butterfly effect

Joined February 2024
17 Photos and videos
Pinned Tweet
🚨 New Blog: *Kimsuky: A Gift That Keeps on Giving* 🎁 Explore Kimsuky APT's multi-stage infection chain using LNK files, VBS scripts, and C2 communication. See how this DPRK threat actor evolves. 🔗 somedieyoungzz.github.io/pos… #Kimsuky #APT #Malware #DPRK
2
23
76
7,937
somedieyoungZZ retweeted
New supply chain threat uncovered CloudSEK TRIAD found an npm campaign using crypto-javascri, a typosquatted package impersonating crypto-js. It steals npm/GitHub credentials, hijacks maintainer accounts, and uses Tor-based C2 to stay harder to disrupt. cloudsek.com/blog/inside-a-t…
1
5
13
1,111
somedieyoungZZ retweeted
Our first Blog post is live, Introduction to RustPack 🔥 msecops.de/blog/posts/rustpa… More to follow in the future for sure!
1
15
119
290,601
somedieyoungZZ retweeted
🚨 New Research Alert: Inside the RedSun Windows 0day A closer look at why this vulnerability exists and how Defender’s own logic enables the system compromise. Read more: cloudsek.com/blog/redsun-win… h/t @WeirdQuadratic 🐐 #Windows #RedSun #0Day
8
24
1,795
somedieyoungZZ retweeted
Here's the exploit in action, using the RedSun PoC (note this is demostrated in virtual machines and this is purely for educational purposes, please don't repilcate the exploit on any systems you are not permited to do so)
Windows defender has been compromised. right now there is a public unpatched exploit that gives any app on your windows PC full system admin access. no password. no popup. nothing your antivirus doesnt stop it. your antivirus IS the exploit. windows defender is the attack vector ransomware gangs can use this to encrypt your entire machine and steal every saved password, browser session, and discord token you have. fully patched windows 11. real time protection on thread
20
284
2,399
198,023
somedieyoungZZ retweeted
CloudSEK Triad has published a detailed investigation into the RAMP cybercrime forum, covering its operations and working from 2021 through its seizure by the FBI in January 2026. Read the full report: cloudsek.com/blog/the-rise-a…
3
4
483
somedieyoungZZ retweeted
10
171
3,002
59,536
somedieyoungZZ retweeted
Sergey Mineev was the greatest APT hunter of all time. He sought no glory, he just loved the hunt. And his discoveries repeatedly redefined our collective knowledge of global cyberespionage.
Heartbroken to hear about the passing of @Skvern0. He was one of the best threat hunters in the industry - even APTs were afraid of him. I’m grateful for the time we worked together and for everything I learned from him. Rest in peace.
22
201
30,946
somedieyoungZZ retweeted
🚨Recent MuddyWater APT campaign, linked to Iranian intelligence, exposed by Ctrl-Alt-Intel 😬 - 10 CVEs used - Custom-developed C2s - EtherHiding malware - Sensitive data stolen ctrlaltintel.com/threat re… Super fun collab-ing with @ice_wzl_cyber to get this published 🔥

7
68
207
44,419
somedieyoungZZ retweeted
Excited to share my latest research on APT37 (aka ScarCruft) and their evolving campaign targeting so-called "isolated" networks through a carefully orchestrated multi-stage infection chain. Key findings: ▶️Ruby-based loader: APT37 is deploying full Ruby runtimes with trojanized script to blend execution within legitimate environments. ▶️USB dead-drop technique: A refined removable media workflow bridges air-gapped segments, leveraging hidden directories to stage tasking and exfiltrate data. ▶️Cloud C2 evolution: The group has expanded its cloud abuse playbook, incorporating Zoho WorkDrive as an operational command-and-control channel. In this research, I detail the full intrusion lifecycle from the initial LNK lure to the deployment of the surveillance backdoors with technical breakdowns. Blog: zscaler.com/blogs/security-r…
2
33
133
9,517
somedieyoungZZ retweeted
Chinese SEO's are apparently also scared of "Silver Fox", which is supposed to be a Chinese APT: 防止银狐等病毒群发诈骗领导和同事 ( "Prevent silver fox and other viruses from sending out mass fraud to defraud leaders and colleagues" ).
3
10
29
5,578
somedieyoungZZ retweeted
⚠️⚠️RAMP FORUM SEIZED !!!⚠️⚠️
7
25
182
28,442
somedieyoungZZ retweeted
A cybersecurity beginner trying to choose a career path
45
116
1,040
29,574
somedieyoungZZ retweeted
Jan 19
The average “cyber threat intel” blogger
8
28
233
11,267
somedieyoungZZ retweeted
[1/3] I retro hunted and identified more relevant samples on VT: - e7b2cc236af9edbe44307d293a7d7fcbb199a286f7eec864f363fcb725c7ef70 -4b795cf2352971f470db2e451ae62dc8c859ed7c4148be48c66a723062fed7a8 -4e1873f43c7c72625e627faa349e454ab81c15fc36d9c7dec1a422b4042b9407
Threat Alert: #CharmingKitten — LNK-Based Loader Campaign with GitLab Payload Lure Filename: Bang_Tinh_Thue_2025.xlsx.lnk Payload Download: gitlab[.]com/zaahen/Zaahen/-/raw/main/i[.]zip ThreatBook Intelligence: na2.hubs.ly/H02-yBl0 [1/3]
2
1
2
398
somedieyoungZZ retweeted
Suspected APT(?) targets Portuguese speaking individuals at Macao 🇲🇴 abuses DLL Sideloading but forgets to deliver loader DLL, ends up pasting the shellcode alone with decoy, idk? 😂🤷‍♂️
1
10
53
5,256