#CTi

2026-03-09

🚨New ransom group blog post!🚨

Group name: incransom
Post title: arbd.com
Info: cti.fyi/groups/incransom.html

#ransomware #cti #threatintelligence #cybersecurity #infosec

2026-03-09

🚨New ransom group blog post!🚨

Group name: incransom
Post title: altaortho.com
Info: cti.fyi/groups/incransom.html

#ransomware #cti #threatintelligence #cybersecurity #infosec

VulDB :verified:vuldb@infosec.exchange
2026-03-09

Improved indicators: Venom RAT (+1), Amatera (+1), ACR Stealer (+2), PureRAT (+1), GuLoader (+1), ArcaneStealer (+1) and DCRat (+1). vuldb.com/?actor #apt #cti #ioc

2026-03-09

🚨New ransom group blog post!🚨

Group name: handala
Post title: Israeli Weather Stations Crippled
Info: cti.fyi/groups/handala.html

#ransomware #cti #threatintelligence #cybersecurity #infosec

2026-03-09

🚨New ransom group blog post!🚨

Group name: handala
Post title: Full Access: Jerusalem’s Security Cameras in Handala’s Hands
Info: cti.fyi/groups/handala.html

#ransomware #cti #threatintelligence #cybersecurity #infosec

2026-03-09

🚨New ransom group blog post!🚨

Group name: play
Post title: Southern Concrete Construction
Info: cti.fyi/groups/play.html

#ransomware #cti #threatintelligence #cybersecurity #infosec

2026-03-09

🚨New ransom group blog post!🚨

Group name: play
Post title: Serrano Industries
Info: cti.fyi/groups/play.html

#ransomware #cti #threatintelligence #cybersecurity #infosec

2026-03-09

🚨New ransom group blog post!🚨

Group name: play
Post title: Infinity Systems
Info: cti.fyi/groups/play.html

#ransomware #cti #threatintelligence #cybersecurity #infosec

2026-03-08

🚨New ransom group blog post!🚨

Group name: play
Post title: Helen Kaminski
Info: cti.fyi/groups/play.html

#ransomware #cti #threatintelligence #cybersecurity #infosec

2026-03-08

🚨New ransom group blog post!🚨

Group name: play
Post title: Facilities USA
Info: cti.fyi/groups/play.html

#ransomware #cti #threatintelligence #cybersecurity #infosec

VulDB :verified:vuldb@infosec.exchange
2026-03-08

Indicators added for: Kinsing (+1), ValleyRAT (+1), GlassWorm (+2), Bashlite (+1), Sliver (+1), Vidar (+1) and Coinminer (+1). vuldb.com/?actor #apt #cti #ioc

2026-03-08

🚨New ransom group blog post!🚨

Group name: play
Post title: Byard F Brogan
Info: cti.fyi/groups/play.html

#ransomware #cti #threatintelligence #cybersecurity #infosec

2026-03-08

🚨New ransom group blog post!🚨

Group name: handala
Post title: Contact Handala
Info: cti.fyi/groups/handala.html

#ransomware #cti #threatintelligence #cybersecurity #infosec

2026-03-07

Wow, now I'm getting malware URLs via reverb.com - way to hand over a long-time threat intel person the IoC's

nothing on VT yet virustotal.com/gui/url/3086617
Zero detections:
urlvoid.com/scan/matyshkazemly
scan failed 403 forbidden: sitecheck.sucuri.net/results/w

urlquery.net/report/7840c1b4-7 redirect and is sinkholed via DNS4EU
Submitted to Pulsedive: pulsedive.com/indicator/?ioc=d

Showing a redirect to Google on checkphish (LOL)
app.checkphish.ai/public/insig

IoC:
www.matyshkazemlya [DOT] com

Message on Reverb.com:
Hey, I've been trying to buy your listing but keep getting a payment error. The site gave me a link with some info for the seller to check — www.matyshkazemlya [DOT] com Could you take a look? Mia Brown

#IR #incidentRespose #CTI #IOC #infosec #cyberz #cybersecurity #infosec #reverb
#suspectdomain #virustotal #pulsedive #URLvoid #threatIntel #ThreatInteligence

VulDB :verified:vuldb@infosec.exchange
2026-03-07

Added some more indicators for: TinyNuke (+1), ACR Stealer (+7), Hook (+1), SmartLoader (+2), Orcus RAT (+1), MimiKatz (+1) and NetSupportManager RAT (+2). vuldb.com/?actor #apt #cti #ioc

2026-03-07

🚨New ransom group blog post!🚨

Group name: handala
Post title: Handala New Telegram
Info: cti.fyi/groups/handala.html

#ransomware #cti #threatintelligence #cybersecurity #infosec

Dave Wilburn :donor:DaveMWilburn@infosec.exchange
2026-03-07

@nyanbinary

Just borrow a tactic from the CTI industry and publish it in a static image pasted into a PDF report hidden behind a registration wall stored at a URL that vanishes during the next corporate merger.

#cti #infosec

2026-03-07

🚨New ransom group blog post!🚨

Group name: termite
Post title: City of Huntington
Info: cti.fyi/groups/termite.html

#ransomware #cti #threatintelligence #cybersecurity #infosec

2026-03-07

🚨New ransom group blog post!🚨

Group name: play
Post title: T a Solberg
Info: cti.fyi/groups/play.html

#ransomware #cti #threatintelligence #cybersecurity #infosec

2026-03-07

🚨New ransom group blog post!🚨

Group name: play
Post title: Select Tool
Info: cti.fyi/groups/play.html

#ransomware #cti #threatintelligence #cybersecurity #infosec

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst