The Brofessor (@glacius_) 's Twitter Profile
The Brofessor

@glacius_

Threat Researcher @teamcymru_S2 | Ex @McAfee ATR

ID: 1034750749

calendar_today25-12-2012 12:54:09

26,26K Tweet

3,3K Followers

316 Following

Team Cymru Threat Research (@teamcymru_s2) 's Twitter Profile Photo

BLOG POST: A write-up on some infrastructure we were tracking during 2024, connected to both #SmartApeSG and #NetSupportRAT activities. They do usually follow one another around but we've exposed direct links from a management and oversight perspective. team-cymru.com/post/tracing-tโ€ฆ

Spamhaus (@spamhaus) 's Twitter Profile Photo

Good news (at first glance): Silent Connection Ltd and Dolphin 1337 Limited, two UK-based corporations flagged by Spamhaus as being used for bulletproof hosting, were compulsory dissolved on January 28th and January 14th, respectively. ๐Ÿ™Œ Unfortunately, their networks (AS215240

The Brofessor (@glacius_) 's Twitter Profile Photo

We have an open position in our malware analysis team, looking for a senior profile: workforcenow.adp.com/mascsr/defaultโ€ฆ Feel free to ask me any questions if I can help :)

Matt Zorich (@reprise_99) 's Twitter Profile Photo

Our team at Microsoft is looking for a senior security researcher to join the fight. We are a global threat hunt team who work tirelessly to protect Microsoft, our customers and make the digital world a safer place. If you are located in or near Cheltenham, UK and interested,

Laluka@OffenSkill (@thelaluka) 's Twitter Profile Photo

Hoy hoy! Rdv demain Mardi 8 Avril, 21h as usual ! ๐Ÿค Topics: - Threat Intel / Analyse Infra & C2๐Ÿ”Ž - Detection & Analyse de Data-Leaks ๐ŸŒŠ Le tout en compagnie de The Brofessor & Ozer ๐Ÿ˜Ž๐Ÿซฐ twitch.tv/thelaluka

Hoy hoy!
Rdv demain Mardi 8 Avril, 21h as usual ! ๐Ÿค

Topics:
- Threat Intel / Analyse Infra & C2๐Ÿ”Ž
- Detection & Analyse de Data-Leaks ๐ŸŒŠ

Le tout en compagnie de <a href="/Glacius_/">The Brofessor</a> &amp; Ozer ๐Ÿ˜Ž๐Ÿซฐ
twitch.tv/thelaluka
The Brofessor (@glacius_) 's Twitter Profile Photo

Since itโ€™s DPRK time for everyone, itโ€™s our turn to share some insights regarding the infrastructure ๐Ÿ˜Š

Sylvain HAJRI (@navlys__) 's Twitter Profile Photo

Excited to share that the #OSINTVillage at leHACK is back this year on June 27โ€“28, 2025! ๐ŸŽ‰ We've got some exciting things planned, so mark your calendars. While we prepare for more updates (coming soon!), you can revisit some of the insightful talks from last year on

Excited to share that the #OSINTVillage at <a href="/_leHACK_/">leHACK</a> is back this year on June 27โ€“28, 2025! ๐ŸŽ‰

We've got some exciting things planned, so mark your calendars.

While we prepare for more updates (coming soon!), you can revisit some of the insightful talks from last year on
The Brofessor (@glacius_) 's Twitter Profile Photo

Hey :) For the second year in a row, I'm incredibly excited to present my research at Virus Bulletin - this time in Berlin, on Friday, September 26 : virusbulletin.com/conference/vb2โ€ฆ Hope to see you there! #vbconference #VB2025

The Brofessor (@glacius_) 's Twitter Profile Photo

Hey :) If you're tracking the SideWinder #APT, they've been reusing the same RTF file to launch new campaigns for months. Still worth monitoring, it can reveal upcoming C2 infrastructure: virustotal.com/gui/file/1955cโ€ฆ

Hey :)

If you're tracking the SideWinder #APT, they've been reusing the same RTF file to launch new campaigns for months. Still worth monitoring, it can reveal upcoming C2 infrastructure: 

virustotal.com/gui/file/1955cโ€ฆ
The Brofessor (@glacius_) 's Twitter Profile Photo

To entities in India: A few PK IPs have direct access to your cameras and routers (Fortinet, MikroTik confirmed). NetFlow analysis shows clear evidence. Please review any inbound connections from: - 154.192.156[.]28 - 154.192.156[.]56 - 154.192.74[.]127 - 154.192.0[.]108

The Brofessor (@glacius_) 's Twitter Profile Photo

Hey :) Heading to Botconf next week! The agenda looks great, as it does every year, and Iโ€™m really looking forward to the talks and catching up with folks :) If youโ€™re going too and want to chat about tracking bad guys (or anything else), feel free to reach out!

Team Cymru Threat Research (@teamcymru_s2) 's Twitter Profile Photo

BLOG POST: We are once again proud to have been involved in #OperationEndgame, this time helping to disrupt #DanaBot. We also got to collaborate closely with our buddies at Black Lotus Labs. You can read about our shared input in our co-authored blog! team-cymru.com/post/inside-daโ€ฆ