Andrew 🌻 Brandt πŸ‡

Words published here do not necessarily reflect views of my employer or any other organization I am affiliated with.

Research and analysis about malware, network forensics, and the intersection of crime with anything that electrons or photons flow through.

Board member of World Cyber Health, the parent organization behind Malware Village and the NO-HAVOC project.

Docent of obsolete technology at @mediaarchaeologylab

Executive director, Elect More Hackers: electmorehackers.com

"By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges." -- Cory Doctorow

Andrew 🌻 Brandt πŸ‡threatresearch@infosec.exchange
2025-06-27

@Viss @neurovagrant @mttaggart @NosirrahSec @tris Viss, you saved me a whole lot of time writing a much more concise answer than I could have!

Andrew 🌻 Brandt πŸ‡threatresearch@infosec.exchange
2025-06-27

Buttons, has nobody told you that you shouldn't try to eat anything larger than several times the volume of your entire body?

#Rats #RatsOfMastodon #PetRat

A cute all-grey rat looks up at the camera while standing on top of a very large watermelon.
Andrew 🌻 Brandt πŸ‡ boosted:
Julia Evansb0rk@jvns.ca
2025-06-26
Andrew 🌻 Brandt πŸ‡ boosted:
Los Angeles TimesLATimes@flipboard.com
2025-06-26

'We are not alone!' San Gabriel Valley residents gather at candlelight vigil to protest ICE raids
latimes.com/california/story/2

Posted into California @california-LATimes

Andrew 🌻 Brandt πŸ‡threatresearch@infosec.exchange
2025-06-26

@benhencke So cute! Are you selling these?

Andrew 🌻 Brandt πŸ‡threatresearch@infosec.exchange
2025-06-26

Hey #Boulder folks. This Saturday at 10:30am at the Boulder Public Library main branch, I'll be moderating a panel discussion/town hall on public safety, organized by Colorado Assembly representative Junie Joseph.

The panel will include rep. Joseph, Boulder police chief Stephen Redfearn, Boulder county sheriff Curtis Johnson, and deputy DA Christian Gardner-Wood.

After the months of protests and the horrific molotov cocktail attack against demonstrators earlier this month, there's a lot on people's minds. This is a chance to ask questions directly to local Boulder law enforcement leadership, share your concerns, and for all of us to listen to one another.

If you're local, I hope you can attend.

#COpolitics #publicsafety #publicsafetyisforeveryone #Colorado #police #crime

A town hall on public safety poster. Boulder public library, 3000 Canyon Blvd. Boulder. Saturday June 28 at 10:30am.
Andrew 🌻 Brandt πŸ‡ boosted:
Alt Alt National Park ServiceAltAltNPS@noc.social
2025-06-25

There’s an active investigation into the access DOGE officials gained to federal IT systems. Fortunately, detailed documentation was kept by many along the way. More DOGE β€œresignations” are expected.
bsky.app/profile/altnps.bsky.s
-
From resistance team of US Natl Park Svc
500+ char posts not resent
Unaffiliated w/ AltNPS
-
#AltNPS #Coup #Activism #NationalParkService #FederalGovernment #USpol #Trump

Andrew 🌻 Brandt πŸ‡threatresearch@infosec.exchange
2025-06-25

Zohran FTW

Andrew 🌻 Brandt πŸ‡ boosted:
2025-06-24

Beware of fake SonicWall VPN app that steals users' credentials

A good reminder not to download apps from non-vendor sites Unknown miscreants are distributing a fake SonicWall app to steal users' VPN credentials.…
#theregister #IT
go.theregister.com/feed/www.th

Andrew 🌻 Brandt πŸ‡threatresearch@infosec.exchange
2025-06-24

@arstechnica Literally submitted this as a talk to Black Hat

Andrew 🌻 Brandt πŸ‡ boosted:
Ars Technicaarstechnica
2025-06-24

The rΓ©sumΓ© is dying, and AI is holding the smoking gun
As thousands of applications flood job posts, 'hiring slop' is kicking off an AI arms race.
arstechnica.com/ai/2025/06/the

Andrew 🌻 Brandt πŸ‡ boosted:
π™½π™΄πšƒπšπ™΄πš‚π™΄π™²netresec@infosec.exchange
2025-06-24

@malware_traffic There's some unknown but interesting C2 traffic going on to net 104.16.0.0/13 (on CloudFlare). An HTTP POST is sent every 30 seconds (see Gantt chart) with gz compressed data.

