imp0rtp3 (@imp0rtp3) 's Twitter Profile
imp0rtp3

@imp0rtp3

Security Researcher, Threat Intelligence And Malware Analysis for fun.
CTI Team Leader in @Fortinet.
Keybase: imp0rtp3
Mastodon: @[email protected]

ID: 1401523690312015873

calendar_today06-06-2021 13:00:49

179 Tweet

803 Followers

296 Following

Arkbird (@arkbird_solg) 's Twitter Profile Photo

I share the Yara rules and the samples for the dropper and the ransomware ARCrypter (+ DTrack and APT32 ELF/MIPS/ARM agent) Yara: github.com/StrangerealInt… Samples: bazaar.abuse.ch/user/114643082…

Lorenzo Franceschi-Bicchierai (@lorenzofb) 's Twitter Profile Photo

NEW: Cybersecurity startup Corellium gave trials to NSO Group and DarkMatter. It also sold to cellphone cracking firms Cellebrite and Elcomsoft in Russia, as well as Pwnzen, a hacking firm with ties to China's government, according to a leaked document. wired.com/story/corelliu…

ESET Research (@esetresearch) 's Twitter Profile Photo

#ESETResearch discovered that #LuckyMouse/#APT27 used a code-signing certificate belonging to VMPsoft, the developer of the VMProtect packer. The signed file is a loader for the SysUpdate backdoor (aka Soldier). We notified VMPSoft of this compromise 1/4 virustotal.com/gui/file/a8527…

#ESETResearch discovered that #LuckyMouse/#APT27 used a code-signing certificate belonging to VMPsoft, the developer of the VMProtect packer. The signed file is a loader for the SysUpdate backdoor (aka Soldier). We notified VMPSoft of this compromise 1/4 
virustotal.com/gui/file/a8527…
ESET Research (@esetresearch) 's Twitter Profile Photo

#ESETresearch discovered an active #Android campaign conducted by the hack-for-hire group #Bahamut. The campaign has been active since January 2022, with malicious apps are distributed through a fake #SecureVPN website Lukas Stefanko welivesecurity.com/2022/11/23/bah… 1/6

Arkbird (@arkbird_solg) 's Twitter Profile Photo

I share yara rules and the samples of the new variant of #blackbasta ransomware. Samples: bazaar.abuse.ch/browse/tag/Bla… Yara : github.com/StrangerealInt…

Kris McConkey (@smoothimpact) 's Twitter Profile Photo

So yesterday was open #threatintel season on the Russia-based Callisto/SEABORGIUM crew, with a triple whammy of blogs from us and a couple of industry friends: PwC: pwc.com/gx/en/issues/c… Recorded Future: recordedfuture.com/exposing-tag-5… Sekoia: blog.sekoia.io/calisto-show-i…

imp0rtp3 (@imp0rtp3) 's Twitter Profile Photo

Advisory of #CVE_2022_42475 (FortiOS SSL-VPN RCE) updated with additional IPs of the threat actor exploiting it: 139.180.184[.]197 66.42.91[.]32 158.247.221[.]101 107.148.27[.]117 139.180.128[.]142 155.138.224[.]122 185.174.136[.]20 fortiguard.com/psirt/FG-IR-22…