Sign in

X_Hunt3r

@x-hunt3r.bsky.social
282 followers 81 following 21 posts

Threat Hunting & Research, Network Forensics | Principal Threat Analyst @ Recorded Future | "Undesirable" | Member CuratedIntel | Views and opinions are my own

PostsRepliesMedia
X_Hunt3r @x-hunt3r.bsky.social · 22/07/2026
This is wild! openai.com/index/huggin...
openai.com
OpenAI and Hugging Face partner to address security incident during model evaluation
OpenAI and Hugging Face share early findings from a security incident during AI model evaluation, highlighting advanced cyber capabilities and lessons for defenders.
000
Reposted by X_Hunt3r
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 01/07/2026
Colleagues of mine at Insikt Group just released new research on the Iran-nexus cluster #TAG-182, deploying #MarkiRAT, a malware family previously observed in use by #FerociousKitten, for internal and external surveillance: www.recordedfuture.com/research/nex...
recordedfuture.com
Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool
Discover how Iranian-nexus threat cluster TAG-182 uses MarkiRAT malware and fake VPN/media apps to conduct cyber surveillance operations against domestic targets.
099
Reposted by X_Hunt3r
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 19/03/2026
1/ Today we’re publishing our annual malicious infrastructure report, providing a broad view of global threat infrastructure. This year, we significantly expanded coverage across malware families, threat categories, and deeper infrastructure insights: www.recordedfuture.com/research/202...
recordedfuture.com
2025 Year in Review: Malicious, Infrastructure
Explore Insikt Group’s 2025 Malicious Infrastructure Report. Gain insights into Cobalt Strike, Vidar infostealers, and AI-driven threats to secure your 2026 strategy.
1910
Reposted by X_Hunt3r
Zack Whittaker @zackwhittaker.com · 11/02/2026
By me: Microsoft has fixed three zero-day bugs in Windows and Office that are being actively abused by hackers to break into people's computers. Microsoft said three of the exploits are now public. Google, which helped find the bugs, said one of them is under “widespread, active exploitation."
techcrunch.com
Microsoft says hackers are exploiting critical zero-day bugs to target Windows and Office users | TechCrunch
Critical security flaws targeting Windows and Office users allow hackers to take complete control of a victim's computer by clicking a malicious link or opening a file. Patch now.
63520
Reposted by X_Hunt3r
CheckFirst @checkfirst.network · 09/02/2026
🔴 𝗡𝗘𝗪 𝗥𝗘𝗣𝗢𝗥𝗧 Last year, we've been able to unearth the infrastructure of the FSB's 16th Centre, combining #OSINT techniques and photos of old medals. We replicated this method to explore the Information Operations Troops (#VIO) of #Russia’s military intelligence service (#GRU).
Report cover showing a dark blue patch with crossed sword, arrow and scroll emblem, titled "Unveiling GRU's Information Operations Troops (VIO)"
12719
X_Hunt3r @x-hunt3r.bsky.social · 07/01/2026
Today, we released new @RecordedFuture research detailing BlueDelta’s expanded credential-harvesting activity observed between February and September 2025. #BlueDelta #APT28 #FANCYBEAR #ForestBlizzard #FROZENLAKE #ITG05 #PawnStorm #Sednit #Sofacy #TA422 (1/5) www.recordedfuture.com/research/gru...
recordedfuture.com
GRU-Linked BlueDelta Evolves Credential Harvesting
Insikt Group reveals how GRU-linked BlueDelta evolved credential-harvesting campaigns targeting government, energy, and research organizations across Europe and Eurasia.
175
X_Hunt3r @x-hunt3r.bsky.social · 17/12/2025
Today, we released new @RecordedFuture research detailing BlueDelta’s sustained credential-harvesting campaign targeting UKR.NET users between June 2024 and April 2025. www.recordedfuture.com/research/blu... #BlueDelta #APT28 #FANCYBEAR #ForestBlizzard #FROZENLAKE #PawnStorm #Sednit #Sofacy (1/5)
recordedfuture.com
BlueDelta’s Persistent Campaign Against UKR.NET
Discover how Russia’s BlueDelta targets UKR.NET users with advanced credential-harvesting campaigns, evolving tradecraft, and multi-stage phishing techniques.
