MoBustami

2.4K posts

MoBustami

MoBustami

@MoBustami

Malware Researcher, Internet Protector, Cyber researcher

Toronto, Canada Katılım Ağustos 2013
295 Takip Edilen472 Takipçiler
Steven Adair
Steven Adair@stevenadair·
@Volexity @PaloAltoNtwks We have seen limited exploitation but impact at multiple customers. We first detected this just two days ago. Impressive response from the Palo Alto Networks team, as they quickly worked with us and have now pushed a Threat Protection signature with a fix to come April 14.
English
1
9
56
11.3K
MoBustami
MoBustami@MoBustami·
I highly recommend watching Kris's talk from 2022. I specifically love the methodology used for their analysis and it is just a work of art.
Kris McConkey@smoothimpact

In September 2022, attendees at the inaugural @labscon_io heard about an actor I described then as "one of the most prolific, most deeply connected, and most technically advanced actors around". Events this week were a reminder that the video never went out, so here it is 👇

English
0
0
1
211
MoBustami
MoBustami@MoBustami·
@f0xtrot_sierra Thank you for sharing this. To help me understand a bit better, is this an indication of preexisting compromise either external or insider or is this trying to show a new tactic? I am sorry if I am missing something obvious here.
English
0
0
0
135
Faith
Faith@f0xtrot_sierra·
We then see the suspicious application 'eM Client' being added and assigned the permission IMAP.AccessAsUser.All, which gives the application the same access to the user's mailboxes as the user logged in via IMAP. User successfully authenticates, we log out and disable ✌️ 2/2
Faith tweet media
English
2
2
17
1.8K
Faith
Faith@f0xtrot_sierra·
Interesting M365 case @HuntressLabs the other day First see user trying to authenticate from IP associated with suspicious ISP Ovh Sas with an unusual user-agent Following failed authentication we see a Service Principal account linking a new device for MFA 🧵 1/2
Faith tweet media
English
1
19
82
18.9K
MoBustami retweetledi
Sam ☁️🪵
Sam ☁️🪵@Sam0x90·
💜Adversary Simulation and Purple friends💜 I'm happy to share this simulation plan which regroups a TOP 35 @MITREattack TTPs from 22-23. Based on open source intel, it's meant to ease the onboarding of more into Purple! Have a look at the readme #CTI #TTP github.com/Sam0x90/CTI/tr…
Sam ☁️🪵 tweet media
English
10
103
383
74.9K
MoBustami retweetledi
Mark Parsons
Mark Parsons@markpars0ns·
Today we are highlighting an actor we are tracking as Volt Typhoon. This activity is targeting US and Guam critical infrastructure. Volt Typhoon has been observed mostly living off the land during our investigations.
Microsoft Threat Intelligence@MsftSecIntel

Volt Typhoon, a Chinese state-sponsored actor, uses living-off-the-land (LotL) and hands-on-keyboard TTPs to evade detection and persist in an espionage campaign targeting critical infrastructure organizations in Guam and the rest of the United States. msft.it/6019gj8eH

English
4
32
79
17.6K
MoBustami
MoBustami@MoBustami·
@ImposeCost Would it be fair to say that attribution matters as long as it is thus serving the enablement of better detection and better understanding of the tradecraft of the TA to enable defenders better map controls and enhance prevention? Not for the whodunit chit chat?
English
0
0
1
387
MoBustami
MoBustami@MoBustami·
Thank you @ImposeCost for this... I could not have said it any better
English
0
0
1
295
MoBustami retweetledi
Van
Van@Wanna_VanTa·
Today, we've released #APT43 🇰🇵. As part of this release, I wanted to highlight some of the background research that went into this. No blue checkmark, so I have to do a normal thread 😅mandiant.com/resources/blog…
English
2
45
118
19.5K
MoBustami
MoBustami@MoBustami·
@Arkbird_SOLG @James_inthe_box @h2jazi so I guess mystery kinda solved. the JS code from the anyrun sample - 915429ec7cda5e26796835b6058b251f once decoded, creates another script that uses the original one as a loader to decrypt it's strings. the dkey, function and some sample clear output is in the below screenshot
MoBustami tweet media
English
1
1
1
259
MoBustami
MoBustami@MoBustami·
@Arkbird_SOLG @James_inthe_box @h2jazi My question still remains on why this sample did not behave like the other sample I highlighted and nothing I can find in relation to the below image. I will keep digging and see
MoBustami tweet media
English
1
1
1
243