Rhys (@rhysdowning_) 's Twitter Profile
Rhys

@rhysdowning_

Threat Researcher / Threat Hunter who loves malware | My views are strictly my own.

ID: 138459664

linkhttp://blog.threatuniverse.co.uk calendar_today29-04-2010 16:10:24

4,4K Tweet

462 Followers

1,1K Following

ANY.RUN (@anyrun_app) 's Twitter Profile Photo

Top 10 last week's threats by uploads 🌐 ⬆️ #Amadey 963 (156) ⬇️ #Remcos 880 (923) ⬇️ #Xworm 792 (967) ⬆️ #Lumma 673 (659) ⬆️ #Tofsee 535 (144) ⬆️ #Snake 403 (326) ⬇️ #Asyncrat 380 (433) ⬇️ #Stealc 157 (171) ⬇️ #Agenttesla 153 (245) ⬇️ #Vidar 151 (178) Track them all:

Top 10 last week's threats by uploads 🌐
⬆️ #Amadey 963 (156)
⬇️ #Remcos 880 (923)
⬇️ #Xworm 792 (967)
⬆️ #Lumma 673 (659)
⬆️ #Tofsee 535 (144)
⬆️ #Snake 403 (326)
⬇️ #Asyncrat 380 (433)
⬇️ #Stealc 157 (171)
⬇️ #Agenttesla 153 (245)
⬇️ #Vidar 151 (178)

Track them all:
Hackread.com (@hackread) 's Twitter Profile Photo

New: Watch out as a new Microsoft Teams vishing attack spotted hackers abusing TeamViewer and Quick Assist to drop malware. Read: hackread.com/microsoft-team… #CyberSecurity #Vishing #TeamViewer #MicrosoftTeams

Who said what? (@g0njxa) 's Twitter Profile Photo

Fresh #Clickfix design campaign spreading #Lumma stealer on X ads impersonating AI sites /newflave.rf.gd /gltgirl.rf.gd Payload: /kutt.it/ReStarT >> /snippet.host/migppg Build hosted on Azure DevOps repo Detonation: app.any.run/tasks/617fda4e…

Fresh #Clickfix design campaign spreading #Lumma stealer on X ads impersonating AI sites

/newflave.rf.gd
/gltgirl.rf.gd

Payload: /kutt.it/ReStarT >> /snippet.host/migppg

Build hosted on Azure DevOps repo

Detonation: app.any.run/tasks/617fda4e…
Cookie Connoisseur (@browsercookies) 's Twitter Profile Photo

How do you catch a DPRK actor you ask? Here are a few things to think about; 1. They love to use a VPN when applying for jobs. Check your HR system.

ANY.RUN (@anyrun_app) 's Twitter Profile Photo

Top 10 last week's threats by uploads 🌐 ⬇️ #Lumma 569 (1077) ⬆️ #Tofsee 363 (263) ⬇️ #Xworm 309 (1099) ⬇️ #Asyncrat 290 (395) ⬆️ #Neconyd 283 (169) ⬇️ #Snake 254 (379) ⬇️ #Remcos 232 (566) ⬇️ #Amadey 156 (380) ⬆️ #Formbook 134 (78) ⬇️ #Agenttesla 114 (271) Track them all:

Top 10 last week's threats by uploads 🌐
⬇️ #Lumma 569 (1077)
⬆️ #Tofsee 363 (263)
⬇️ #Xworm 309 (1099)
⬇️ #Asyncrat 290 (395)
⬆️ #Neconyd 283 (169)
⬇️ #Snake 254 (379)
⬇️ #Remcos 232 (566)
⬇️ #Amadey 156 (380)
⬆️ #Formbook 134 (78)
⬇️ #Agenttesla 114 (271)

Track them all:
vx-underground (@vxunderground) 's Twitter Profile Photo

I don't know what they're putting in the water, but these anime profile-picture nerds are cookin' .es3n1n reverse engineered Windows Security Center service and found how to interop with it. This includes disabling it and being a memester See attached post for details

I don't know what they're putting in the water, but these anime profile-picture nerds are cookin'

.<a href="/es3n1n/">es3n1n</a> reverse engineered Windows Security Center service and found how to interop with it. This includes disabling it and being a memester

See attached post for details
ANY.RUN (@anyrun_app) 's Twitter Profile Photo

Top 10 last week's threats by uploads 🌐 ⬆️ #Lumma 753 (524) ⬆️ #Remcos 556 (130) ⬆️ #Xworm 427 (163) ⬆️ #Asyncrat 349 (165) ⬆️ #Snake 342 (182) ⬆️ #Agenttesla 299 (119) ⬆️ #Amadey 194 (185) ⬇️ #Neconyd 190 (286) ⬆️ #Quasar 114 (74) ⬆️ #Dcrat 87 (74) Track them all:

Top 10 last week's threats by uploads 🌐
⬆️ #Lumma 753 (524)
⬆️ #Remcos 556 (130)
⬆️ #Xworm 427 (163)
⬆️ #Asyncrat 349 (165)
⬆️ #Snake 342 (182)
⬆️ #Agenttesla 299 (119)
⬆️ #Amadey 194 (185)
⬇️ #Neconyd 190 (286)
⬆️ #Quasar 114 (74)
⬆️ #Dcrat 87 (74)
Track them all:
ⱤɄ₲ ₱ɄⱠⱠ ₣ł₦ĐɆⱤ 💋 (@rugpullfinder) 's Twitter Profile Photo

🚨 The Fake Ledger That Stole Everything (1/8) James* thought he was safe. He used a Ledger hardware wallet, kept his 24 words private, and followed every crypto security tip out there. Then one day… a package arrived. 🧵👇

🚨 The Fake Ledger That Stole Everything

(1/8)
James* thought he was safe. He used a Ledger hardware wallet, kept his 24 words private, and followed every crypto security tip out there.

Then one day… a package arrived.
🧵👇
Back Engineering Labs (@backengineerlab) 's Twitter Profile Photo

Given the recent events with VMPSoft DMCA'ing educational YouTube videos demonstrating how to unpack malware protected with VMProtect, we have decided to release a free to use unpacker which works for all versions of VMP 3.x including the most recent version. Simply sign

Given the recent events with VMPSoft DMCA'ing educational YouTube videos demonstrating how to unpack malware protected with VMProtect, we have decided to release a free to use unpacker which works for all versions of VMP 3.x including the most recent version.

Simply sign
ANY.RUN (@anyrun_app) 's Twitter Profile Photo

Top 10 last week's threats by uploads 🌐) ⬇️ #Lumma 733 (825) ⬆️ #Asyncrat 494 (447) ⬇️ #Remcos 491 (624) ⬆️ #Snake 432 (338) ⬇️ #Xworm 430 (440) ⬆️ #Amadey 249 (224) ⬇️ #Agenttesla 221 (265) ⬆️ #Dcrat 216 (126) ⬆️ #Stealc 136 (130) ⬆️ #Quasar 132 (78) Track them all:

Top 10 last week's threats by uploads 🌐)
⬇️ #Lumma 733 (825)
⬆️ #Asyncrat 494 (447)
⬇️ #Remcos 491 (624)
⬆️ #Snake 432 (338)
⬇️ #Xworm 430 (440)
⬆️ #Amadey 249 (224)
⬇️ #Agenttesla 221 (265)
⬆️ #Dcrat 216 (126)
⬆️ #Stealc 136 (130)
⬆️ #Quasar 132 (78)
Track them all:
Cyber Ghost (@cyberghost13337) 's Twitter Profile Photo

A new clickfix technique, FileFix, developed by mr.d0x, is being used in the wild—poorly. Website tersmoles[.]com delivers a "Legitimate Chrome Installer" using FileFix. The attacker didn’t even change the path and filename—just copy-pasted code directly from demo website

A new clickfix technique, FileFix, developed by <a href="/mrd0x/">mr.d0x</a>, is being used in the wild—poorly.

Website tersmoles[.]com delivers a "Legitimate Chrome Installer" using FileFix.

The attacker didn’t even change the path and filename—just copy-pasted code directly from demo website