@ffforward

Threat Researcher @proofpoint | @Cryptolaemus1

Joined May 2010
So I have started a new job this week, as a Threat Researcher for @proofpoint. Can you imagine working with such an awesome team that finds and shares stuff like this? 🙌👏🥳
32
10
2
239
Found some IOCs here too: github.com/rtkwlf/wolf-tools… Something's off, second set of domains (but same actor) is used against RU and BY. Also odd w. english panel imo. (won't link, unprotected and has live IP but easy to figure out). Moving to EtherHiding for the injects too.
1/4 🇺🇦 @500mk500 @_CERT_UA An ongoing campaign compromised multiple Ukrainian websites to display a fake Cloudflare verification ClickFix lure:
3
1
10
1,996
No, #Trickbot is NOT back. What Fortinet forgot to mention is that the samples they analyzed are known Anchor DNS from 2020. I'm not even kidding. Better read from back then: netscout.com/blog/asert/drop…
🚨 TrickBot is back with a stealthier command and control method. The new variant replaces traditional HTTP communications with DNS tunneling, making malicious traffic harder to detect on Windows. Listen/Read: hackread.com/new-trickbot-va… #CyberSecurity #Malware #TrickBot #Windows
19
1
37
10,013
So for those interested, the "scam" was an #ErrTraffic affil that got their inject on the site. It served NetSupport RAT to Win users and another (possibly broken) payload to mac users. If you did follow any of the fake #ClickFix captcha your computer might be infected. >
We identified and resolved a security incident on our site earlier today. A compromised account was exploited to inject a malicious script, briefly exposing users to scam content. The site was taken offline immediately, the script removed, and the account secured. We're back up. If you notice anything unusual, reach out.
1
6
11
3,018
ErrTraffic C2 cdnpro-987[.]xyz PS Payload domain cdnportal-us[.]xyz (dynamic PowerShell command and URI path) PowerShell downloads a 16MB encrypted 7z file, > EXE. The EXE will do profiling (including refresh rate) > #NetSupportRAT and run it. NetSupport C2 178[.]16[.]55[.]191.
1
2
7
1,112
Tommy M (TheAnalyst) retweeted
Proofpoint threat researchers identified a new malware-as-a-service named #TrustConnect. Notably, it masquerades as a legitimate remote monitoring and management tool, marking an evolution in how attackers weaponize trust around enterprise tooling. brnw.ch/21x05Vh
1
8
2
24
10,294
Tommy M (TheAnalyst) retweeted
Thanks to the proofpoint team for highlighting "TrustConnect Software PTY LTD". The actor got the cert hoping to look like a legitimate RMM—but in collaboration with Proofpoint—we didn't let them maintain the illusion. See Proofpoint's blog for all the details.
Would you run AdobeReader.exe from a days-old company called "TrustConnect Software PTY LTD" just because they managed to purchase an Extended Validation certificate? New blog out together with @proofpoint @threatinsight proofpoint.com/us/blog/threa…
2
12
27
5,479
Would you run AdobeReader.exe from a days-old company called "TrustConnect Software PTY LTD" just because they managed to purchase an Extended Validation certificate? New blog out together with @proofpoint @threatinsight proofpoint.com/us/blog/threa…
12
2
59
21,405
Tommy M (TheAnalyst) retweeted
As the security landscape evolves and expands, Proofpoint observed many threat actors disappear from email threat data in 2025. But TA584 maintained operational consistency, w/ recent shifts demonstrating its attempt to infect a broader range of targets. brnw.ch/21wZsWU
1
5
9
2,100
Tommy M (TheAnalyst) retweeted
BTW looked at this thing back in September that likely is related: virustotal.com/gui/domain/fe… which then goes back to at least January last year.
1
4
1
1,331
Tommy M (TheAnalyst) retweeted
Nice writeup, but Smokest might not be a good name, its likely just a campaign indicator. Example virustotal.com/gui/file/0bd1… Fake OBS > Donut > Amadey > Various MSI > PowerShell that I have seen lead to either this or CastleRAT via Python loader, Smokest120[.]zip.
1
3
2
11
20,470
Tommy M (TheAnalyst) retweeted
Proofpoint is proud to have assisted law enforcement in the #OperationEndgame investigation that led to the Nov. 13, 2025 disruption of #Rhadamanthys and #VenomRAT—#malware used by multiple cybercriminals. Rhadamanthys: brnw.ch/21wXsCc VenomRAT: brnw.ch/21wXsCd
1
13
2
23
4,106
Tommy M (TheAnalyst) retweeted
Since 14 Oct., we’ve tracked a high volume XWorm campaign targeting Germany. The activity is attributed to TA584, a sophisticated #cybercrime group tracked since 2020. Messages are sent from hundreds of compromised sender accounts impersonating ELSTER and contain malicious URLs.
1
8
1
11
3,113
Tommy M (TheAnalyst) retweeted
Threat actors continue to abuse GitHub to deliver malware, this time: #LummaStealer. We identified GitHub notification emails that kick off the attack chain. Messages are sent when the threat actor, using an actor-controlled account, comments on existing GitHub issues. 🧵
1
15
50
7,117
Tommy M (TheAnalyst) retweeted
The notifications contain shortened URLs that will lead to an actor-controlled website. The website will perform filtering functions, and if those checks are passed, the visitor will be redirected to a website that presents a fake GitHub-branded CAPTCHA instructing users to verify they are human.
3
5
9
2,809
Tommy M (TheAnalyst) retweeted
We identified GitHub notification emails that kick off the attack chain. The emails are likely generated by the threat actor creating an issue in an actor-controlled repository with a fake security warning, and then tagging legitimate accounts who receive notifications that they have been tagged, with the text from the issue.
1
4
9
2,714
Tommy M (TheAnalyst) retweeted
Proofpoint @threatinsight identified a unique attack chain leveraging GitHub notifications to deliver #Rhadamanthys. We first spotted this post by @anyrun_app about ClickFix delivering Rhadamanthys and began investigating. 🔍
🚨 How #Rhadamanthys Stealer Slips Past Defenses using ClickFix ⚠️ Rhadamanthys is now delivered via ClickFix, combining technical methods and social engineering to bypass automated security solutions, making detection and response especially challenging. 👾 While earlier ClickFix campaigns mainly deployed #NetSupport RAT or #AsyncRAT, this C++ infostealer ranks in the upper tier for advanced evasion techniques and extensive data theft capabilities. #ANYRUN Sandbox lets SOC teams observe and execute complex chains, revealing evasive behavior and providing intelligence that can be directly applied to detection rules, playbooks, and proactive hunting. 🔗 Execution Chain: ClickFix ➡️ msiexec ➡️ exe-file ➡️ infected system file ➡️ PNG-stego payload In a recent campaign, the phishing domain initiates a ClickFix flow (#MITRE T1566), prompting the user to execute a malicious MSI payload hosted on a remote server. 🥷 The installer is silently executed in memory (#MITRE T1218.007), deploying a stealer component into a disguised software directory under the user profile. The dropped binary performs anti-VM checks (T1497.001) to avoid analysis. In later stages, a compromised system file is used to initiate a TLS connection directly to an IP address, bypassing DNS monitoring. 📌 For encryption, attackers use self-signed TLS certificates with mismatched fields (e.g., Issuer or Subject), creating distinctive indicators for threat hunting and expanding an organization’s visibility into its threat landscape. 🖼️ The C2 delivers an obfuscated PNG containing additional payloads via steganography (T1027.003), extending dwell time and complicating detection. 🎯 See execution on a live system and download actionable report: app.any.run/tasks/a101654d-7… 🔍 Use these #ANYRUN TI Lookup search queries to track similar campaigns and enrich #IOCs with live attack data from threat investigations across 15K SOCs: intelligence.any.run/analysi… intelligence.any.run/analysi… intelligence.any.run/analysi… intelligence.any.run/analysi… 👾 IOCs: 84.200[.]80.8 179.43[.]141.35 194.87[.]29.253 flaxergaurds[.]com temopix[.]com zerontwoposh[.]live loanauto[.]cloud wetotal[.]net Find more indicators in the comments 💬 Protect critical assets with faster, deeper visibility into complex threats using #ANYRUN 🚀 #ExploreWithANYRUN
4
26
1
77
11,590
Tommy M (TheAnalyst) retweeted
New e-crime insights: TA4557, known for distributing More_eggs malware, notably expanded to an int'l audience in recent campaigns. Per our data, the recruiter-focused TA was seen targeting orgs in France, England & Ireland, in addition to typical North America-targeted threats.
1
25
2
52
33,116
Tommy M (TheAnalyst) retweeted
Proofpoint also recently observed this activity delivering #GootLoader. Google Ads for a fake document creation app (lawliner[.]com) led to a malicious document creation website, on which users are directed to enter their email address.
1
5
53
8,499