fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

8.6K
active users

#VXUnderground

0 posts0 participants0 posts today
B'ad Samurai 🐐<p>Solid combo in today's USPS media mail 🐢 delivery.</p><p><a href="https://infosec.exchange/tags/VXUnderground" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VXUnderground</span></a></p>
Dan<p>VX Underground Zine Black Mass Volume III <br><a href="https://mini-01-s3.vx-underground.org/samples/Papers/Other/VXUG%20Zines/2025-07-22%20-%20Black%20Mass%20Volume%20III.pdf" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">mini-01-s3.vx-underground.org/</span><span class="invisible">samples/Papers/Other/VXUG%20Zines/2025-07-22%20-%20Black%20Mass%20Volume%20III.pdf</span></a> <a href="https://chaos.social/tags/zine" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>zine</span></a> <a href="https://chaos.social/tags/vx" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>vx</span></a> <a href="https://chaos.social/tags/vxunderground" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>vxunderground</span></a> <a href="https://chaos.social/tags/vxscene" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>vxscene</span></a></p>
Xavier Ashe :donor:<p>A picture of my wrist has been posted to the <a href="https://infosec.exchange/tags/vxunderground" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>vxunderground</span></a> chat (along with a funny message my watch gave me at the time). Does this make me an <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a> rockstar now? Or should I be worried about <a href="https://infosec.exchange/tags/AI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AI</span></a> counting my freckles and doxing me?<br><a href="https://t.me/vxunderground/6456" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">t.me/vxunderground/6456</span><span class="invisible"></span></a></p>
Plugged Potato<p>vx-underground's extracted cat picture torrent is so large, Linux Mint's file manager is struggling to open it. I think I'm in heaven</p><p><a href="https://vx-underground.org/Torrents" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">vx-underground.org/Torrents</span><span class="invisible"></span></a></p><p><a href="https://infosec.exchange/tags/caturday" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>caturday</span></a> <a href="https://infosec.exchange/tags/vxunderground" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>vxunderground</span></a> <a href="https://infosec.exchange/tags/cat" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cat</span></a> <a href="https://infosec.exchange/tags/torrent" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>torrent</span></a> <a href="https://infosec.exchange/tags/linuxmint" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>linuxmint</span></a></p>
Xavier Ashe :donor:<p><a href="https://infosec.exchange/tags/VXUnderground" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VXUnderground</span></a> has posted a "best of" page with their favorite papers. I think some of these should be required reading for red teamers, malware researchers, or vulnerability researchers. Thoughts?<br><a href="https://vx-underground.org/Best%20Of" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">vx-underground.org/Best%20Of</span><span class="invisible"></span></a><br><a href="https://infosec.exchange/tags/redteam" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>redteam</span></a> <a href="https://infosec.exchange/tags/malware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>malware</span></a> <a href="https://infosec.exchange/tags/malware_research" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>malware_research</span></a> <a href="https://infosec.exchange/tags/vulnerability" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>vulnerability</span></a></p>
stf<p>i like the fediverse, but i miss <a href="https://chaos.social/tags/vxunderground" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>vxunderground</span></a></p>
Tarnkappe.info<p>📬 Banshee Stealer Quellcode geleakt: macOS-Malware unschädlich gemacht<br><a href="https://social.tchncs.de/tags/ITSicherheit" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ITSicherheit</span></a> <a href="https://social.tchncs.de/tags/Malware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Malware</span></a> <a href="https://social.tchncs.de/tags/BansheeStealer" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BansheeStealer</span></a> <a href="https://social.tchncs.de/tags/ElasticSecurityLabs" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ElasticSecurityLabs</span></a> <a href="https://social.tchncs.de/tags/macOS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>macOS</span></a> <a href="https://social.tchncs.de/tags/macOSMalware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>macOSMalware</span></a> <a href="https://social.tchncs.de/tags/QuellcodeLeak" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>QuellcodeLeak</span></a> <a href="https://social.tchncs.de/tags/VXUnderground" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VXUnderground</span></a> <a href="https://sc.tarnkappe.info/ad2a32" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">sc.tarnkappe.info/ad2a32</span><span class="invisible"></span></a></p>
