Sabitlenmiş Tweet
Resecurity®
1.3K posts

Resecurity®
@RESecurity
We provide technology that empowers organizations to reimagine their security & protect what matters #SaaS #RiskManagement #CyberThreatIntelligence
Los Angeles, California Katılım July 2016
1.5K Takip Edilen6.6K Takipçiler
2026 Yıllık Özeti
@RESecurity hesabının Twitter yılını gör

FBI just warned that a hacking group is walking into law offices and pretending to be IT support, plugging USB drives into computers to steal data
The group, known as the Silent Ransom Group (SRG), has been targeting professional services firms including law offices in the United States, with activity reported in recent years. Security researchers link parts of their infrastructure and tactics to actors previously associated with the Conti ransomware ecosystem, which broke apart after its disruption in 2022. While SRG is not a direct continuation of Conti, many analysts believe there is operational overlap in tooling and social engineering methods
Unlike traditional ransomware groups that rely heavily on malware encryption, SRG operations are built around **social engineering and impersonation**. Their attacks often begin with phishing emails or phone calls where they pose as internal IT support or trusted service providers. The goal is to create urgency by inventing technical problems and convincing employees to hand over access or follow instructions
A common tactic is “callback phishing,” where the victim is prompted to call a number controlled by the attackers. On the call, the attackers guide the target into installing remote access tools or granting permissions under the guise of fixing a security issue. Once access is established, they focus on locating and exfiltrating sensitive data rather than deploying destructive malware
FBI reporting also notes that in some cases, if remote social engineering attempts fail, attackers may escalate to **physical approaches**, including sending individuals to a victim’s location posing as IT personnel. In these scenarios, the attacker attempts to gain direct access to a workstation and may use external storage devices to copy data. This is not the primary method of attack, but rather a lower-frequency escalation path when other methods do not succeed
After data theft, SRG typically shifts to extortion. Victims receive demands threatening to leak or sell stolen information unless payment is made. In some cases, pressure tactics may include repeated contact or direct negotiation attempts
The FBI has highlighted key warning signs of these intrusions, including unauthorized individuals attempting to access workstations, unexpected IT support requests, and the presence of unfamiliar external devices connected to company systems

English

@TYOBlackHatNews Resecurity is the first to uncover the SRG's Fast Flux network infrastructure and is sharing this intelligence with the #cybersecurity community to disrupt their malicious activities and enable ISP/DNS providers to counter this threat. resecurity.com/blog/article/s…
English

Silent Ransom Group(SRG):DNSファストフラックスインフラの全容解明
blackhatnews.tokyo/archives/110000
日本語

@nakajimeeee Resecurity is the first to uncover the SRG's Fast Flux network infrastructure and is sharing this intelligence with the #cybersecurity community to disrupt their malicious activities and enable ISP/DNS providers to counter this threat. resecurity.com/blog/article/s…
English

【ソーシャルエンジニアリング・恐喝】IT部門を騙り「画面共有してください」、米国法律事務所を標的にした音声フィッシング恐喝団の全貌
MandiantとGoogle Threat Intelligence Groupは、2026年1月から5月にかけて米国の法律・金融・専門サービス業を集中的に狙う恐喝キャンペーンを実施する脅威グループ「UNC3753」(別名:Luna Moth、Silent Ransom Group)を詳細に分析した。攻撃の起点は「請求書を送った」という無害な口実メールだ。被害者が不審に思って社内ITに問い合わせようとした矢先、攻撃者が「IT担当者」を装って電話をかけ、Zoom・Teams・Quick AssistでのRMM(遠隔管理ツール)インストールへ誘導する。
侵入後の動作は驚くほど速い。iManageなどの法律文書管理システムをキーワード検索で狙い撃ちにし、W-2フォーム・SSN・秘密保持契約書・M&A関連文書を一括収集。WinSCPやRcloneで攻撃者管理のクラウドストレージへ転送するまでの全工程が1時間以内で完結したケースも確認された。データ窃取完了から30分以内に3日間の回答期限を設けた恐喝メールが届き、期限を過ぎれば従業員・取引先・クライアントへの通知とリークサイト「LEAKEDDATA」への公開を脅迫する。
さらにFBIサイバーFLASHアラートが裏付ける通り、音声フィッシングが失敗した標的に対してはIT技術者を装った人物を物理的にオフィスへ送り込み、USBストレージでのデータ直接窃取を試みるという、サイバーと物理が融合した新たなエスカレーション戦術も確認されている。
cloud.google.com/blog/topics/th…
日本語

