Tommy M (TheAnalyst) @ffforward
Threat Researcher @proofpoint | @Cryptolaemus1 Joined May 2010-
Tweets4K
-
Followers15K
-
Following199
-
Likes6K
Found some IOCs here too: github.com/rtkwlf/wolf-to… Something's off, second set of domains (but same actor) is used against RU and BY. Also odd w. english panel imo. (won't link, unprotected and has live IP but easy to figure out). Moving to EtherHiding for the injects too.
@UK_Daniel_Card DS them self are soft-routing to 4.1-Flash even if you select Pro because they think it's superior. But I wonder if it isn't better to have both Qwen3.8-Flash-Next and GLM-5.3-Flash working together if you have access to run models of that size?
@cyb3rops Getting these kind of refusals from 3.7, worked when stepping back to 3.6
No, #Trickbot is NOT back. What Fortinet forgot to mention is that the samples they analyzed are known Anchor DNS from 2020. I'm not even kidding. Better read from back then: netscout.com/blog/asert/dro…
🚨 TrickBot is back with a stealthier command and control method. The new variant replaces traditional HTTP communications with DNS tunneling, making malicious traffic harder to detect on Windows. Listen/Read: hackread.com/new-trickbot-v… #CyberSecurity #Malware #TrickBot #Windows
@malwrhunterteam Always fun to ask Gemini about the SPA JS on these 😅
ErrTraffic C2 cdnpro-987[.]xyz PS Payload domain cdnportal-us[.]xyz (dynamic PowerShell command and URI path) PowerShell downloads a 16MB encrypted 7z file, > EXE. The EXE will do profiling (including refresh rate) > #NetSupportRAT and run it. NetSupport C2 178[.]16[.]55[.]191.
So for those interested, the "scam" was an #ErrTraffic affil that got their inject on the site. It served NetSupport RAT to Win users and another (possibly broken) payload to mac users. If you did follow any of the fake #ClickFix captcha your computer might be infected. >
We identified and resolved a security incident on our site earlier today. A compromised account was exploited to inject a malicious script, briefly exposing users to scam content. The site was taken offline immediately, the script removed, and the account secured. We're back up.
@DarkandDarkerWA @vxunderground Yeah, the command you get is dynamically built so the full URI and filename it will be saved as will differ over time. The zip is encrypted and contains an exe in this case. That EXE will profile the machine and if passed, it will drop and run NetSupprt.
@eastsidemccarty @Gizmodo It's not from ads, some #ErrTraffic affiliate has compromised them. Inject is in main response.
@DanielStitzel @Gizmodo Yes, compromised by some #ErrTraffic #ClickFix affiliate. Inject is in main response
@malwrhunterteam Likely who we call TA4922, some details in proofpoint.com/us/blog/threat… Some outlets calls them "Silver Fox APT" based on... that they, like every small-time Chinese threat actors, use WinOS 4.0/ValleyRAT where the source code was leaked... in 2022... 🤷♂️
Proofpoint threat researchers identified a new malware-as-a-service named #TrustConnect. Notably, it masquerades as a legitimate remote monitoring and management tool, marking an evolution in how attackers weaponize trust around enterprise tooling. brnw.ch/21x05Vh
Thanks to the proofpoint team for highlighting "TrustConnect Software PTY LTD". The actor got the cert hoping to look like a legitimate RMM—but in collaboration with Proofpoint—we didn't let them maintain the illusion. See Proofpoint's blog for all the details.
Would you run AdobeReader.exe from a days-old company called "TrustConnect Software PTY LTD" just because they managed to purchase an Extended Validation certificate? New blog out together with @proofpoint @threatinsight proofpoint.com/us/blog/threat…
Would you run AdobeReader.exe from a days-old company called "TrustConnect Software PTY LTD" just because they managed to purchase an Extended Validation certificate? New blog out together with @proofpoint @threatinsight proofpoint.com/us/blog/threat…
@malwrhunterteam Bot that is installed after the stealer in this campaign for example: jeromesegura.com/malvertising/2… Exfils data > 38.244.158[.]56/contact > Trojanize Ledger (sassonco[.]com/zxc/app.zip and Trezor sassonco[.]com/zxc/apptwo.zip> above URL via installBot(homeDir, cachedPassword, botUrl)
As the security landscape evolves and expands, Proofpoint observed many threat actors disappear from email threat data in 2025. But TA584 maintained operational consistency, w/ recent shifts demonstrating its attempt to infect a broader range of targets. brnw.ch/21wZsWU
@malwrhunterteam @LogMeIn Resolve, a lot of abuse of it right now. companyid=621183840131085098
@malwrhunterteam Some similarities how the PowerShell loader works. But if I recall correctly this older thing instead used Deno to to download and run Python+script, not sure I looked much deeper than that
@malwrhunterteam BTW looked at this thing back in September that likely is related: virustotal.com/gui/domain/fet… which then goes back to at least January last year.
