Morgan Demboski

365 posts

Morgan Demboski banner
Morgan Demboski

Morgan Demboski

@MorganDemboski

Cyber Threat Intel Analyst 🏹 @Sophos | A self-proclaimed expert in cyber & geopolitics (opinions = my own)

Washington, D.C. Katılım Temmuz 2021
691 Takip Edilen1K Takipçiler
Morgan Demboski retweetledi
Kostas
Kostas@Kostastsale·
Check out this awesome report by Sophos on Chinese APT threat actors. There is much to learn from this technical breakdown; it's not your ordinary threat actor. Reading this report, you will notice that they used tools like impacket for lateral movement, which provides an opportunity for detection. ➡️Interesting use of Living-Off-the-Land binaries that I personally haven't seen before - instsrv.exe and srvany.exe. ➡️Multiple defense evasion methods to hide their tracks and evade detection, including a clever way to read DNS traffic and block AV/EDR-related domains. (but still uses impacket 🤷‍♂️🤦‍♂️) ➡️Interesting choice of data being staged for exfiltration. Overall, this prolonged intrusion had everything, and the authors did an incredible job of laying out all the details for the rest of the community. 🙏👏 Check it out here 🔗: news.sophos.com/en-us/2024/06/…
English
6
112
307
32.7K
Morgan Demboski retweetledi
Sophos X-Ops
Sophos X-Ops@SophosXOps·
We have high confidence that the goal of the campaign was cyberespionage in support of Chinese state interests. We are moderately confident that these activities were directed by a single organization due to coordination and sharing of TTPs. /3
Sophos X-Ops tweet mediaSophos X-Ops tweet media
English
1
4
9
2.1K
Morgan Demboski retweetledi
Sophos X-Ops
Sophos X-Ops@SophosXOps·
In the investigation that followed, MDR tracked at least three clusters of intrusion activity from March 2023 to December 2023, and found previously unreported malware. We also observed tools & infrastructure that overlapped with other public reporting on Chinese actors /2
Sophos X-Ops tweet media
English
1
5
12
1.3K
Morgan Demboski
Morgan Demboski@MorganDemboski·
This has been a monster of an investigation & writeup to put together - A campaign we call Operation Crimson Palace involving several Chinese state-sponsored actors coordinating activity in a single network Happy to finally share this intel ⤵️ news.sophos.com/en-us/2024/06/…
English
1
7
19
1.5K
Morgan Demboski retweetledi
J⩜⃝mie Williams
J⩜⃝mie Williams@jamieantisocial·
gotta ❤️ these attribution diagrams
J⩜⃝mie Williams tweet media
English
0
5
46
21.6K
Morgan Demboski retweetledi
Horizon3 Attack Team
Horizon3 Attack Team@Horizon3Attack·
The recent #Fortinet #FortiClient Endpoint Management Server (EMS) SQL injection vulnerability, CVE-2023-48788, allows an unauth attacker to obtain RCE as SYSTEM on the server. IOCs, POC, and deep-dive blog to be released next week. In the meantime, check DAS service logs for malicious looking queries. fortiguard.fortinet.com/psirt/FG-IR-24…
GIF
English
0
104
218
34.9K
Morgan Demboski retweetledi
Kostas
Kostas@Kostastsale·
One of the best talks I've seen on this topic to date by @MorganDemboski. A thorough explanation of how to cluster Threat Actors by using multiple data sources focused on TTPs. If you're interested in tracking & attribution, you should watch this! youtu.be/ZNf0T1yHl8s?si…
YouTube video
YouTube
English
0
23
94
6.7K
Morgan Demboski retweetledi
vx-underground
vx-underground@vxunderground·
When a Lockbit affiliate tries to log into the Lockbit panel this is what they see
vx-underground tweet media
English
38
339
2.3K
336.6K
Morgan Demboski retweetledi
AzAl Security
AzAl Security@azalsecurity·
Lockbit just emailed this to all of their affiliates.
AzAl Security tweet media
English
56
187
1K
292.6K
Morgan Demboski
Morgan Demboski@MorganDemboski·
My hometown getting a great rep 😂
AzAl Security@azalsecurity

#Lockbit listed Fulton County, GA as a victim. As of this writing, Fulton County’s municipal government website is experiencing a system outage. Fulton County is located in Atlanta, Georgia and is also the site of a criminal investigation against former President Donald Trump regarding election interference and home to DA Fani Williams who is embroiled in a romance controversy.

English
0
0
3
311
Morgan Demboski retweetledi
Stef Rand
Stef Rand@techieStef·
Really enjoying @MorganDemboski's talk on clustering RaaS affiliates, I love hearing how other teams approach this kind of work! The case studies she shared are great examples of focusing on tracking early details & behaviors, and not just the ransomware/payload. #CTISummit
English
0
2
16
797
Morgan Demboski retweetledi
Andy Piazza
Andy Piazza@klrgrz·
Awesome talk about clustering badness from @MorganDemboski today at SANS CTI Summit - highly recommend checking out the replay when it’s available!
GIF
English
0
1
11
816
Morgan Demboski retweetledi
Ismael Valenzuela
Ismael Valenzuela@aboutsecurity·
“A threat activity cluster (TAC) is not an attribution, but it can be a stepping stone. When we say a victim was attacked by #BlackCat ransomware, it’s not attribution but rather a TAC. It’s about the WHAT (the pattern), rather than the WHO.” @MorganDemboski discussing the RaaS ecosystem at #CTISummit
Ismael Valenzuela tweet media
Washington, DC 🇺🇸 English
1
6
24
2.7K
Morgan Demboski retweetledi
J⩜⃝mie Williams
J⩜⃝mie Williams@jamieantisocial·
Clustering != Attribution "But luckily, people are typically creatures of habit" ~"Look for narrowly focused details that would be hard for anyone besides the adversary to replicate" 🔍 @MorganDemboski #CTISummit
J⩜⃝mie Williams tweet mediaJ⩜⃝mie Williams tweet mediaJ⩜⃝mie Williams tweet media
English
3
14
92
9.3K
Morgan Demboski
Morgan Demboski@MorganDemboski·
Since October, we've not only seen an uptick in Akira #ransomware attacks, but also a new trend of Akira actors stealing data without deploying ransomware for extortion. Check out my latest article for more info on Akira's latest tactics ⤵️ news.sophos.com/en-us/2023/12/…
English
0
3
11
1.2K
Morgan Demboski
Morgan Demboski@MorganDemboski·
The real highlight of my Spotify Wrapped 🎁 Thanks @riskybusiness for your weekly episodes and for being my #1 podcast!
Morgan Demboski tweet media
English
0
1
2
366