Search results
  1. 9 Sep 2021
  2. 18 Mar 2021

    We're currently working on a report on / ransomware. Should have the report out in a week or so (each report takes 40+ hours of work). Interested in the C2 IPs, files, mem dumps, logs, etc. ahead of time?⬇️

    Show this thread
  3. Show this thread
  4. 14 May 2020

    DO IT!!!! Please we need to be rid of this orange carbuncle.

  5. 21 Apr 2021

    The ransomware group REvil, aka , published a blog on its site in which it claimed to have infiltrated the computer network of Computer Inc. primary supplier of Stolen info about: Apple Watch Apple Macbook Air Apple Macbook Pro ThinkPadZ6om

  6. 23 Aug 2020
  7. 7 Sep 2021

    is back !! (checked today 070920:00 UTC -3)

  8. 8 Nov 2021

    Five affiliates to / were arrested during operation , which involved 17 countries, Europol, & . The arrested affiliates are suspected of 7 000 infections, asking for over €200 million in ransom. More ➡️

    Show this thread
  9. Group hacked Kenneth Copeland and leaked related data to the .

  10. 18 Mar 2021

    / - Affiliate "sub": "7088" - Adds "Company Name" in the ransom note. - {EXT}-read-me-<company_name>.txt - "bootcfg /raw /a /safeboot:network /id 1" - "bcdedit /set {current} safeboot network"

  11. Feb 14

    T3 2021 was quite a busy period for ransomware. According to , the first and biggest spike occurred on September 9, caused by / hitting South Africa 🇿🇦, only days before the country's Department of Justice saw its systems encrypted. 1/5

    Show this thread
  12. 4 Mar 2021

    This week we saw significant growth in activity from , and . while appears to be winding down considerably.

  13. 21 Feb 2020

    Interesting to see how / operators track security researchers and adapt their game appropriately!

  14. 21 Mar 2021

    We're seeing a lot of chatter about Acer/Exchange and wanted to share something from our report. ➡️The TAs first lateral movement was to our Exchange server. ➡️➡️Cobalt Strike SCM exec from beachhead ➡️Exchange was vulnerable ➡️➡️Exchange was not exploited /

    Show this thread
  15. 18 Aug 2020

    Today's Snort rule release is a doozy. We've got new coverage for , and perhaps most notably,

  16. 13 Nov 2020
  17. 16 Jun 2021
  18. 12 Feb 2021

    🇮🇹 MD5: 6543523F2483B9365FD1AED238879588 VER: 2.3 SUB: "5781" Price: 963.436 XMR first 48h after 1926.872 XMR ≈ 200,000 USD after ≈ 400,000 USD RDP Client: WIN-1L9F5B0JHVM IP: 193.169.252.]125

Loading seems to be taking a while.

Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.