Cedric Pernet
@cedricpernet.bsky.social
1.6K followers 180 following 76 posts
Senior Threat Researcher @ Proofpoint. Cybercrime / Cyberespionage aficionado. Has worked in several CSIRTs/CERTs. Metal & Rock dude, never enough guitars. Motorcycles fan. Wrote a book in French language on cyberespionage. Ex-Law Enforcement Officer
Posts Media Videos Starter Packs
cedricpernet.bsky.social
Infamous BreachForums Is Back Online With All Old Accounts and Posts Restored - cybersecuritynews.com/breachforums...
#cybercrime
Reposted by Cedric Pernet
threatinsight.proofpoint.com
We recently discovered an infostealer in our data that we originally dubbed "Aurotun," named for a misspelling of "autorun" in its strings.

After collab w/ @intel471.bsky.social, @malwareindepth.com & others, we believe this malware is actually MonsterV2, a newer version of an existing infostealer.
cedricpernet.bsky.social
Very happy and proud that one of my "weekend research" has been exposed in an article from Le Monde.

I had spent some time during my short unemployed period to dig into #Traffyque infrastructure.
www.lemonde.fr/pixels/artic...
#cybercrime #lemonde
Reposted by Cedric Pernet
josephcox.bsky.social
New from 404 Media: the age of realtime deepfake fraud is here. Scammers in Nigeria are using realtime deepfakes to change their race, facial hair, gender, more to appear as someone else on video calls. Results very realistic now. Also tricking verification systems www.404media.co/the-age-of-r...
The Age of Realtime Deepfake Fraud Is Here
Fraudsters are able to change their race, facial hair, voice, and more during live video calls with very little effort. Scammers are already fooling the elderly and verification systems.
www.404media.co
cedricpernet.bsky.social
Belgian beer drove him crazy :-)
Reposted by Cedric Pernet
cedricpernet.bsky.social
Weaver Ant, the Web Shell Whisperer: Tracking a Live China-nexus Operation - www.sygnia.co/threat-repor... #APT #longpersistence
Reposted by Cedric Pernet
campuscodi.risky.biz
The Grandoreiro malware operation is back up and running after some of its members were detained last year.

Forcepoint has detected new large-scale phishing operations spreading the banking trojan to users in Europe and Latin America

www.forcepoint.com/blog/x-labs/...
Grandoreiro Trojan Distributed via Contabo-Hosted Servers in Phishing Campaigns
Cybercriminals are spreading the Grandoreiro banking trojan in Mexico, Argentina and Spain through phishing emails impersonating a tax agency.
www.forcepoint.com
cedricpernet.bsky.social
Pulling the Threads on the Phish of Troy Hunt - www.validin.com/blog/pulling... #cybercrime #phishing
Reposted by Cedric Pernet
cedricpernet.bsky.social
Following the discreet layoffs at Trend Micro at the end of last year, I am now incredibly proud to announce that I just joined the powerful forces of @proofpoint.com ! I feel very gifted and honored to start working with such an amazing team of researchers !
Reposted by Cedric Pernet
untersin.gr
L'Assemblée nationale entame aujourd'hui l'examen de la loi narcotrafic et de ses backdoors. La mesure serait au mieux inefficace, au pire dangereuse, mais Bruno Retailleau s'y accroche, affirmant contre les évidences qu'il ne s'agit pas ni d'une backdoor, ni d'un affaiblissement du chiffrement.
Loi contre le narcotrafic : Bruno Retailleau confirme son soutien à une disposition controversée visant le chiffrement des messages
Le ministre de l’intérieur a tenté de rassurer sur l’encadrement de ces « backdoors », qui permettraient aux forces de l’ordre d’accéder aux échanges chiffrés. Il s’est cependant dit « sans illusion »...
www.lemonde.fr
Reposted by Cedric Pernet
numb.comfortab.ly
If you miss Tweetdeck, or just want to be able to see multiple feeds at once - give deck.blue a try, it's awesome!
Widescreen monitor displays 7 columns of Bluesky feeds.
cedricpernet.bsky.social
Interesting read on new technics used by cybercriminals to scam people and cash out stolen money - How Phished Data Turns into Apple & Google Wallets - krebsonsecurity.com/2025/02/how-... #cybercrime #scam #China #mobile
Reposted by Cedric Pernet
rikmer.bsky.social
@shodanhq.bsky.social Awesome! Shodan History is back in the UI. Nice!!! Thank you.
But I have a question regarding trends.shodan.io. all trends I do are stopping at October 2024. Why? Please make them to the current data again. I love it and need it. :)
Shodan
Shodan Trends - Discover how the Internet has changed over time.
trends.shodan.io
cedricpernet.bsky.social
get a dollar for every vague attribution to Winnti as well, then you can buy a castle :-)
Reposted by Cedric Pernet
wxs.bsky.social
This is really interesting and good work by Volexity. I'm not sure how many places are looking for this kind of abuse or have outright prevented it. As a provider finding this kind of abuse has got to be difficult too.
stevenadair.bsky.social
We have been tracking multiple Russian APT groups aggressively targeting organizations with Microsoft Device Code authentication phishing. The attackers got creative with tricking users into granting them access to their accounts. Have a look at our blog for all the details!
volexity.com
@volexity.com recently identified multiple Russian threat actors targeting users via #socialengineering + #spearphishing campaigns with Microsoft 365 Device Code authentication (a well-known technique) with alarming success: www.volexity.com/blog/2025/02...

#dfir #threatintel #m365security