Calwarez (@calwarez) 's Twitter Profile
Calwarez

@calwarez

Leads Malicious Infrastructure Discovery @ Recorded Future | Views my own

ID: 1590287446297776128

calendar_today09-11-2022 10:18:12

74 Tweet

139 Takipçi

335 Takip Edilen

Virus Bulletin (@virusbtn) 's Twitter Profile Photo

Insikt Group releases a deep dive into the Lumma infostealer, active since 2022, and the affiliates behind it. The analysis highlights new, previously undocumented tools and evidence that affiliates run multiple schemes simultaneously. recordedfuture.com/research/behin…

Insikt Group releases a deep dive into the Lumma infostealer, active since 2022, and the affiliates behind it. The analysis highlights new, previously undocumented tools and evidence that affiliates run multiple schemes simultaneously. recordedfuture.com/research/behin…
Calwarez (@calwarez) 's Twitter Profile Photo

Highly recommend this report on TAG-144. It breaks down the group's operations into five distinct clusters and reveals some serious tradecraft! From using compromised government emails to hiding payloads in JPGs. A deep dive into a very sophisticated threat.

The Hacker News (@thehackersnews) 's Twitter Profile Photo

⚠️ Cyber researchers just exposed 5 attack clusters tied to hacking group Blind Eagle—targeting Colombia’s government, banks, and critical sectors since 2024. They’re using cracked RATs, fake bank portals, and even Discord & Google Drive to deliver malware. Details →

⚠️ Cyber researchers just exposed 5 attack clusters tied to hacking group Blind Eagle—targeting Colombia’s government, banks, and critical sectors since 2024.

They’re using cracked RATs, fake bank portals, and even Discord & Google Drive to deliver malware.

Details →
Calwarez (@calwarez) 's Twitter Profile Photo

This report on Stark Industries is a fantastic case study in the cat-and-mouse game between hosting providers and law enforcement. The new "Threat Activity Enabler" (TAE) terminology is spot-on and highlights the critical role these providers play in the cybercrime ecosystem.

780th Military Intelligence Brigade (Cyber) (@780thc) 's Twitter Profile Photo

Recorded Future: Stark Industries, along with its CEO and owner, was formally sanctioned by the Council of the European Union on May 20, 2025, for enabling Russian state-sponsored cyber operations | recordedfuture.com/research/one-s… Recorded Future

urlscan.io (@urlscanio) 's Twitter Profile Photo

Thanks to the awesome work by our team we can finally announce our official urlscan cli tool: urlscan.io/blog/2025/09/0… - Submit scans, run searches, find domains, get creative. Feel free to share your use-cases with us on X! Download on Github or homebrew.

Thanks to the awesome work by our team we can finally announce our official urlscan cli tool: urlscan.io/blog/2025/09/0… - Submit scans, run searches, find domains, get creative. Feel free to share your use-cases with us on X! Download on Github or homebrew.
Brian Liston (@brianjliston) 's Twitter Profile Photo

⚡️ New report out today from our team at Recorded Future: “Russian Influence Assets Converge on Moldovan Elections” Ahead of the upcoming parliamentary elections, we touch on multiple Russia-based/linked influence operations we assess are attempting to destabilize Moldova,

Lawrence_Sec (@lawrence_sec) 's Twitter Profile Photo

A significant amount of #CastleLoader C2 infrastructure identified by Julian-Ferdinand and Jerri P in their latest report was tied to #ThreatActivityEnabler 🇬🇧 FEMO IT SOLUTIONS #AS214351 utilising 🇩🇪 aurologic GmbH #AS30823 as their sole upstream provider. One to watch out for!