Pyrzout :vm:<p>NationalPublicData.com Hack Exposes a Nation’s Data <a href="https://krebsonsecurity.com/2024/08/nationalpublicdata-com-hack-exposes-a-nations-data/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">krebsonsecurity.com/2024/08/na</span><span class="invisible">tionalpublicdata-com-hack-exposes-a-nations-data/</span></a> <a href="https://social.skynetcloud.site/tags/NationalPublicDatabreach" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NationalPublicDatabreach</span></a> <a href="https://social.skynetcloud.site/tags/NationalCriminalDataLLC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NationalCriminalDataLLC</span></a> <a href="https://social.skynetcloud.site/tags/AtlasDataPrivacyCorp" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AtlasDataPrivacyCorp</span></a> <a href="https://social.skynetcloud.site/tags/TrinityEntertainment" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TrinityEntertainment</span></a> <a href="https://social.skynetcloud.site/tags/HaveIBeenPwnedcom" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HaveIBeenPwnedcom</span></a> <a href="https://social.skynetcloud.site/tags/TwistedHistoryLLC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TwistedHistoryLLC</span></a> <a href="https://social.skynetcloud.site/tags/InstantCheckmate" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InstantCheckmate</span></a> <a href="https://social.skynetcloud.site/tags/ALittleSunshine" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ALittleSunshine</span></a> <a href="https://social.skynetcloud.site/tags/recordschecknet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>recordschecknet</span></a> <a href="https://social.skynetcloud.site/tags/SalvatoreVerini" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SalvatoreVerini</span></a> <a href="https://social.skynetcloud.site/tags/TheComingStorm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TheComingStorm</span></a> <a href="https://social.skynetcloud.site/tags/JericoPictures" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>JericoPictures</span></a> <a href="https://social.skynetcloud.site/tags/ShadowgladeLLC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ShadowgladeLLC</span></a> <a href="https://social.skynetcloud.site/tags/PeopleConnect" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PeopleConnect</span></a> <a href="https://social.skynetcloud.site/tags/VXUnderground" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VXUnderground</span></a> <a href="https://social.skynetcloud.site/tags/DataBreaches" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DataBreaches</span></a> <a href="https://social.skynetcloud.site/tags/TruthFinder" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TruthFinder</span></a> <a href="https://social.skynetcloud.site/tags/InfraGard" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfraGard</span></a> <a href="https://social.skynetcloud.site/tags/SalVerini" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SalVerini</span></a> <a href="https://social.skynetcloud.site/tags/TroyHunt" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TroyHunt</span></a> <a href="https://social.skynetcloud.site/tags/USDoD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>USDoD</span></a> <a href="https://social.skynetcloud.site/tags/SXUL" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SXUL</span></a> <a href="https://social.skynetcloud.site/tags/fbi" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>fbi</span></a></p>
Pyrzout :vm:<p>Alleged Boss of ‘Scattered Spider’ Hacking Group Arrested <a href="https://krebsonsecurity.com/2024/06/alleged-boss-of-scattered-spider-hacking-group-arrested/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">krebsonsecurity.com/2024/06/al</span><span class="invisible">leged-boss-of-scattered-spider-hacking-group-arrested/</span></a> <a href="https://social.skynetcloud.site/tags/NoahMichaelUrban" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NoahMichaelUrban</span></a> <a href="https://social.skynetcloud.site/tags/ScatteredSpider" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ScatteredSpider</span></a> <a href="https://social.skynetcloud.site/tags/NeerDoWellNews" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NeerDoWellNews</span></a> <a href="https://social.skynetcloud.site/tags/TylerBuchanan" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TylerBuchanan</span></a> <a href="https://social.skynetcloud.site/tags/VXUnderground" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VXUnderground</span></a> <a href="https://social.skynetcloud.site/tags/DataBreaches" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DataBreaches</span></a> <a href="https://social.skynetcloud.site/tags/SIMSwapping" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SIMSwapping</span></a> <a href="https://social.skynetcloud.site/tags/MurciaToday" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MurciaToday</span></a> <a href="https://social.skynetcloud.site/tags/SIMswapping" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SIMswapping</span></a> <a href="https://social.skynetcloud.site/tags/WebFraud20" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WebFraud20</span></a> <a href="https://social.skynetcloud.site/tags/Mailchimp" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Mailchimp</span></a> <a href="https://social.skynetcloud.site/tags/DoorDash" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DoorDash</span></a> <a href="https://social.skynetcloud.site/tags/lastpass" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>lastpass</span></a> <a href="https://social.skynetcloud.site/tags/0ktapus" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>0ktapus</span></a> <a href="https://social.skynetcloud.site/tags/Caesars" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Caesars</span></a> <a href="https://social.skynetcloud.site/tags/GroupIB" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GroupIB</span></a> <a href="https://social.skynetcloud.site/tags/KingBob" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>KingBob</span></a> <a href="https://social.skynetcloud.site/tags/signal" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>signal</span></a> <a href="https://social.skynetcloud.site/tags/TheCom" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TheCom</span></a> <a href="https://social.skynetcloud.site/tags/Okta" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Okta</span></a> <a href="https://social.skynetcloud.site/tags/Sosa" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Sosa</span></a> <a href="https://social.skynetcloud.site/tags/fbi" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>fbi</span></a> <a href="https://social.skynetcloud.site/tags/MGM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MGM</span></a></p>
Baker Street Forensics<p>If you’re writing YARA rules or doing other kinds of detection engineering, you’ll want to have a test bed that you can run your rules against.&nbsp; This is known as a corpus. For your corpus you’ll want to have both <em>Goodware</em> (known good operating system files), as well as a library of malware files.</p><p>One source to get a lot of malware samples is from <a href="https://vx-underground.org/" rel="nofollow noopener" target="_blank">VX-Underground</a>.&nbsp; What I really appreciate about VX-Underground is that in addition to providing lots of malware samples, they also produce an <a href="https://vx-underground.org/APTs/Yearly%20Archives" rel="nofollow noopener" target="_blank">annual archive</a> of samples and papers. You can download a whole year’s worth of samples and papers, from 2010 to 2023.</p><p><strong>Pandora’s Box</strong></p><p>Just to understand the structure here, I have a USB device called “Pandora.” On the root of the drive is a folder called “APT”, and within that is a “Samples” directory. Inside the samples directory is the .7z download for 2023 from VX-Underground. There’s also a python script… we’ll get to that soon enough.</p><p>The first thing we’ll need to do is unzip the download with <em>the usual password</em>.</p><pre><code>7zz x 2023.7z</code></pre><p>Once the initial extraction is complete you can delete the original 2023.7z archive.</p><p>Within the archive for each year, there is a directory for the sample, with sub-directories of ‘Samples’ and ‘Papers.’ &nbsp;Every one of the samples is also password protected zip file.</p><p>This makes sense from a safety perspective, but it makes it impossible to scan against all the files at once.</p><p><strong>Python to the Rescue</strong></p><p>We can utilize a Python script to recursively go through the contents of our malware folder and unzip all the password protected files, while keeping those files in their original directories.</p><p>You may have noticed in the first screenshot that I have a script called <strong>ExtractSamples.py</strong> in my APT directory. </p><p>We will use this for the recursive password protected extractions.</p><pre><code>Python ExtractSamples.py</code></pre><p>A flurry of code goes by, and you congratulate yourself on you Python prowess. Now if we look again at our contents, we’ve got the extracted sample and the original zip file.&nbsp;</p><p>Let’s get rid of all the zip files as we don’t need them cluttering up the corpus.