Allison Wikoff

261 posts

Allison Wikoff banner
Allison Wikoff

Allison Wikoff

@SaltyWikoff

#threatintel Americas Lead @pwc. Hype woman. Beach Rat. Former Adjunct @Columbia. Lover of all the APTs. | All views are my own.

Tham gia Ağustos 2014
820 Đang theo dõi651 Người theo dõi
Allison Wikoff đã retweet
Curtis
Curtis@cybershtuff·
🚨 Possible first Iranian wiper activity since the start of the war. Handala (MOIS-linked) claims targeting Stryker Corporation, reportedly pushing a wiper to Intune-managed endpoints. Now, who's got samples for analysis?
English
5
13
104
20.8K
Allison Wikoff đã retweet
Nariman Gharib
Nariman Gharib@NarimanGharib·
URGENT SECURITY ALERT: Iranian Revolutionary Guards intelligence has initiated a phishing campaign targeting individuals abroad who are involved in Iran-related activities. The current attack specifically targets WhatsApp users. Do not click on suspicious links.
Nariman Gharib tweet mediaNariman Gharib tweet media
English
0
1K
2K
338.9K
Allison Wikoff
Allison Wikoff@SaltyWikoff·
Good summary re: leaks. A couple older links in reference to Ravin Academy eur-lex.europa.eu/legal-content/… pwc.com/gx/en/issues/c…
Hamid Kashfi@hkashfi

I wanted to do some commentary on the recent CharmingKitten leak, but the data and content seem to be mostly tampered with. Perhaps their future updates might show more, but as is, there's little to cover and makes me the UI playing along. All files have their metadata cleaned up and retouched, and by the few seconds time variance across them, it is possible that it's a much larger stash, taking few seconds to touch everything. On technical side, there's very little to highlight, other than using mostly opportunistic attempts and public PoC tools and exploits to gain access to targets, beside typical phishing campaigns. The irony in their logs and notes? They target a lot of domestic websites and Iranian orgs and companies :) That tells you how unhinged everything is out there in their org. Similar to the leak from few years ago related to OilRig internals, we're seeing heavily filtered and handpicked logs and target names and countries. How to get a better picture? Scan internet for live webshells with matching naming schemes. Detailed time logging and reporting might stand out at first glance, in a positive and interesting way, but it's worth noting that demanding that template mostly comes from deep mistrust between the ranked employers and operators, rather than following some sort of guard railing to monitor for internal policy violation, as it would be more common on the western side. Another noteworthy point one can see through the logs is that this is a team span across multiple locations and buildings, working in parallel. Typically staffed around 15-20, which is similar to dropped names here. At least some of the operators were participating in Ravin Academy's Red-Team classes, which is self explanatory. While Ravin can always take the plausible deniability route and claim they don't know who their students are, as someone closely familiar with that scene and echo system, I'd call that out. On the other hand, Ravin and similar entities are doing legitimate work within context of Iran's laws and in favor of their nation/gov. Training alone, cannot be a reason to question them. Attribution to incidents by overlapping TTPs, coding style and OpSec failures? Sure! Let's see what drops next and whether we will observe something significant. I also asked Gemini to crunch the logs and generate some notes: gist.github.com/Hamid-K/f4288d…

English
0
0
2
622
Allison Wikoff
Allison Wikoff@SaltyWikoff·
Always fun to rep the pwc #threatintel team and talk about kittens, particularly in a local setting. #BSidesTampa was a great time and looking forward to next year. Also thrilled to break out my homage to the unofficial (according to me) state bird, the Sandhill Crane 🤣🤣
Allison Wikoff tweet media
English
0
1
8
353
Allison Wikoff đã retweet
Dark Reading
Dark Reading@DarkReading·
Last week Dark Reading took a break from The Moscone Center and headed over to PwC’s offices in San Francisco, CA to meet up with PwC’s director and Americas lead for global threat intelligence, Allison Wikoff. She shares with us what she was most excited about for RSAC 2025! #rsac2025 #darkreading #darkreadingconfidential
English
1
1
2
3.7K
Allison Wikoff đã retweet
FBI
FBI@FBI·
The FBI and DOJ announced a court-authorized operation that removed PlugX malware from thousands of computers in the U.S. and abroad. PRC-sponsored hackers used PlugX to target businesses, governments, and Chinese dissidents. Find more information here: fbi.gov/news/press-rel…
FBI tweet media
English
107
305
681
55.2K
Allison Wikoff đã retweet
FBI
FBI@FBI·
This week on Ahead of the Threat, #FBI's Bryan Vorndran and Equifax's Jamil Farshchi speak with Charles Carmakal, Chief Technology Officer at Mandiant, about disturbing trends in #cybersecurity attacks and techniques to avoid them. Watch the episode here: youtube.com/watch?v=eehL_V…
YouTube video
YouTube
FBI tweet media
English
64
48
140
25.5K
Allison Wikoff đã retweet
The Banshee Queen👑
The Banshee Queen👑@cyberoverdrive·
It finally happened - I am ALSO in the Blue place ✨🌌 Same handle & name as here! (Not an impersonator 😛) Not leaving this cursed app YET, but considering. Also couldn’t bear missing out on a) the awesome #cti / #threatintel community (💖) & b) my awesome handle! Cya there too!
The Banshee Queen👑 tweet media
English
2
0
14
1K
Allison Wikoff đã retweet
Tom Hegel
Tom Hegel@TomHegel·
🚨 New Research Drop: 🇰🇵 DPRK IT Workers | A Network of Active Front Companies and Their Links to China. 🟣 Newly Disrupted Front Companies by USG. 🟣 Impersonating US based software and tech orgs. 🟣 Links to still-active front orgs, CN association 🇨🇳. sentinelone.com/labs/dprk-it-w…
English
1
25
63
9.4K
Allison Wikoff đã retweet
FBI Atlanta
FBI Atlanta@FBIAtlanta·
Statement from FBI Atlanta.
FBI Atlanta tweet media
43
615
1.3K
226.5K