Florian Roth ⚡️ @cyb3rops
224K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim
mRr3b00t @UK_Daniel_Card
126K Followers 8K Following Chief Artificial Intelligence Cyber Security Scientist Counter Brain Worms Collective Member former Helpdesk AI infection status: clean
Will @BushidoToken
39K Followers 3K Following Senior Threat Intel Advisor @TeamCymru Co-founder @CuratedIntel Co-author @SANSForensics FOR589 Co-founder @BSidesBournemth #126: REvil @darknetdiaries
Justin Elze @HackingLZ
74K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
Kostas @Kostastsale
21K Followers 500 Following I like building things that solve real problems, working across cybersecurity, product, and research | 🇬🇷🇨🇦
Stephan Berger @malmoeb
30K Followers 1K Following Head of Investigations @InfoGuardAG https://t.co/A5lnFAu7eX
Max_Malyutin @Max_Mal_
13K Followers 305 Following Threat Researcher, Blue Team, DFIR, Malware Analysis, and Reverse Engineering. “⚔️What do we say to God of malware, Not today⚔️”
blackorbird @blackorbird
44K Followers 703 Following Peace and Love. Just Analysis/Hunter/Youtuber/AiCoder/Entrepreneur/. #APT #threatIntelligence #Exploit #CTI #meme #cyber #hacker #OSINT #Ai Need Remote Job
Germán Fernández @1ZRR4H
39K Followers 467 Following 🏴☠️ OFFENSIVE-INTEL 🏴☠️ Cyber Threat Intelligence by Hackers | Security Researcher at https://t.co/rDrSxZStZD | @CuratedIntel Member | 🥷🧠🇨🇱
Andrew Thompson @ImposeCost
42K Followers 2K Following SVP of Adversary Operations @GreyNoiseIO. Former @USMC and @Mandiant. There's no finish line in security.
James @James_inthe_box
22K Followers 470 Following
💻 Sherrod @sherrod_im
39K Followers 7K Following Difficult mystery girl connected to the divine forces of the universe.
Karsten Hahn @struppigel
26K Followers 783 Following MalwareAnalysisForHedgehogs, Principal Malware Researcher at GDATA, he/him 🦔🌈🏳️⚧️
JAMESWT @JAMESWT_WT
37K Followers 562 Following #Independent #Malware #Hunter 😎All spaghetti is pasta, but not all pasta is spaghetti😎 https://t.co/KCFBJcHHcW
Gi7w0rm @Gi7w0rm
19K Followers 820 Following Threat Intelligence Analyst | Projects: https://t.co/azRpNg9NJQ & https://t.co/SyvUfXpbmI | If I post false intel, contact me! Support me: https://t.co/5WgDqr0K8p 🇪🇺🇩🇪🇺🇦🌈
Katie Nickels @likethecoins
55K Followers 3K Following Director of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
Matthew @embee_research
14K Followers 2K Following Security Researcher, Creating and Sharing Educational Content.
Will Dormann is on Ma... @wdormann
27K Followers 1K Following I play with vulnerabilities and exploits. I used to be here on Twitter but now I'm here: @[email protected] https://t.co/hXggdAVkSQ
Catalin Cimpanu @campuscodi
106K Followers 2K Following Cybersecurity reporter. I'm mostly active on BlueSky and Mastodon.