New #ransomware projects have been identified that could be linked to the Silent Ransom Group (SRG), including Spy Corporate, which emerged in May 2026. Fast Flux provides the SRG with resilient infrastructure to extort AmLaw 100 firms. Overlap in DNS/IP - Learn More: resecurity.com/blog/article/s…
English

🚨 Ransomware Alert: 🇺🇸
We started monitoring a new ransomware group, "SPY CORPORATE." They had added a victim in their portal.
Hahn Loeser & Parks LLP (hahnlaw.com), a USA-based law practice, has reportedly fallen victim to SPY CORPORATE Ransomware.
🔍Key Details:
🛡️Threat actor: SPY CORPORATE
📅 Reported on: 21/05/26

English

Fast Flux provides the SRG with resilient infrastructure to extort victims. The @FBI recently issued an advisory about this #ransomware group, which is actively targeting top AmLaw 100 firms (and other industries) through social engineering and in-person attacks. ic3.gov/CSA/2026/26052…

English

Resecurity is the first to uncover the SRG's Fast Flux network infrastructure and is sharing this intelligence with the #cybersecurity community to disrupt their malicious activities and enable ISP/DNS providers to counter this threat. resecurity.com/blog/article/s…
English

Resecurity collaborated with @MicrosoftDCU to help better understand how Fox Tempest operated. Microsoft also noted coordination with @Europol’s European Cybercrime Centre (EC3) and the @FBI, underscoring the importance of public-private collaboration in disrupting #cybercrime infrastructure. microsoft.com/en-us/security…
English

On May 19, 2026, @Microsoft unsealed a legal case in the U.S. District Court for the Southern District of New York targeting Fox Tempest, a #cybercrime service that abused Microsoft Artifact Signing to obtain fraudulent code-signing certificates. blogs.microsoft.com/on-the-issues/…
English

Resecurity supported @MicrosoftDCU in its disruption of Fox Tempest, a financially motivated threat actor operating a malware-signing-as-a-service (MSaaS) capability used by #cybercriminals to make malicious files appear legitimate. resecurity.com/press/article/…

English

GEOINT in the Iran War: Targeting, Intelligence, and the Battle for Information thedefensepost.com/2026/04/14/geo… via @defensepost
English

Resecurity is proud to announce that it has been named a 2026 Cyber 150 Winner, a prestigious recognition awarded to the most innovative and impactful #cybersecurity companies worldwide. Congratulations, team! 👏businesswire.com/news/home/2026…
English

Resecurity Supported Phoenix Challenge® 2026 – Information Operations (IO) Excellence in #Cyberspace #Cybersecurity #AI businesswire.com/news/home/2026…
English
@RESecurity karşılaştırmaları
@cyber_rekk vs @resecurity @resecurity vs @tyoblackhatnews @nakajimeeee vs @resecurity @fbi vs @resecurity @microsoftdcu vs @resecurity @europol vs @resecurity
Kendi karşılaştırmanı oluştur Keşfet
Benzer Profiller
Türk Amatör Paylaşım
@turkamator88
219.2K görüntülenme
狱
@wx1n11124
138.4K görüntülenme
Türk ifşa Aleyna
@turkifsa_aley
46.8K görüntülenme
邪恶无机酱
@ne_puppy
41.7K görüntülenme
狗爹和小桃🍑
@cccxxxyyyiii
35.4K görüntülenme
少萝之家
@slzjtt
29.1K görüntülenme
Gulili谷鲤里
@gulililucky
19.5K görüntülenme
乳糖超不耐
@oooosugar
18.9K görüntülenme
