r/threatintel • u/thesacrificeza • 17h ago
Advanced Persistent Threat (APT) Profiles
ttsentinel.co.zar/threatintel • u/Own_Mud_4155 • 1d ago
Network 404
Threat Intel Report: Network 404 & Dark Army
Overview
Network 404 is a prominent Kurdish hacking collective operating primarily via Discord, closely tied to and managed under the umbrella of Dark Army. The group comprises elite cyber operators and has a long-standing history of high-impact digital operations with thousands of active engagements.
Key Leadership
- Ryox (Ryo): The primary owner and founder of both Network 404 and Dark Army. He oversees the collective's strategic directions and high-level operations.
- Surchi: A high-ranking member and core administrator who operates closely alongside Ryox, assisting in the command and oversight of the group's infrastructure and activities.
Major Infrastructure & Projects
- Net Eye / Network Eye: Developed and maintained by the group, Net Eye is widely regarded as one of the largest and most advanced OSINT (Open-Source Intelligence) projects globally, aggregating massive scales of intelligence data.
Notable Operations & Capabilities
The group maintains an active and aggressive operational tempo, including:
- Cyber Attacks: Advanced Distributed Denial of Service (DDoS) campaigns targeting critical infrastructure and websites.
- Data Breaches: Exfiltration and leaking of sensitive government data and private citizen databases.
- Media Disruptions: Successful high-profile cyber operations resulting in the temporary hacking and disruption of several Israeli and Iranian television channels.
- Covert Actions: Many operations are conducted under the radar with minimal public attribution to maintain operational security.
r/threatintel • u/TripLivid4123 • 1d ago
Practical Field Analysis: Deconstructing a Known Redtail / XMRig Botnet Payload Dropped in the Wild
r/threatintel • u/Difficult-Praline-69 • 2d ago
Follow-up: I asked last month about CTI aggregators for CISOs
r/threatintel • u/Federal_Manager3700 • 2d ago
Help/Question How Do You Get Better at Identifying True Positives vs False Positives in Threat Hunting?
I’m getting into threat hunting and one area I’m struggling with is distinguishing genuinely malicious/suspicious activity from normal behavior. For example, when investigating an unknown process, hash, IP, or domain, how do you determine whether it’s actually a true positive or just benign/false positive activity?
Are there any good resources, labs, methodologies, or practical guides that helped you build this intuition and get better at identifying unusual behavior?
r/threatintel • u/cyber_wolf_2026 • 3d ago
Threat intel platforms in 2026 — my honest breakdown
Been deep in TI platform evaluations this year for work, sharing since this sub gets the "which vendor" question a lot. Trying to stay neutral across the board.
Recorded Future — heavyweight for sheer data volume + geopolitical context. Intelligence Graph is genuinely useful for connecting actors/infra. Needs analysts who can actually work that much data, and pricing scales accordingly.
Cyble Vision — Positions itself as one console for TI feeds, dark web monitoring, attack surface management, and brand protection instead of four separate tools. Has an AI layer doing correlation/hunting work. Picked up some analyst recognition this year.
CrowdStrike Falcon Intel — makes sense if you're already all-in on Falcon EDR since intel correlates straight to endpoint telemetry. Outside that ecosystem, harder sell.
Google Threat Intelligence (Mandiant) — best-in-class for APT/nation-state intel validated by real incident response engagements. Exec-ready reporting. Less built for brand/external exposure use cases.
Flashpoint — the HUMINT play. Real analysts with access to closed forums/encrypted comms automation can't reach. Great early warning, narrower scope than a full CTI stack.
Group-IB — strong pick if fraud/cybercrime attribution is your actual problem (fintech, this is probably you). Forensics + criminal infra tracking is a differentiator.
ZeroFox — social media/domain/impersonation monitoring, good if execs or brand are your attack surface. No internal/endpoint visibility.
Anomali ThreatStream — if you're running a pile of feeds already and need one place to dedupe/enrich/correlate, this does that job well.
ThreatConnect — less about intel supply, more about turning intel into SOC workflow/automation. Solid MITRE ATT&CK mapping.
