Nexus Threat Intel

44 posts

Nexus Threat Intel banner
Nexus Threat Intel

Nexus Threat Intel

@NexsusIntelSec

Nexus Threat Intel | Independent Threat Researcher 🛡️ ​Deep-dive analysis on malware infrastructure and cloud evasion techniques. Finding what automated scans

Italia Katılım Nisan 2026
16 Takip Edilen0 Takipçiler
Nexus Threat Intel
Nexus Threat Intel@NexsusIntelSec·
Proof of Cloaking: The server returns 403 Forbidden only when it detects analysis. It hides the phishing from providers but hits victims. Why is @Netcraft blind to this? 🕵️‍♂️ @lastknight @revolutapp
Nexus Threat Intel tweet media
English
0
0
0
2
Nexus Threat Intel
Nexus Threat Intel@NexsusIntelSec·
I sent professional PDF reports with forensic evidence. Results? ​Alibaba: "Address not found" ​Google: "Address not found" ​You are protecting scammers by being unreachable. Fix your abuse channels. [Screenshot of the delivery failure] @alibaba_cloud @Google
Nexus Threat Intel tweet mediaNexus Threat Intel tweet media
English
0
0
0
3
Nexus Threat Intel
Nexus Threat Intel@NexsusIntelSec·
Why do your bots say "Clean"? SERVER-SIDE CLOAKING. 🕵️‍♂️ ​They check from Desktop. If you use curl -A "iPhone", the server triggers an immediate 302 Redirect to a credential harvester. ​I analyzed the UmiJS code: patchRoutes is the smoking gun. Cc: @briankrebs @gcluley
Nexus Threat Intel tweet media
English
0
0
0
4
Nexus Threat Intel
Nexus Threat Intel@NexsusIntelSec·
@Unit42_Intel Incredible analysis on WebSocket backdoors. I've been tracking similar obfuscation patterns on .cfd infrastructures lately—mostly hiding phishing lures behind mobile-only cloaking. The level of sophistication is rising. Great work team! 🛡️ #NexusThreatIntel
English
0
0
0
14
Unit 42
Unit 42@Unit42_Intel·
Obfuscated #WebSocket backdoors are injecting credit card skimmers into hundreds of compromised websites. The payload sends stolen card information back to attacker's C2 domains. Details at: bit.ly/42HyNb3
Unit 42 tweet media
English
6
146
668
54.4K
Nexus Threat Intel
Nexus Threat Intel@NexsusIntelSec·
@GroupIB Great insights on insider threats. On the external front, I'm seeing a massive surge in cloaking techniques on .cfd infrastructures to hide phishing landing pages. Just neutralized a cluster today. The battle is on every front! 🛡️ #NexusThreatIntel
English
0
0
0
1
Group-IB Global
Group-IB Global@GroupIB·
This Labor Day, the most dangerous hire isn't the one who failed the background check. It's the one who passed it. DPRK-linked IT workers are infiltrating companies through legitimate hiring pipelines, earning salaries, and exfiltrating data from the inside. Group-IB researchers have mapped exactly how it works. The numbers tell the story. Read the full blog here: bit.ly/4d3XzXX #ThreatIntelligence #DPRK #InsiderThreat #Infosec #LaborDay #GroupIB
Group-IB Global tweet mediaGroup-IB Global tweet media
English
1
4
15
780