Uptime Hamster: 10d 5h 41mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21

Base de datos de filtraciones

151 registros (pagina 3 de 4) · Twitter/X: 151.

Filtro: twitter/x. Limpiar

Todas Twitter/X (151)
Unit 42 Intel: Codeless attack: An attacker types plain text into a chat app. An #LLM turns the text into shell commands on the victim. Stolen files come back through the same chat. Zero coding skills needed to operate, and no custom infrastructure to detect. Details at https://bit.ly/4eBC2GL 2026-06-18
Unit42_Intel Twitter/X

Codeless attack: An attacker types plain text into a chat app. An #LLM turns the text into shell commands on the victim. Stolen files come back through the same chat. Zero coding skills needed to operate, and no custom infrastructure to detect. Detai…

Leer articulo →
Unit 42 Intel: AI agents use third-party skills with privileged access. Many of these skills deviate from their declared behavior. While most mismatches are simple documentation errors, the real threat lies in multi-stage attack chains. Read our analysis for details: https://bit.ly/4ekzAnR 2026-06-18
Unit42_Intel Twitter/X

AI agents use third-party skills with privileged access. Many of these skills deviate from their declared behavior. While most mismatches are simple documentation errors, the real threat lies in multi-stage attack chains. Read our analysis for detail…

Leer articulo →
StealthMole: RT by @stealthmole_int: Come and join us today for our another webinar! This time we gonna take a look at the financial infrastructure of a darkweb platform called #SnuffCinema! Visit @stealthmole_int website and register today! Register now: https://lnkd.in/gnq9P9uT 2026-06-17
stealthmole_int Twitter/X

RT by @stealthmole_int: Come and join us today for our another webinar! This time we gonna take a look at the financial infrastructure of a darkweb platform called #SnuffCinema! Visit @stealthmole_int website and register today! Register now: https:/…

Leer articulo →
StealthMole: RT by @stealthmole_int: 𝐀 𝐁𝐈𝐆 𝐭𝐡𝐚𝐧𝐤-𝐲𝐨𝐮 𝐭𝐨 @stealthmole_int , @offbyoneconf 𝐍𝐞𝐭𝐰𝐨𝐫𝐤𝐢𝐧𝐠 𝐒𝐩𝐨𝐧𝐬𝐨𝐫 𝐟𝐨𝐫 𝐭𝐡𝐞 𝟑𝐫𝐝 𝐲𝐞𝐚𝐫 𝐫𝐮𝐧𝐧𝐢𝐧𝐠! Meet the team at @offbyoneconf 2026! Grand Copthorne Waterfront Hotel Singapore 14–15 Sept 2026 https://merch.starlabs.sg/products/ob1-2026 2026-06-16
stealthmole_int Twitter/X

RT by @stealthmole_int: 𝐀 𝐁𝐈𝐆 𝐭𝐡𝐚𝐧𝐤-𝐲𝐨𝐮 𝐭𝐨 @stealthmole_int , @offbyoneconf 𝐍𝐞𝐭𝐰𝐨𝐫𝐤𝐢𝐧𝐠 𝐒𝐩𝐨𝐧𝐬𝐨𝐫 𝐟𝐨𝐫 𝐭𝐡𝐞 𝟑𝐫𝐝 𝐲𝐞𝐚𝐫 𝐫𝐮𝐧𝐧𝐢𝐧𝐠! Meet the team at @offbyoneconf 2026! Grand Copthorne Waterfront Hotel Singapore 14–15 Sept 2026 https://merch.starlabs.sg/product…

Leer articulo →
Unit 42 Intel: We detected a malicious browser extension campaign that trojanizes legitimate extensions to serve ads covertly. The extension categories include ad blocking, messaging privacy, screen recording and music control. 1,000+ installations so far. Details at https://bit.ly/4xtQcT3 2026-06-16
Unit42_Intel Twitter/X

We detected a malicious browser extension campaign that trojanizes legitimate extensions to serve ads covertly. The extension categories include ad blocking, messaging privacy, screen recording and music control. 1,000+ installations so far. Details …

