Threat Researcher at @Huntio | DM me for Collaboration on Threat Intel & Hunting ๐Ÿค| All Views are my Ownโš ๏ธ

Joined November 2024
245 Photos and videos
Pinned Tweet
8 Sep 2025
The Attack Capture from @Huntio tracked #APT #Lazarus on an #open #directory. Further, @virustotal analysis shows another parent "update93m" for one of unzipped file drivfixer[.]sh. New C2: avalabs-digital[.]store ~ 10 days ago @500mk500 @MichalKoczwara @malwrhunterteam
4
19
87
21,634
Demon retweeted
#APT36 #TransparentTribe PPT for Breifing at HQ Norther Command(ZIP) bd260bf220b310ebdd9ab0b50114f627 #Crimson #RAT c6409e078bad9094ab4b26dad5219f6c /excel/excel.bat /excel/office.bat PPT for Breifing at HQ Norther Command.pptx.lnk C2: 155.117.45.44 @500mk500 @PrakkiSathwik
3
11
34
2,217
#APT #Sidewinder targets #SriLankan #Navy 5th sightings for "mailsserver-lk[.]com" - Another Webpage tracked by @Huntio URL: sdgf9af72f31706769d32bf1ff66cdec1d1gkj5jg95jg5k0hkg95kg0tk[.]pages[.]dev Ref: x.com/volrant136/status/1988โ€ฆ @500mk500 @MichalKoczwara @malwrhunterteam
12 Nov 2025
#APT #Sidewinder targets #SriLankan #Navy 4th sightings for "mailsserver-lk[.]com" - Another Webpage tracked by @Huntio URL: https://copeparliament[.]github[.]io/mails.navy.lk/ Ref: x.com/volrant136/status/1981โ€ฆ @500mk500 @MichalKoczwara @malwrhunterteam
3
8
22
1,740
Demon retweeted
#APT36 #TransparentTribe DG NIA ppt regarding ongoing issues.ppam b90da532d80f3acc6c2c13f4c3d87cb8 https[:]//nianew.xyz/ @Namecheap download.php?file=mod.pptx download.php?file=PowerToys.zip (Password@2026) #Golang #PowerToys.exe @PrakkiSathwik @500mk500
#APT36 #TransparentTribe #APT #Phishing DD_MCO Quota Available.xlam 7a7a99eee3855c2fe0fe0f5c20d0490c kickstartercareer[.]website @Namecheap @500mk500 @smica83 /mod.pptx /careers/download.php?file=1ad8693349b53dd62bc9fe9509bfc8f7_1772974194.zip (Password@2025)
2
6
14
1,304
๐Ÿšจ ALERT: A fake #Bangladesh Election Commission #NID portal is actively #scamming citizens. โš ๏ธnid-bangladesh-cms-portal-registrat-theta[.]vercel[.]app โ€ผ๏ธadmin / admin123 | 4 spaces for security code cc: @500mk500 @MichalKoczwara @malwrhunterteam
1
4
8
919
๐Ÿ’ธ THE MONEY TRAIL: 1. submitRechargeRequest() collects real payments to Nagad number 01981597776 2. admApproveRecharge() manually credits fake balance after real money is received 3. Passwords stored in plaintext 4. Payment screenshots stored in Firebase โ€” fully exposed
1
2
2
338
2
184
๐Ÿšจ #ThreatHunting Alert | Using @Huntio Spotted a 20 phishing page impersonating #Microsoft #Teams transcripts, luring victims into downloading #ScreenConnect (RMM abuse). IoCs: pastebin.com/Jxgs2dv6 cc: @500mk500 @MichalKoczwara @malwrhunterteam
2
10
53
4,332
Page title: "Download Transcript | Microsoft Teams" #Flow: Honeypot hidden input field to detect bots 2-second dwell time check before button activates Mobile device blocker โ€” desktop victims only Fast clickers redirected to facebook[.]com (decoy)
1
2
3
817
Demon retweeted
Observed activity associated with Donot Group (APT). Lure document: โ€ข INVITATION FOR THE EID-UL-ADHA IFTAAR RECEPTION .xltm โ€ข 54715f6d79797cadc8ccbcd8e8bd22d0 Observed payload: โ€ข 2b420e55cacf0a6cdb04f13e6c16c79b Observed C2 infrastructure: โ€ข greezupdto[.]info โ€ข shadoworkz[.]info #Donot #DonotGroup #APT #IOC
1
6
25
3,121
Demon retweeted
May 27
