@BushidoTokeni
iAccount based inUnited Kingdom
About this account
- Account based in
- United Kingdom
- Connected via
- United Kingdom App Store
Account-level information from X, not a live location or the device used for a specific post.
Senior Threat Intel Advisor @TeamCymru Co-founder @CuratedIntel Co-author @SANSForensics FOR589 Co-founder @BSidesBournemth #126: REvil @darknetdiaries
🇬🇧
Joined March 2013
- Tweets13K
- Following3.4K
- Followers38.7K
- Likes37K
Pinned Tweet
📝 Looking to get into infrastructure analysis for CTI? I recommend studying the following aspects/topics in-depth:
PDNS
WHOIS Records
BGP Peers
HTTP Titles, Response Headers & ETags
X509 Cert Issuers & Subjects & JA4X
JARM
SSH Host Keys & HASSH
Favicon Hashes
OpenDirs
Related resource by the @CuratedIntel community: github.com/curated-intel/Att…
New Blog 🇬🇧 UK Cybercrime Journal: Manchester Airport Group Breached by FulcrumSec
🔗 blog.bushidotoken.net/2026/0…
Very interesting Blockchain Dead Drop (BDD) for C2 infrastructure TTP shift documented by @chainalysis chainalysis.com/blog/etherhi…
I am very glad to finally share publicly some interesting research I’ve been doing into ransomware infrastructure TTPs. This has been a long-running collaboration with a trusted partner who we can’t name but deeply appreciate their support. Read it here 👇
team-cymru.com/post/ransomwa…
True global internet intelligence 👇
INTEL BRIEF
The fastest way to move a hunt forward is knowing what an IP is before you chase it. Total Insights informational tags do exactly that. They describe the infrastructure and context behind an address so you can filter the noise and spend your time on what is actually huntable. Built by a team of analysts that know this pain intimately.
List of interesting informational context tag categories:
TAG # of IPs
Residential - 172M
VPS - 140M
CGNAT - 89M
Router - 12.3M
SOCKS - 7.6M
CDN - 7.5M
IoT - 5.3M
Proxy - 1.3M
Scanner - 1.25M
Shared-host - 1.06M
Bogon - 300K
The real value is at the model level. Router resolves to 261 device-model tags across 58 vendors, IoT breaks into 56 device types, and ICS into 97 device families. When you can see the exact make and model, both attribution and filtering get sharper and hunts become more efficient (looking at you ORBs 😉).
For threat hunting this is the difference between chasing and clearing. Bogon, sinkhole, honeypot, top-site, and CDN let you drop non-actionable addresses fast. CGNAT and shared-host warn you that one IP maps to many users, so you weight it accordingly. VPS, router, and IoT tell you what you are actually looking at before you spend a cycle on it.
#TotalInsights #ThreatIntel #ThreatHunting #DFIR
team-cymru.com/total-insight…
Team Cymru tracks 1,021,627 IPs tied to IPIDEA 👇
INTEL BRIEF
A January 2026 disruption knocked down IPIDEA's proxy network (excellent work GTIG,Cloudflare,Lumen,Spur). We watched the operators rebuild from near-zero starting in April 2026 and climb back to near-full operation by August 2026.
Team Cymru tracks 1,021,627 IPs tied to IPIDEA today. We also see backconnect/Tier2 controllers for the IPIDEA network that is used to manage the nodes. This backonnect/Tier2 is almost entirely Chinese hyperscale cloud providers. The re-built backconnect layer is nearing it's pre-takedown size, going from 7,400 active tier-2 controllers before the disruption to over 6,713 currently.
Backconnect controllers by country location:
Singapore 6,477
Hong Kong 194
United States 86
China 53
Seychelles 11
Sample backconnect controllers already carrying an open SOCKS proxy in Total Insights:
43.130.39.236 socks + vps
43.135.179.24 socks + vps
170.106.143.236 socks + vps
43.173.74.230 socks + vps
43.173.85.38 socks + vps
Any sufficiently motivated proxy-as-infrastructure provider is likely going to reconstitute after its controllers are seized, often larger than before, on fresh backconnect nodes. Catching and defending means tracking the network infrastructure layer, via a detection engineering process, and tagging nodes in near real-time. It also means inspecting device types that are typically abused by similar proxy networks. Expect this to a be an enduring norm.
#TotalInsights #ThreatIntel #ResidentialProxy
team-cymru.com/total-insight…
New Blog! 🇬🇧 UK Cybercrime Journal: ExfilSquad Emerges
- ExfilSquad’s extortion campaign targets UK public sector orgs, education, and law enforcement
- ExfilSquad's primary attack vector involves exploiting CRM platforms and Microsoft Power Pages
🔗 blog.bushidotoken.net/2026/0…
Many Orgs are still getting rocked by Mobile-focused phishing & social eng. it is much harder to defend against compared to traditional Win/Mac endpoints. No EDR, no Proxy, and no Content Scanning Gateways for SMS, Messaging Apps, and other in-app messages. Tough one to prevent.
Definitely check this BGP Hijack incident out… “a small number of Virtualizor installations received a malicious update package while their traffic was diverted” 👀
The August 2026 Virtualizor Incident in BGPHorizon
bgphorizon.com/blog/virtuali…
#virtualizor #bgp #bgphijack #bgphorizon
You already know the types of groups to use FRP 🇨🇳👇
INTEL DROP
FRP tunnels in our Total Insights detection pipeline. 40,708 FRP-tagged hosts right now, 2,712 of them rated malicious across 216 ASNs, concentrated in China, the US, Hong Kong, and Singapore. FRP (Fast Reverse Proxy) is an open-source reverse-proxy tunneler that crews use to pivot into networks and front their C2.
Coexisting + FRP:
138.124.53.170 proxy:frp + bph
79.137.204.191 proxy:frp + bph + kev-vulnerable
45.8.113.127 proxy:frp + malware-hosting + kev-vulnerable
51.75.31.123 proxy:frp + phishing + open-dir
128.1.211.110 proxy:frp + scanner + brute-force
47.87.80.23 proxy:frp + open-dir
45.145.229.183 proxy:frp + risknet
183.250.89.44 proxy:frp + gen-ai:new-api + gitlab
152.136.59.90 proxy:frp + iot:crestron + ipsec
104.239.66.54 proxy:frp + risknet + kev-vulnerable
213.21.254.149 proxy:frp + bph
185.221.196.112 proxy:frp + bph + kev-vulnerable
138.124.14.123 proxy:frp + bph
Some FRP nodes double as C2 on the same host:
192.210.193.156 proxy:frp + controller:vshell
111.231.59.28 proxy:frp + controller:vshell
117.72.72.254 proxy:frp + controller:supershell
#TotalInsights #ThreatIntel #FRP
team-cymru.com/total-insight…
Suddenly nostalgic for 2021-era malware botnets… the success of #OpEndgame is clear
New Blog! 🇬🇧 UK Cybercrime Journal: ACRO Breach Report
— Between July 2021 and June 2023, the UK Criminal Records Office had 3 separate breaches
— It had an SQLi attack on its Kentico CMS followed by Mimikatz
— 4x Trend Micro AV alerts were ignored
🔗 blog.bushidotoken.net/2026/0…
🚨 Gshell is not one to miss! Start hunting with some IOCs shared below 👇
INTEL DROP
Gshell command-and-control cluster likely targeting Pakistani based orgs. Gshell is a China-aligned C2 framework observed being used against government and financial organizations.
103.112.97.64
103.112.97.163
103.112.97.199
134.122.204.46
134.122.204.86
134.122.204.106
207.56.28.60
207.56.28.82
The hosts group tightly into three back-to-back blocks:
103.112.97.0/24, 3 hosts
134.122.204.0/24, 3 hosts
207.56.28.0/24, 2 hosts
One block runs more than Gshell. 134.122.204.0/24 also hosts CobaltStrike, Plugx, Supershell.
credit Gshell discovery @huntio
#TotalInsights #ThreatIntel #gshell
team-cymru.com/total-insight…
North Korean live reaction to when the $1.5 billion crypto theft hits
Manchester Airport Group told the BBC they refused to pay the ransom. So to all Cybercrime Underground watchers, be on the look out for the data of 8.7 million customers being offered or leaking soon… bbc.co.uk/news/articles/c7v4…
Watch out for those RMMs!
INTEL DROP
Remote-management tools are the access layer for a lot of live intrusions. Right now we're tracking 1,123 malicious IPs running RMM software (AnyDesk, ScreenConnect, MeshCentral, RustDesk) across 307 ASNs, most of it in the US, the Netherlands, and Germany, with India and Russia rounding out the top five.
RMM staging malware:
185.187.84.31 screen-connect + malware-hosting
91.92.240.17 screen-connect + malware-hosting
91.92.34.123 screen-connect + malware-hosting
RMM co-located with C2:
102.165.14.23 anydesk + screen-connect + purerat
108.171.194.80 anydesk + venomrat
117.18.127.179 anydesk + xworm
91.92.42.118 meshcentral + cobaltstrike
RMM with an open directory exposing malware or C2 config:
103.68.109.59 anydesk + open-dir + malware-hosting
129.80.196.225 meshcentral + open-dir + malware-hosting
51.79.134.41 anydesk + open-dir + xworm + malware-config
115.159.33.118 rustdesk + open-dir + cyberstrikeai + proxy:nps
Bulletproof hosting + brute-force:
91.220.163.50 anydesk + bph
149.104.30.78 rustdesk + proxy:frp
68.64.183.125 komari + proxy:frp
210.212.136.3 anydesk + scanner:brute-force
#TotalInsights #ThreatIntel #RMM #C2
team-cymru.com/total-insight…