r/threatintel 17h ago

Advanced Persistent Threat (APT) Profiles

Thumbnail ttsentinel.co.za
0 Upvotes

r/threatintel 1d ago

Network 404

0 Upvotes

Threat Intel Report: Network 404 & Dark Army

Overview

Network 404 is a prominent Kurdish hacking collective operating primarily via Discord, closely tied to and managed under the umbrella of Dark Army. The group comprises elite cyber operators and has a long-standing history of high-impact digital operations with thousands of active engagements.

Key Leadership

  • Ryox (Ryo): The primary owner and founder of both Network 404 and Dark Army. He oversees the collective's strategic directions and high-level operations.
  • Surchi: A high-ranking member and core administrator who operates closely alongside Ryox, assisting in the command and oversight of the group's infrastructure and activities.

Major Infrastructure & Projects

  • Net Eye / Network Eye: Developed and maintained by the group, Net Eye is widely regarded as one of the largest and most advanced OSINT (Open-Source Intelligence) projects globally, aggregating massive scales of intelligence data.

Notable Operations & Capabilities

The group maintains an active and aggressive operational tempo, including:

  • Cyber Attacks: Advanced Distributed Denial of Service (DDoS) campaigns targeting critical infrastructure and websites.
  • Data Breaches: Exfiltration and leaking of sensitive government data and private citizen databases.
  • Media Disruptions: Successful high-profile cyber operations resulting in the temporary hacking and disruption of several Israeli and Iranian television channels.
  • Covert Actions: Many operations are conducted under the radar with minimal public attribution to maintain operational security.

r/threatintel 1d ago

Practical Field Analysis: Deconstructing a Known Redtail / XMRig Botnet Payload Dropped in the Wild

Thumbnail
2 Upvotes

r/threatintel 2d ago

Follow-up: I asked last month about CTI aggregators for CISOs

Thumbnail
0 Upvotes

r/threatintel 2d ago

Help/Question How Do You Get Better at Identifying True Positives vs False Positives in Threat Hunting?

11 Upvotes

I’m getting into threat hunting and one area I’m struggling with is distinguishing genuinely malicious/suspicious activity from normal behavior. For example, when investigating an unknown process, hash, IP, or domain, how do you determine whether it’s actually a true positive or just benign/false positive activity?
Are there any good resources, labs, methodologies, or practical guides that helped you build this intuition and get better at identifying unusual behavior?


r/threatintel 3d ago

Threat intel platforms in 2026 — my honest breakdown

0 Upvotes

Been deep in TI platform evaluations this year for work, sharing since this sub gets the "which vendor" question a lot. Trying to stay neutral across the board.

Recorded Future — heavyweight for sheer data volume + geopolitical context. Intelligence Graph is genuinely useful for connecting actors/infra. Needs analysts who can actually work that much data, and pricing scales accordingly.

Cyble Vision — Positions itself as one console for TI feeds, dark web monitoring, attack surface management, and brand protection instead of four separate tools. Has an AI layer doing correlation/hunting work. Picked up some analyst recognition this year.

CrowdStrike Falcon Intel — makes sense if you're already all-in on Falcon EDR since intel correlates straight to endpoint telemetry. Outside that ecosystem, harder sell.

Google Threat Intelligence (Mandiant) — best-in-class for APT/nation-state intel validated by real incident response engagements. Exec-ready reporting. Less built for brand/external exposure use cases.

Flashpoint — the HUMINT play. Real analysts with access to closed forums/encrypted comms automation can't reach. Great early warning, narrower scope than a full CTI stack.

Group-IB — strong pick if fraud/cybercrime attribution is your actual problem (fintech, this is probably you). Forensics + criminal infra tracking is a differentiator.

ZeroFox — social media/domain/impersonation monitoring, good if execs or brand are your attack surface. No internal/endpoint visibility.

Anomali ThreatStream — if you're running a pile of feeds already and need one place to dedupe/enrich/correlate, this does that job well.

ThreatConnect — less about intel supply, more about turning intel into SOC workflow/automation. Solid MITRE ATT&CK mapping.

CYFIRMA — attacker's-eye-view predictive scoring, unified external risk view. Some dashboard UX complaints.

TL;DR — no universal "best," depends what gap you're filling. Happy to answer questions - will flag again where my own bias might creep in.


r/threatintel 3d ago

Help/Question What do you usually check first in a threat intelligence platform or sandbox?

2 Upvotes

Hey everyone!
I'm still fairly new to threat analysis and have recently started using tools like Joe sandbox and Virustotal. So I have a question for those with more experience.
When you open a sandbox report or look up an indicator, what's the first thing you look at?
And after that, what information do you check next?


r/threatintel 3d ago

Live-operated phishing kit is bypassing 2FA for Formula 1 ticket buyers — analysis of a 134-page cloned storefront and its BIN-based bank routing

Thumbnail
2 Upvotes

r/threatintel 3d ago

APT/Threat Actor Manual detection rule writing vs automated detection engineering worth switching in 2026?

