@malbeacon

Threat intelligence company, illuminating adversaries since 2017.

Joined August 2021
New Op Report: a live DPRK linked operator ran a full "PolinRider" supply chain intrusion inside it. Package lure → JS C2 → Python stealer → persistence disguised as a .NET service. Not a signature feed. The operator, captured live.
1
4
7
1,066
🩸 KongTuke ClickFix → an EtherRAT that reads its C2 off the Ethereum blockchain. No registrar, no takedown. Then hands-on-keyboard to SystemBC. 12 days, captured live w/ full TLS inspection.
1
4
12
754
New Op Report with @proofpoint PackClient, a new C2 framework from Chinese speaking actor TA4922, detonated in a live DeceptionPro honeynet. The RAT was just the doorman. 4.5 hours in, the operator enrolled the victim into an attacker owned ManageEngine Endpoint Central server.
1
1
2
233
New Op Report: an operator took the bait on one of our honeynets and ran the whole chain. Phishing lure to batch script to silent ScreenConnect install, hands-on-keyboard then XLoader / FormBook. Interactive RMM + automated stealer in one op. Not a pairing we'd seen before.
1
4
8
830
Mustang Panda walked into two DeceptionPro environments and stayed for days. IBM X-Force wrote it all up: a brand new hidden VNC backdoor (Havencode), Toneshell v10 over WebSockets, a full exfil playbook, and typos in the shell proving a human was typing.
1
9
2
31
5,000
MalBeacon retweeted
#XWorm #AdaptixC2 #ScreenConnect I have been working with @malbeacon and the deception.pro platform. Here's a write up of a recent deception operation👇 blog.deception.pro/blog/xwor…
1
9
20
2,999
Proofpoint baited a cargo/transport industry threat actor into performing its activities in a decoy environment operated by Deception.Pro for 30+ days. The result: rare, visibility into post‑compromise operations, tooling, and decision‑making. proofpoint.com/us/blog/threa…
1
9
3
31
9,613
New @Proofpoint blog: cargo theft actor spent 30 days inside DeceptionPro environment revealing: * 4 RMM tools * Malicious code signing-as-a-service * 13+ PowerShell scripts, and bank access. * HoK activity whole way. This is real adversary telemetry. Link in thread.
1
3
21
1,749
ClickFix isn’t “just a trick”—it’s an on-ramp to hands-on-keyboard ops. We mapped EDR telemetry to a timeline tied to Velvet Tempest + activity consistent w/ Termite ransomware tradecraft. IOCs + defender takeaways inside. link in thread..
1
1
206
Introducing: What is this stealer? A new repository that allows you to identify Stealer malware by the system information text file format commonly included in stealer malware exfiltration. Yara Rules included! Check it out and contribute! github.com/MalBeacon/what-is…
2
10
1,673
Adversary Illuminated - Operating #StealC C2: 176.124.198[.]17 Location: Frankfurt am Main, DE ASN: AS210644
1
328