Leer articulo →
Unit 42 Intel: Cloud logging services provide visibility but attackers target them to create weak spots. By manipulating encryption keys or redirecting log flows they can evade detection and monitor activity in real time. Our research analyzes these risks: https://bit.ly/3SlMYAJ 2026-06-16
Unit42_Intel Twitter/X

Cloud logging services provide visibility but attackers target them to create weak spots. By manipulating encryption keys or redirecting log flows they can evade detection and monitor activity in real time. Our research analyzes these risks: https://…

Leer articulo →
eCrime.ch: RT by @ecrime_ch: #ESETresearch has observed DeadLock ransomware expanding its use of Polygon blockchain smart contracts. Previously used only for chat proxy server address rotation, DeadLock has now added a new contract with the gang's DLS entries - a first of its kind we are aware of. 1/6 2026-06-16
ecrime_ch Twitter/X

RT by @ecrime_ch: #ESETresearch has observed DeadLock ransomware expanding its use of Polygon blockchain smart contracts. Previously used only for chat proxy server address rotation, DeadLock has now added a new contract with the gang's DLS entr…

Leer articulo →
Unit 42 Intel: Actors weaponize #AI hype: fake LLM domains, branded C2 infrastructure and payment skimmers. We tracked three active campaigns abusing AI lures and infrastructure. Details at https://bit.ly/3SHlc1D 2026-06-15
Unit42_Intel Twitter/X

Actors weaponize #AI hype: fake LLM domains, branded C2 infrastructure and payment skimmers. We tracked three active campaigns abusing AI lures and infrastructure. Details at https://bit.ly/3SHlc1D Palo Alto Networks Unit 42 threat intelligence on AP…

Leer articulo →
StealthMole: RT by @stealthmole_int: D4D 해커톤 두 번째 참여기업 - StealthMole . StealthMole은 D4D 해커톤 기간 중 해커톤 참가자들이 실제 다크웹에 있는 정보를 정제된 형태의 API로 제공받아, 이를 기반으로 개발할 수 있도록 지원합니다. . *StealthMole(스텔스몰)은 다크웹, 딥웹, 그리고 사이버 범죄 생태계를 추적하는 사이버 위협 인텔리전스(CTI, Cyber Threat Intelligence) 전문 기업입니다. . D4D 해커톤과 함께하는 기업은 지속해서 업데이트 예정입니다. 참가 신청 : https://luma.com/d4d 2026-06-12
stealthmole_int Twitter/X

RT by @stealthmole_int: D4D 해커톤 두 번째 참여기업 - StealthMole . StealthMole은 D4D 해커톤 기간 중 해커톤 참가자들이 실제 다크웹에 있는 정보를 정제된 형태의 API로 제공받아, 이를 기반으로 개발할 수 있도록 지원합니다. . *StealthMole(스텔스몰)은 다크웹, 딥웹, 그리고 사이버 범죄 생태계를 추적하는 사이버 위협 인텔리전스(CTI, Cyber Threat Intelligence) …

Leer articulo →
Unit 42 Intel: Unit 42 is tracking the active targeting of Oracle PeopleSoft servers by Bling Libra (aka #ShinyHunters). Our analysis reveals suspected exploitation of RCE flaw CVE-2026-35273 and primary targeting of the education sector since at least late May 2026. https://bit.ly/4xpxKLb 2026-06-12
Unit42_Intel Twitter/X

Unit 42 is tracking the active targeting of Oracle PeopleSoft servers by Bling Libra (aka #ShinyHunters). Our analysis reveals suspected exploitation of RCE flaw CVE-2026-35273 and primary targeting of the education sector since at least late May 202…

Leer articulo →
StealthMole: RT by @stealthmole_int: Government-Related Darkweb/Deepweb Leak Activity — First Week of June 2026 Observed activity consists of 26 government-related leak or sale postings and 4 ransomware/extortion listings tied to public-sector or government-associated entities. The activity is distributed across multiple underground forums and Tor-hosted leak sites, with visible concentration on darkforums, spear, and craxpro. 2026-06-10
stealthmole_int Twitter/X

RT by @stealthmole_int: Government-Related Darkweb/Deepweb Leak Activity — First Week of June 2026 Observed activity consists of 26 government-related leak or sale postings and 4 ransomware/extortion listings tied to public-sector or government-assoc…