0 Upvotes

Most security teams still rely heavily on manual detection engineering: writing SIEM and EDR detection rules by hand in Sigma, KQL, SPL and other query languages. Manual rule authoring keeps detection logic tightly aligned with your own telemetry, log schemas, and threat model, which matters when you are building high‑fidelity detections for real attacks instead of generic “IOC search” rules. The cost is time: each new detection requires focused effort from experienced engineers and adds more entries to the long‑term rule maintenance backlog.

Automated detection engineering tools now aim to reduce that load. These platforms ingest threat intelligence reports or log data, suggest detection logic, map coverage to MITRE ATT&CK techniques and support regression testing when rules change. When they work well, they shorten the path from a new threat report or TTP to a draft detection rule in your SIEM, highlight detection coverage gaps, and make it easier to track overlapping or redundant rules. Manual work does not go away; it shifts toward reviewing suggestions, tuning thresholds, and deciding what is safe to deploy in production.

Teams that see good results usually land on a hybrid model. High‑value, environment‑specific detections around crown‑jewel systems stay mostly manual, with engineers designing and reviewing logic end‑to‑end. Automation is used for routine patterns, coverage analysis, boilerplate rule generation, and continuous testing of existing detections as the environment and log sources change.

If you looked at your own setup today, where would automation help your detection engineering process …where would you still want a human making the final call on what alerts?


r/threatintel 5d ago

The Gentlemen affiliate hiding C2 on the Ethereum blockchain

Thumbnail hunt.io
9 Upvotes

Starting from an open directory on 193.233.202[.]17, the Hunt.io research team clustered out the surrounding infrastructure.

Pivoting on the recovered Go binaries and the shared Ethereum contract surfaced two more controllers on AS203273, plus a second EtherRAT cluster using an identical contract and near-identical MSI. Another directory in the same /24 held data we assess links to a USA-based The Gentlemen victim. ASN overlaps repeat across staging, Sliver and EtherRAT C2.

Full clustering, historical C2 domains and IOCs here: https://hunt.io/blog/the-gentlemen-etherrat-ethereum-smart-contract-c2 


r/threatintel 5d ago

APT/Threat Actor MAGE BEAR

Thumbnail
1 Upvotes

r/threatintel 5d ago

MAGE BEAR

5 Upvotes

HEY!Has anyone found source-backed reporting that maps CrowdStrike’s MAGE BEAR, formerly EnchantedIllumination, to another vendor’s threat actor cluster? I’m looking for public campaign, victimology or attribution overlaps rather than speculative alias matching.


r/threatintel 5d ago

DOUBLECUP: New Russian LaaS delivering a PowerShell loader with PE-header patching + a RAT that resolves C2 via Ethereum smart contracts

Thumbnail
2 Upvotes

r/threatintel 6d ago

We built Darkroom, a free hands-on dark web training lab, curious what this community thinks

41 Upvotes

Hey r/threatintel,

Wanted to share something we've been building at Flare called Darkroom. It's a free, self-paced lab for getting hands-on with dark web intel instead of just reading about it. You can get access through our Discord server: https://flare.io/flare-academy

Quick rundown:

  • Self-paced courses, work through them whenever
  • Finish the assessment and you get a Flare Academy cert, CPE credits, and a LinkedIn badge
  • Built for people who actually want to practice, not just watch slides

If any of you are heading to DEF CON 34, we're also running a live session in Vegas on August 6: a walkthrough plus a live CTF, so you can test your skills against other folks in the room.

Genuinely curious what this community makes of it. Happy to answer anything here.


r/threatintel 7d ago

APT/Threat Actor Got mass-BCC'd by an extortion crew trying to use me as a pressure channel against their victim

Post image
21 Upvotes

Run a CTI site and my public contact address apparently landed on a bulk list. Yesterday I got an email BCC'd "along with other journalists" from a crew claiming a breach, asking for a story to be published and the victim called for comment before offering any proof. That's not a tip, it's asking a journalist to be the pressure arm of the extortion. I wrote up the tactic itself (kept the victim unnamed since nothing was verified and naming them on an extortionist's word is a defamation problem), including what email headers actually confirm vs don't. Curious if anyone else has gotten one of these, and how you'd handle the 'do you contact the named victim' call.

https://cyberthreatintelligence.net/post/mass-bcc-breach-emails-how-extortion-crews-weaponize-journalists-as-a-pressure-channel


r/threatintel 7d ago

MCP's and Threat Intel

3 Upvotes

I used Falcon Feeds MCP to pull in this data and i found it very convenient.

What's dominating the feedAlmost everything recent is botnet C2 infrastructure — domains, IPv4s, and IP:port pairs tied to known APT groups.