</p><p>We can start by running a find command to identify all the 7zip files.</p><pre><code>find . -type f -name '*.7z' -print</code></pre><p>After you’ve checked the output and verified the command above is <strong>only grabbing the 7z files you want to delete</strong>, we can update the command to delete the found files.</p><pre><code>find . -type f -name '*.7z' -delete<br></code></pre><p>One more a directory listing to verify:</p><p>Success. All the 7z files are removed and all the sample files are intact.</p><p>GitHub Link: <a href="https://github.com/dwmetz/Toolbox/blob/main/ExtractSamples.py" rel="nofollow noopener" target="_blank">ExtractSamples.py</a></p><p><em>Time to go write some new detections!</em></p><p><a href="https://bakerstreetforensics.com/2024/02/01/growing-your-malware-corpus/" rel="nofollow noopener" target="_blank">https://bakerstreetforensics.com/2024/02/01/growing-your-malware-corpus/</a></p><p><a rel="nofollow noopener" class="hashtag u-tag u-category" href="https://bakerstreetforensics.com/tag/7zip/" target="_blank">#7zip</a> <a rel="nofollow noopener" class="hashtag u-tag u-category" href="https://bakerstreetforensics.com/tag/dfir/" target="_blank">#DFIR</a> <a rel="nofollow noopener" class="hashtag u-tag u-category" href="https://bakerstreetforensics.com/tag/malware/" target="_blank">#Malware</a> <a rel="nofollow noopener" class="hashtag u-tag u-category" href="https://bakerstreetforensics.com/tag/python/" target="_blank">#Python</a> <a rel="nofollow noopener" class="hashtag u-tag u-category" href="https://bakerstreetforensics.com/tag/security/" target="_blank">#security</a> <a rel="nofollow noopener" class="hashtag u-tag u-category" href="https://bakerstreetforensics.com/tag/vx-underground/" target="_blank">#VXUnderground</a> <a rel="nofollow noopener" class="hashtag u-tag u-category" href="https://bakerstreetforensics.com/tag/yara/" target="_blank">#yara</a></p>
gtbarry<p>Ubisoft says it's investigating reports of a new security breach </p><p>Ubisoft is investigating whether it suffered a breach after images of the company's internal software and developer tools were leaked online. </p><p><a href="https://mastodon.social/tags/VXUnderground" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VXUnderground</span></a> <a href="https://mastodon.social/tags/ubisoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ubisoft</span></a> <a href="https://mastodon.social/tags/microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>microsoft</span></a> <a href="https://mastodon.social/tags/sharepoint" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>sharepoint</span></a> <a href="https://mastodon.social/tags/games" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>games</span></a> <a href="https://mastodon.social/tags/gaming" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>gaming</span></a> <a href="https://mastodon.social/tags/databreach" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>databreach</span></a> <a href="https://mastodon.social/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a> <a href="https://mastodon.social/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersecurity</span></a> <a href="https://mastodon.social/tags/hackers" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>hackers</span></a> <a href="https://mastodon.social/tags/hacking" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>hacking</span></a> <a href="https://mastodon.social/tags/hacked" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>hacked</span></a></p><p><a href="https://www.bleepingcomputer.com/news/security/ubisoft-says-its-investigating-reports-of-a-new-security-breach/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/ubisoft-says-its-investigating-reports-of-a-new-security-breach/</span></a></p>
nopcorn<p>Came across this article from last year about VXUG. Learned some new stuff from it. </p><p>How vx-underground is building a hacker’s dream library <a href="https://therecord.media/how-vx-underground-is-building-a-hackers-dream-library" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">therecord.media/how-vx-undergr</span><span class="invisible">ound-is-building-a-hackers-dream-library</span></a></p><p><a href="https://infosec.exchange/tags/malware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>malware</span></a> <a href="https://infosec.exchange/tags/VXUnderground" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VXUnderground</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/hacking" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>hacking</span></a></p>
