Colin Cowie

Curating news on Malware Research & Information Security 🧬🏹

Threat Intelligence Analyst @ Sophos MDR

(Posts are my own and do not necessarily reflect the views of my employer)

Colin Cowie boosted:
Randahl Finkrandahl
2025-06-12

Imagine if in 1944, President Roosevelt had sat down at his desk to write and congratulate Hitler and express his commitment to the success of Nazi Germany.

This US administration is killing the American brand faster than a forrest fire consumes dried-out pine trees in August.

Dear Americans, get rid of your turncoat government.

Source: state.gov/releases/2025/06/rus

Colin Cowie boosted:
2025-05-20

New investigation out from our @DomainTools investigations team - our researchers identified over a hundred domains and Chrome browser extensions mimicking legitimate services, but also enabling malicious backend connections and code execution.

dti.domaintools.com/dual-funct

#infosec #cybersecurity #threatintel

edit: ARGH WRONG LINK. coffee.

Colin Cowie boosted:
Zack Whittakerzackwhittaker
2025-05-14

New: Senior White House official Russell Vought, who's also the acting head of the Consumer Financial Protection Bureau, has scrapped a plan that would have blocked data brokers from selling Americans' personal and financial information, including Social Security numbers.

techcrunch.com/2025/05/14/whit

Colin Cowie boosted:
2025-04-23

Infoblox Threat Intel had the opportunity to collaborate with the United Nations Office on Drugs and Crime (#UNODC) for their latest report on South East Asian Crime. The report is titled "Inflection Point". It is a great in-depth analysis of the triads and how they fuel the current scam epidemic.

Organized crime is booming - as you can see with the picture below which shows the growth in the physical footprint of the compounds they operate.

Our part of the collaboration (pages 37-42 of the 90+ page report) were around a single actor that we can track in #dns -- naturally!

We analysed a number of illegal Chinese-operated gambling websites and soon found out they were operated by the same 'gambling provider' we named Vault Viper. Vault viper develops its very own "secure gambling browser". Of course it's #malware.

Through DNS, we discovered the companies behind Vault Viper were in fact controlled by Suncity - a criminal junket whose founder has been convicted of laundering billions of dollars.

unodc.org/roseap/en/2025/04/cy

Illegal gambling is not harmless fun. It fuels some of the largest criminal networks in the world.

The entire report is worth reading to get the latest view from experts on the world of organized crime in Asia that is running #scam, #pigbutchering, #humantrafficking, #cybercrime, #malware, #illegalgambling, illegal porn and who knows what else. The image below shows just how much it has grown in a few years from physical footprints.

We'll be releasing a detailed report on Vault Viper in the coming months.

#infobloxthreatintel #infoblox
#organizedcrime #china

satellite imagery showing the growth of crime compounds in south east asia over a few year period
Colin Cowie boosted:
Volexity :verified:volexity@infosec.exchange
2025-04-22

New on the @volexity Blog: Multiple Russian threat actors are leveraging Signal, WhatsApp, and a compromised Ukrainian government email address to impersonate EU officials. This latest round of phishing attacks abuses first-party Microsoft Entra apps and OAuth to compromise targets.

volexity.com/blog/2025/04/22/p

#dfir #threatintel

Colin Cowie boosted:
mattjaymattjay
2025-04-18

🧵 THREAD: A federal whistleblower just dropped one of the most disturbing cybersecurity disclosures I’ve ever read.

He's saying DOGE came in, data went out, and Russians started attempting logins with new valid DOGE passwords

Media's coverage wasn't detailed enough so I dug into his testimony:

Colin Cowie boosted:
2025-04-17

On Wednesday, CISA warned federal agencies to secure their SonicWall Secure Mobile Access (SMA) 100 series appliances against attacks exploiting a high-severity remote code execution vulnerability.

bleepingcomputer.com/news/secu

Colin Cowie boosted:
Osma A 🇫🇮🇺🇦osma@mas.to
2025-04-16

Bluesky didn't reach a federated stage where you could choose a service provider in a free country before they started to censor people based on authoritarian demands.

Email screenshot:

From: noreply@bsky.so...

Alıcılar: ben

Türkçe diline çevir

Hi there,

We are writing to inform you that we have received a formal request from a legal authority in Turkey regarding the removal of your account associated with the following handle (@carekavga.bsky.social) on Bluesky.

The legal authority has claimed that this content violates local laws in Turkey. As a result, we are required to review the request in accordance with local regulations and Bluesky's policies.

Following a thorough review, we have determined that the content in question violates local laws in Turkey, as outlined in the legal request. In compliance with these legal provisions, we have restricted access to your account for users.
Colin Cowie boosted:
2025-04-16

Finally put together a proper story on this funding debacle for MITRE's CVE program.

