Emanuele De Lucia(@Manu_De_Lucia) 's Twitter Profileg
Emanuele De Lucia

@Manu_De_Lucia

doing stuff and solving problems at @cluster25_io // #DFIR #CTI #APT #CyberSecurity #Malware #ThreatIntelligence

ID:977272715500498951

linkhttps://www.emanueledelucia.net/ calendar_today23-03-2018 19:55:46

587 Tweets

2,3K Followers

224 Following

Follow People
Yashraj Solanki(@RustyNoob619) 's Twitter Profile Photo

Day36: LNK Droppers used by Russian APT in a past campaign 🐧

github.com/RustyNoob-619/…

My first encounter with LNK files and Base64 content

#100DaysofYARA Day36: LNK Droppers used by Russian APT in a past campaign 🐧 github.com/RustyNoob-619/… My first encounter with LNK files and Base64 content
account_circle
Cluster25(@cluster25_io) 's Twitter Profile Photo

🚨Cluster25 investigated a possible campaign targeting dissidents. Using different lures, the aimed at organizations and citizens, leveraging a . Read more on: blog.cluster25.duskrise.com/2024/01/30/rus…

account_circle
Emanuele De Lucia(@Manu_De_Lucia) 's Twitter Profile Photo

It took about 2 months to detect a compromise by a nation-state adversary. Now, the question to ask yourself, to learn from this event, is: how long would it take me ? 🙄 29

account_circle
Emanuele De Lucia(@Manu_De_Lucia) 's Twitter Profile Photo

🎆 🎇 Wishing all of you guys a glitch-free 2024 ! May your code be secure, your firewalls impenetrable, and your New Year filled with encrypted adventures. 🙂 🌐 🎉

account_circle
Emanuele De Lucia(@Manu_De_Lucia) 's Twitter Profile Photo

I wrote here a blogpost about how / gang managed to 'unseize' their DLS (Dedicated Leak Site). To be fair, it must be said that they technically did not 'unseized' anything 😄
emanueledelucia.net/a-blackcat-and…

account_circle
Emanuele De Lucia(@Manu_De_Lucia) 's Twitter Profile Photo

Had a look at the / kill-chain for its recent comeback. Long-story-short: msiexec.exe -> MSI[\dA-Z]+\.tmp -> rundll32.exe -> KROST.dll,hvsi rule available at github.com/edelucia/rules…

account_circle
Cluster25(@cluster25_io) 's Twitter Profile Photo

🚨A seemingly legitimate profile contacts you via direct message and offers you a job, sending a PDF file. This is the beginning of a bad story that leads to infection. Read more on: blog.cluster25.duskrise.com/2023/10/25/the…

account_circle
Cluster25(@cluster25_io) 's Twitter Profile Photo

🚨 Cluster25 has uncovered phishing attacks likely linked to a pro-Russia nation-State adversary. These attacks, conducted in the context of the RU-UA conflict zone, leverage a recently discovered vulnerability (CVE-2023-38831) affecting WinRAR. Read more: blog.cluster25.duskrise.com/2023/10/12/cve…

account_circle
Cluster25(@cluster25_io) 's Twitter Profile Photo

We are happy to announce that is now integrated with through a dedicated connector. OpenCTI connectors are a crucial components to enable organizations to easily ingest, enrich and/or export data. github.com/OpenCTI-Platfo…

account_circle