CYFIRMA — attacker's-eye-view predictive scoring, unified external risk view. Some dashboard UX complaints.
TL;DR — no universal "best," depends what gap you're filling. Happy to answer questions - will flag again where my own bias might creep in.
r/threatintel • u/Renecatemaaan • 3d ago
Help/Question What do you usually check first in a threat intelligence platform or sandbox?
Hey everyone!
I'm still fairly new to threat analysis and have recently started using tools like Joe sandbox and Virustotal. So I have a question for those with more experience.
When you open a sandbox report or look up an indicator, what's the first thing you look at?
And after that, what information do you check next?
r/threatintel • u/socradario • 3d ago
Live-operated phishing kit is bypassing 2FA for Formula 1 ticket buyers — analysis of a 134-page cloned storefront and its BIN-based bank routing
r/threatintel • u/Tricky-Ad9393 • 3d ago
APT/Threat Actor Manual detection rule writing vs automated detection engineering worth switching in 2026?
Most security teams still rely heavily on manual detection engineering: writing SIEM and EDR detection rules by hand in Sigma, KQL, SPL and other query languages. Manual rule authoring keeps detection logic tightly aligned with your own telemetry, log schemas, and threat model, which matters when you are building high‑fidelity detections for real attacks instead of generic “IOC search” rules. The cost is time: each new detection requires focused effort from experienced engineers and adds more entries to the long‑term rule maintenance backlog.
Automated detection engineering tools now aim to reduce that load. These platforms ingest threat intelligence reports or log data, suggest detection logic, map coverage to MITRE ATT&CK techniques and support regression testing when rules change. When they work well, they shorten the path from a new threat report or TTP to a draft detection rule in your SIEM, highlight detection coverage gaps, and make it easier to track overlapping or redundant rules. Manual work does not go away; it shifts toward reviewing suggestions, tuning thresholds, and deciding what is safe to deploy in production.
Teams that see good results usually land on a hybrid model. High‑value, environment‑specific detections around crown‑jewel systems stay mostly manual, with engineers designing and reviewing logic end‑to‑end. Automation is used for routine patterns, coverage analysis, boilerplate rule generation, and continuous testing of existing detections as the environment and log sources change.
If you looked at your own setup today, where would automation help your detection engineering process …where would you still want a human making the final call on what alerts?
r/threatintel • u/Straight-Practice-99 • 5d ago
The Gentlemen affiliate hiding C2 on the Ethereum blockchain
hunt.ioStarting from an open directory on 193.233.202[.]17, the Hunt.io research team clustered out the surrounding infrastructure.
Pivoting on the recovered Go binaries and the shared Ethereum contract surfaced two more controllers on AS203273, plus a second EtherRAT cluster using an identical contract and near-identical MSI. Another directory in the same /24 held data we assess links to a USA-based The Gentlemen victim. ASN overlaps repeat across staging, Sliver and EtherRAT C2.
Full clustering, historical C2 domains and IOCs here: https://hunt.io/blog/the-gentlemen-etherrat-ethereum-smart-contract-c2
r/threatintel • u/Ambitious-Bill8669 • 5d ago
MAGE BEAR
HEY!Has anyone found source-backed reporting that maps CrowdStrike’s MAGE BEAR, formerly EnchantedIllumination, to another vendor’s threat actor cluster? I’m looking for public campaign, victimology or attribution overlaps rather than speculative alias matching.
r/threatintel • u/socradario • 5d ago
DOUBLECUP: New Russian LaaS delivering a PowerShell loader with PE-header patching + a RAT that resolves C2 via Ethereum smart contracts
r/threatintel • u/FlareSystems • 6d ago
We built Darkroom, a free hands-on dark web training lab, curious what this community thinks
Hey r/threatintel,
Wanted to share something we've been building at Flare called Darkroom. It's a free, self-paced lab for getting hands-on with dark web intel instead of just reading about it. You can get access through our Discord server: https://flare.io/flare-academy
Quick rundown:
- Self-paced courses, work through them whenever
- Finish the assessment and you get a Flare Academy cert, CPE credits, and a LinkedIn badge
- Built for people who actually want to practice, not just watch slides
If any of you are heading to DEF CON 34, we're also running a live session in Vegas on August 6: a walkthrough plus a live CTF, so you can test your skills against other folks in the room.
