@21code_talker34i
iAccount based inJapan!
About this account
- Account based in
- Japan
- Connected via
- Japan Android App
! X says this location may be affected by a proxy or VPN.
Account-level information from X, not a live location or the device used for a specific post.
💻️勉強中🖊️📖 AI🧠🤖,Cybersecurity🖥️🔑
🇯🇵
Joined April 2025
- Tweets407
- Following174
- Followers57
- Likes850
コード retweeted
Mentioned 'ssce5532.dll' as a #PlugX related sample uploaded @abuse_ch
bazaar.abuse.ch/sample/1279f…
🚨 Mustang Panda Uses OIC Invitation to Deliver PlugX
The infection begins with OIC_Invitation_General_Official.lnk, which launches PowerShell to download an archive, extract its contents, and execute GRrte.exe. 📦
🎭 The malware displays an OIC-themed PDF decoy in Adobe Acrobat while a Jarte-derived executable is abused to load the attacker-controlled ssce5532.dll through DLL side-loading.
🔍 The side-loaded DLL searches the local payload set and works with irun.dat — an XOR-obfuscated payload that decrypts with key 0x72, exposing an embedded PE image associated with the final PlugX stage.
⚙️ The malware installs its operational components under C:\Users\Public\JartePortable\ and establishes persistence through:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\JartePortable
🌐 The persisted Jarte.exe communicates over TCP/443 with infrastructure associated with castanaksa[.]com, providing capabilities including remote execution, file management, process control, host discovery, registry manipulation, and network communications.
🎯 The OIC-themed lure may indicate an attempt to attract recipients interested in Organization of Islamic Cooperation-related affairs, although the analyzed sample alone does not establish the exact victim profile.
🔎 Full analysis:
buff.ly/xZo9K7f
#MustangPanda #PlugX #Malware #ThreatIntel #CyberSecurity #APT #DFIR
コード retweeted
AIによる政府システムのハッキング、米オープンAIのエージェントで初めて検知 豪
cnn.co.jp/tech/35252896.html
いつもの
2026年8月のサイバーセキュリティレポートを発行しました。
・米政府、民間企業による対サイバー犯罪攻撃制度を創設へ
・ロシア系APTによる公共Wi-Fi悪用攻撃「CaptiveCrunch」
・中国系ルーターのバックドア事案が示した通信機器リスク
jp.security.ntt/insights_res…
#CSR #CyberSecurityReport #CyberSecurity #NTTSecurity
Check Pointによると、NoName057(16)は、2026年8月24日、日本の組織に対するDDoSキャンペーン「#OpJapan」を発表した
コード retweeted
Infrastructure linked to ShadowPad has been observed using TLS certificates impersonating well-known companies for years.
79.133.56[.]90, identified as a ShadowPad fallback C&C server in @proofpoint 's recent BlueMoon research revealed a self-signed certificate with an issuer and subject common name of "Google LLC."
Pivoting on this name and the JA4x fingerprint (2bab15409345_2bab15409345_5318375af521) returned 8 IPs, some dating back to late 2024.
The most recent servers returned from the query:
64.118.130[.]140 (AS138997)
- qnap-connect[.]com
- requests[.]it[.]com
223.26.61[.]236 (AS152194)
- dns.asusrouterapi[.]com
- dns.microsoftstoreapi[.]com
31.192.107[.]162 (AS50867)
- work.officialm[.]com
157.20.182[.]150 (AS152485)
64.7.199[.]26 (AS399629)
GPT-6 Astra is state-of-the-art on FrontierMath Tier 4, ARC-AGI 3, and TerminalBench-4.0.
GPT‑6 Astra is also a major advance for scientific discovery, with state-of-the-art performance on Terminal-Bench Science 0.1 and HealthBench Pro.
コード retweeted
日本語ばらまきマルウェアメールの接到を観測しています。『観測数多めです』
件名 : 【全社通知】給与改定および人事異動について
件名 : 【ご挨拶】製品の直接仕入れ・お取引検討に関するご連絡/社名
など。。。
Sample : tria.ge/260902-brmglsej3w/be…
C2 : 204.194.50[.]231
#valleyRAT
コード retweeted
We identified multiple LNK samples showing strong technical and thematic overlap with recent #Kimsuky activity described by ENKI WhiteHat.
