/2026By me: Microsoft has fixed three zero-day bugs in Windows and Office that are being actively abused by hackers to break into people's computers. Microsoft said three of the exploits are now public. Google, which helped find the bugs, said one of them is under “widespread, active exploitation."techcrunch.comMicrosoft says hackers are exploiting critical zero-day bugs to target Windows and Office users | TechCrunchCritical security flaws targeting Windows and Office users allow hackers to take complete control of a victim's computer by clicking a malicious link or opening a file. Patch now. 63520
Reposted by X_Hunt3rCheckFirst @checkfirst.network · 09/02/2026🔴 𝗡𝗘𝗪 𝗥𝗘𝗣𝗢𝗥𝗧 Last year, we've been able to unearth the infrastructure of the FSB's 16th Centre, combining #OSINT techniques and photos of old medals. We replicated this method to explore the Information Operations Troops (#VIO) of #Russia’s military intelligence service (#GRU). 12719
X_Hunt3r @x-hunt3r.bsky.social · 07/01/2026Today, we released new @RecordedFuture research detailing BlueDelta’s expanded credential-harvesting activity observed between February and September 2025. #BlueDelta #APT28 #FANCYBEAR #ForestBlizzard #FROZENLAKE #ITG05 #PawnStorm #Sednit #Sofacy #TA422 (1/5) www.recordedfuture.com/research/gru...recordedfuture.comGRU-Linked BlueDelta Evolves Credential HarvestingInsikt Group reveals how GRU-linked BlueDelta evolved credential-harvesting campaigns targeting government, energy, and research organizations across Europe and Eurasia. 175
X_Hunt3r @x-hunt3r.bsky.social · 17/12/2025Today, we released new @RecordedFuture research detailing BlueDelta’s sustained credential-harvesting campaign targeting UKR.NET users between June 2024 and April 2025. www.recordedfuture.com/research/blu... #BlueDelta #APT28 #FANCYBEAR #ForestBlizzard #FROZENLAKE #PawnStorm #Sednit #Sofacy (1/5)recordedfuture.comBlueDelta’s Persistent Campaign Against UKR.NETDiscover how Russia’s BlueDelta targets UKR.NET users with advanced credential-harvesting campaigns, evolving tradecraft, and multi-stage phishing techniques. 132
X_Hunt3r @x-hunt3r.bsky.social · 16/09/2025Great work by Sekoia uncovering new #BlueDelta #APT28 #Sofacy #FancyBear #ForestBlizzard #TAG110 malware samples. Linked to CERT-UA’s BeardShell & Covenant frameworks + revealed fresh weaponized docs & subtle TTPs. Activity ties to Russia-nexus ops incl. Double-Tap. blog.sekoia.io/apt28-operat...blog.sekoia.ioAPT28 Operation Phantom Net VoxelAPT28 Operation Phantom Net Voxel: weaponized Office lures, COM-hijack DLL, PNG stego to Covenant Grunt via Koofr, BeardShell on icedrive. 021
Reposted by X_Hunt3rCynthia Brumfield @metacurity.com · 15/09/2025Ukraine claims cyberattacks on Russian election systems; Moscow confirms disruptions therecord.media/ukraine-clai...therecord.mediaUkraine claims cyberattacks on Russian election systems; Moscow confirms disruptionsUkraine said it was responsible for disrupting websites related to Russian election infrastructure as voters went to the polls in occupied territories. 042
Reposted by X_Hunt3rBrian Liston @brianjliston.bsky.social · 03/09/2025New report published today from our team at Recorded Future: “Russian Influence Assets Converge on Moldovan Elections” www.recordedfuture.com/research/rus...recordedfuture.comRussian Influence Assets Converge on Moldovan ElectionsAhead of Moldova’s 2025 elections, Russia-linked influence operations seek to undermine EU integration, discredit President Sandu, and destabilize democratic processes through coordinated disinformati... 065
Reposted by X_Hunt3rCalwarez @calwarez.bsky.social · 27/08/2025This report on Stark Industries is a fantastic case study in the cat-and-mouse game between hosting providers and law enforcement. The new "Threat Activity Enabler" (TAE) terminology is spot-on and highlights the critical role these providers play in the cybercrime ecosystem. 033
Reposted by X_Hunt3rAlexander Martin @alexmartin.bsky.social · 27/08/2025Scandi noir meets The Wire... 🇫🇮🚢 The captain of a Russia-linked oil tanker that damaged five subsea cables in the Baltic Sea on Christmas Day was instructed by his shipping company to destroy evidence after the ship was seized by Finnish authorities, according to a wiretap transcript.therecord.mediaFinnish police wiretap reveals Russian ‘shadow fleet’ captain instructed to destroy evidenceThe captain of a Russia-linked oil tanker that damaged five subsea cables in the Baltic Sea was reportedly instructed to destroy evidence after the ship was seized by authorities. 05622
