Aida Akl · @AAKL
233 followers · 538 posts · Server noc.social
Daniel Lunghi · @thehellu
128 followers · 8 posts · Server infosec.exchange

My latest research on (/#EmissaryPanda/#LuckyMouse) is out ! It includes analysis of a new version of SysUpdate ported to Linux, a new communication protocol through DNS TXT requests, a VMProtect certificate compromise, and probable infection vector trendmicro.com/en_us/research/

#apt #irontiger #apt27

Last updated 3 years ago

Daniel Lunghi · @thehellu
91 followers · 5 posts · Server infosec.exchange

I have been working on targeted attacks for a long time now, first as an incident responder, and now doing threat intelligence at Trend Micro.
I usually focus for a while on a threat actor, and when I feel I know enough, publish something about it. The fun part is that very often, while investigating a threat actor, you end up finding stuff on another one, which you can add to your TODO list once the current investigation is completed :)
BTW, this is a good reason to be careful with the attribution out there, infrastructure overlap and tool sharing are common stuff nowadays.

Some of my previous work on groups:

:
trendmicro.com/en_us/research/
:
trendmicro.com/fr_fr/research/
trendmicro.com/en_us/research/
/#Bahamut:
trendmicro.com/en_us/research/
A bit of all previous actors:
first.org/resources/papers/tal

:
trendmicro.com/en_us/research/
documents.trendmicro.com/asset

Maybe APT37 (unconfirmed):
trendmicro.com/en_us/research/

/#Tonto:
vb2020.vblocalhost.com/uploads
Operation DRBControl:
trendmicro.com/vinfo/us/securi
:
trendmicro.com/en_us/research/
trendmicro.com/vinfo/us/securi
/#EarthSmilodon:
trendmicro.com/en_no/research/
trendmicro.com/en_us/research/

#introduction #apt #patchwork #confucius #urpage #muddywater #earthakhlut #earthberberoka #irontiger

Last updated 3 years ago