@malbeaconi
iAccount based inUnited Kingdom
About this account
- Account based in
- United Kingdom
- Connected via
- United Kingdom Android App
Account-level information from X, not a live location or the device used for a specific post.
Threat intelligence company, illuminating adversaries since 2017.
Joined August 2021
- Tweets35
- Following9
- Followers319
- Likes29
Pinned Tweet
New Op Report: a live DPRK linked operator ran a full "PolinRider" supply chain intrusion inside it. Package lure → JS C2 → Python stealer → persistence disguised as a .NET service.
Not a signature feed. The operator, captured live.
🩸 KongTuke ClickFix → an EtherRAT that reads its C2 off the Ethereum blockchain. No registrar, no takedown.
Then hands-on-keyboard to SystemBC. 12 days, captured live w/ full TLS inspection.
Timeline, ET sigs, IOCs
🔗 blog.deception.pro/blog/kong…
Op Report:
blog.deception.pro/blog/hok-…
New Op Report with @proofpoint PackClient, a new C2 framework from Chinese speaking actor TA4922, detonated in a live DeceptionPro honeynet.
The RAT was just the doorman. 4.5 hours in, the operator enrolled the victim into an attacker owned ManageEngine Endpoint Central server.
Full timeline, IOCs, and defender takeaways:
blog.deception.pro/blog/new-…
Companion research from @proofpoint:
proofpoint.com/us/blog/threa…
New Op Report: an operator took the bait on one of our honeynets and ran the whole chain.
Phishing lure to batch script to silent ScreenConnect install, hands-on-keyboard then XLoader / FormBook.
Interactive RMM + automated stealer in one op. Not a pairing we'd seen before.
Full kill chain + IoCs:
blog.deception.pro/blog/pdf-…
MalBeacon retweeted
#XWorm #AdaptixC2 #ScreenConnect
I have been working with @malbeacon and the deception.pro platform.
Here's a write up of a recent deception operation👇
blog.deception.pro/blog/xwor…
MalBeacon retweeted
Proofpoint baited a cargo/transport industry threat actor into performing its activities in a decoy environment operated by Deception.Pro for 30+ days.
The result: rare, visibility into post‑compromise operations, tooling, and decision‑making. proofpoint.com/us/blog/threa…
New @Proofpoint blog: cargo theft actor spent 30 days inside DeceptionPro environment revealing:
* 4 RMM tools
* Malicious code signing-as-a-service
* 13+ PowerShell scripts, and bank access.
* HoK activity whole way.
This is real adversary telemetry.
Link in thread.
🚨 Trojanized CPU-Z → STXRAT → PureLogs Stealer → PureHVNC → 54hrs of exfil through a hidden QEMU VM.
We caught everything after.
First documented full post-exploitation chain for this campaign. IOCs & hunting artifacts link in thread
#ThreatIntel #DFIR #Malware
ClickFix isn’t “just a trick”—it’s an on-ramp to hands-on-keyboard ops.
We mapped EDR telemetry to a timeline tied to Velvet Tempest + activity consistent w/ Termite ransomware tradecraft. IOCs + defender takeaways inside.
link in thread..
check out our deception.pro operation report:
blog.deception.pro/blog/clic…
Introducing: What is this stealer?
A new repository that allows you to identify Stealer malware by the system information text file format commonly included in stealer malware exfiltration. Yara Rules included!
Check it out and contribute!
github.com/MalBeacon/what-is…
Adversary Illuminated - Operating #StealC
C2: 176.124.198[.]17
Location: Frankfurt am Main, DE
ASN: AS210644