Expel

4.2K posts

Expel banner
Expel

Expel

@ExpelSecurity

Human-led, AI-accelerated security.

Katılım Ağustos 2016
281 Takip Edilen12.8K Takipçiler
Expel
Expel@ExpelSecurity·
Need a high-level overview of the latest Mini Shai Hulud? Aaron Walton breaks down how the latest supply chain attack happened, what defenders should do now, and prepare for the next one. expel.com/blog/mini-shai…[…]pl/?utm_medium=social&utm_source=twitter&utm_campaign=blog-promo
English
0
1
0
248
Expel retweetledi
Decipher
Decipher@DecipherSec·
Come join our own @DennisF and our friends from @ExpelSecurity on June 1 in National Harbor for a candid, off-the-record conversation about the new era of AI-assisted vulnerability research, patching pain, and what's coming next. info.expel.com/event-mythos-u…
English
0
1
1
343
Expel
Expel@ExpelSecurity·
If you suspect compromise: containment before rotation. Disable unauthorized services first, then rotate GitHub PATs, npm publish tokens, AWS access keys, and HashiCorp Vault tokens. Pin your dependencies to verified hashes going forward. (6/7)
English
1
1
0
118
Expel
Expel@ExpelSecurity·
By now you've probably seen the Mini Shai Hulud supply chain story. TeamPCP compromised 170+ npm and PyPI packages—TanStack, Mistral AI, OpenSearch, and more. Here's what you need to know if you're responding right now. (1/7)
English
1
1
2
424
Expel retweetledi
The DFIR Report
The DFIR Report@TheDFIRReport·
Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware In April, we observed an intrusion that began with a malicious MSI masquerading as Sysinternals RAMMap and ended in domain-wide deployment of The Gentlemen ransomware. The intrusion featured EtherRAT, Ethereum-based EtherHiding C2 configuration, TryCloudflare tunnels, GoTo Resolve, Rclone exfiltration to Wasabi, and a newer malware framework named TukTuk. TukTuk stood out for its resilient C2 design, using SaaS and cloud platforms such as ClickHouse and Supabase, with support for Ably, Dropbox, GitHub Issues, direct HTTP, Slack, and Arweave-based dead-drop configuration retrieval. Detection opportunities included! ➡️ Full report is linked in the replies. #ThreatIntel #ThreatHunting #DigitalForensics
The DFIR Report tweet media
English
4
38
99
22K
Expel
Expel@ExpelSecurity·
@ug0tpwn3d Marcus figured they since they use BeaverTail malware prominently and Beavers are Rodents, he could go with "Rodent" to avoid stealing someone else's name. Since there's 6 teams, it ended up as HexagonalRodent. The funny name contributed to it being chosen.
English
1
0
3
52
Expel
Expel@ExpelSecurity·
Marcus Hutchins, principal threat researcher at Expel, has been tracking the group we call HexagonalRodent, a subgroup likely affiliated with DPRK's Famous Chollima, since late 2025. 1/6
English
4
7
66
8.7K
Expel retweetledi
WIRED
WIRED@WIRED·
One group of hackers used AI for everything from vibe coding their malware to creating fake company websites—and stole as much as $12 million in three months. wired.com/story/ai-tools…
English
0
27
58
31.7K