Leer articulo →
StealthMole: Security OSINT Highlights — First Week of June 2026 Reporting collected during the first week of June 2026 is dominated by vulnerability disclosures and exploitation-related alerts, with a secondary concentration in malware, espionage, and intrusion activity supported by file-hash and IP indicators. 2026-06-10
stealthmole_int Twitter/X

Security OSINT Highlights — First Week of June 2026 Reporting collected during the first week of June 2026 is dominated by vulnerability disclosures and exploitation-related alerts, with a secondary concentration in malware, espionage, and intrusion …

Leer articulo →
Group-IB Threat Intelligence: How are threat actors combining session hijacking, browser profile cloning, HVNC, and cryptocurrency-focused tooling into a commercial Malware-as-a-Service offering? Our latest analysis of SilabRAT explores its infrastructure, ClickFix-driven infection chains, technical capabilities, and the threat actor behind its development. Read the full report: https://link.group-ib.com/4xluZub 2026-06-10
GroupIB_TI Twitter/X

How are threat actors combining session hijacking, browser profile cloning, HVNC, and cryptocurrency-focused tooling into a commercial Malware-as-a-Service offering? Our latest analysis of SilabRAT explores its infrastructure, ClickFix-driven infecti…

Leer articulo →
Group-IB Threat Intelligence: SilabRAT places significant emphasis on #cryptocurrency theft. Beyond harvesting credentials and browser data, it can identify wallet-related artifacts and automatically attempt password recovery using credentials collected from infected systems. These additions reflect the growing focus on direct monetization within modern #malware ecosystems. 2026-06-10
GroupIB_TI Twitter/X

SilabRAT places significant emphasis on #cryptocurrency theft. Beyond harvesting credentials and browser data, it can identify wallet-related artifacts and automatically attempt password recovery using credentials collected from infected systems. The…

Leer articulo →
Group-IB Threat Intelligence: One of SilabRAT's most notable capabilities is its use of Hidden Virtual Network Computing (HVNC). By interacting with services directly from the victim's device, attackers can perform account activity, access sensitive platforms, and conduct fraudulent operations while appearing as a legitimate user originating from the trusted device and IP address. #InfoSec 2026-06-10
GroupIB_TI Twitter/X

One of SilabRAT's most notable capabilities is its use of Hidden Virtual Network Computing (HVNC). By interacting with services directly from the victim's device, attackers can perform account activity, access sensitive platforms, and condu…

Leer articulo →
Group-IB Threat Intelligence: As browser security evolves, attackers are moving beyond traditional cookie theft. #SilabRAT advertises browser profile cloning, allowing operators to replicate a victim's browser environment, including extensions, storage, and fingerprinting artifacts. This enables access to authenticated sessions that may otherwise resist conventional session hijacking techniques. #CyberThreats #ThreatIntelligence 2026-06-10
GroupIB_TI Twitter/X

As browser security evolves, attackers are moving beyond traditional cookie theft. #SilabRAT advertises browser profile cloning, allowing operators to replicate a victim's browser environment, including extensions, storage, and fingerprinting ar…

Leer articulo →
Group-IB Threat Intelligence: #SilabRAT is a newly emerging Malware-as-a-Service (#MaaS) platform developed by the threat actor "o1oo1" and advertised on underground forums since late 2025. Sold for $5,000 per month, the Remote Access Trojan (#RAT) combines credential theft, session hijacking, HVNC access, Chrome App-Bound Encryption bypasses using COM elevation, and cryptocurrency-focused tooling into a single platform built for financially motivated cybercrime. 2026-06-10
GroupIB_TI Twitter/X

#SilabRAT is a newly emerging Malware-as-a-Service (#MaaS) platform developed by the threat actor "o1oo1" and advertised on underground forums since late 2025. Sold for $5,000 per month, the Remote Access Trojan (#RAT) combines credential t…

Leer articulo →
StealthMole: RT by @stealthmole_int: How do you go from a single Bitcoin wallet to an entire dark web infrastructure? Join our webinar on June 17 as we explore how following financial indicators helped map the hidden network behind Snuff Cinema. June 17, 2026 4:00 PM SGT Register: https://us06web.zoom.us/webinar/register/WN_pXm4B-eCQ9mkdOxyx1eM-w #OSINT #ThreatIntel #DarkWeb #SnuffCinema #Bitcoin #StealthMole 2026-06-09
stealthmole_int Twitter/X

