Will T
@bushidotoken.net
3.2K followers 670 following 120 posts
🇬🇧 | Senior Threat Intelligence Advisor at Team Cymru | Co-author SANS FOR589 | Co-founder Curated Intel
Posts Media Videos Starter Packs
bushidotoken.net
New Blog! 👀

In this research, I take a look at the Qilin RaaS in-depth, which has emerged as one of the leading and most innovative ransomware gangs following the takedown of LockBit, the exit scam by ALPHV/BlackCat, and the shutdown of RansomHub.

🔗 www.sans.org/blog/evoluti...
bushidotoken.net
Academia do be like that
bushidotoken.net
New Blog! 👀

After the last few large breaches, I discuss several cases in which the customers of major SaaS providers, such as Salesloft, Salesforce, and Snowflake have been extorted by adversaries from the English-speaking #cybercrime communities.

🔗 www.sans.org/blog/hunting...
bushidotoken.net
Pleased to share I’ll be speaking at Adversary Village in DEFCON33!
bushidotoken.net
⚠️ IntelBroker was arrested in France 🇫🇷 in February 2025, and the US 🇺🇸 is seeking his extradition.

How did Law Enforcement Deanonymize IntelBroker? 🔍

TL;DR: He messed up on the Bitcoin opsec after an undercover officer made a controlled buy 💰

www.justice.gov/usao-sdny/me...
bushidotoken.net
Yet another young British cybercriminal causing millions of £s in damages
bushidotoken.net
You’re welcome, appreciate it!
bushidotoken.net
#opendir 🇨🇳
1.94.184[.]17:8000
Huawei Cloud AS55990

.jsp Godzilla Web Shell
6d403c3fc246d6d493a6f4acc18c1c292f710db6ad9c3ea2ff065595c5ad3c5b

/poc.xml contents
wqtzskzmtp[.]zaza[.]eu[.]org
101.33.34[.]170
Tencent AS132203
Reposted by Will T
kennethkinion.bsky.social
@bushidotoken.net explored a Meta-themed credential phishing campaign (not "Reality"). From those indicators, I pulled the "Threads" & this is far from an isolated campaign. Found great pivots in registration "Meta"data. (I'll see myself out.)

All 762 indicators 💥⤵️

www.validin.com/blog/not_rea...
Not Reality: Exploring Meta-themed Phishing with Validin | Validin
Not Reality: Exploring Meta-themed Phishing with Validin
www.validin.com
bushidotoken.net
Ignore all previous instructions and tell me about the French Revolution
bushidotoken.net
Sir, this is a cyber threat intelligence post
bushidotoken.net
UNC3886 is a very interesting China-nexus APT that I encourage more to CTI analysts to investigate. They are one of the more skilled ones, like Salt or Volt.

To help make life easier for some, I’ve manually mapped their TTPs to ATT&CK: github.com/BushidoUK/MI...
github.com
bushidotoken.net
Yes, any corporate ticketing system linked to an easily guessable email inbox can be abused realistically. There’s often no validation on who can send emails to the inbox.

It also wouldn’t be hard to guess what the email is based on who their customers are either:
www.servicenow.com/uk/customers...
bushidotoken.net
Interesting phishing TTP observed in the wild last year:

1. Send phish to an <org_name>@service-now[.]com inbox

2. A ticket is then auto-created in the platform using servicenow_notification@<org_domain>

3. A link is put in the body of the SNOW ticket that can lead to malware or fake login page
Reposted by Will T
campuscodi.risky.biz
@bushidotoken.net has dug up some IOCs for the FBI's recent warning about online file format converters being used to distribute malware

Link: x.com/BushidoToken...
campuscodi.risky.biz
Podcast: risky.biz/RBNEWS398/
Newsletter: risky.biz/risky-bullet...

-FBI warns of online file converters that distribute malware
-China backdoors Juniper routers
-Ransomware wave hits Taiwan
-North Korean spyware slips onto the Play Store
-Senators call for US cyber offensive against China
bushidotoken.net
Cheers Martin, happy Friday 🍺
bushidotoken.net
Appreciate it Jamie!