132
X_Hunt3r @x-hunt3r.bsky.social · 16/09/2025
Great work by Sekoia uncovering new #BlueDelta #APT28 #Sofacy #FancyBear #ForestBlizzard #TAG110 malware samples. Linked to CERT-UA’s BeardShell & Covenant frameworks + revealed fresh weaponized docs & subtle TTPs. Activity ties to Russia-nexus ops incl. Double-Tap. blog.sekoia.io/apt28-operat...
blog.sekoia.io
APT28 Operation Phantom Net Voxel
APT28 Operation Phantom Net Voxel: weaponized Office lures, COM-hijack DLL, PNG stego to Covenant Grunt via Koofr, BeardShell on icedrive.
021
Reposted by X_Hunt3r
Cynthia Brumfield @metacurity.com · 15/09/2025
Ukraine claims cyberattacks on Russian election systems; Moscow confirms disruptions therecord.media/ukraine-clai...
therecord.media
Ukraine claims cyberattacks on Russian election systems; Moscow confirms disruptions
Ukraine said it was responsible for disrupting websites related to Russian election infrastructure as voters went to the polls in occupied territories.
042
Reposted by X_Hunt3r
Brian Liston @brianjliston.bsky.social · 03/09/2025
New report published today from our team at Recorded Future: “Russian Influence Assets Converge on Moldovan Elections” www.recordedfuture.com/research/rus...
recordedfuture.com
Russian Influence Assets Converge on Moldovan Elections
Ahead of Moldova’s 2025 elections, Russia-linked influence operations seek to undermine EU integration, discredit President Sandu, and destabilize democratic processes through coordinated disinformati...
065
Reposted by X_Hunt3r
Calwarez @calwarez.bsky.social · 27/08/2025
This report on Stark Industries is a fantastic case study in the cat-and-mouse game between hosting providers and law enforcement. The new "Threat Activity Enabler" (TAE) terminology is spot-on and highlights the critical role these providers play in the cybercrime ecosystem.
033
Reposted by X_Hunt3r
Alexander Martin @alexmartin.bsky.social · 27/08/2025
Scandi noir meets The Wire... 🇫🇮🚢 The captain of a Russia-linked oil tanker that damaged five subsea cables in the Baltic Sea on Christmas Day was instructed by his shipping company to destroy evidence after the ship was seized by Finnish authorities, according to a wiretap transcript.
therecord.media
Finnish police wiretap reveals Russian ‘shadow fleet’ captain instructed to destroy evidence
The captain of a Russia-linked oil tanker that damaged five subsea cables in the Baltic Sea was reportedly instructed to destroy evidence after the ship was seized by authorities.
05622
X_Hunt3r @x-hunt3r.bsky.social · 21/08/2025
Is it really 2025?! Cisco Smart Install and SNMP brute attacks... We are giving the FSB an easy ride. Great report by the Talos team! blog.talosintelligence.com/static-tundra/
blog.talosintelligence.com
Russian state-sponsored espionage group Static Tundra compromises unpatched end-of-life network devices
A Russian state-sponsored group, Static Tundra, is exploiting an old Cisco IOS vulnerability to compromise unpatched network devices worldwide, targeting key sectors for intelligence gathering.
010
X_Hunt3r @x-hunt3r.bsky.social · 21/08/2025
Fantastic new report by @julianferdinand.bsky.social and @aejleslie.bsky.social exposing Lumma’s vast info-stealing ecosystem—where affiliates juggle scams, MaaS platforms, and evasion tools to stay ahead of defenders💪 Great work team 🔥
041
Reposted by X_Hunt3r
Greg Lesnewich @greg-l.bsky.social · 17/04/2025
Saher's first blog on the scourge that is ClickFix usage in the espionage space!! Had to sneak in the UNK_RemoteRogue RDP shenanigans as well - a thus far unattributed group we assess to be Russia-aligned, using a pretty fun set of email tactics
1167
Reposted by X_Hunt3r
The Shadowserver Foundation @shadowserver.bsky.social · 12/04/2025
Attention! Check your Compromised Website Report for critical events tagged “fortinet-compromised” and follow Fortinet's mitigation advice on compromised devices: fortinet.com/blog/psirt-b... Data available from 2025-04-11+ shadowserver.org/what-we-do/n...
31410
Reposted by X_Hunt3r
Catalin Cimpanu @campuscodi.risky.biz · 04/03/2025
Snoop, a Romanian investigative journalism outlet, has linked an online advertising company named AdNow to intelligence officials from Russia's FSB and SVR services snoop.ro/pe-urmele-ba...