RT by @stealthmole_int: How do you go from a single Bitcoin wallet to an entire dark web infrastructure? Join our webinar on June 17 as we explore how following financial indicators helped map the hidden network behind Snuff Cinema. June 17, 2026 4:0…

Leer articulo →
Unit 42 Intel: We detected a #Browser-in-the-Browser phishing campaign using a draggable, OS/browser-fingerprinted popup with a spoofed OAuth URL. It evades detection by blocking debugging, fragmenting keywords, and redirecting bots. Details at https://bit.ly/49Md3yO 2026-06-08
Unit42_Intel Twitter/X

We detected a #Browser-in-the-Browser phishing campaign using a draggable, OS/browser-fingerprinted popup with a spoofed OAuth URL. It evades detection by blocking debugging, fragmenting keywords, and redirecting bots. Details at https://bit.ly/49Md3…

Leer articulo →
Unit 42 Intel: Unit 42 provides indicators of activity and mitigations for PAN-OS CVE-2026-0257, an authentication bypass in GlobalProtect. https://bit.ly/4fu1rEo 2026-06-05
Unit42_Intel Twitter/X

Unit 42 provides indicators of activity and mitigations for PAN-OS CVE-2026-0257, an authentication bypass in GlobalProtect. https://bit.ly/4fu1rEo Palo Alto Networks Unit 42 threat intelligence on APT groups, ransomware operations and emerging cyber…

Leer articulo →
Unit 42 Intel: We detected an evasive #ClickFix injection with a fake Lirunex payment platform lure tricking the user into requesting the SSL certificate path through a file dialog box but silently delivers a RAT disguised as image files. Details at https://bit.ly/4eo0Sea 2026-06-05
Unit42_Intel Twitter/X

We detected an evasive #ClickFix injection with a fake Lirunex payment platform lure tricking the user into requesting the SSL certificate path through a file dialog box but silently delivers a RAT disguised as image files. Details at https://bit.ly/…

Leer articulo →
Unit 42 Intel: FlutterShell is a new macOS backdoor spread by malvertising. Built with Flutter, it uses a WebView-based architecture for adware, allowing attackers to remain dynamic. We discuss its evolution, variants and command structure in a recent campaign. https://bit.ly/43TZaLr 2026-06-04
Unit42_Intel Twitter/X

FlutterShell is a new macOS backdoor spread by malvertising. Built with Flutter, it uses a WebView-based architecture for adware, allowing attackers to remain dynamic. We discuss its evolution, variants and command structure in a recent campaign. htt…

Leer articulo →
Unit 42 Intel: We are tracking Pink (CL-CRI-1147), a new Com-affiliated extortion brand whose leak site went live 5/31/26. Pink uses vishing and IT impersonation to phish credentials/MFA, then exfiltrates enterprise cloud storage and productivity data to extort victims: https://bit.ly/4en565G 2026-06-03
Unit42_Intel Twitter/X

We are tracking Pink (CL-CRI-1147), a new Com-affiliated extortion brand whose leak site went live 5/31/26. Pink uses vishing and IT impersonation to phish credentials/MFA, then exfiltrates enterprise cloud storage and productivity data to extort vic…

Leer articulo →
Unit 42 Intel: An update to our Threat Brief on npm supply chain attacks discusses the latest compromise, pushing a payload named Miasma. The tradecraft used substantially matches Mini Shai-Hulud malware used by TeamPCP. Read now: https://bit.ly/4cwtCk3 2026-06-02
Unit42_Intel Twitter/X

An update to our Threat Brief on npm supply chain attacks discusses the latest compromise, pushing a payload named Miasma. The tradecraft used substantially matches Mini Shai-Hulud malware used by TeamPCP. Read now: https://bit.ly/4cwtCk3 Palo Alto N…

Leer articulo →
Group-IB Threat Intelligence: How do #threatactors fabricate massive data breaches from old leaks and why are organizations wasting resources investigating them? Group-IB details the operational patterns, keyword indicators, and analytical methodology to identify and dismiss "leads data" from Chinese-speaking #cybercrime communities. Read the full technical analysis now: https://link.group-ib.com/42P3viG 2026-05-20
GroupIB_TI Twitter/X

