Daniel
dansomware.bsky.social
Daniel
@dansomware.bsky.social
threat research @ proofpoint
Reposted by Daniel
New episode of DISCARDED, and it's a banger with @ransomwaresommelier.com! We make jokes, talk about comic books and ransomware, and learn the best wine to pair with Op Endgame!
Apple: podcasts.apple.com/us/podcast/d...
Spotify: open.spotify.com/episode/645S...
Web: www.spreaker.com/episode/hack...
Hackers, Heists, and Heroes: The Evolving Ransomware Game
open.spotify.com
December 18, 2024 at 3:57 PM
People find hope in all kinds of places. Herschel Walker is going to be named ambassador to the Bahamas in place of being in charge of US missile defense.
December 18, 2024 at 4:06 AM
Reposted by Daniel
Dropping some new research on TA397/Bitter 🚨

Hidden in Plain Sight | TA397’s New Attack Chain Delivers Espionage RATs

Report:
www.proofpoint.com/us/blog/thre...
Hidden in Plain Sight: TA397’s New Attack Chain Delivers Espionage RATs | Proofpoint US
Key findings  Proofpoint observed advanced persistent threat (APT) TA397 targeting a Turkish defense sector organization with a lure about public infrastructure projects in Madagascar.   The attack...
www.proofpoint.com
December 17, 2024 at 12:10 PM
Reposted by Daniel
In December 11 and 12, 2024, a spearphishing campaign targeted at least 20 Autonomous System (AS) owners, predominantly Internet Service Providers (ISPs), and purported to come from the Network Operations Center (NOC) of a prominent European ISP.

🧵⤵️
Interesting susp targeted phish targeting an Italian telecom.
1) spoofing swisscom (note 'S', domain just reg'd)
2) leveraging encrypted rar + lnk + self signed pdf reader
3) BGP lure (fits with theme of email). BGP is the third leg in the outage triumvirate)
December 12, 2024 at 9:18 PM
Reposted by Daniel
Catch @greg-l.bsky.social and I talking about Mach-O binary similarity methods, YARA-X, and all the cool APT malware we pulled apart at #OBTS v7 today at 11:50am HST 🌺
December 6, 2024 at 8:43 PM
Reposted by Daniel
New episode of DISCARDED where we sit down with the 🐐 Mark Kelly, our lead China analyst, to talk all things China APT! Tune in wherever you get your podcasts. 🔮

Web: www.proofpoint.com/us/podcasts/...

Apple: podcasts.apple.com/us/podcast/d...

Spotify: open.spotify.com/episode/2AtJ...
DISCARDED | Proofpoint | Proofpoint US
www.proofpoint.com
December 4, 2024 at 12:38 AM
Reposted by Daniel
"The flow uses a documented execution hijack of IE4uinit. By supplying a “side-loaded” .inf file to IE4uinit, it can be used to load and execute COM scriptlets..."

🌟New report out Monday, December 2nd by
@_pete_0, @svch0st and guest contributor @k3dg3 from
@proofpoint!
December 1, 2024 at 2:45 PM
Even though @hultquist.bsky.social and @selenalarson.bsky.social feel it's appropriate to move on to Christmas movies already... it's my family's Thanksgiving tradition to watch a relatively unknown classic each year: Run Fatboy Run (m.imdb.com/title/tt0425...)
Run Fatboy Run (2007) ⭐ 6.5 | Comedy, Romance, Sport
1h 40m | PG-13
m.imdb.com
November 29, 2024 at 5:55 PM
Reposted by Daniel
November 26, 2024 at 6:38 PM