๐Ÿšจ ๐ŸŒ New report: Exposing a Global Smishing Operation Across 19 Countries We started hunting after Romania's official payment portal posted a public phishing warning. Here's what we found: - 1,628 malicious URLs across 33 backend IPs and three continents - Targets include government portals, road police, postal services, and telecoms in 19 countries - One 128-character metadata hash present in every single phishing page ๐Ÿ‘‰ Full report: hunt.io/blog/massive-smishinโ€ฆ
2
7
11
1,701
Demon retweeted
May 21
๐Ÿ‡ธ๐Ÿ‡ฆ ๐Ÿ‡ฎ๐Ÿ‡ท ๐—ก๐—ฒ๐˜„ ๐— ๐—ถ๐—ฑ๐—ฑ๐—น๐—ฒ ๐—˜๐—ฎ๐˜€๐˜ ๐—บ๐—ฎ๐—น๐—ถ๐—ฐ๐—ถ๐—ผ๐˜‚๐˜€ ๐—ถ๐—ป๐—ณ๐—ฟ๐—ฎ๐˜€๐˜๐—ฟ๐˜‚๐—ฐ๐˜๐˜‚๐—ฟ๐—ฒ ๐—ฟ๐—ฒ๐—ฝ๐—ผ๐—ฟ๐˜: ๐Ÿญ,๐Ÿฏ๐Ÿฑ๐Ÿฌ ๐—–๐Ÿฎ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฟ๐˜€ ๐— ๐—ฎ๐—ฝ๐—ฝ๐—ฒ๐—ฑ ๐—”๐—ฐ๐—ฟ๐—ผ๐˜€๐˜€ ๐Ÿต๐Ÿด ๐—ฃ๐—ฟ๐—ผ๐˜ƒ๐—ถ๐—ฑ๐—ฒ๐—ฟ๐˜€ Over a three-month window, we mapped more than 1,350 active C2 servers operating across 98 infrastructure providers in 14 Middle Eastern countries, covering telecoms, shared hosting, and VPS environments. ๐Ÿ‘‰ Read the full report: hunt.io/blog/middle-east-malโ€ฆ Here's what the data shows: โ†’ A single telecom carrier accounts for nearly 72% of all detected regional C2 activity, most of it tied to compromised customer endpoints rather than provider-level abuse โ†’ C2 infrastructure makes up over 96% of all observed malicious artifacts in the region โ†’ Tactical RMM leads the malware family breakdown with 92 unique C2 IPs, followed by Keitaro TDS (71) and Acunetix (38) โ†’ The malware mix covers a wide range of attack types - IoT botnets (Mozi, Hajime, Mirai), remote access tools (AsyncRAT, Sliver, Cobalt Strike), active scanning (Acunetix), and phishing infrastructure (Gophish, Keitaro TDS) โ†’ Campaigns in the dataset include Eagle Werewolf espionage operations, the DYNOWIPER destructive campaign targeting Poland's energy sector, and RondoDox botnet exploitation infrastructure on Iranian hosting The main takeaway is that malicious infrastructure in the region is not evenly spread. A small set of providers keeps showing up across unrelated campaigns and malware families, which is where the tracking value is. Provider-level visibility is what lets defenders get ahead of that pattern, rather than reacting to individual indicators that rotate daily. Full breakdown, including infrastructure observables, HuntSQL queries, and campaign examples, is in the report ๐Ÿ‘‡ hunt.io/blog/middle-east-malโ€ฆ
14
31
3,028
#Impersonation | #CNIC harvesting | Interior Ministry of #Pakistan Interesting, I found interiorgovpk[.]site last year and now a new one identified. ๐Ÿ”—https://www.interiorgovpk[.]life/ Ref: x.com/volrant136/status/1938โ€ฆ cc: @500mk500 @MichalKoczwara @malwrhunterteam
28 Jun 2025
1/ Possible #APT #Sidewinder targets #Pakistan Ministry of Interior using #Fake #Website running fake Online Permit Verification System. ๐Ÿ”— https://interiorgovpk[.]site Based on Analysis, the site requests CNIC input, then fetches userMappings.json and display the error (if CNIC wrong) or record as html (if correct). @500mk500 @Cyberteam008 @ginkgo_g @MichalKoczwara @malwrhunterteam #CyberSecurity #ThreatIntel #OSINT #Pakistan #GovSpoofing #Phishing #SidewinderAPT
1
4
15
1,033
Demon retweeted
๐Ÿšจ New research from Joe Security: A spear-phishing campaign targeting Pakistanโ€™s PSCA & PPIC3 abused โšก VS Code Remote Tunnels and Discord webhooks for stealthy remote access. Instead of stealing Microsoft accounts, attackers enrolled victim machines into their own VS Code tunnel infrastructure using device-code authentication - a clever twist on classic phishing techniques. ๐ŸŽฏ Key findings: ๐Ÿ”น Malicious Office macros downloading & executing `code.exe` ๐Ÿ”น Abuse of legitimate VS Code tunneling workflows ๐Ÿ”น Discord webhooks used for exfiltration & status reporting ๐Ÿ”น ClickOnce-based PDF delivery chain impersonating Adobe Reader ๐Ÿ”น Trusted Microsoft infrastructure leveraged for persistence & stealth This campaign highlights how threat actors increasingly weaponize legitimate developer tooling to blend into normal cloud traffic. โ˜๏ธ๐Ÿ’ป Read the full analysis here ๐Ÿ‘‡ buff.ly/BE5w9Yq #CyberSecurity #ThreatIntelligence #MalwareAnalysis #Phishing #VSCode #Microsoft #BlueTeam #DFIR #JoeSecurity