How do #threatactors fabricate massive data breaches from old leaks and why are organizations wasting resources investigating them? Group-IB details the operational patterns, keyword indicators, and analytical methodology to identify and dismiss &quo…

Leer articulo →
Group-IB Threat Intelligence: Validation of sample datasets from claims targeting Gulf banks showed that names and phone numbers were sourced from the 2021 Facebook leak while corresponding password hashes were taken from the October 2020 Eatigo breach, creating composite records that contain legitimate individual identifiers but do not represent actual customers of the targeted organizations. 2026-05-20
GroupIB_TI Twitter/X

Validation of sample datasets from claims targeting Gulf banks showed that names and phone numbers were sourced from the 2021 Facebook leak while corresponding password hashes were taken from the October 2020 Eatigo breach, creating composite records…

Leer articulo →
Group-IB Threat Intelligence: These brokers, operating channels like #Aiqianjin and #YiqunData on Telegram, in addition to other individual brokers on dark web forums such as Exchange Market and Chang'An Sleepless Night, post between 500 to over 1,000 messages monthly across these platforms — a volume that would represent an unprecedented number of real breaches if true. 2026-05-20
GroupIB_TI Twitter/X

These brokers, operating channels like #Aiqianjin and #YiqunData on Telegram, in addition to other individual brokers on dark web forums such as Exchange Market and Chang'An Sleepless Night, post between 500 to over 1,000 messages monthly across…

Leer articulo →
Group-IB Threat Intelligence: Chinese-speaking data brokers are flooding #darkweb forums and #Telegram with advertisements for massive datasets, but Group-IB analysis shows these are largely compiled from prior breaches like the 2021 Facebook leak and the 2020 Eatigo incident. 2026-05-20
GroupIB_TI Twitter/X

Chinese-speaking data brokers are flooding #darkweb forums and #Telegram with advertisements for massive datasets, but Group-IB analysis shows these are largely compiled from prior breaches like the 2021 Facebook leak and the 2020 Eatigo incident. Gr…

Leer articulo →
Group-IB Threat Intelligence: The Phoenix #PhaaS ecosystem operates on a subscription model with dedicated #Telegram sales channels, offering SMS phishing platforms at $80/week or $1999/year, e-commerce phishing kits with 3D and PP plugin support for $1999 lifetime, and custom source code for APP account phishing or complex independent sites. With nearly 13,000 members in their support chat and structured onboarding tutorials, this represents a fully commercialized, community-driven #cybercrime operation. 2026-04-29
GroupIB_TI Twitter/X

The Phoenix #PhaaS ecosystem operates on a subscription model with dedicated #Telegram sales channels, offering SMS phishing platforms at $80/week or $1999/year, e-commerce phishing kits with 3D and PP plugin support for $1999 lifetime, and custom so…

Leer articulo →
Group-IB Threat Intelligence: Threat actors are leveraging advanced SMS delivery methods, including rogue Base Transceiver Station (BTS) equipment that broadcasts stronger signals than legitimate towers to inject phishing messages directly to nearby devices without passing through carrier routing systems. This technique bypasses sender authentication and #spam filtering, allowing messages to appear under trusted brand names with no operator visibility, making carrier-level detection nearly impossible. #TelecomSecurity 2026-04-29
GroupIB_TI Twitter/X

Threat actors are leveraging advanced SMS delivery methods, including rogue Base Transceiver Station (BTS) equipment that broadcasts stronger signals than legitimate towers to inject phishing messages directly to nearby devices without passing throug…

Leer articulo →
Group-IB Threat Intelligence: Victimology analysis shows overlapping global targeting across both campaigns. Reward Points phishing primarily targets #financial services and telecom users across #APAC, while Failed Parcel Delivery campaigns focus on logistics entities across Europe, APAC, and the US. Despite sector-specific lures, the geographic distribution and brand impersonation patterns indicate coordinated deployment within the same smishing infrastructure. #ThreatIntel 2026-04-29
GroupIB_TI Twitter/X

