
New from @RecordedFuture! @_whoisnt and I break down Threat Activity Enablers (TAEs), the often overlooked backbone of modern cyber operations. 🔗recordedfuture.com/blog/threat-ac…
Jerri P
41 posts


New from @RecordedFuture! @_whoisnt and I break down Threat Activity Enablers (TAEs), the often overlooked backbone of modern cyber operations. 🔗recordedfuture.com/blog/threat-ac…




On my phone right now but everyone should start blocking this abusive ASN. AS Number 214472 Tons of abuse reported and staying online. Thank you security researchers for sending abuse towards @abuse_ch making this visible. Oh and of course it is a downstream from pfcloud.


NEW: Block one ASN, disrupt sixteen malware families. OMEGATECH (AS202412) — a three-month-old bulletproof hosting network with 18 /24 prefixes (4,608 IPs). One subnet alone hosts 67 C2 servers: Remcos (6,562 sightings), AsyncRAT (4,379), Amadey, Latrodectus, XWorm, Stealc, DCRat, LOBSHOT, Eye Pyramid, Mirai, Bashlite, Quasar, ClearFake, SectopRAT, SuperShell, SheetRAT. Seychelles .sc abuse contact. Pfcloud UG transit. Zero legitimate traffic. We recovered an Amadey credential stealer plugin (cred64.dll) targeting Chrome, Firefox, Outlook, Thunderbird, FileZilla, WinSCP, and Monero wallets. 3 YARA + 10 Suricata on GitHub. Full writeup: intel.breakglass.tech/post/omegatech… h/t @Fact_Finder03