17
30
3,065
#APT #Sidewinder Targets #Pakistan ๐Ÿ‡ต๐Ÿ‡ฐ New โœ… Tracked by @Huntio โš ๏ธhttps://www-sbp-org-pk[.]interior-ministry[.]com/53645092/adobe-reader ref: x.com/volrant136/status/2020โ€ฆ cc: @500mk500 @MichalKoczwara @malwrhunterteam
#APT #SideWinder attribution using @Huntio Platform 1/ I started pivoting on URL "hXXps://swo-gov-pk.grabfiles[.]net/52863484/adobe-reader" and found a unique pattern: /8-digits/adobe-reader Ref: x.com/__0XYC__/status/201961โ€ฆ cc: @500mk500 @MichalKoczwara @malwrhunterteam
4
17
1,537
#DocuSign/#Microsoft OAuth #Phishing Attack Targeting #Srilanka ๐Ÿ‡ฑ๐Ÿ‡ฐ 1 spz2-unv8-sx9a.sc0656-srilankan-com-s-account[.]workers[.]dev Ref: x.com/volrant136/status/2056โ€ฆ cc: @500mk500 @MichalKoczwara @malwrhunterteam
#DocuSign/#Microsoft OAuth #Phishing Attack Targeting #Srilanka ๐Ÿ‡ฑ๐Ÿ‡ฐ It impersonates DocuSign, uses REAL Microsoft OAuth, and steals full account access. https://r3rx-geuk-l544.sc0656-srilankan-com-s-account.workers[.]dev Here's how it works ๐Ÿ‘‡
7
10
1,073
#APT #Sidewinder New Samples 412ad811db5097af62929d88e01c3527 interior-gov-pk[.]direct880[.]net 759703585f0feae8dec679db380fb0ac moha-gov-np[.]direct880[.]net Ref: x.com/Cyberteam008/status/20โ€ฆ cc: @500mk500 @MichalKoczwara @malwrhunterteam
#SideWinder #APT / #RazorTiger Targeting ๐Ÿ‡ต๐Ÿ‡ฐ ๐Ÿ‡ณ๐Ÿ‡ต ๐Ÿ‡ง๐Ÿ‡ฉ ๐Ÿ‡ฆ๐Ÿ‡ซ Governments. Infra [Government entities mimicking]: 94.126.224[.]99 mofa-go-np.direct880[.]net [Ministry of Foreign Affairs, Nepal] mofa-gov-np.direct880[.]net [Ministry of Foreign Affairs, Nepal] pakun-org.direct880[.]net [Permanent Mission of Pakistan to the United Nations] www-fbr-gov-pk.direct880[.]net [Federal Board of Revenue, Pakistan] geneva-mofa-gov-bd.direct880[.]net [Ministry of Foreign Affairs, Bangladesh] www-securitycouncilreport-org[.]direct880[.]net [Targeting Afghanistan Govt.] www.direct880[.]net direct880[.]net Below are associated malicious files used for Phishing campaign: File: Afghanistan, March 2026 Monthly Forecast _ Security Council Report.pdf MD5: dba2260f73884da6f274fe8246988e8c C2: www-securitycouncilreport-org.direct880[.]net File: importantadvisory.docx MD5: 616fbbce1f4719c37e4e02e01605d3b1 C2: TCP 94.126.224[.]99:443 / mofa-gov-np.direct880[.]net Notes: 1. Header Title of all the web pages originally in Malayalam (Indian Language), which translates in English is "The most important thing is to be happy". 2. It is exploiting #CVE-2017-0199 (RCE vulnerability in MS Office) using the malicious word file (importantadvisory.docx). 3. RTF (Rich Text Format) file used for the campaign is "Fontlayer.rtf". We may find additional campaign files by searching this RTF file using VT Enterprise account. Anyone having VT premium access can search and share additional infra here, if found. #SideWinder #APT #Malware #ioc
9
31
3,758
#DocuSign/#Microsoft OAuth #Phishing Attack Targeting #Srilanka ๐Ÿ‡ฑ๐Ÿ‡ฐ It impersonates DocuSign, uses REAL Microsoft OAuth, and steals full account access. https://r3rx-geuk-l544.sc0656-srilankan-com-s-account.workers[.]dev Here's how it works ๐Ÿ‘‡
2
7
16
2,316
Deofucated Code for Analysis
1
1
1
192