marktsec
banner
marktsec.bsky.social
marktsec
@marktsec.bsky.social
63 followers 14 following 470 posts
💫Threat Intel💫 Automation💫 Threat Analysis 💫OSINT💫 Testing 💫Network Security💫 https://github.com/marktsec
Posts Media Videos Starter Packs
Reposted by marktsec
Ravin Academy, the private school that recruits and trains hackers for Iran's MOIS intelligence service , has been hacked and its data leaked

www.iranintl.com/202510230171

blog.narimangharib.com/posts/2025%2...

Public searchable database: ravin-academy.com
BreachForums Reinstated
Spectre RAT v10 new capabilities: autorun, VNC, DLL sideloading, clipper, keylogger, Telegram notifications, anti-VM. Hunt for unexpected autorun registry changes, anomalous DLL loads and suspicious outbound connections.
#infosec #ThreatIntel
🚨 Ransomware mimic pay2key v0.16.1 Selling fully autonomous ransomware: buyers control ALL encryption keys, custom affiliate programs, and guaranteed product updates. Mimic variant, evasive, and tailored for affiliates. #ransomware #infosec #threatintel
🚨 Darkweb alert: Blockchain-powered botnets now feature encrypted smart contracts, anti-VM, autorun, and parent process ID spoofing for advanced malware delivery. No domains, no servers, no takedowns. Source code + panel available
#infosec #threatintel
"The Gentlemen" Win/Linux/ESXi lockers major update.
Adds persistent self-restart (schtasks + registry), a silent mode that preserves filenames/timestamps, built-in network/domain spread (WMI/SC/PowerShell/etc.),
#ransomware #infosec #ThreatIntel
⚠️ ALERT: DragonForce Ransomware announces an open partner program — no vetting, free partner services (file analysis, decryption, call service, storage) and a registration onion link in the post.
#Ransomware #ThreatIntel #infosec
VIDAR Stealer v2.0 being promoted. Vendor claims rewrite to C (C99), custom CRT, NT-API usage, automatic morphing per build, multithreaded collection & upload, and runtime obfuscation. Potential for improved stealth and faster exfil.
#ThreatIntel #infosec #infostealer #vidar
NOVA “Locker WIN” update — now advanced Rust. Changes: spawns 10 workers for multi-run encryption, skips already-encrypted files, self-deletes, clears device logs, drops .me ransom note, and claims to bypass AI-security endpoints.
#ransomware #threatintel #infosec
AresLoader, a resident Windows loader advertised on darknet. Written in C; uses HTTPS + JWT, runs EXE payloads, Flask admin with IP whitelist, 2FA & RBAC. Targets corporate workstations/servers.
#Infosec #ThreatIntel