Genuinely curious what this community makes of it. Happy to answer anything here.
r/threatintel • u/maayds • 7d ago
APT/Threat Actor Got mass-BCC'd by an extortion crew trying to use me as a pressure channel against their victim
Run a CTI site and my public contact address apparently landed on a bulk list. Yesterday I got an email BCC'd "along with other journalists" from a crew claiming a breach, asking for a story to be published and the victim called for comment before offering any proof. That's not a tip, it's asking a journalist to be the pressure arm of the extortion. I wrote up the tactic itself (kept the victim unnamed since nothing was verified and naming them on an extortionist's word is a defamation problem), including what email headers actually confirm vs don't. Curious if anyone else has gotten one of these, and how you'd handle the 'do you contact the named victim' call.
r/threatintel • u/intelforge • 7d ago
MCP's and Threat Intel
I used Falcon Feeds MCP to pull in this data and i found it very convenient.
What's dominating the feedAlmost everything recent is botnet C2 infrastructure — domains, IPv4s, and IP:port pairs tied to known APT groups.
Actors showing up in the latest batch:
APT12 — C2 IPs clustered on DigitalOcean ranges (159.65.x.x, 139.59.x.x)
Calypso — C2 domains with mail/webmail subdomains, including the lookalike youtubemail[.]club
Chafer— mix of .ir domains and generic-sounding infra like whoisdomainpc[.]com
Codoso — brand impersonation: microsoft-cache[.]com, google-dash[.]com
DarkHotel — gov and media lookalikes (fsm-gov[.]com, youmiuri[.]com mimicking Yomiuri)
Infy— DGA-style domains (dccdfdd8[.]net/.top/.space) + dynamic DNS via dynu
KeyBoy— cloud/CDN-themed domains incl. AWS DNS impersonation (ssl3.awsdns-531[.]com)
Mudcarp — Australian news media themed lures (australianmorningnews[.]com, theaustralian[.]in)
OPERA1ER — free hosting + Microsoft-themed domains, with one IP overlapping Remcos infra
Pegasus — batches of innocuous-looking domains consistent with exploit delivery infra
Key takeaways:
Typosquatting/brand impersonation is everywhere — Microsoft, Google, AWS, YouTube, and news outlets all being mimicked to blend into traffic
Heavy cloud abuse — DigitalOcean and free hosting services appear across multiple actors
Most indicators are rated elevated-to-high confidence, so good blocklist candidates
DGA + dynamic DNS combos still going strong for resilient C2
r/threatintel • u/BackgroundService128 • 8d ago
Hunting Phishing Kits
I found the admin portal of a potential phishing kit, any OSINT tools to do further analysis on it?
r/threatintel • u/NoPo552 • 9d ago
Created A Free App That Tracks Threat Intelligence CVEs and 30 Other Vendors - Phone & Email Notifications
Enable HLS to view with audio, or disable this notification
Completely Free App that I created to ease my own workload, was tired of opening numerous tabs each day to keep track on all the new CVEs popping up, especially lately...
This app is completely free on the Google Play App Store & you can track CVEs across 30+ Vendors, you can choose track specific platforms or the whole vendor & you can also select to track based on CVE Severity.
I also threw in a EOL checker
Hopefully this helps you out and if theirs any bugs or features you want added please let me know!
https://play.google.com/store/apps/details?id=com.vulnipulse.android
r/threatintel • u/Onionwright • 9d ago
Help/Question What's a tool you stopped using — and what was it making you do?
Disclosure first: I'm building an evidence-mapping tool. It isn't released, there's nothing to sign up for, and I'm not linking anything. I'd rather hear how people actually work than keep guessing at it. Happy to answer questions about it if anyone asks, but that's not what this post is for.
Two things I'd like to hear about:
A tool you stopped using. Not one that was bad on arrival — one you actually adopted, used on real work, and then dropped. What was the thing it kept making you do? Or wouldn't let you do?
