Dmitry Melikov (@dmitriymelikov) 's Twitter Profile
Dmitry Melikov

@dmitriymelikov

Threat Researcher @AWNetworks #cti #apt Former Threat Researcher @BlackBerry, @InQuest

ID: 1640839903

calendar_today02-08-2013 16:22:14

1,1K Tweet

2,2K Followers

318 Following

Nextron Research ⚡️ (@nextronresearch) 's Twitter Profile Photo

We’ve partnered with Arctic Wolf 🐺 Arctic Wolf - They extend their detection coverage with Nextron’s curated Sigma rule feed: 700+ high-quality rules - Most of our rules are generic, technique-focused, and designed to detect unknown threats - not just IOCs - We get structured

We’ve partnered with Arctic Wolf 🐺 <a href="/AWNetworks/">Arctic Wolf</a> 

- They extend their detection coverage with Nextron’s curated Sigma rule feed: 700+ high-quality rules
- Most of our rules are generic, technique-focused, and designed to detect unknown threats - not just IOCs
- We get structured
Ismael Valenzuela (@aboutsecurity) 's Twitter Profile Photo

Thrilled to team up with Florian Roth ⚡️ & the talented Nextron Systems crew to bring curated #Sigma rules into Arctic Wolf. Big step forward in advancing threat detection together! 🚀 👉 nextron-systems.com/2025/08/28/adv…

Phishing for Answers (@phish4answers) 's Twitter Profile Photo

New post alert! We work with Dmitry Bestuzhev to analyze trends in #LatinAmerica : 🔒 Ransomware ↑ 259% 🐺 New players like Golden Mexican Wolf emerge 💰 Banking Trojans like Mispadu still thriving 🌍 APTs expand influence across the region Link here ➡: shorturl.at/hhVQa

Dmitry Melikov (@dmitriymelikov) 's Twitter Profile Photo

The #GPUGate malware, distributed via GitHub and Google Ads, uses GPU encryption. Targets users in Western Europe. #GPUGate Arctic Wolf arcticwolf.com/resources/blog…

The #GPUGate malware, distributed via GitHub and Google Ads, uses GPU encryption. Targets users in Western Europe.

#GPUGate <a href="/AWNetworks/">Arctic Wolf</a> 
arcticwolf.com/resources/blog…
Cyber Security News (@the_cyber_news) 's Twitter Profile Photo

🚨 "GPUGate" Malware Abuses Google Ads and GitHub to Deliver Advanced Malware Payload Read more: cybersecuritynews.com/gpugate-abuses… ➡️ A sophisticated malware campaign, dubbed "GPUGate," abuses Google Ads and GitHub's repository structure to trick users into downloading malicious

🚨 "GPUGate" Malware Abuses Google Ads and GitHub to Deliver Advanced Malware Payload 

Read more: cybersecuritynews.com/gpugate-abuses…

➡️ A sophisticated malware campaign, dubbed "GPUGate," abuses Google Ads and GitHub's repository structure to trick users into downloading malicious
xiu (@osint_barbie) 's Twitter Profile Photo

Dmitry Melikov thank you for sharing this article 🫶 macOS-related IoCs mentioned: hxxps://gitpage[.]app/git/mac virustotal.com/gui/file/b13d2…

Ismael Valenzuela (@aboutsecurity) 's Twitter Profile Photo

🚫 These threat actors tried to hide their code behind the GPU. We caught them anyways. 🐺 Our Arctic Wolf Labs team uncovered a threat actor abusing GitHub’s repository structure and Google Ads to redirect users to a malicious download, while a GPU-gated decryption routine kept

🚫 These threat actors tried to hide their code behind the GPU. We caught them anyways.

🐺 Our <a href="/AWNetworks/">Arctic Wolf</a> Labs team uncovered a threat actor abusing GitHub’s repository structure and Google Ads to redirect users to a malicious download, while a GPU-gated decryption routine kept
Kimberly (@stopmalvertisin) 's Twitter Profile Photo

Arctic Wolf | #GPUGate Malware: Malicious GitHub Desktop Implants Use Hardware-Specific Decryption, Abuse Google Ads to Target Western Europe bit.ly/46cmLYO

Dmitry Melikov (@dmitriymelikov) 's Twitter Profile Photo

Brazilian #Caminho Loader Employs LSB #Steganography and #Fileless Execution to Deliver Multiple Malware Families Across South America, Africa, and Eastern Europe. arcticwolf.com/resources/blog…

Brazilian #Caminho Loader Employs LSB #Steganography and #Fileless Execution to Deliver Multiple Malware Families Across South America, Africa, and Eastern Europe.

arcticwolf.com/resources/blog…
Ismael Valenzuela (@aboutsecurity) 's Twitter Profile Photo

Our team at Arctic Wolf has identified and analyzed a new malware loader we’re calling #Caminho, a Brazilian-origin Loader-as-a-Service op employing LSB #steganography to conceal .NET payloads within image files hosted on legitimate platforms. Full analysis, IOCs, and

Dmitry Melikov (@dmitriymelikov) 's Twitter Profile Photo

🚨 New Brazilian Malware Uses Hidden Messages in Images to Stay Under the Radar "#Caminho" - a steganography malware loader originating from Brazil. It uses #LSB (Least Significant Bit) steganography to hide malicious .NET payloads inside innocent-looking image files. To the

Dmitry Melikov (@dmitriymelikov) 's Twitter Profile Photo

#UNC6384 weaponizes .lnk to deliver PlugX — incidents observed against diplomatic missions in Hungary and Belgium (Sep–Oct 2025). #cybersecurity #apt arcticwolf.com/resources/blog…

#UNC6384 weaponizes .lnk to deliver PlugX — incidents observed against diplomatic missions in Hungary and Belgium (Sep–Oct 2025). 
#cybersecurity #apt 

arcticwolf.com/resources/blog…
Steven Lim (@0x534c) 's Twitter Profile Photo

From LNK to PlugX: Tracking UNC6384’s Zero-Day Abuse Chain arcticwolf.com/resources/blog… Chinese threat actor UNC6384 is actively exploiting a newly disclosed Windows LNK zero-day vulnerability (ZDI-CAN-25373) to target European diplomats with PlugX malware via Canon DLL sideloading,

From LNK to PlugX: Tracking UNC6384’s Zero-Day Abuse Chain

arcticwolf.com/resources/blog…

Chinese threat actor UNC6384 is actively exploiting a newly disclosed Windows LNK zero-day vulnerability (ZDI-CAN-25373) to target European diplomats with PlugX malware via Canon DLL sideloading,
Kimberly (@stopmalvertisin) 's Twitter Profile Photo

Arctic Wolf | UNC6384 Weaponizes ZDI-CAN-25373 Vulnerability to Deploy PlugX Against Hungarian and Belgian Diplomatic Entities arcticwolf.com/resources/blog…

Virus Bulletin (@virusbtn) 's Twitter Profile Photo

Arctic Wolf Labs reports that the China-linked threat actor UNC6384 targeted European diplomatic entities in Hungary and Belgium during September and October 2025, exploiting ZDI-CAN-25373 and deploying PlugX RAT malware. arcticwolf.com/resources/blog…

Arctic Wolf Labs reports that the China-linked threat actor UNC6384 targeted European diplomatic entities in Hungary and Belgium during September and October 2025, exploiting ZDI-CAN-25373 and deploying PlugX RAT malware. arcticwolf.com/resources/blog…
Ismael Valenzuela (@aboutsecurity) 's Twitter Profile Photo

We just published new research on a #RomCom intrusion where we observed the actor leveraging SocGholish (FakeUpdate) to deliver a Mythic Agent payload against a U.S. organization that appears to be affiliated with Ukraine. Full write-up here: 🔗 arcticwolf.com/resources/blog…