A significant amount of #CastleLoader  C2 infrastructure identified by <a href="/JulianVoeg/">Julian-Ferdinand</a> and <a href="/_whoisnt/">Jerri P</a> in their latest report was tied to #ThreatActivityEnabler 🇬🇧 FEMO IT SOLUTIONS #AS214351 utilising 🇩🇪 aurologic GmbH #AS30823 as their sole upstream provider. One to watch out for!
Jerri P (@_whoisnt) 's Twitter Profile Photo

Check out the latest @recordedfuture report from Julian-Ferdinand , Marius, and me on TAG-150, where we break down CastleLoader and CastleRAT (Python + C variants). Recent TTP: C2 deaddrops on Steam Community pages, marking a new infrastructure tactic 🔗recordedfuture.com/research/from-…

Check out the latest @recordedfuture report from <a href="/JulianVoeg/">Julian-Ferdinand</a> , Marius, and me on TAG-150, where we break down CastleLoader and CastleRAT (Python + C variants). 

Recent TTP: C2 deaddrops on Steam Community pages, marking a new infrastructure tactic 

🔗recordedfuture.com/research/from-…
Virus Bulletin (@virusbtn) 's Twitter Profile Photo

Insikt Group identifies a new threat actor, TAG-150, active since at least March 2025. Its multi-layered infrastructure is used to deploy likely self-developed malware families, including CastleLoader, CastleBot, and the newly documented CastleRAT. recordedfuture.com/research/from-…

Insikt Group identifies a new threat actor, TAG-150, active since at least March 2025. Its multi-layered infrastructure is used to deploy likely self-developed malware families, including CastleLoader, CastleBot, and the newly documented CastleRAT. recordedfuture.com/research/from-…
The DFIR Report (@thedfirreport) 's Twitter Profile Photo

🌟New report out today!🌟 Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs Analysis and reporting completed by Renzon, EncapsulateJay, Roman Konicek, & Adam Rowe Audio: Available on Spotify, Apple, YouTube and more! Report:⬇️

🌟New report out today!🌟

Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs

Analysis and reporting completed by <a href="/r3nzsec/">Renzon</a>, <a href="/EncapsulateJ/">EncapsulateJay</a>, <a href="/rkonicekr/">Roman Konicek</a>, &amp; Adam Rowe

Audio: Available on Spotify, Apple, YouTube and more!

Report:⬇️
Lawrence_Sec (@lawrence_sec) 's Twitter Profile Photo

Great blog from briankrebs referencing our recent report on #StarkIndustries. Makes a very good point to highlight the links to MIR Hosting again. Where there are Dutch prefixes under these providers, there is usually always MIR upstream. krebsonsecurity.com/2025/09/bullet…

Mark Kelly (@markkelly0x) 's Twitter Profile Photo

🚨🇨🇳💰 New Threat Insight blog on TA415 (APT41) economy and trade-themed spearphishing against US govt, think tanks & academia. The campaigns used U.S.-China economic lures and spoofed the Chair of the House Select Committee on CCP competition + the US-China Business Council.

🚨🇨🇳💰 New <a href="/threatinsight/">Threat Insight</a> blog on TA415 (APT41) economy and trade-themed spearphishing against US govt, think tanks &amp; academia. 

The campaigns used U.S.-China economic lures and spoofed the Chair of the House Select Committee on CCP competition + the US-China Business Council.
Lawrence_Sec (@lawrence_sec) 's Twitter Profile Photo

The UK has sanctioned Aeza International, citing its involvement in destabilising Ukraine by providing internet services to Russian disinformation campaigns. This follows OFAC sanctions in July. gov.uk/government/new…

Spamhaus (@spamhaus) 's Twitter Profile Photo

Already decided what's for dinner today? Fancy some fish? 🎣 If so, 14B Turner Street in 🇬🇧 Manchester might be the place to go. Its ground floor seems to host an Italian restaurant, according to Google Street View, which certainly has fish on the menu. 🍽️ Craving a more

Already decided what's for dinner today? Fancy some fish? 🎣 If so, 14B Turner Street in 🇬🇧 Manchester might be the place to go. Its ground floor seems to host an Italian restaurant, according to Google Street View, which certainly has fish on the menu. 🍽️ 

Craving a more
Calwarez (@calwarez) 's Twitter Profile Photo

Great work by my colleague, Lawrence_Sec ! He dives deep into the systemic flaw where "neutral" internet governance lets sanctioned ISPs evade restrictions and continue supporting #cyberattacks and #disinformation. A must-read on the infrastructure gap. 👇