Fernando Manzanarez @FernandoMa61306
15 Followers 4K Following
t0xk | Ni(c)k @_t0xk
5 Followers 307 Following Offensive security Nothing was your own expect the few cubic centimetres inside your skull - George Orwell, 1984
Griffendor @Griffend0R
2 Followers 333 Following
TheHuman @TheHuman_8
3 Followers 346 Following
RDT @WobbaMan
33 Followers 186 Following Malware Analysis | Reverse Engineering | Threat Intelligence | Open to opportunities
Adrian Niedzielski @AdrianNiednu
4 Followers 727 Following
Paweł Chramiec @pcout3r
58 Followers 288 Following Security Cloud Engineer | Mainly intrested in: Threat Hunting, Threat Intelligence, Cloud Security, SecDevOps, Cloud Pentesting
Adonay @AdonayTesh30815
11 Followers 985 Following
Ricardo P. 🏴☠... @danalystreport
8 Followers 290 Following Security Analyst - Detections, Threat Intelligence, Email-borne Threats, Infrastructure Hunting, Domain Categorization
Koniec Netu @PatoMaffija
3 Followers 86 Following
Supul Wickramaratna @SupulWick
7 Followers 68 Following
Jordan Pterson @JordanPterson
5 Followers 397 Following
sikiru @sikirugjge
0 Followers 101 Following
Rick B @rickxb52
21 Followers 453 Following
TEDI | @ElonMus82510990
0 Followers 12 Following
MuX @MX143587
3 Followers 67 Following
Brian @Brian2078113190
57 Followers 874 Following
ShadowOpCode @ShadowOpCode
1K Followers 181 Following 🧠 Malware analyst & reverse engineer 🦠 Ransomware, loaders, stealers & RATs 🔬 Reverse engineering • crypto • tooling 📍 Technical research. No buzzwords.
Pagpag Phone @pagpag80065
0 Followers 91 Following
Sandra Chan @SandraChan48268
0 Followers 95 Following
John Mercer @3phemeris
53 Followers 470 Following @CenaOnSecurity Main Account | Constellation CEO building MaxQ — a build package for Grok Bot’s computer. Sharing the work. Follow along!
Venkata Satish Guttul... @snakeyesV1
3K Followers 4K Following Ex-CISO https://t.co/E3wzyAP4qW | vCISO | Cybersecurity Advisor, Auditor, Academic Board Member
Daniel Schiavini @danschiavini
0 Followers 17 Following
Brahim Mohamed @BrahimMoha43702
7 Followers 104 Following
ibra @ibrapre
2 Followers 1K Following
Oqanuzun @justoqan
24 Followers 160 Following
Buscando amenazas...!... @SEGDIGPE
26 Followers 207 Following "La ciberseguridad no es sólo tecnología, sino también personas." Kevin Mitnick.
Hiren Shinde @hiren_shinde
28 Followers 562 Following Javascript developer, Flutter, Python, DevOps & InfoSec.
Cesar @wcaiocesar
3 Followers 938 Following
Carlos Vieira @carlos_crowsec
3K Followers 659 Following Founder @quimerax_intel | Partner @Hakaioffsec
Green Connected @GreenConnect254
2 Followers 286 Following
P-Virendra @786virendra_P
0 Followers 122 Following
Xx1nsert_NamexX @Xx1nsert_NamexX
10 Followers 569 Following
bookhaus @dasbookhaus
2 Followers 112 Following
Umeer Shah @0x2sroke2nalo
6 Followers 116 Following
sachidananda sharma @sachin24_05
5 Followers 88 Following
Eniel Corzo Rodriguez @EnielR22370
2 Followers 38 Following
Melovichko @Melovichkoyegy
0 Followers 153 Following
Ibrahim Abdurrahman @ibrahim_haxor
668 Followers 7K Following Android Software & Hardware Engineer | Ethical Hacker & Penetration Tester | Bug Bounty Hunter | Reverse Engineering
Isabela Leon Castillo @Isabela_LeonC
5 Followers 172 Following
Jane @Janefsiw
0 Followers 88 Following
vx-underground @vxunderground
449K Followers 375 Following The largest collection of malware source code, samples, and papers on the internet. Password: infected
Florian Roth ⚡️ @cyb3rops
224K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim
MalwareHunterTeam @malwrhunterteam
257K Followers 39 Following Official MHT Twitter account. Check out ID Ransomware (created by @demonslay335). More photos & gifs, less malware.
mRr3b00t @UK_Daniel_Card
126K Followers 8K Following Chief Artificial Intelligence Cyber Security Scientist Counter Brain Worms Collective Member former Helpdesk AI infection status: clean
BleepingComputer @BleepinComputer
258K Followers 206 Following Breaking cybersecurity and technology news, guides, and tutorials that help you get the most from your computer. DMs are open, so send us those tips!