X_Hunt3r @x-hunt3r.bsky.social · 21/08/2025Is it really 2025?! Cisco Smart Install and SNMP brute attacks... We are giving the FSB an easy ride. Great report by the Talos team! blog.talosintelligence.com/static-tundra/blog.talosintelligence.comRussian state-sponsored espionage group Static Tundra compromises unpatched end-of-life network devicesA Russian state-sponsored group, Static Tundra, is exploiting an old Cisco IOS vulnerability to compromise unpatched network devices worldwide, targeting key sectors for intelligence gathering. 010
X_Hunt3r @x-hunt3r.bsky.social · 21/08/2025Fantastic new report by @julianferdinand.bsky.social and @aejleslie.bsky.social exposing Lumma’s vast info-stealing ecosystem—where affiliates juggle scams, MaaS platforms, and evasion tools to stay ahead of defenders💪 Great work team 🔥 041
Reposted by X_Hunt3rGreg Lesnewich @greg-l.bsky.social · 17/04/2025Saher's first blog on the scourge that is ClickFix usage in the espionage space!! Had to sneak in the UNK_RemoteRogue RDP shenanigans as well - a thus far unattributed group we assess to be Russia-aligned, using a pretty fun set of email tactics 1167
Reposted by X_Hunt3rThe Shadowserver Foundation @shadowserver.bsky.social · 12/04/2025Attention! Check your Compromised Website Report for critical events tagged “fortinet-compromised” and follow Fortinet's mitigation advice on compromised devices: fortinet.com/blog/psirt-b... Data available from 2025-04-11+ shadowserver.org/what-we-do/n... 31410
Reposted by X_Hunt3rCatalin Cimpanu @campuscodi.risky.biz · 04/03/2025Snoop, a Romanian investigative journalism outlet, has linked an online advertising company named AdNow to intelligence officials from Russia's FSB and SVR services snoop.ro/pe-urmele-ba... 17934
Reposted by X_Hunt3rCalwarez @calwarez.bsky.social · 28/02/2025🪡 Our 2024 Malicious Infrastructure Report showcases the results of our detections across hundreds of malware families and threat actors, revealing victims in 200+ countries and highlighting the global scale of cyber threats. Blog: www.recordedfuture.com/research/202... (1/10) 1106
Reposted by X_Hunt3rVolexity @volexity.com · 13/02/2025@volexity.com recently identified multiple Russian threat actors targeting users via #socialengineering + #spearphishing campaigns with Microsoft 365 Device Code authentication (a well-known technique) with alarming success: www.volexity.com/blog/2025/02... #dfir #threatintel #m365securityvolexity.comMultiple Russian Threat Actors Targeting Microsoft Device Code AuthenticationStarting in mid-January 2025, Volexity identified several social-engineering and spear-phishing campaigns by Russian threat actors aimed at compromising Microsoft 365 (M365) accounts. These attack cam... 23218
X_Hunt3r @x-hunt3r.bsky.social · 13/02/2025New Insikt Report just landed: RedMike AKA Salt Typhoon targeting of Global Telcos. www.recordedfuture.com/research/red...recordedfuture.com 051
Reposted by X_Hunt3rJosh Stroschein | The Cyber Yeti @jstrosch.bsky.social · 10/02/2025🔥 Live streams resume this week! Greg Lesnewich joins us to talk about 100 Days of Yara, some Yara rule tips and the current state of email borne threats! buff.ly/4gukMSN 🗓️ Thursday at 2pm CSTbuff.ly100 Days of Yara, Yara Rule Tips and The Current State of Email borne Threats with Greg LesnewichYara is one of the most versatile tools in cyber security. Come learn about creating effective and efficient rules with the creator of the 100 Days of Yara, ... 0135
Reposted by X_Hunt3rAlena Popova @alenapopova.bsky.social · 28/01/2025Ukrainian military officials, lawmakers, and experts are discussing the creation of a separate branch of Ukraine's Armed Forces dedicated to cyberspace operations, according to the General Staff of Ukraine. kyivindependent.com/ukraine-cons...kyivindependent.comUkrainian military considering creation of new cyber army branchUkrainian military, lawmakers, and experts discussed the creation of a separate branch of Ukraine's Armed Forces dedicated to cyberspace operations, the General Staff said on Oct. 24. 031
Reposted by X_Hunt3rAlexander Leslie @aejleslie.bsky.social · 23/01/2025New report! Check it out. This research examines the operations of Crazy Evil — a Russian-speaking “traffer team” and cryptoscam gang — which has victimized thousands of people with infostealer malware. Blog: www.recordedfuture.com/research/cra... PDF: go.recordedfuture.com/hubfs/report...recordedfuture.com"Crazy Evil" Cryptoscam Gang: Unmasking a Global Threat in 2024Explore how the "Crazy Evil" cryptoscam gang operates, infecting thousands worldwide with infostealer malware. Learn how its tactics pose a threat to the Web3 ecosystem and digital asset security. 1124
Reposted by X_Hunt3rWill T @bushidotoken.net · 20/01/2025New Blog! Tracking Adversaries: Ghostwriter APT Infrastructure 🇧🇾 blog.bushidotoken.net/2025/01/trac...blog.bushidotoken.netTracking Adversaries: Ghostwriter APT InfrastructureCTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security 0164
