Alexey Firsh
@alexey_firsh
Head of threat intelligence at Rostelecom-Solar,
former @googlecloud, @kaspersky
ID: 2533323049
29-05-2014 20:02:01
273 Tweet
1,1K Followers
163 Following
Nice write-up on a new Chinese-language attack framework "Alchimist" targeting Windows, Linux and Mac machines by Cisco Talos Intelligence Group blog.talosintelligence.com/2022/10/alchim… I found one more c2: 45.32.74[.]229
Check out our quick follow-up on Mandiant (part of Google Cloud) research on UNC4034 apt cluster who distribute their malware in a form of job offers from a big tech companies. blog.virustotal.com/2022/11/not-dr…
I know I'm around 1.5 years late, but looks like Microsoft Threat Intelligence included the ViceLeaker activity we covered in 2019 in their Iranian threat actors overview. Kaspersky, 2019: securelist.com/fanning-the-fl… Microsoft, 2021: microsoft.com/en-us/security…
We're revealing details of an obscure debugging feature in the Apple A12-A16 SoC’s that bypasses all of the hard-to-hack hardware-based memory protections on new iPhones. Its not used by the firmware and we don't know how the attackers found out about it. securelist.com/operation-tria…