🛡 H3lium@infosec.exchange/:~# :blinking_cursor:​<p>📣 Exciting News! 📚 VXunderground has just dropped the highly anticipated Black Mass Volume 2 book and the best part? You can download it for FREE! (or support them and buy a physical copy on Amazon for example</p><p>Ever wanted to have a coloring picture of a Ransomware operator or a SOC employee sprinkled in between your Infosec articles? Well here's your chance! </p><p>👉 Get your copy here: <a href="https://samples.vx-underground.org/root/Papers/Other/VXUG%20Zines/2023-09-19%20-%20Black%20Mass%20Volume%20II.pdf" rel="nofollow noopener" target="_blank">Black Mass Volume II PDF</a></p><p>Dive into the world of underground knowledge, hacking, and security with this latest release. It's a treasure trove of insights, research, and information that you won't want to miss. Whether you're a seasoned hacker or just curious about the world of cybersecurity, this book has something for everyone.</p><p>Spread the word and share the love for VXunderground's commitment to open knowledge! <a href="https://infosec.exchange/tags/BlackMassVolume2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BlackMassVolume2</span></a> <a href="https://infosec.exchange/tags/VXunderground" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VXunderground</span></a> <a href="https://infosec.exchange/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Cybersecurity</span></a> <a href="https://infosec.exchange/tags/FreeDownload" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FreeDownload</span></a> 📖💻🔒</p>
Just Another Blue Teamer<p>The next installment of the SentinelOne and <a href="https://ioc.exchange/tags/VXUnderground" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VXUnderground</span></a> blog series features Millie Nym as they demonstrate their unique reverse engineering techniques as they analyze a sample of ArechClient2. Enjoy and Happy Hunting!</p><p>***As usual, for this <a href="https://ioc.exchange/tags/miniCTF" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>miniCTF</span></a>, I am going to leave out a piece of information and it is your job to find it! DM me with the answer or leave a comment!<br>Hint: Check the links in the article!***</p><p>Notable MITRE ATT&amp;CK TTPs:<br>TA0005 - Defense Evasion<br>T1055.? - Process Injection: [fill in this blank]<br>T1562 - Impair Defenses: Disable or Modify Tools<br>T1112 - Modify Registry</p><p>TA0009 - Collection<br>T1005 - Data from Local System</p><p>TA0011 - Command and Control<br>T1102 - Web Service</p><p><a href="https://ioc.exchange/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberSecurity</span></a> <a href="https://ioc.exchange/tags/ITSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ITSecurity</span></a> <a href="https://ioc.exchange/tags/InfoSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfoSec</span></a> <a href="https://ioc.exchange/tags/BlueTeam" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BlueTeam</span></a> <a href="https://ioc.exchange/tags/ThreatIntel" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ThreatIntel</span></a> <a href="https://ioc.exchange/tags/ThreatHunting" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ThreatHunting</span></a> <a href="https://ioc.exchange/tags/ThreatDetection" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ThreatDetection</span></a> <a href="https://ioc.exchange/tags/HappyHunting" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HappyHunting</span></a> <a href="https://ioc.exchange/tags/readoftheday" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>readoftheday</span></a> </p><p>Reverse Engineering Walkthrough | Analyzing A Sample Of Arechclient2<br><a href="https://www.sentinelone.com/blog/reverse-engineering-walkthrough-analyzing-a-sample-of-arechclient2/" rel="nofollow noopener" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">sentinelone.com/blog/reverse-e</span><span class="invisible">ngineering-walkthrough-analyzing-a-sample-of-arechclient2/</span></a></p>
Just Another Blue Teamer<p><a href="https://ioc.exchange/tags/HappyMonday" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HappyMonday</span></a> everyone! I am back from a weeklong "vacation" with an article from the SentinelOne blog but the research was conducted by Pol Thill. There was a challenge thrown down by <a href="https://ioc.exchange/tags/VXUnderground" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VXUnderground</span></a> and SentinelOne looking for research that was conducted but not previously published, which I think is a really interesting concept and needs to happen more often!</p><p>Anyways, here is Pol's research on Neo_Net, the Kingpin of Spanish eCrime! Enjoy and Happy Hunting!</p><p>Link in the comments!</p><p>Notable MITRE ATT&amp;CK TTPs and Behaviors:<br>Mobile Matrix:<br>TA0035 - Collection<br>T1636.004 - Protected User Data: SMS Messages</p><p>TA0037 - Command and Control<br>T1437.001 - Application Layer Protocol: Web Protocols<br>T1481.003 - Web Service: One-Way Communication</p><p><a href="https://ioc.exchange/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberSecurity</span></a> <a href="https://ioc.exchange/tags/ITSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ITSecurity</span></a> <a href="https://ioc.exchange/tags/InfoSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfoSec</span></a> <a href="https://ioc.exchange/tags/BlueTeam" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BlueTeam</span></a> <a href="https://ioc.exchange/tags/ThreatIntel" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ThreatIntel</span></a> <a href="https://ioc.exchange/tags/ThreatHunting" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ThreatHunting</span></a> <a href="https://ioc.exchange/tags/ThreatDetection" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ThreatDetection</span></a> <a href="https://ioc.exchange/tags/HappyHunting" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HappyHunting</span></a> <a href="https://ioc.exchange/tags/readoftheday" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>readoftheday</span></a></p><p>Neo_Net | The Kingpin of Spanish eCrime<br><a href="https://www.sentinelone.com/blog/neo_net-the-kingpin-of-spanish-ecrime/" rel="nofollow noopener" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">sentinelone.com/blog/neo_net-t</span><span class="invisible">he-kingpin-of-spanish-ecrime/</span></a></p>
Tarnkappe.info<p>📬 Lesetipps: LockBit-Ransomware vs. MacOS und tote Vögel als Drohnen<br><a href="https://social.tchncs.de/tags/Lesetipps" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Lesetipps</span></a> <a href="https://social.tchncs.de/tags/ElonMusk" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ElonMusk</span></a> <a href="https://social.tchncs.de/tags/kattascha" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>kattascha</span></a> <a href="https://social.tchncs.de/tags/PentagonLeak" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PentagonLeak</span></a> <a href="https://social.tchncs.de/tags/PiaLamberty" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PiaLamberty</span></a> <a href="https://social.tchncs.de/tags/pompompurin" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>pompompurin</span></a> <a href="https://social.tchncs.de/tags/RichardRoberson" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>RichardRoberson</span></a> <a href="https://social.tchncs.de/tags/TiloJung" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TiloJung</span></a> <a href="https://social.tchncs.de/tags/VolkerWissing" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VolkerWissing</span></a> <a href="https://social.tchncs.de/tags/VXUnderground" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VXUnderground</span></a> <a href="https://tarnkappe.info/lesetipps/lesetipps-lockbit-ransomware-vs-macos-und-tote-voegel-als-drohnen-273053.html" rel="nofollow noopener" target="_blank"><span class="invisible">https://</span><span class="ellipsis">tarnkappe.info/lesetipps/leset</span><span class="invisible">ipps-lockbit-ransomware-vs-macos-und-tote-voegel-als-drohnen-273053.html</span></a></p>
Brett Callow<p><a href="https://infosec.exchange/tags/vxunderground" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>vxunderground</span></a> has met the same fate as <a href="https://infosec.exchange/tags/BreachForums" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BreachForums</span></a> - and about time too. Kudos to the Cybercrime Unit of the canton of Vaud and all the other agencies involved in the action. <a href="https://infosec.exchange/tags/TangoDown" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TangoDown</span></a> </p><p>vx-underground.org</p>
Tarnkappe.info<p>📬 Lesetipps: Und wann klopfen die Hacker auch bei euch an die Tür?<br><a href="https://social.tchncs.de/tags/Anonymous" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Anonymous</span></a> <a href="https://social.tchncs.de/tags/Cyberangriffe" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Cyberangriffe</span></a> <a href="https://social.tchncs.de/tags/DarkCommerce" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DarkCommerce</span></a> <a href="https://social.tchncs.de/tags/Datenschutz" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Datenschutz</span></a> <a href="https://social.tchncs.de/tags/Empfehlungen" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Empfehlungen</span></a> <a href="https://social.tchncs.de/tags/Internet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Internet</span></a> <a href="https://social.tchncs.de/tags/ITSicherheit" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ITSicherheit</span></a> <a href="https://social.tchncs.de/tags/Kurios" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Kurios</span></a> <a href="https://social.tchncs.de/tags/Lesetipps" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Lesetipps</span></a> <a href="https://social.tchncs.de/tags/Linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Linux</span></a> <a