The campaign targeted South Korean and Japanese victims through phishing emails delivering OneDrive-hosted ZIP archives containing malicious LNK files.
The identified LNK samples use suspicious command-line execution, embedded/script-like content, URL-based payload retrieval, and in several cases unusually large LNK files.
Further pivoting uncovered multiple samples matching the THOR/Valhalla rule:
SUSP_LNK_SuspiciousCommands_Jan23_3
The overlap is particularly interesting because the reported Kimsuky chain uses a malicious LNK to execute PowerShell and curl, download logo.png as bot.vbe into %APPDATA%, and execute the VBScript.
The broader campaign then establishes persistence through a scheduled task and deploys additional PowerShell-based capabilities for system discovery, Thunderbird/Outlook email collection, keylogging, and installation of legitimate remote-access tools including Chrome Remote Desktop and AnyDesk.
Several of the samples we identified also use Japanese/Korean-themed filenames and exhibit LNK characteristics including url-pattern, long-command-line-arguments, large-file, high-entropy, and executes-dropped-file.
Valhalla / THOR Rules:
SUSP_LNK_SuspiciousCommands_Jan23_3
valhalla.nextron-systems.com…
SUSP_LNK_Dec24
valhalla.nextron-systems.com…
SUSP_LNK_Curl_Download_Jul22_2
valhalla.nextron-systems.com…
SUSP_LNK_Big_Link_File
valhalla.nextron-systems.com…
SUSP_Dir_Ref_in_File_AppData
valhalla.nextron-systems.com…
Report:
enki.co.kr/en/media-center/b…
Samples:
6e6addf3e7287cf160054ef4647f8c67754f3cdc6efbdf21f117cb98c4c95534
49000d685f7c2ae1ddd5d40ca754562318e49c3a2534540951490f22756a3227
44dc1939dcaea681f5c39ed6f5f81a80ca5f59e72be7f938ac3afe5adb484042
018c31af135a0bc5e068df26d866440b28164aa4a659ea7df47bcbaab4a898cd
864ed6df1ba1b615f2db460666e2aee72a025754f5d78be3d83ec8e3c41d4a09
169586b6eb36b17520ef5afd206da86c4de89eb01d6294ba9631414271ba752f
コード retweeted
ValleyRAT is a signed adware-backed backdoor that uses DLL sideloading, disables defenses, and loads encrypted payloads to exfiltrate keystrokes, screenshots, and system data, with Silver Fox likely behind it. securelist.com/valleyrat-bac…
コード retweeted
アリババのLLM「Qwen」利用数はGoogleの5倍 中国AIとどう生きるか
nikkei.com/article/DGXZQOUC2…
コード retweeted
We asked an unreleased research version of Claude to take a stab at the Riemann hypothesis.
It didn’t solve it, but it did make strides on a related problem: it increased the lower bound for the fraction of zeros of the Riemann zeta function that satisfy the hypothesis from 41.6% to 67.2%.
anthropic.com/research/riema…
【Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia】
We identified several Kimsuky spear phishing campaigns against South Korean and Japanese targets in the first half of 2026.
enki.co.kr/en/media-center/b…
IoC(IP)
・103.77.242[.]187
→VPSMMO COMPANY LIMITED
・160.187.147[.]119
→INTERDIGI JOINT STOCK COMPANY
・84.247.145[.]65
→Contabo Asia Private Limited
・210.183.177[.]217
→Korea Telecom
・103.249.117[.]183
→FUTE JOINT STOCK COMPANY
コード retweeted
The ENKI WhiteHat Threat Research Team has identified a number of recent Kimsuky spear-phishing cases against South Korean and Japanese targets. The threat actor spread LNK malware through phishing emails carrying OneDrive share links. enki.co.kr/en/media-center/b…
Cisco Talos
Thursday, August 20, 2026 06:00
UAT-10147
IoC
・139[.]180[.]197[.]150
・18[.]140[.]163[.]186