Victimology analysis shows overlapping global targeting across both campaigns. Reward Points phishing primarily targets #financial services and telecom users across #APAC, while Failed Parcel Delivery campaigns focus on logistics entities across Euro…

Leer articulo →
Group-IB Threat Intelligence: Since January 2025, Group-IB has tracked over 2,500 #phishing domains tied to a single #PhaaS ecosystem known as the "Phoenix System" (不死鳥系統), which has targeted more than 70 organizations across financial services, telecom, and logistics. 2026-04-29
GroupIB_TI Twitter/X

Since January 2025, Group-IB has tracked over 2,500 #phishing domains tied to a single #PhaaS ecosystem known as the "Phoenix System" (不死鳥系統), which has targeted more than 70 organizations across financial services, telecom, and logistics. …

Leer articulo →
eCrime.ch: RT by @ecrime_ch: Did you know that @CISAgov's Known Exploited Vulnerabilities (KEV) catalogue includes a "knownRansomwareCampaignUse" field? If you want to pull just the CVEs that have this field set to "Known" (i.e. that have been associated with ransomware activity), I whipped up a 'lil curl command for ya: curl -L https://for528.com/cves-kev-json | jq -c '.vulnerabilities[] | select(.knownRansomwareCampaignUse == "Known")' Easy peasy! Note: You'll need jq installed (e.g. 2026-04-12
ecrime_ch Twitter/X

RT by @ecrime_ch: Did you know that @CISAgov's Known Exploited Vulnerabilities (KEV) catalogue includes a "knownRansomwareCampaignUse" field? If you want to pull just the CVEs that have this field set to "Known" (i.e. that ha…

Leer articulo →
eCrime.ch: New claim on the shame-site for #ransomware / #datatheft group #TiMc. Organization: Seidor S.A. Location: #Spain Industry: #ITServicesAndITConsulting Staff: 5,001-10,000 employees Learn more at https://ecrime.ch 2026-04-09
ecrime_ch Twitter/X

New claim on the shame-site for #ransomware / #datatheft group #TiMc. Organization: Seidor S.A. Location: #Spain Industry: #ITServicesAndITConsulting Staff: 5,001-10,000 employees Learn more at https://ecrime.ch eCrime.ch cybercrime intelligence cove…

Leer articulo →
eCrime.ch: New claim on the shame-site for #ransomware / #datatheft group #LockBit5.0. Organization: Comunidad Andina Location: #Peru Industry: #InternationalAffairs Staff: 5,001-10,000 employees Learn more at https://ecrime.ch 2026-04-09
ecrime_ch Twitter/X

New claim on the shame-site for #ransomware / #datatheft group #LockBit5.0. Organization: Comunidad Andina Location: #Peru Industry: #InternationalAffairs Staff: 5,001-10,000 employees Learn more at https://ecrime.ch eCrime.ch cybercrime intelligence…

Leer articulo →
eCrime.ch: New claim on the shame-site for #ransomware / #datatheft group #BlackShrantac. Organization: PT. Mowilex Location: #Indonesia Industry: #WholesaleBuildingMaterials Staff: 1,001-5,000 employees Learn more at https://ecrime.ch 2026-04-09
ecrime_ch Twitter/X

New claim on the shame-site for #ransomware / #datatheft group #BlackShrantac. Organization: PT. Mowilex Location: #Indonesia Industry: #WholesaleBuildingMaterials Staff: 1,001-5,000 employees Learn more at https://ecrime.ch eCrime.ch cybercrime inte…

Leer articulo →
eCrime.ch: New claim on the shame-site for #ransomware / #datatheft group #XP95. Organization: NNPC Health Maintenance Organization (HMO) Ltd. Location: #Nigeria Industry: #Insurance Staff: 11-50 employees Learn more at https://ecrime.ch 2026-04-09
ecrime_ch Twitter/X

New claim on the shame-site for #ransomware / #datatheft group #XP95. Organization: NNPC Health Maintenance Organization (HMO) Ltd. Location: #Nigeria Industry: #Insurance Staff: 11-50 employees Learn more at https://ecrime.ch eCrime.ch cybercrime in…