href="https://social.tchncs.de/tags/Malware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Malware</span></a> <a href="https://social.tchncs.de/tags/Podcast" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Podcast</span></a> <a href="https://social.tchncs.de/tags/ReverseEngineering" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ReverseEngineering</span></a> <a href="https://social.tchncs.de/tags/Videos" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Videos</span></a> <a href="https://social.tchncs.de/tags/Bildungszwecke" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Bildungszwecke</span></a> <a href="https://social.tchncs.de/tags/Gcam" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Gcam</span></a> <a href="https://social.tchncs.de/tags/GhostSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GhostSec</span></a> <a href="https://social.tchncs.de/tags/HomeGallery" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HomeGallery</span></a> <a href="https://social.tchncs.de/tags/JackRhysider" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>JackRhysider</span></a> <a href="https://social.tchncs.de/tags/MediaGoblin" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MediaGoblin</span></a> <a href="https://social.tchncs.de/tags/novaGallery" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>novaGallery</span></a> <a href="https://social.tchncs.de/tags/OpBalochistan" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpBalochistan</span></a> <a href="https://social.tchncs.de/tags/qTox" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>qTox</span></a> <a href="https://social.tchncs.de/tags/RalfRosanowski" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>RalfRosanowski</span></a> <a href="https://social.tchncs.de/tags/truecrime" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>truecrime</span></a> <a href="https://social.tchncs.de/tags/uTOX" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>uTOX</span></a> <a href="https://social.tchncs.de/tags/VXUnderground" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VXUnderground</span></a> <a href="https://social.tchncs.de/tags/Wyroczen" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Wyroczen</span></a> <a href="https://tarnkappe.info/lesetipps/lesetipps-und-wann-klopfen-die-hacker-auch-bei-euch-an-die-tuer-265998.html" rel="nofollow noopener" target="_blank"><span class="invisible">https://</span><span class="ellipsis">tarnkappe.info/lesetipps/leset</span><span class="invisible">ipps-und-wann-klopfen-die-hacker-auch-bei-euch-an-die-tuer-265998.html</span></a></p>
Tarnkappe.info<p>📬 Activision gehackt: Leak geheimer Call of Duty-Dokumente<br><a href="https://social.tchncs.de/tags/Cyberangriffe" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Cyberangriffe</span></a> <a href="https://social.tchncs.de/tags/Gaming" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Gaming</span></a> <a href="https://social.tchncs.de/tags/ActivisionBlizzard" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ActivisionBlizzard</span></a> <a href="https://social.tchncs.de/tags/Activisiongehackt" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Activisiongehackt</span></a> <a href="https://social.tchncs.de/tags/CallofDuty" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CallofDuty</span></a> <a href="https://social.tchncs.de/tags/PhishingAngriff" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PhishingAngriff</span></a> <a href="https://social.tchncs.de/tags/PhishingAttacke" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PhishingAttacke</span></a> <a href="https://social.tchncs.de/tags/Sicherheitsvorfall" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Sicherheitsvorfall</span></a> <a href="https://social.tchncs.de/tags/VXUnderground" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VXUnderground</span></a> <a href="https://tarnkappe.info/artikel/gaming/activision-gehackt-leak-geheimer-call-of-duty-dokumente-265832.html" rel="nofollow noopener" target="_blank"><span class="invisible">https://</span><span class="ellipsis">tarnkappe.info/artikel/gaming/</span><span class="invisible">activision-gehackt-leak-geheimer-call-of-duty-dokumente-265832.html</span></a></p>
Tyler Durden<p>The one thing I miss on mastodon is vx-underground :-/ <a href="https://social.c3l.lu/tags/vx" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>vx</span></a> <a href="https://social.c3l.lu/tags/virus" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>virus</span></a> <a href="https://social.c3l.lu/tags/vxunderground" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>vxunderground</span></a> <a href="https://social.c3l.lu/tags/itsec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>itsec</span></a> <a href="https://social.c3l.lu/tags/itsecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>itsecurity</span></a></p>