The C2 servers use domain names like:
πŸ”₯ event-time-microsoft[.]org
πŸ”₯ windows-msgas[.]com
πŸ”₯ event-datamicrosoft[.]live
πŸ”₯ eventdata-microsoft[.]live

They also use this trycloudflare.com domain:
πŸ”₯ varying-rentals-calgary-predict.trycloudflare[.]com

Anyone knows what malware this is?

Unknown malware C2 traffic to:
104.16.230.132
104.16.231.132
104.21.16.1
104.21.24.186
104.21.64.1
104.21.80.1
104.21.96.1
104.21.112.1

Domain names:
event-time-microsoft[.]org
windows-msgas[.]com
event-datamicrosoft[.]live
eventdata-microsoft[.]live
varying-rentals-calgary-predict.trycloudflare[.]com
Andrew 🌻 Brandt πŸ‡threatresearch@infosec.exchange
2025-06-22

@mc_frontalot there are nice barcades in Denver and Boulder if that's your jam

Andrew 🌻 Brandt πŸ‡threatresearch@infosec.exchange
2025-06-22

@campuscodi why is Cloudflare allowed to evade sanctions against doing business there?

Andrew 🌻 Brandt πŸ‡ boosted:
Catalin Cimpanucampuscodi
2025-06-22

Russian internet traffic to Cloudflare infrastructure has fallen by 30% after the country's communications watchdog started filtering traffic to the service.

This is the agency's way of telling local companies to switch from the provider before it gets fully blocked.

kommersant.ru/doc/7808154

Andrew 🌻 Brandt πŸ‡ boosted:
2025-06-22

New Phishing Threat Leverages Government Domains to Targetv Employee Credentials

Recently a sophisticated phishing campaign targeting employees has beenidentified using fake toll payment notices to deceive victims.

Pulse ID: 68575ac30df6bedce4b1b5c0
Pulse Link: otx.alienvault.com/pulse/68575
Pulse Author: cryptocti
Created: 2025-06-22 01:22:11

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CyberSecurity #Government #InfoSec #OTX #OpenThreatExchange #Phishing #bot #cryptocti

Andrew 🌻 Brandt πŸ‡ boosted:
Kim Scheinbergkims@mas.to
2025-06-22

A thing I don't say enough...

Over on Bluesky, the Discovery feed right now is pretty much
Iran
Impeach
Iran
Impeach
Remember Bush?
What about congress?
Impeach

And, like, I get it. This is a pretty serious dire thing. But my feed here is:

Iran
Hashtaggames
Jaws
Impeach
Caturday
Iran
LookAtMyCoolArt
AuroraPic
Impeach
FunnyTextFromMyFriend
WroughtIronFenceAsPeeledBanana
What about congress?
CoolPhoto

And as far as my mental health goes? The latter is so much better than the former, AINEC. TY

Andrew 🌻 Brandt πŸ‡ boosted:
VissViss
2025-06-19

creating an account on, then putting all your data into whatever the newest "we built this all with ai" tech company product is

Andrew 🌻 Brandt πŸ‡ boosted:
Not Just Bikes πŸ‡³πŸ‡±notjustbikes@notjustbikes.com
2025-06-19

I had already basically written-off ever going back to the United States ever again, but these (repeated) stories of completely innocent travellers getting detained and deported are the nail in the coffin.

newyorker.com/news/the-lede/ho

Andrew 🌻 Brandt πŸ‡ boosted:
demi7en πŸŽ—πŸ‡ͺπŸ‡Ίdemi7en@infosec.exchange
2025-06-19

@heidilifeldman The USA has such deep structural/cultural issues with religion, dumbness, greed and cullibility that, as a European, I often feel frustrated beyond belief trying to "stand with you" fellow libs but I try to hang on...

The American fascist project has for over a decade drained your country's historical ability to help democracy movements around the world, and that is by design. UK's brexit (many same people behind it), PRC's crushing of Hong Kong's civil society and military expansionism, russia's invasion of Ukraine and renewed imperial belligerence, Burma/Myanmar freedom struggle, much of Africa under authoritarian rule, Netanyahu's Israel under attack and lashing out...

Democracy and civil liberties are under attack globally and the enemies feel increasingly emboldened, with china and russia the main instigators and providers.

All democracies since ca. 1990 are guilty of putting profits above values and empowering autocrats instead of using their then-powerful positions to prioritize democratic development. So here we are.

The despots are collaborating to save their despotic asses and they want democracy eradicated. Our democracies should finally wisen up to that fact.

β€œYour freedom and mine cannot be separated. ”

Nelson Mandela realised that. We should have listened.

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst