Nart Villeneuve
2.2K posts


@TLP_R3D The indirect linkage is likely because of the use of a common Bullet Proof hosting service in this case.
English

🚨 Cybersecurity Alert 🚨 Phishing domains indirectly linked to #Snatch Ransomware detected! IP 51.250.13.110 located in Russia. Domains appear to target Canada Financial Services.
· simplihl[.]help - Spoofing Simplii Financial
· bmo-importantnotice[.]com - Spoofing Bank of Montreal (BMO)
· rbc-secureaccess[.]ca - Spoofing Royal Bank of Canada (RBC)
· verificationerror[.]com - Generic
· canadarevenue-agcy[.]info - Spoofing Canada Revenue Agency
· direct-gi[.]com - Unclear target
· actve-accept[.]com - Generic
· 4-easyweb-td[.]com - Spoofing TD Bank
· rbccappbnk.[.]om - Spoofing Royal Bank of Canada (RBC)
Stay vigilant and always verify links! #CyberSecurity #PhishingAlert #C2Engine #KryptoKloud

English
Nart Villeneuve retweetledi

NEW @citizenlab report -- extensive analysis of censored search results in 8 #China accessible search platforms.
#MicrosoftBing's "political censorship rules" found to be "broader and affected more search results than Baidu."
Authors: Jeffrey Knockel, Ken Kato & @emiledirks
The Citizen Lab@citizenlab
🚨NEW REPORT: MISSING LINKS ⛓️. Are you unable to get answers to your online searches? Multiple levels of #censorship affects eight #China accessible search platforms including #MicrosoftBing blocking all or some results. citizenlab.ca/2023/04/a-comp…
English
Nart Villeneuve retweetledi
Nart Villeneuve retweetledi

It must've seemed like a clever PR idea. But Loblaws' "price freeze" on no-name products has turned out to be an own goal. My take for @TorontoStar @StarBusiness today: thestar.com/business/opini…. Plus: the surge in corporate profits amidst inflation is a an economy-wide problem. /2
English
Nart Villeneuve retweetledi

In this excellent #CTIS2022 presentation @xme quoted youtube.com/watch?v=c3Ydb-… , ~50% of ransomware cases they analyzed began with use of valid RDP/VPN creds, but ~27% came from maldocs (#QAKBOT etc.). They also had one case of #RACCOON. The valid credentials come from somewhere!

YouTube
English

Two interesting tweets in my feed that intersect today: twitter.com/xme/status/158… and twitter.com/bmcder02/statu….
Blake@bmcder02
My first blog with @MicrosoftDART! This is a post incident report, talking about some of the TTPs we saw in a recent ransomware incident. This really emphasizes the importance of doing a post ransomware IR. microsoft.com/security/blog/…
English

But IR teams often run into issues trying to determine the initial access vector as @bmcder02 noted -- data retention limits and re-imaging compromised hosts etc. (microsoft.com/security/blog/…).
English
Nart Villeneuve retweetledi

I'm incredibly proud of @selenalarson and @dansomware's report on COVID social engineering. Telling threat stories over long periods of time is not our strength, they tackled this with grace and integrity. proofpoint.com/us/blog/threat…

English
Nart Villeneuve retweetledi

@PJ47596176 They forgot "Ghostnet" -- the OG threat actor name, and conceived by a non-industry group :)
English
Nart Villeneuve retweetledi

As we begin the new legislative session at Queen’s Park, I have one question for Doug Ford: What does ‘getting it done’ mean to you?
This was your commitment to Ontarians during the spring campaign. But if this summer is an example, ppl are in for a hard 4 years. 1/ #onpoli
English
Nart Villeneuve retweetledi

Great to see @ShaneHuntley testify before @HouseIntel today. I'm really proud of the work @Google TAG has been doing to combat spyware & speak out against the industry.
Adaptation of Shane's remarks here:blog.google/threat-analysi…
English








