Mar_Pich (@mar_pich) 's Twitter Profile
Mar_Pich

@mar_pich

Threat Intelligence analyst @CERTCyberdef | GCTI | 🇫🇷

ID: 1585536093465763841

linkhttps://research.cert.orangecyberdefense.com/ calendar_today27-10-2022 07:38:10

55 Tweet

1,1K Followers

157 Following

Mar_Pich (@mar_pich) 's Twitter Profile Photo

Biiiig changelog for our #ransomware cartography! 🤠New version (v27) available on our CERT GitHub: github.com/cert-orangecyb… 💡Entities are clickable for our World Watch clients to read more about threat groups and malware strains. #cyberthreatintelligence #cti Orange Cyberdefense

Biiiig changelog for our #ransomware cartography! 
🤠New version (v27) available on our CERT GitHub: github.com/cert-orangecyb…
💡Entities are clickable for our World Watch clients to read more about threat groups and malware strains.
#cyberthreatintelligence #cti <a href="/orangecyberdef/">Orange Cyberdefense</a>
CERT Orange Cyberdefense (@certcyberdef) 's Twitter Profile Photo

Several weeks ago, our #CERT analysts Mar_Pich Vincent Hinderer and alex investigated a malicious ongoing campaign targeting one of our client and leveraging a little documented multistage #loader we dubbed #MintsLoader🥬🧀. github.com/cert-orangecyb… ⬇️

Several weeks ago, our #CERT analysts <a href="/Mar_Pich/">Mar_Pich</a> <a href="/vhinderer/">Vincent Hinderer</a>  and <a href="/_alexb___/">alex</a> investigated a malicious ongoing campaign targeting one of our client and leveraging a little documented multistage #loader we dubbed #MintsLoader🥬🧀.
github.com/cert-orangecyb…
⬇️
CERT Orange Cyberdefense (@certcyberdef) 's Twitter Profile Photo

📍For more than 8 months, our threat researchers from Orange Cyberdefense have worked on mapping 🇨🇳 China's civil-military–industrial complex when it comes to #cyberespionage operations. ⛯ Consult our newly published deep-dive report and interactive map here: research.cert.orangecyberdefense.com/hidden-network…

CERT Orange Cyberdefense (@certcyberdef) 's Twitter Profile Photo

While monitoring recent #Emmenhtal iterations, we observed a distinct politically-aligned cluster 🇪🇺, strongly differing from usual financially motivated Emmenhtal distribs. This cluster drops another malware we dubbed #Edam Dropper🧀 🔗 github.com/cert-orangecyb…

CERT Orange Cyberdefense (@certcyberdef) 's Twitter Profile Photo

New variant of #Emmenhtal loader actively distributed since early December and leading to #Lumma #DarkGate and/or #SectopRAT. 🚩#Emmenhtalv2 adopts new obfuscation features and is currently not well detected by AV solutions. Initial access: fake CAPTCHA, #ClickFix, phishing.

CERT Orange Cyberdefense (@certcyberdef) 's Twitter Profile Photo

🧵/ Over the last months, our CyberSOC & CERT teams have been tracking a malicious cluster leveraging #WsgiDAV servers to distribute commodity #RATs, including in Europe🇪🇺. ⛓️Multistage infection chain: LNK>VBS>BAT>Powershell>ZIP>Python We track this activity as Blue Stylthon🧀

🧵/ Over the last months, our CyberSOC &amp; CERT teams have been tracking a malicious cluster leveraging #WsgiDAV servers to distribute commodity #RATs, including in Europe🇪🇺. 
⛓️Multistage infection chain: LNK&gt;VBS&gt;BAT&gt;Powershell&gt;ZIP&gt;Python
We track this activity as Blue Stylthon🧀
CERT Orange Cyberdefense (@certcyberdef) 's Twitter Profile Photo

🆕New version of our #ransomware mapping is out on our GitHub! ➡️github.com/cert-orangecyb… V28 (!) includes latest newcomers and recent ecosystem evolutions.🔍 As always, feedback is welcome! #cti #threatintel #blackbasta #ransomhub #lockbit

🆕New version of our #ransomware mapping is out on our GitHub!
➡️github.com/cert-orangecyb…
V28 (!) includes latest newcomers and recent ecosystem evolutions.🔍
As always, feedback is welcome!
#cti #threatintel #blackbasta #ransomhub #lockbit
CERT Orange Cyberdefense (@certcyberdef) 's Twitter Profile Photo

🔎In recent campaigns, TAs create new #GitHub repositories populated with an AI-generated README and filled with fake backdated commits. We also observed similar distributions via inactive repositories typically forked with a new release containing #SmartLoader ultimately added.