17934
Reposted by X_Hunt3r
Calwarez @calwarez.bsky.social · 28/02/2025
🪡 Our 2024 Malicious Infrastructure Report showcases the results of our detections across hundreds of malware families and threat actors, revealing victims in 200+ countries and highlighting the global scale of cyber threats. Blog: www.recordedfuture.com/research/202... (1/10)
1106
Reposted by X_Hunt3r
Volexity @volexity.com · 13/02/2025
@volexity.com recently identified multiple Russian threat actors targeting users via #socialengineering + #spearphishing campaigns with Microsoft 365 Device Code authentication (a well-known technique) with alarming success: www.volexity.com/blog/2025/02... #dfir #threatintel #m365security
volexity.com
Multiple Russian Threat Actors Targeting Microsoft Device Code Authentication
Starting in mid-January 2025, Volexity identified several social-engineering and spear-phishing campaigns by Russian threat actors aimed at compromising Microsoft 365 (M365) accounts. These attack cam...
23218
X_Hunt3r @x-hunt3r.bsky.social · 13/02/2025
New Insikt Report just landed: RedMike AKA Salt Typhoon targeting of Global Telcos. www.recordedfuture.com/research/red...
recordedfuture.com
051
Reposted by X_Hunt3r
Josh Stroschein | The Cyber Yeti @jstrosch.bsky.social · 10/02/2025
🔥 Live streams resume this week! Greg Lesnewich joins us to talk about 100 Days of Yara, some Yara rule tips and the current state of email borne threats! buff.ly/4gukMSN 🗓️ Thursday at 2pm CST
buff.ly
100 Days of Yara, Yara Rule Tips and The Current State of Email borne Threats with Greg Lesnewich
Yara is one of the most versatile tools in cyber security. Come learn about creating effective and efficient rules with the creator of the 100 Days of Yara, ...
0135
Reposted by X_Hunt3r
Alena Popova @alenapopova.bsky.social · 28/01/2025
Ukrainian military officials, lawmakers, and experts are discussing the creation of a separate branch of Ukraine's Armed Forces dedicated to cyberspace operations, according to the General Staff of Ukraine. kyivindependent.com/ukraine-cons...
kyivindependent.com
Ukrainian military considering creation of new cyber army branch
Ukrainian military, lawmakers, and experts discussed the creation of a separate branch of Ukraine's Armed Forces dedicated to cyberspace operations, the General Staff said on Oct. 24.
031
Reposted by X_Hunt3r
Alexander Leslie @aejleslie.bsky.social · 23/01/2025
New report! Check it out. This research examines the operations of Crazy Evil — a Russian-speaking “traffer team” and cryptoscam gang — which has victimized thousands of people with infostealer malware. Blog: www.recordedfuture.com/research/cra... PDF: go.recordedfuture.com/hubfs/report...
recordedfuture.com
"Crazy Evil" Cryptoscam Gang: Unmasking a Global Threat in 2024
Explore how the "Crazy Evil" cryptoscam gang operates, infecting thousands worldwide with infostealer malware. Learn how its tactics pose a threat to the Web3 ecosystem and digital asset security.
1124
Reposted by X_Hunt3r
Will T @bushidotoken.net · 20/01/2025
New Blog! Tracking Adversaries: Ghostwriter APT Infrastructure 🇧🇾 blog.bushidotoken.net/2025/01/trac...
blog.bushidotoken.net
Tracking Adversaries: Ghostwriter APT Infrastructure
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
0164
Reposted by X_Hunt3r
TechCrunch @techcrunch.com · 13/01/2025
UK domain giant Nominet confirms cybersecurity incident linked to Ivanti VPN hacks
tcrn.ch
UK domain giant Nominet confirms cybersecurity incident linked to Ivanti VPN hacks
Nominet, the U.K. domain registry that maintains .co.uk domains, has experienced a cybersecurity incident that it confirmed is linked to the recent exploitation of a new Ivanti VPN vulnerability. In an email to customers, seen by TechCrunch, Nominet…
12210
Reposted by X_Hunt3r
Alexander Leslie @aejleslie.bsky.social · 07/01/2025
New report! Check it out. This research examines the global proliferation of Russian surveillance technologies, their use by repressive governments, and possible data-sharing with Russian intelligence. Blog: www.recordedfuture.com/research/tra... PDF: go.recordedfuture.com/hubfs/report...
recordedfuture.com
Unveiling Russian Surveillance Tech Expansion in Central Asia and Latin America
A new report by Recorded Future’s Insikt group finds that countries across Central Asia and Latin America are increasingly basing their digital surveillance practices on Russia's System for Operative ...