Leer articulo →
eCrime.ch: New claim on the shame-site for #ransomware / #datatheft group #Lynx. Organization: ACN Healthcare LLC / ACN Healthcare RCM Services Pvt. Ltd. Location: #UnitedStates Industry: #OutsourcingAndOffshoringConsulting Staff: 1,001-5,000 employees Learn more at https://ecrime.ch 2026-04-09
ecrime_ch Twitter/X

New claim on the shame-site for #ransomware / #datatheft group #Lynx. Organization: ACN Healthcare LLC / ACN Healthcare RCM Services Pvt. Ltd. Location: #UnitedStates Industry: #OutsourcingAndOffshoringConsulting Staff: 1,001-5,000 employees Learn mo…

Leer articulo →
eCrime.ch: New claim on the shame-site for #ransomware / #datatheft group #Beast. Organization: irmler.rechtsanwälte Inh. RA Prof. H.Henning Irmler Location: #Germany Industry: #LawPractice Staff: 2-10 employees Learn more at https://ecrime.ch 2026-04-09
ecrime_ch Twitter/X

New claim on the shame-site for #ransomware / #datatheft group #Beast. Organization: irmler.rechtsanwälte Inh. RA Prof. H.Henning Irmler Location: #Germany Industry: #LawPractice Staff: 2-10 employees Learn more at https://ecrime.ch eCrime.ch cybercr…

Leer articulo →
eCrime.ch: New claim on the shame-site for #ransomware / #datatheft group #PayoutsKing. Organization: Grace Design Studios, LLC Location: #UnitedStates Industry: #ArchitectureAndPlanning Staff: 201-500 employees Learn more at https://ecrime.ch 2026-04-09
ecrime_ch Twitter/X

New claim on the shame-site for #ransomware / #datatheft group #PayoutsKing. Organization: Grace Design Studios, LLC Location: #UnitedStates Industry: #ArchitectureAndPlanning Staff: 201-500 employees Learn more at https://ecrime.ch eCrime.ch cybercr…

Leer articulo →
eCrime.ch: New claim on the shame-site for #ransomware / #datatheft group #Gentlemen. Organization: PsychPlus Location: #UnitedStates Industry: #MentalHealthCare Staff: 1,001-5,000 employees Learn more at https://ecrime.ch 2026-04-09
ecrime_ch Twitter/X

New claim on the shame-site for #ransomware / #datatheft group #Gentlemen. Organization: PsychPlus Location: #UnitedStates Industry: #MentalHealthCare Staff: 1,001-5,000 employees Learn more at https://ecrime.ch eCrime.ch cybercrime intelligence cove…

Leer articulo →
eCrime.ch: New claim on the shame-site for #ransomware / #datatheft group #Qilin. Organization: Roettgers Company, Inc. Location: #UnitedStates Industry: #OilAndGas Staff: 11-50 employees Learn more at https://ecrime.ch 2026-04-09
ecrime_ch Twitter/X

New claim on the shame-site for #ransomware / #datatheft group #Qilin. Organization: Roettgers Company, Inc. Location: #UnitedStates Industry: #OilAndGas Staff: 11-50 employees Learn more at https://ecrime.ch eCrime.ch cybercrime intelligence coverin…

Leer articulo →
Group-IB Threat Intelligence: How do fake remote developers pass interviews and technical assessments? They rely on #AI for real‑time responses, recycled project repositories across multiple personas, pre‑written response templates tailored to each job, and hiring or buying real employees accounts/personas. Some personas even presented themselves as a “development company” to inspire confidence. Our blog exposes the full playbook from developing an intruder account to the tools used to secure a job long-term. 2026-04-08
GroupIB_TI Twitter/X

How do fake remote developers pass interviews and technical assessments? They rely on #AI for real‑time responses, recycled project repositories across multiple personas, pre‑written response templates tailored to each job, and hiring or buying real …

Leer articulo →
Group-IB Threat Intelligence: #DPRK IT workers don’t rely on traditional intrusions; they exploit trust in legitimate platforms. Our research links the same infrastructure to 2021 attempts to buy verified Upwork accounts, and reveals a service stack that includes Payoneer, Wise, AnyDesk, and even OpenAI. Once a synthetic persona gains reputation on GitHub or LinkedIn, it becomes a powerful vector for sanctions evasion and insider placement. The real risk? Money theft and withdrawal to DPRK, espionage, supply chain. 2026-04-08
GroupIB_TI Twitter/X