🔎In recent campaigns, TAs create new #GitHub repositories populated with an AI-generated README and filled with fake backdated commits.
We also observed similar distributions via inactive repositories typically forked with a new release containing #SmartLoader ultimately added.
CERT Orange Cyberdefense (@certcyberdef) 's Twitter Profile Photo

🆕New version of #Emmenhtal loader actively distributed worldwide since early March, leading to #Lumma or #Rhadamanthys stealers. Very low AV detection on VT for now. Similarly to V2, Emmenhtal V3 masquerades as #mp3 or #mp4 files, including relaxation songs.🧘‍♀️

🆕New version of #Emmenhtal loader actively distributed worldwide since early March, leading to #Lumma or #Rhadamanthys stealers.
Very low AV detection on VT for now. 
Similarly to V2, Emmenhtal V3 masquerades as #mp3 or #mp4 files, including relaxation songs.🧘‍♀️
CERT Orange Cyberdefense (@certcyberdef) 's Twitter Profile Photo

💡Our colleagues from Orange Cyberdefense CyberSOC 🇩🇪 just published insights on several December 2024 intrusions leveraging #socialengineering tactics to distribute #DarkGate, #BlackBasta, as well as a custom credential harvester. ➡️orangecyberdefense.com/de/blog/threat…

💡Our colleagues from Orange Cyberdefense CyberSOC 🇩🇪 just published insights on several December 2024 intrusions leveraging #socialengineering tactics to distribute #DarkGate, #BlackBasta, as well as a custom credential harvester.
 ➡️orangecyberdefense.com/de/blog/threat…
PIVOTcon (@pivot_con) 's Twitter Profile Photo

Everything ready for #PIVOTcon25 Day2! Quick morning ☕️ and we are prepared to listen to the top #ThreatIntel #ThreatResearch #CTI Let’s pivot ! 🤟

Everything ready for #PIVOTcon25 Day2! Quick morning ☕️ and we are prepared to listen to the top #ThreatIntel #ThreatResearch #CTI Let’s pivot ! 🤟
NATO CCDCOE (@ccdcoe) 's Twitter Profile Photo

#CyCon2025 Workshop Day is underway! Today, we're diving into9️⃣dynamic sessions exploring the future of cyber conflict and defence. More photos: flic.kr/s/aHBqjCfJfS

#CyCon2025 Workshop Day is underway! Today, we're diving into9️⃣dynamic sessions exploring the future of cyber conflict and defence. More photos: flic.kr/s/aHBqjCfJfS
Virtual Routes (@virtualroutes) 's Twitter Profile Photo

#CyCon2025 mission accomplished! 🎯 #VirtualRoutes workshop Ransomware : Crime, Conflict, and Cyber Defences is done. Thank you to the brilliant leads Max Smeets, Gijs van Loon, Mar_Pich, Roxana Radu & James Shires, everyone who joined us and NATO CCDCOE for having us!

#CyCon2025 mission accomplished! 🎯 #VirtualRoutes workshop Ransomware : Crime, Conflict, and Cyber Defences is done. Thank you to the brilliant leads <a href="/Maxwsmeets/">Max Smeets</a>, <a href="/gijsvloon/">Gijs van Loon</a>, <a href="/Mar_Pich/">Mar_Pich</a>, <a href="/r0xanaradu/">Roxana Radu</a> &amp; James Shires, everyone who joined us and <a href="/ccdcoe/">NATO CCDCOE</a> for having us!
Mar_Pich (@mar_pich) 's Twitter Profile Photo

🆕 Just released a blogpost on a #Sorillus RAT campaign our CERT Orange Cyberdefense observed in March. Likely 🇧🇷 threat actors, use of numerous tunneling services like ngrok[.]app, ngrok[.]dev, ngrok[.]pro, localto[.]net, ply[.]gg, campaign still active… ➡️ orangecyberdefense.com/global/blog/ce…

🆕 Just released a blogpost on a #Sorillus RAT campaign our <a href="/CERTCyberdef/">CERT Orange Cyberdefense</a> observed in March.
Likely 🇧🇷 threat actors, use of numerous tunneling services like ngrok[.]app, ngrok[.]dev, ngrok[.]pro, localto[.]net, ply[.]gg, campaign still active…

➡️ orangecyberdefense.com/global/blog/ce…
Mar_Pich (@mar_pich) 's Twitter Profile Photo

Check out our latest report on a DPRK intrusion related to #OpDreamJob 🇰🇵!Shoutout to alex for his reverse engineering and to the whole CERT Orange Cyberdefense team for their contributions! 🤗

CERT Orange Cyberdefense (@certcyberdef) 's Twitter Profile Photo

Last week, our International CyberSOC team detected a wave of #phishing emails sent to several customers in Germany🇩🇪. Designed for Microsoft 365 credentials harvesting, the campaign relies on #bubbleapps subdomains spoofing company names.

Last week, our International CyberSOC team detected a wave of #phishing emails sent to several customers in Germany🇩🇪. Designed for Microsoft 365 credentials harvesting, the campaign relies on #bubbleapps subdomains spoofing company names.