Will @BushidoToken
39K Followers 3K Following Senior Threat Intel Advisor @TeamCymru Co-founder @CuratedIntel Co-author @SANSForensics FOR589 Co-founder @BSidesBournemth #126: REvil @darknetdiaries
Unit 42 @Unit42_Intel
71K Followers 81 Following The latest research and news from Unit 42, the Palo Alto Networks (@paloaltontwks) Threat Intelligence and Security Consulting Team covering incident response.
Kostas @Kostastsale
21K Followers 500 Following I like building things that solve real problems, working across cybersecurity, product, and research | 🇬🇷🇨🇦
Max_Malyutin @Max_Mal_
13K Followers 305 Following Threat Researcher, Blue Team, DFIR, Malware Analysis, and Reverse Engineering. “⚔️What do we say to God of malware, Not today⚔️”
The DFIR Report @TheDFIRReport
70K Followers 0 Following Real Intrusions by Real Attackers, the Truth Behind the Intrusion
Germán Fernández @1ZRR4H
39K Followers 467 Following 🏴☠️ OFFENSIVE-INTEL 🏴☠️ Cyber Threat Intelligence by Hackers | Security Researcher at https://t.co/rDrSxZStZD | @CuratedIntel Member | 🥷🧠🇨🇱
ςεяβεяμs - м�... @c3rb3ru5d3d53c
27K Followers 243 Following 💕 Malware Reverse Engineer & Malware Geneticist 💕 #Binlex Developer https://t.co/EKYUS9Itvd 👩💻 She/Her
Andrew Thompson @ImposeCost
42K Followers 2K Following SVP of Adversary Operations @GreyNoiseIO. Former @USMC and @Mandiant. There's no finish line in security.
James @James_inthe_box
22K Followers 470 Following
💻 Sherrod @sherrod_im
39K Followers 7K Following Difficult mystery girl connected to the divine forces of the universe.
JAMESWT @JAMESWT_WT
37K Followers 562 Following #Independent #Malware #Hunter 😎All spaghetti is pasta, but not all pasta is spaghetti😎 https://t.co/KCFBJcHHcW
Katie Nickels @likethecoins
55K Followers 3K Following Director of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
Will Dormann is on Ma... @wdormann
27K Followers 1K Following I play with vulnerabilities and exploits. I used to be here on Twitter but now I'm here: @[email protected] https://t.co/hXggdAVkSQ
Catalin Cimpanu @campuscodi
106K Followers 2K Following Cybersecurity reporter. I'm mostly active on BlueSky and Mastodon.
Anurag @Malwarehunterr
1K Followers 487 Following Threat hunting | Malware Analysis | These views are my own and not my employers. https://t.co/cERmryTU76
Cris Brafman Kittner @criskittner
2K Followers 1K Following Cyber geek at @FireEye, @Mandiant, @GoogleCloud, now @Proofpoint. Interplanetary enthusiast. History geek. Opinions my own.
crep1x @crep1x
3K Followers 316 Following Lead cybercrime analyst, tracking adversaries activities & infrastructure, at @sekoia_io
OSINTdefender @sentdefender
2.5M Followers 2K Following Open Source Intelligence Monitor focused on Europe and Conflicts across the World. RT ≠ Endorsement. Want to Support my Work? https://t.co/PcUbewwuEZ
Gootloader @Gootloader
1K Followers 380 Following Security researcher dedicated to pissing off the Gootloader Threat Actor.
Squiblydoo @SquiblydooBlog
5K Followers 100 Following Creator of Debloat and https://t.co/tIYqmw6pxt Support: https://t.co/l9kCPRoD2y Join the Debloat/CertGraveyard discord: https://t.co/ZcWIqa6ZA9
Ole Villadsen @OleVilladsen
345 Followers 109 Following Threat researcher @proofpoint. Views are my own.
hasherezade @hasherezade
91K Followers 967 Following Programmer, #malware analyst. Author of #PEbear, #PEsieve, #TinyTracer. Private account. All opinions expressed here are mine only (not of my employer etc)
H!S3 @0x48215333
176 Followers 373 Following f*society | #BlueTeam | Love #MISP hate #Malware | in a complicated relationship with #Emotet, #QakBot,#PikaBot and #FluBot | *riendly
jungman @notajungman
972 Followers 6K Following undefined, and any attempt would be ill advised and unrefined. Also, it's time to start shrugging.