Reposted by X_Hunt3rTechCrunch @techcrunch.com · 13/01/2025UK domain giant Nominet confirms cybersecurity incident linked to Ivanti VPN hackstcrn.chUK domain giant Nominet confirms cybersecurity incident linked to Ivanti VPN hacksNominet, the U.K. domain registry that maintains .co.uk domains, has experienced a cybersecurity incident that it confirmed is linked to the recent exploitation of a new Ivanti VPN vulnerability. In an email to customers, seen by TechCrunch, Nominet… 12210
Reposted by X_Hunt3rAlexander Leslie @aejleslie.bsky.social · 07/01/2025New report! Check it out. This research examines the global proliferation of Russian surveillance technologies, their use by repressive governments, and possible data-sharing with Russian intelligence. Blog: www.recordedfuture.com/research/tra... PDF: go.recordedfuture.com/hubfs/report...recordedfuture.comUnveiling Russian Surveillance Tech Expansion in Central Asia and Latin AmericaA new report by Recorded Future’s Insikt group finds that countries across Central Asia and Latin America are increasingly basing their digital surveillance practices on Russia's System for Operative ... 2108
Reposted by X_Hunt3rCatalin Cimpanu @campuscodi.risky.biz · 02/01/2025DOOM-based CAPTCHA system doom-captcha.vercel.appdoom-captcha.vercel.appDOOM® CAPTCHAProve you're human by playing DOOM 96820
X_Hunt3r @x-hunt3r.bsky.social · 17/12/2024Russia's 'Sovereign Runet' initiative aims to isolate its internet from the global web, posing significant challenges to the cybercrime underworld that thrives on international connectivity. #CyberSecurity #Runet www.cybercrimediaries.com/post/russia-...cybercrimediaries.comRussia's Sovereign RuNet: A Challenge to the Cybercrime Underworld?In this blog, we will explore the extent to which the legislative and technical evolutions of the RuNet have impacted the Russian-speaking.. 195
Reposted by X_Hunt3rAlexander Leslie @aejleslie.bsky.social · 10/12/2024New report! Check it out. This research examines the role of Chinese international communication centers (ICCs) in amplifying propaganda via inauthentic social media activity, foreign influencers, and more. Blog: www.recordedfuture.com/research/bre... PDF: go.recordedfuture.com/hubfs/report...recordedfuture.comChina’s Propaganda Expansion: Inside the Rise of International Communication Centers (ICCs)China's ICCs reshape global propaganda via targeted messaging, social media, and influence networks to amplify the Communist Party's voice globally. 153
X_Hunt3r @x-hunt3r.bsky.social · 10/12/2024Great to be back at Cyber Threat for a third year. Awesome talks, great networking, and a very fresh and fun CTF. #cyberthreat24 020
X_Hunt3r @x-hunt3r.bsky.social · 05/12/2024🚨 New Report Alert: Insikt Group has uncovered #BlueAlpha, a Russian FSB-linked threat group overlapping with #Gamaredon, conducting a cyber-espionage campaign against Ukrainian targets. www.recordedfuture.com/research/blu...recordedfuture.comBlueAlpha Leverages Cloudflare Tunnels for GammaDrop InfrastructureBlueAlpha, a Russian cyber group, uses Cloudflare Tunnels to deploy GammaDrop malware, escalating challenges in targeting Ukrainian entities. 042
Reposted by X_Hunt3rJulian-Ferdinand Vögele @julianferdinand.bsky.social · 25/11/2024@milenkowski.bsky.social and I are looking forward to presenting together at #CyberThreat2024 in London next month. We‘ll be discussing China-nexus APTs engaging in cybercriminal activities like ransomware. 074
Reposted by X_Hunt3rWill T @bushidotoken.net · 18/11/2024Looking for more people to follow on BlueSky? Find the @curatedintel.bsky.social folks here: go.bsky.app/Kfp62Uh 32817
X_Hunt3r @x-hunt3r.bsky.social · 21/11/2024A new TAG-110 report, including victimology and recent C2 infrastructure, has just landed. #TAG110 #BlueDelta #APT28 www.recordedfuture.com/research/rus...recordedfuture.comRussia-Aligned TAG-110 Targets Asia and Europe with HATVIBE and CHERRYSPYTAG-110, a Russia-aligned threat group, targets organizations across Asia and Europe using HATVIBE and CHERRYSPY malware for espionage. Learn how Recorded Future's analysis uncovers the group’s tactic... 050
Reposted by X_Hunt3rToby Lewis @tobaslouis.co.uk · 19/11/2024As we're in this rapid growth of @bsky.app, not only are we going to see accnts impersonating high profile individuals, but critically, impersonating high reputation news sources. All it would take is some imaginative "Breaking News" to hit public confidence. Can the real BBC News please stand up? 053
Reposted by X_Hunt3rPIVOTcon @pivotcon.bsky.social · 19/11/2024#PIVOTcon25 registration is now OPEN 🤟📥📥📥 pivotcon.org #CTI #ThreatResearch #ThreatIntel Please read carefully the whole 🧵 for the rules about invite -> registration (1/5)media.tenor.comtwo men are standing next to each other with the words " we open it up " on the screenALT: two men are standing next to each other with the words " we open it up " on the screen 24222