
Joe
@jinx_soda
#AdvancedPractices Threat Analysis 🦅 @Mandiant
Tweets are my own
ID: 764330902184951808
13-08-2016 05:21:02
277 Tweet
560 Takipçi
487 Takip Edilen





New Mandiant (part of Google Cloud) blog on UNC4393, the primary user of BASTA. ✨ TTP shifts post-QAKBOT takedown, particularly regarding initial access. ✨ Increased custom malware, though LOTL & commodity tools still prevalent. 🔥 Josh++ Joe @nicastronaut cloud.google.com/blog/topics/th…






“Malware distribution groups are tricky to look at as a collective, so let’s narrow it down to some of my *least* favorites…” See ya next week, mWISE Conference 🫶🏼 #mWISE2024



Great technical post on LummaC2 obfuscation and how to deobfuscate samples through symbolic backward slicing: cloud.google.com/blog/topics/th… 🫸🫷 Chuong Dong and Nino!


🔥new blog detailing 0day exploitation of Ivanti appliances as well as newly observed malware families tracked as PHASEJAM and DRYHOOK. We also detail activity related to the previously observed SPAWN malware ecosystem tied to China nexus cluster UNC5337. cloud.google.com/blog/topics/th…