Intel-Ops

113 posts

Intel-Ops banner
Intel-Ops

Intel-Ops

@Intel_Ops_io

Adversary Infrastructure Hunting & Training Curated Threat Intelligence Feed (Coming Soon) https://t.co/N9OKrTrvV0 https://t.co/3YFZfEbgpI

参加日 Ocak 2024
4 フォロー中2.4K フォロワー
固定されたツイート
Intel-Ops
Intel-Ops@Intel_Ops_io·
🚨New Partnership Announcement!🚨 All students will receive enhanced access to @Validin providing improved hunting capabilities. Upcoming training on Validin and real-life use cases tracking threat actors are on the way! inc. dedicated Discord channel for Validin. 🔥🔥🔥
Intel-Ops tweet media
English
4
2
30
20.7K
Intel-Ops
Intel-Ops@Intel_Ops_io·
Infrastructure predominantly distributed across Flyservers S.A. hosting, but the following also used: HOSTKEY-USA, Global Layer B.V. Bunea TELECOM SRL, DATAHOME S.A, Krez 999 Eood, Fbw Networks SAS.
English
0
1
1
1.2K
Intel-Ops
Intel-Ops@Intel_Ops_io·
Activity: Chaos Remote Administration Tool. Hijack Loader delivers StealC, Danabot. FakeUpdates delivers Rhadamanthys. PowerShell to retrieve payloads. Historical use of Cobalt Strike and Metasploit Cerber and Xorist ransomware samples identified.
English
1
1
3
1.3K
Intel-Ops
Intel-Ops@Intel_Ops_io·
We're tracking an interesting cluster linked to ShadowSyndicate that suggests that the operators are involved in various initial access campaigns, leverage multiple post-exploitation techniques, tools and ransomware.
Intel-Ops tweet media
English
2
7
36
4.7K
Intel-Ops
Intel-Ops@Intel_Ops_io·
New impersonation domains for @anydesk and @NotionHQ delivering malicious MSI packages, likely via SEO poisoning: 45.93.20[.]93 - AS 57523 (Chang Way Tech Co. Ltd) amydlesk[.]com (0/93) notlilon[.]co (1/93) notliion[.]com (8/93)
Intel-Ops tweet mediaIntel-Ops tweet media
English
2
14
55
20.3K
Intel-Ops
Intel-Ops@Intel_Ops_io·
Interesting recently created (2024-05-22) domain impersonating @GEHealthCare. Resolving to 46.101.212[.]131, running #CobaltStrike server. Using @Huntio we can see: ➡️the DNS record, ➡️Hoster: @digitalocean, ➡️Watermark: 987654321 (cracked version).
Intel-Ops tweet mediaIntel-Ops tweet mediaIntel-Ops tweet media
English
0
9
39
5.1K
Intel-Ops がリツイート
Michael Koczwara
Michael Koczwara@MichalKoczwara·
APT43/Kimsuky (Black Banshee)🇰🇵 /141.11.95.135 /67.217.60.68 /67.217.62.219 /185.141.171.31 /185.203.119.14 /note.iiiii.info /share-defence.uberlingen.com /imagedownload.ignorelist.com /signin-ym.quest /mnlp.quest /oso-usps.com /drives.youramys.com /www.uidlogin.o-r.kr /wilsoncenter.port0.org /drive.wilsoncenter.port0.org /wilsoncenter.0rg.us /drive.wilsoncenter.0rg.us /naververify.p-e.kr /uidlogin.o-r.kr /atlanticcouncil.youramys.com /atlanticacouncil.org.youramys.com H/T @1ZRR4H
Michael Koczwara tweet media
English
7
36
154
26.7K
Intel-Ops がリツイート
Michael Koczwara
Michael Koczwara@MichalKoczwara·
We are pleased to announce a new partnership between @Intel_Ops_io and @Huntio🤝 This partnership will provide all current and new IntelOps students with access to the Hunt.io platform. Students will learn to use the platform effectively for exploring new pivoting methods and hunting for malicious infrastructure, including new C2s🥷, APTs 🇮🇷 🇰🇵 🇷🇺 🇨🇳 and ransomware groups 🔐 hunt.io academy.intel-ops.io/courses/huntin…
Michael Koczwara tweet media
English
0
11
95
7.8K
Intel-Ops がリツイート
Michael Koczwara
Michael Koczwara@MichalKoczwara·
Cybersecurity "experts" be like... APTs in 2024 will be using Artificial Intelligence to create undetectable malware, payloads, zero-day exploits, cyber weapons, and probably some cyber nuclear bombs too🥱 Meanwhile, APTs (Muddy Water 🇮🇷)in 2024 🙃
Michael Koczwara tweet media
English
8
43
306
50K
Intel-Ops がリツイート
Michael Koczwara
Michael Koczwara@MichalKoczwara·
This one is a good example how infrastructure is reused by different actors. 216.189.159[.]34 - BianLian Ransomware💰 216.189.159[.]34 - North Korean APT 🇰🇵 @Intel_Ops_io
GIF
English
4
10
54
8K
Intel-Ops がリツイート
Validin
Validin@ValidinLLC·
New feature now available to premium AND community users! Per popular request, Validin now supports pivoting of certificate SHA256 hashes in addition to SHA1. This pivot makes it easier to continue searches from or on other platforms that favor SHA256.
Validin tweet mediaValidin tweet media
English
0
8
23
3.7K
Intel-Ops
Intel-Ops@Intel_Ops_io·
Coming soon, students will also be able to have access to the @Huntio platform to use for Threat Hunting!
English
0
0
5
613
Intel-Ops
Intel-Ops@Intel_Ops_io·
To conduct similar analysis and track threats such as these, we offer students a "Hunting Adversary Infrastructure" course: academy.intel-ops.io - students gain special Intel-Ops accounts for the @ValidinLLC platform (additional query and API credits) to help with learning.
English
1
0
5
724
Intel-Ops
Intel-Ops@Intel_Ops_io·
🚨Hunting Black Basta's Cobalt Strike🧵 Intel-Ops is actively tracking #CobaltStrike servers in the wild, including those deployed by #BlackBasta. In this post, we’ll cover some findings from our analysis of #C2 servers included in the FBI/CISA advisory. @Intel_Ops/hunting-black-bastas-cobalt-strike-96a81a6ea781" target="_blank" rel="nofollow noopener">medium.com/@Intel_Ops/hun…
Intel-Ops tweet media
English
1
26
87
13.5K