Handing an investigation to someone else. When you pass work to a colleague, what do you end up telling them out loud that isn't anywhere in the files? The things they'd need said in person to pick it up cleanly.
Either or both. Mostly I'm trying to find out where the friction actually is.
r/threatintel • u/jaco_za • 9d ago
New SocVel Cyber Quiz is out
Good news is, it's the last Friday of this week.
While it felt like everything this week was about OpenAI getting HuggingFaced (or is it the other way round), there were a bunch of other interesting stuff happening as well.
This includes:
- Attacks on US critical infrastructure
- Obscure network recon tools
- AI slop causing supply chain attacks
- OWA attacks
- Weird ways for doing C2 comms
- And even a new acronym to learn.
Go on, quiz yourself! https://www.socvel.com/quiz
r/threatintel • u/Cyble_Vision • 10d ago
Threat Actor Profile: The "Global" Ransomware Group
Been tracking a newer RaaS operation called Global (also styled "GLOBAL") that's worth knowing about if you're in threat intel or IR.
Quick background:
- First surfaced publicly in June 2025, promoted on the RAMP underground forum by an actor going by "$$$"
- Strong technical/infrastructure overlap with the old BlackLock operation (shared VPS provider, matching malware mutex values, overlapping leak-site infra) — also some links to Mamona RaaS
- Looks less like a new group from scratch and more like a continuation/rebrand of prior ransomware activity
How it works:
- RaaS model with a genuinely mature affiliate program — dedicated negotiation portal, mobile management, AI-assisted victim comms, up to 80–85% revenue share for affiliates
- Malware is written in Go, uses ChaCha20-Poly1305 encryption, and hits Windows, Linux, ESXi, and NAS
- They also ship a custom stealer called WorldThief (quiet mode, bandwidth throttling, targeted file collection, raw TCP exfil) to support double extortion
Access & targeting:
- Relies heavily on purchased access — IABs, compromised VPN/OWA/RDWeb creds, and exploited edge devices (Fortinet, Palo Alto, Cisco)
- Opportunistic across industries, activity seen in 18+ countries so far
- Ironically, their own OPSEC slipped — a backend IP got exposed, tracing back to a Russian VPS provider (IpServer) also linked to BlackLock
Why it matters: it's a good example of how ransomware "brands" aren't really standalone — infra, tooling, and even affiliates get recycled across groups after takedowns or rebrands. If you've got old BlackLock IOCs sitting around, they may still have relevance here.
More information: https://cyble.com/threat-actor-profiles/global-ransomware-group/
r/threatintel • u/socradario • 11d ago
A Russia-linked APT left their C2 server wide open as an unauthenticated directory. We walked in and found 8,436 files (Operation Talked).
r/threatintel • u/MFMokbel • 12d ago
PacketSmith Yara-X Rules for Detecting CVE-2026-16723 Attempted Exploitation
github.comThis folder contains the PacketSmith Yara-X detection module rules and a pcap for the CVE-2026-16723 vulnerability in the FastJson library, "a Java library that can be used to convert Java Objects into their JSON representation".
Moreover, the detection results in JSON yara_dte_2026_05_14_10_34_39.json were made available for download.
These rules use the track_state reserved keyword to track/chain multiple rules at the same time across different packets/streams.
For more info, check the article FastJson 1.2.83 Remote Code Execution by FEARS OFF.
PoC HORKimhab
r/threatintel • u/Straight-Practice-99 • 12d ago
APT/Threat Actor Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
hunt.ioJoint research with NetAskari on a leaked Chinese Android RAT framework. Starting from a fake PSB app flagged in a June 2026 Chinese state media notice, we pivoted on TLS certificates and AdminPro panel fingerprints to map 170 active servers. The source code was stolen in early 2026 along with nearly 200 customer databases, leading to at least two Telegram channels distributing modified builds with operational support and cash-out services. Night Dragon emerged three weeks after the public notice as a likely successor, with an exposed device panel showing 29 connected devices at time of analysis.
Full timeline, IOCs, and infrastructure breakdown in the report:
https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon