Rural cybersecurity practitioner and seasoned brewer. Opinions are my own, I work @HarfangLab (former GREAT, CISO and FR Gov).

Joined February 2020
2 Photos and videos
2026 starts with abduction🥷, massive protests✊ and intentions to dispose🧊, on top of tensions wars🪖 we got out of 2025 with - cyber ppl are humbly reminded of the quite minor role cyber threats💾play in global risks and changes.
1
2
89
Yet they do. In 2026 we expect a new lot of unwanted - sometimes avoidable - developments in cyberspace. After a full review of last year's predictions, our HarfangLab 2026 Threatscape report anticipates 9 trends and threats 🔦. harfanglab.io/insidethelab/2…
1
94
Likely state-sponsored TA still targeting orgs with WhatsApp🤳 mail 📩 phishing in 🇪🇺 in December. Goal is to get access to the MS account of high value targets. TA is particularly interested in people or organisations that run activities in 🇺🇦
1
1
2
509
Up to now we identified tgts in NGOs and think-tanks. In december, threat actor notably leveraged an online profile using "Janis Cerny" name, who pretends to be a diplomat working with the EU. Mail is janiscerny[@]seznam[.]cz, and WhatsApp profile/number is [ 42]0 735 596 5[65]
1
2
188
Mails can contain invitation to online meeting (ie MS Teams), but link is replaced to trick the user into signing-in (using MS device code flow which requires a manually entered and TA-generated code). Similar campaigns and TTPS previously documentd by Volexity and Elastic.
2
199
Late summer our stuff stopped an infection chain involving a driver, a previously undocumented malicious IIS module, and ASP .NET viewstate abuse.
1
3
8
4,385
All tools speak CN, operators leveraged a CN RMM service, domains are registered in CN and some infra is at Alibaba Cloud - it's likely way more CN-language and specifics than an actual CN operator would need...
1
1
356
Anyway, we wanted to tell a bit later, but we had to rush it now, as fellows did publish about the same toolset today (as "TOLLBOOTH"). We're fewer guys but we may still have found a bit more. IOCs & Yaras: harfanglab.io/insidethelab/r…
5
15
3,150
Documents 📃 about alleged IRGC 🇮🇷cyber ops are being disclosed since last week (#KittenBusters). 2nd batch of data includes a reference to our work @HarfangLab: "see reports on publicly available tools (such as BellaCiao and CYCLOPS) – these are malware tools used"
1
5
4
2,417
"ea3e059ca58eec16a98691bcae372170d83b97c0_Shell failed[.]txt" contains WebShell filenames which match those dropped by some BellaCiao samples. Several IPs and domains that are listed as "targets" in Episodes 1 and 2 indeed match targets of BellaCiao malware that I know of.
1
1
189
Because of simplicity of associated exploitation and tools, several third parties could have hijacked and/or mimicked past or recent BellaCiao/CYCLOPS-related activity and infrastructure... but it starts to quacks quite like a duck 🦆 to me. harfanglab.io/insidethelab/c…
2
197
We @aridjourney @ArielJT at HarfangLab had a look at archives containing weaponized XLS spreadsheets dropping C# and C downloaders, likely intended for targets in Ukraine and Poland
1
6
11
4,635
We found striking similarities with previously reported activity from UNC1151, sometimes referred to as UAC-0057, FrostyNeighbor or Ghostwriter
1
1
612