crep1x
@crep1x.bsky.social
86 followers
41 following
19 posts
Lead cybercrime analyst, tracking adversaries activities & infrastructure, at @sekoia.io
Posts
Media
Videos
Starter Packs
Reposted by crep1x
crep1x
@crep1x.bsky.social
· Apr 16
Threat actors misuse Node.js to deliver malware and other malicious payloads | Microsoft Security Blog
Since October 2024, Microsoft Defender Experts has observed and helped multiple customers address campaigns leveraging Node.js to deliver malware and other payloads that ultimately lead to information...
www.microsoft.com
crep1x
@crep1x.bsky.social
· Apr 16
Reposted by crep1x
crep1x
@crep1x.bsky.social
· Mar 20
crep1x
@crep1x.bsky.social
· Mar 20
TDR analysts published an analysis of the new #ClearFake variant that relies on compromised websites injected with the malicious JavaScript framework, the #EtherHiding technique, and the #ClickFix social engineering tactic.
buff.ly/vbiVbsN
buff.ly/vbiVbsN
ClearFake’s New Widespread Variant: Increased Web3 Exploitation for Malware Delivery
ClearFake spreads malware via compromised websites, using fake CAPTCHAs, JavaScript injections, and drive-by downloads.
blog.sekoia.io
crep1x
@crep1x.bsky.social
· Jan 24
crep1x
@crep1x.bsky.social
· Jan 22
TDR analysts analysed the supply chain attack targeting Chrome browser extensions, which potentially affected hundreds of thousands of end users in December 2024.
https://buff.ly/4auQ0HN
https://buff.ly/4auQ0HN
Reposted by crep1x
crep1x
@crep1x.bsky.social
· Jan 16
crep1x
@crep1x.bsky.social
· Jan 16
crep1x
@crep1x.bsky.social
· Jan 16
🔍 TDR analysts discovered a new Adversary-in-the-Middle (#AiTM) #phishing kit, specifically targeting Microsoft 365 accounts and circumventing 2-step verification: Sneaky 2FA
https://blog.sekoia.io/sneaky-2fa-exposing-a-new-aitm-phishing-as-a-service/
#detection #sneaky2fa
https://blog.sekoia.io/sneaky-2fa-exposing-a-new-aitm-phishing-as-a-service/
#detection #sneaky2fa
Sneaky 2FA: exposing a new AiTM Phishing-as-a-Service
In this blog post, learn about Sneaky 2FA, a new Adversary-in-the-Middle (AiTM) phishing kit targeting Microsoft 365 accounts.
blog.sekoia.io