
Seongsu Park
@unpacker
Zscaler APT Research | Formerly Kaspersky GREAT | Threat Intelligence Hustler | Tweets are my own | Keybase: @seongsupark | Mastodon: @[email protected]
ID: 124484493
19-03-2010 15:02:17
9,9K Tweet
11,11K Followers
1,1K Following

Three Buddy Problem Episode 28 - the first of 2025 is out! With Ryan Naraine and J. A. Guerrero-Saade we discuss the US Treasury/BeyondTrust hack, APT group naming bad examples of bad examples, a new variant of the Xdr33 CIA Hive malware discovered by Nextron Research âĄïž and exclusive








I analyzed thousands of messages from 35+ suspected state-sponsored hacktivist groups using machine learningâuncovering hidden connections through writing styles, language and topics. After a year of research, hereâs what we found and how we did it. đ research.checkpoint.com/2025/modern-ap⊠1/






Weâre seeing a clear trend: attackers are bypassing the endpoint entirely. Not just avoiding traditional EDR-monitored systems by pivoting to embedded and edge devices, but now also operating purely in the cloud. No shell, no malware, no persistence on the endpoint. Just an OAuth


HEADS-UP! Professor Thomas Rid is a guest buddy on the pod this week. Currently cooking in the lab đđ„ Thomas Rid J. A. Guerrero-Saade Costin Raiu Listen, watch, subscribe! Apple: bit.ly/3budprob YouTube: bit.ly/TBP-YT Spotify: bit.ly/3DH5wEO