"A critical resource that cybersecurity professionals worldwide rely on to identify, mitigate and fix security vulnerabilities in software and hardware is in danger of breaking down. The federally funded, non-profit research and development organization MITRE warned today that its contract to maintain the Common Vulnerabilities and Exposures (CVE) program -- which is traditionally funded each year by the Department of Homeland Security -- expires on April 16."

krebsonsecurity.com/2025/04/fu

Colin Cowie boosted:
2025-04-15

Today's story looks at how the POTUS's revenge tour is targeting cybersecurity leaders and election security efforts.

"President Trump last week revoked security clearances for Chris Krebs, the former director of the Cybersecurity and Infrastructure Security Agency (CISA) who was fired by Trump after declaring the 2020 election the most secure in U.S. history. The White House memo, which also suspended clearances for other security professionals at Krebs's employer SentinelOne, comes as CISA is facing huge funding and staffing cuts."

krebsonsecurity.com/2025/04/tr

A Getty Images photo of Chris Krebs from 2020, seen seated in front of a microphone testifying to Congress.Gen. Timothy Howell, until recently the director of the National Security Agency and the U.S. Cyber Command. Howell is seated in his military uniform, answering questions at the Billington Cybersecurity conference.
Colin Cowie boosted:
2025-04-10

Full analysis of Ivanti Connect Secure CVE-2025-22457 via @stephenfewer — full RCE, exploitation non-trivial (at least as it stands now).

We should all be assuming that for any popular or high-profile technology, particularly network edge devices, adversaries have piles of software they're actively reverse engineering and developing complex exploit chains for, regardless of whether vulnerabilities are disclosed publicly as security issues or not. TAs are putting time, resources, and focus into learning the internals of *many* of these systems. If the technology industry broadly — and we ALL live in glass houses here — can't match that investment with expertise and evolution, I'm not sure we can expect the current attack landscape to improve.

attackerkb.com/topics/0ybGQIkH

Colin Cowie boosted:
2025-04-09
Colin Cowie boosted:
Lorenzo Franceschi-Bicchierailorenzofb@infosec.exchange
2025-04-09

NEW: A recently published court document shows the locations of WhatsApp victims targeted with NSO Group's spyware.

The document lists 1,223 victims in 51 countries, including Mexico, India, Morocco, United Kingdom, United States, Spain, Hungary, Netherlands, etc.

This targeting was over a span of around two months in 2019, according to WhatsApp's lawsuit against NSO Group.

techcrunch.com/2025/04/09/cour

Colin Cowie boosted:

2025-03-26 (Wednesday): #SmartApeSG traffic for a fake browser update page leads to a #NetSupport #RAT infection. A zip archive for #StealC sent over the #NetSupportRAT C2 traffic.

The #StealC infection uses DLL side-loading by a legitimate EXE to #sideload the malicious DLL.

A #pcap from an infection, the associated #malware samples, and #IOCs are available at at malware-traffic-analysis.net/2

Compromised website showing SmartApeSG page for fake browser update.Traffic from an infection filtered in Wireshark.NetSupport RAT persistent on an infected Windows host.Zip archive and extracted files for follow-up StealC malware.
Colin Cowie boosted:
2025-03-24

Tycoon 2FA (a prominent AitM phishing kit), targeting Microsoft and Google accounts, uses a new CAPTCHA page instead of the custom Cloudflare Turnstile page

e.g.
hxxps://ymi.bvyunz.]ru/3v4jfQ-cUo/
hxxps://xau.kolivax.]ru/ckYHFJN/
hxxps://ffqt.lzirleg.]es/VajlR/

Current decoy pages used since 18 March, changing every 3/4 weeks since the beginning of 2025:

urlscan.io/search/#page.title%

Colin Cowie boosted:
Lorenzo Franceschi-Bicchierailorenzofb@infosec.exchange
2025-03-24

NEW: Ukrzaliznytsia, Ukraine’s state-owned railway operator, said it has been hit by a large-scale cyberattack that disrupted online ticket sales, but trains continue to run.

techcrunch.com/2025/03/24/cybe

Colin Cowie boosted:
Lorenzo Franceschi-Bicchierailorenzofb@infosec.exchange
2025-03-21

NEW: Valve removed a video game from Steam after users reported that its free demo was actually an infostealer malware.

Very similar thing happened last month with another video game laced with malware.

techcrunch.com/2025/03/21/valv

Colin Cowie boosted:
Ars Technicaarstechnica
2025-03-21

CEO of AI ad-tech firm pledging “world free of fraud” sentenced for fraud
Prosecutors: Firm offering "300% more" fraud detection oversold revenue by 700%.
arstechnica.com/gadgets/2025/0

Colin Cowie boosted:
2025-03-20

My latest blog post is live. We must stop using knowledge-based "multifactor" authentication. It isn't multiple factors, it is one with a small ephemeral bit. Tools like evilgnx2 make MFA bypass trivial, it is high-time we make serious plans to migrate to passkeys.

news.sophos.com/en-us/2025/03/

#InfoSec @SophosXOps

2025-03-19

@dnsprincess personally I don't like Vegas enough to justify the costs of a ticket, hotel and food during the trip

I'm gonna try to spend my money and energy at events that are local to me (Seattle) :blobcatgooglyshrug:

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst