The Banshee Queen👑

3K posts

The Banshee Queen👑 banner
The Banshee Queen👑

The Banshee Queen👑

@cyberoverdrive

#threatintel @RecordedFuture but views are mine only. Ex @PwC_uk. Malware & infrastructure analysis with a side of cyberpunk 🌃🌌 She/her, support 🏳️‍🌈🏳️‍⚧️✨

Katılım Temmuz 2019
820 Takip Edilen2.4K Takipçiler
The Banshee Queen👑 retweetledi
NetAskari
NetAskari@NetAskari·
@ZianTT_Official has found another data breach of Integrity Tech. We have no further information unfortunately, nor access to any of the data, so we can't assess the true nature and validity of the claim.
NetAskari tweet mediaNetAskari tweet media
English
1
5
15
2K
Michael R
Michael R@nahamike01·
Active cluster on Vultr/The Constant Company (AS20473) using ZeroSSL certs spoofing Kaspersky & McAfee. Tradecraft shows similarities to APT41; however, analysis is ongoing. 45.77.176[.]85 217.69.1[.]147 80.240.16[.]246 64.20.75[.]136 kasperskysecure[.]com McAfeeupdates[.]com
Michael R tweet mediaMichael R tweet mediaMichael R tweet media
English
4
20
60
7.1K
The Banshee Queen👑 retweetledi
Security Alliance
Security Alliance@_SEAL_Org·
DPRK IT workers are now recruiting people on upwork/freelancer to hand over their accounts + install anydesk so they can work under someone else's identity We found folders of IDs, recruitment scripts, and 80/20 payment splits. This scales way better than individual infiltration & platforms need to detect the behavior (rmm tools, impossible travel) not just verify the identity. Full research from SEAL Intel: radar.securityalliance.org/from-north-kor…
English
9
27
111
16K
The Banshee Queen👑 retweetledi
Tay 💖
Tay 💖@tayvano_·
The DPRK IT Workers are increasingly using people to do their bidding on-demand rather than buying accounts / IDs. Happen to stumble on someone hunting for such plebs tonight. 😁
Tay 💖 tweet media
English
15
6
81
7.5K
The Banshee Queen👑 retweetledi
The Banshee Queen👑 retweetledi
aptwhatnow
aptwhatnow@aptwhatnow·
aptwhatnow tweet mediaaptwhatnow tweet mediaaptwhatnow tweet mediaaptwhatnow tweet media
ZXX
0
2
4
1.3K
The Banshee Queen👑 retweetledi
aptwhatnow
aptwhatnow@aptwhatnow·
Large multilateral effort regarding DPRK Cyber Ops and the IT Work efforts. There is so much to unpack here and a lot of orgs/countries took a swing at it. Check it out and will post some pics for pizzazz. msmt.info/Publications/d…
aptwhatnow tweet media
English
3
49
190
24.8K
The Banshee Queen👑 retweetledi
Cookie Connoisseur
Cookie Connoisseur@browsercookies·
Thanks for the call out Matt Burgess! It's true, DPRK boyz are acting as architects, structural engineers, and stamping/approving designs in the United States for a quick dollar. They steal legitimate licenses and make up stamps. Time to do something. wired.com/story/north-ko…
Cookie Connoisseur tweet media
English
0
5
16
1.4K
The Banshee Queen👑 retweetledi
bbsz
bbsz@blackbigswan·
Guide on how to make a #DPRK friend and get rekt for life in the process by being a North Korean mule. 1) They can initiate contact outside of the regular IT-related channels. Discord channels like "Learn Korean together", gaming communities etc. 2) They will continue to talk with you for months if they feel there's a chance you'll give them access to your PC (RDP), identity (real and digital) or run chores (go for interviews) for them. They will complain it's hard to do work in US/EU from their location. 3) They will act friendly but extremely pushy. They have a scenario to follow but they will improvise too. They will try to make themselves more credible by sending you some money ("for a new PC"). 4) It will sometimes feel like you're talking with few different people, because you are. 5) They will jump on the call without any issues. The usual DPRK-call tactics apply.
bbsz tweet mediabbsz tweet media
Cookie Connoisseur@browsercookies

@0dongfeng Book flight to DPRK Take propaganda posters and pictures Try to leave DPRK with them Enjoy life with DPRK frenz

English
1
5
27
6.1K
The Banshee Queen👑 retweetledi
Cookie Connoisseur
Cookie Connoisseur@browsercookies·
How do you catch a DPRK actor you ask? Here are a few things to think about; 1. They love to use a VPN when applying for jobs. Check your HR system.
English
25
172
1.5K
210.6K
The Banshee Queen👑 retweetledi
CYBERWARCON
CYBERWARCON@CYBERWARCON·
ZXX
2
15
48
11.7K
The Banshee Queen👑 retweetledi
CYBERWARCON
CYBERWARCON@CYBERWARCON·
Congratulations to Dakota Cary and Adam Meyers on being named to the 2025 CyberScoop 50 Awards! Both are past CYBERWARCON speakers who make an impact in the cyber community. Dakota Cary — Most Inspiring Up & Comer Adam Meyers — Industry Leadership cyberscoop.com/2025-cyberscoo…
English
1
1
27
4.1K
The Banshee Queen👑 retweetledi
ZachXBT
ZachXBT@zachxbt·
11/ The main challenge faced in fighting DPRK ITWs at companies include the lack of collaboration between services and the private sector. There’s also the negligence by the teams hiring them who become combative when alerted. ITWs are in no way sophisticated but are persistent since there’s so many flooding the job market globally for roles. Payoneer is commonly being used to convert fiat into crypto from dev work. I have already covered multiple times on indicators of what to look out for so I will not repeat those again.
ZachXBT tweet media
English
41
60
746
188K
The Banshee Queen👑 retweetledi
ZachXBT
ZachXBT@zachxbt·
1/ An unnamed source recently compromised a DPRK IT worker device which provided insights into how a small team of five ITWs operated 30+ fake identities with government IDs and purchased Upwork/LinkedIn accounts to obtain developer jobs at projects.
ZachXBT tweet mediaZachXBT tweet media
English
403
867
6.5K
1.1M
The Banshee Queen👑 retweetledi
Gi7w0rm
Gi7w0rm@Gi7w0rm·
Quck analysis of new #ToolShell payload observed by @leak_ix: Paylaod is a .dll executed in memory. Sha-256: 3461da3a2ddcced4a00f87dcd7650af48f97998a3ac9ca649d7ef3b7332bd997 It collects System Info and the sensitive machine key. Sends back in response. Single Request takeover.
Gi7w0rm tweet media
Gi7w0rm@Gi7w0rm

⚠️ New payload in the relation to #ToolShell . Attackers now don't need the static file anymore, leaking keys from memory without leaving the file. This means the existence of a file is not a reliable IoC anymore.

English
4
46
150
25.3K
The Banshee Queen👑 retweetledi
Tay 💖
Tay 💖@tayvano_·
I'm personally aware of 44 different crypto companies that these 9 guys have worked between 2020 and today. No less than 18 of those projects were subsequently hacked. (More were probably hacked but it was hidden from public view.) Bro.
Tay 💖 tweet media
English
0
7
21
2.4K
The Banshee Queen👑 retweetledi
Tay 💖
Tay 💖@tayvano_·
Your remote employee "Jack" who has "9 years of rich experience developing blockchain" and a 3-6 month old github is a DPRK IT Worker. His buddy, with a brand new github called "jacky-[projectname]-dev", is also a DPRK IT Worker.
GIF
English
23
15
224
14.8K