2108
Reposted by X_Hunt3r
Catalin Cimpanu @campuscodi.risky.biz · 02/01/2025
DOOM-based CAPTCHA system doom-captcha.vercel.app
doom-captcha.vercel.app
DOOM® CAPTCHA
Prove you're human by playing DOOM
96820
X_Hunt3r @x-hunt3r.bsky.social · 17/12/2024
Russia's 'Sovereign Runet' initiative aims to isolate its internet from the global web, posing significant challenges to the cybercrime underworld that thrives on international connectivity. #CyberSecurity #Runet www.cybercrimediaries.com/post/russia-...
cybercrimediaries.com
Russia's Sovereign RuNet: A Challenge to the Cybercrime Underworld?
In this blog, we will explore the extent to which the legislative and technical evolutions of the RuNet have impacted the Russian-speaking..
195
Reposted by X_Hunt3r
Alexander Leslie @aejleslie.bsky.social · 10/12/2024
New report! Check it out. This research examines the role of Chinese international communication centers (ICCs) in amplifying propaganda via inauthentic social media activity, foreign influencers, and more. Blog: www.recordedfuture.com/research/bre... PDF: go.recordedfuture.com/hubfs/report...
recordedfuture.com
China’s Propaganda Expansion: Inside the Rise of International Communication Centers (ICCs)
China's ICCs reshape global propaganda via targeted messaging, social media, and influence networks to amplify the Communist Party's voice globally.
153
X_Hunt3r @x-hunt3r.bsky.social · 10/12/2024
Great to be back at Cyber Threat for a third year. Awesome talks, great networking, and a very fresh and fun CTF. #cyberthreat24
020
X_Hunt3r @x-hunt3r.bsky.social · 05/12/2024
🚨 New Report Alert: Insikt Group has uncovered #BlueAlpha, a Russian FSB-linked threat group overlapping with #Gamaredon, conducting a cyber-espionage campaign against Ukrainian targets. www.recordedfuture.com/research/blu...
recordedfuture.com
BlueAlpha Leverages Cloudflare Tunnels for GammaDrop Infrastructure
BlueAlpha, a Russian cyber group, uses Cloudflare Tunnels to deploy GammaDrop malware, escalating challenges in targeting Ukrainian entities.
042
Reposted by X_Hunt3r
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 25/11/2024
@milenkowski.bsky.social and I are looking forward to presenting together at #CyberThreat2024 in London next month. We‘ll be discussing China-nexus APTs engaging in cybercriminal activities like ransomware.
074
Reposted by X_Hunt3r
Will T @bushidotoken.net · 18/11/2024
Looking for more people to follow on BlueSky? Find the @curatedintel.bsky.social folks here: go.bsky.app/Kfp62Uh
32817
X_Hunt3r @x-hunt3r.bsky.social · 21/11/2024
A new TAG-110 report, including victimology and recent C2 infrastructure, has just landed. #TAG110 #BlueDelta #APT28 www.recordedfuture.com/research/rus...
recordedfuture.com
Russia-Aligned TAG-110 Targets Asia and Europe with HATVIBE and CHERRYSPY
TAG-110, a Russia-aligned threat group, targets organizations across Asia and Europe using HATVIBE and CHERRYSPY malware for espionage. Learn how Recorded Future's analysis uncovers the group’s tactic...
050
Reposted by X_Hunt3r
Toby Lewis @tobaslouis.co.uk · 19/11/2024
As we're in this rapid growth of @bsky.app, not only are we going to see accnts impersonating high profile individuals, but critically, impersonating high reputation news sources. All it would take is some imaginative "Breaking News" to hit public confidence. Can the real BBC News please stand up?
Screengrab of search results in Bluesky for the handle "bbcnews". It shows a list of accounts all of which could be the real BBC news, but it's unclear.
053
Reposted by X_Hunt3r
PIVOTcon @pivotcon.bsky.social · 19/11/2024
#PIVOTcon25 registration is now OPEN 🤟📥📥📥 pivotcon.org #CTI #ThreatResearch #ThreatIntel Please read carefully the whole 🧵 for the rules about invite -> registration (1/5)
media.tenor.com
two men are standing next to each other with the words " we open it up " on the screen
ALT: two men are standing next to each other with the words " we open it up " on the screen
24222