Casperinous @Casperinous
678 Followers 571 Following
Kyle Cucci @d4rksystem
6K Followers 573 Following Threat Research @proofpoint | Author of "Evasive Malware" @nostarch | Talks about cybercrime, threat intel, and malware stuff.
DogsVoiceUK @dogsvoiceuk
170 Followers 52 Following Animal welfare in the UK private security industry is non-existent, we aim to expose that and raise awareness. [email protected]
Alexis Dorais-Joncas ... @adorais
2K Followers 843 Following Sr Manager, APT Threat Research @Proofpoint
@bingohotdog@infosec.... @bingohotdog
81 Followers 162 Following fighting malicious traffic by moonlight 🌙. she/her.
Isaac @isashau
81 Followers 443 Following Detection Person at Emerging Threats/Proofpoint - Tweets are my own etc.
Daniel @dansomware
335 Followers 693 Following threat research @proofpoint // tweets are probably someone else's
PeterM🌻 @AltShiftPrtScn
3K Followers 100 Following Work in DFIR, fighting the good fight. Don't go 5 minutes without saying ransomware. Created as a failsafe: https://t.co/zIAq2Hz99E
Colin Cowie👨🏼�... @th3_protoCOL
3K Followers 875 Following Threat Intelligence 🏹 Malware Research 🧬 Managed Detection and Response @Sophos
ICSNick @IcsNick
1K Followers 558 Following Time to leave this platform. If you like to contact me professionally, find me on LinkedIn.
dao ming si @dms1899
1K Followers 258 Following work time: defender fun time: malware hoarder/puzzle solver/capacity tester member of: @Cryptolaemus1 fan of: @hatching_io @sublime_sec
Christopher Dawson @mrdatahs
5K Followers 4K Following Dad, Husband, Writer, Threat Intelligence at Proofpoint - Words are my own. He/him
John Hammond @_JohnHammond
326K Followers 3K Following Cybersecurity Researcher @HuntressLabs Just Hacking Training @JustHackingHQ w/ @ethicalhacker https://t.co/UtsNJiyQtS && https://t.co/narO3sz7y6
nao_sec @nao_sec
13K Followers 155 Following
Kirk Soluk @KirkSoluk
167 Followers 368 Following Senior Manager, Security Research - Arctic Wolf Labs
Assi9 @assi9
802 Followers 4K Following Happiest guy in the room. Tweeting about #geekdad #linux #infosec #3Dprinting #dogs #drones and all things #nerdy. Chaotic Neutral
Arnold Osipov @osipov_ar
1K Followers 320 Following MSTIC RE @Microsoft | Ex @Morphisec, Check Point Research | RE, Malware & Threat hunting | Software Engineer.
Autumn Good @autumn_good_35
7K Followers 366 Following 晴れ時々セキュリティ、所により一時スイーツ。 セキュリティは趣味ですけど仕事にも活かしていきたいですね。Security Hobbyist. Ice Cream Researcher. 日本アイスマニア協会会員
MaximumEffort...Have ... @joewise34
157 Followers 133 Following
Digital_Monet @aRtAGGI
2K Followers 253 Following Binary and Art Recovery Specialist. aka "The White Glove"
ZACKATT&CK @ZackDoesML
99 Followers 71 Following applying machine learning to infosec. opinions may not be my own but they are definitely not my employer's. he/him.
Adrian Covich @AdrianCovich
142 Followers 2K Following Interested in infosec topics (amongst other things). SE director at Proofpoint Australia- views my own.
sam scholten @samkscholten
420 Followers 634 Following head of detection @sublime_sec 🕵️ fmr: @proofpoint https://t.co/SL2P9joPu8
Konstantin Klinger @kk_onstantin
711 Followers 761 Following Detection Engineering | he/him | 🌱⚽️🏃♂️🚴♂️🏊♂️ | tweets are my own
Jason Ford @JasonFord
278 Followers 177 Following