#DPRK IT workers don’t rely on traditional intrusions; they exploit trust in legitimate platforms. Our research links the same infrastructure to 2021 attempts to buy verified Upwork accounts, and reveals a service stack that includes Payoneer, Wise, …

Leer articulo →
Group-IB Threat Intelligence: The operation goes far beyond fake resumes. We found archived “persona packages” containing a generated California driver’s license for “Dominic Williams” and a full profile for “Dejan Teofilovic” with inconsistent locations (Serbia vs. Philippines). The same archive held AI‑assisted job application templates, #AI assisted prompts to “sound more naturally English,” and pre‑written bid proposals showing how threat actors scale synthetic #remoteworker campaigns. #SyntheticIdentity #ThreatIntel 2026-04-08
GroupIB_TI Twitter/X

The operation goes far beyond fake resumes. We found archived “persona packages” containing a generated California driver’s license for “Dominic Williams” and a full profile for “Dejan Teofilovic” with inconsistent locations (Serbia vs. Philippines).…

Leer articulo →
eCrime.ch: New claim on the shame-site for #ransomware / #datatheft group #INCRansom. Organization: RX Management Pty. Ltd. Location: #Australia Industry: #PharmaceuticalManufacturing Staff: 201-500 employees Learn more at https://ecrime.ch 2026-04-08
ecrime_ch Twitter/X

New claim on the shame-site for #ransomware / #datatheft group #INCRansom. Organization: RX Management Pty. Ltd. Location: #Australia Industry: #PharmaceuticalManufacturing Staff: 201-500 employees Learn more at https://ecrime.ch eCrime.ch cybercrime…

Leer articulo →
eCrime.ch: New claim on the shame-site for #ransomware / #datatheft group #Akira. Organization: Mabco Constructions S.A. / B&A Contractors S.A. / Mabetex Group Location: #Switzerland Industry: #Construction Staff: 201-500 employees Learn more at https://ecrime.ch 2026-04-08
ecrime_ch Twitter/X

New claim on the shame-site for #ransomware / #datatheft group #Akira. Organization: Mabco Constructions S.A. / B&A Contractors S.A. / Mabetex Group Location: #Switzerland Industry: #Construction Staff: 201-500 employees Learn more at https://ecr…

Leer articulo →
eCrime.ch: New claim on the shame-site for #ransomware / #datatheft group #WorldLeaks. Organization: Deaconess Hospital, Inc. / Deaconess Health System Inc. Location: #UnitedStates Industry: #HospitalsAndHealthCare Staff: 10,001+ employees Learn more at https://ecrime.ch 2026-04-08
ecrime_ch Twitter/X

New claim on the shame-site for #ransomware / #datatheft group #WorldLeaks. Organization: Deaconess Hospital, Inc. / Deaconess Health System Inc. Location: #UnitedStates Industry: #HospitalsAndHealthCare Staff: 10,001+ employees Learn more at https:/…

Leer articulo →
eCrime.ch: New claim on the shame-site for #ransomware / #datatheft group #Krybit. Organization: Gerald Zisser GmbH Location: #Austria Industry: #Construction Staff: 11-50 employees Learn more at https://ecrime.ch 2026-04-08
ecrime_ch Twitter/X

New claim on the shame-site for #ransomware / #datatheft group #Krybit. Organization: Gerald Zisser GmbH Location: #Austria Industry: #Construction Staff: 11-50 employees Learn more at https://ecrime.ch eCrime.ch cybercrime intelligence covering fina…

Leer articulo →
eCrime.ch: New claim on the shame-site for #ransomware / #datatheft group #Kairos. Organization: South Florida Injury Centers, Inc. Location: #UnitedStates Industry: #MedicalPractice Staff: 2-10 employees Learn more at https://ecrime.ch 2026-04-08
ecrime_ch Twitter/X

New claim on the shame-site for #ransomware / #datatheft group #Kairos. Organization: South Florida Injury Centers, Inc. Location: #UnitedStates Industry: #MedicalPractice Staff: 2-10 employees Learn more at https://ecrime.ch eCrime.ch cybercrime int…

Leer articulo →