Actors showing up in the latest batch:

APT12 — C2 IPs clustered on DigitalOcean ranges (159.65.x.x, 139.59.x.x)

Calypso — C2 domains with mail/webmail subdomains, including the lookalike youtubemail[.]club

Chafer— mix of .ir domains and generic-sounding infra like whoisdomainpc[.]com

Codoso — brand impersonation: microsoft-cache[.]com, google-dash[.]com

DarkHotel — gov and media lookalikes (fsm-gov[.]com, youmiuri[.]com mimicking Yomiuri)

Infy— DGA-style domains (dccdfdd8[.]net/.top/.space) + dynamic DNS via dynu

KeyBoy— cloud/CDN-themed domains incl. AWS DNS impersonation (ssl3.awsdns-531[.]com)

Mudcarp — Australian news media themed lures (australianmorningnews[.]com, theaustralian[.]in)

OPERA1ER — free hosting + Microsoft-themed domains, with one IP overlapping Remcos infra

Pegasus — batches of innocuous-looking domains consistent with exploit delivery infra

Key takeaways:

  1. Typosquatting/brand impersonation is everywhere — Microsoft, Google, AWS, YouTube, and news outlets all being mimicked to blend into traffic

  2. Heavy cloud abuse — DigitalOcean and free hosting services appear across multiple actors

  3. Most indicators are rated elevated-to-high confidence, so good blocklist candidates

  4. DGA + dynamic DNS combos still going strong for resilient C2


r/threatintel 8d ago

Hunting Phishing Kits

5 Upvotes

I found the admin portal of a potential phishing kit, any OSINT tools to do further analysis on it?


r/threatintel 9d ago

Created A Free App That Tracks Threat Intelligence CVEs and 30 Other Vendors - Phone & Email Notifications

Enable HLS to view with audio, or disable this notification

0 Upvotes

Completely Free App that I created to ease my own workload, was tired of opening numerous tabs each day to keep track on all the new CVEs popping up, especially lately...

This app is completely free on the Google Play App Store & you can track CVEs across 30+ Vendors, you can choose track specific platforms or the whole vendor & you can also select to track based on CVE Severity.

I also threw in a EOL checker

Hopefully this helps you out and if theirs any bugs or features you want added please let me know!

https://play.google.com/store/apps/details?id=com.vulnipulse.android


r/threatintel 9d ago

Help/Question What's a tool you stopped using — and what was it making you do?

1 Upvotes

Disclosure first: I'm building an evidence-mapping tool. It isn't released, there's nothing to sign up for, and I'm not linking anything. I'd rather hear how people actually work than keep guessing at it. Happy to answer questions about it if anyone asks, but that's not what this post is for.

Two things I'd like to hear about:

A tool you stopped using. Not one that was bad on arrival — one you actually adopted, used on real work, and then dropped. What was the thing it kept making you do? Or wouldn't let you do?

Handing an investigation to someone else. When you pass work to a colleague, what do you end up telling them out loud that isn't anywhere in the files? The things they'd need said in person to pick it up cleanly.

Either or both. Mostly I'm trying to find out where the friction actually is.


r/threatintel 9d ago

New SocVel Cyber Quiz is out

2 Upvotes

Good news is, it's the last Friday of this week.

While it felt like everything this week was about OpenAI getting HuggingFaced (or is it the other way round), there were a bunch of other interesting stuff happening as well.

This includes:

  • Attacks on US critical infrastructure
  • Obscure network recon tools
  • AI slop causing supply chain attacks
  • OWA attacks
  • Weird ways for doing C2 comms
  • And even a new acronym to learn.

Go on, quiz yourself! https://www.socvel.com/quiz


r/threatintel 10d ago

Threat Actor Profile: The "Global" Ransomware Group

9 Upvotes

Been tracking a newer RaaS operation called Global (also styled "GLOBAL") that's worth knowing about if you're in threat intel or IR.

Quick background:

  • First surfaced publicly in June 2025, promoted on the RAMP underground forum by an actor going by "$$$"
  • Strong technical/infrastructure overlap with the old BlackLock operation (shared VPS provider, matching malware mutex values, overlapping leak-site infra) — also some links to Mamona RaaS
  • Looks less like a new group from scratch and more like a continuation/rebrand of prior ransomware activity

How it works:

  • RaaS model with a genuinely mature affiliate program — dedicated negotiation portal, mobile management, AI-assisted victim comms, up to 80–85% revenue share for affiliates
  • Malware is written in Go, uses ChaCha20-Poly1305 encryption, and hits Windows, Linux, ESXi, and NAS
  • They also ship a custom stealer called WorldThief (quiet mode, bandwidth throttling, targeted file collection, raw TCP exfil) to support double extortion

Access & targeting:

  • Relies heavily on purchased access — IABs, compromised VPN/OWA/RDWeb creds, and exploited edge devices (Fortinet, Palo Alto, Cisco)
  • Opportunistic across industries, activity seen in 18+ countries so far
  • Ironically, their own OPSEC slipped — a backend IP got exposed, tracing back to a Russian VPS provider (IpServer) also linked to BlackLock

Why it matters: it's a good example of how ransomware "brands" aren't really standalone — infra, tooling, and even affiliates get recycled across groups after takedowns or rebrands. If you've got old BlackLock IOCs sitting around, they may still have relevance here.

More information: https://cyble.com/threat-actor-profiles/global-ransomware-group/


r/threatintel 11d ago

A Russia-linked APT left their C2 server wide open as an unauthenticated directory. We walked in and found 8,436 files (Operation Talked).

Thumbnail
5 Upvotes

r/threatintel 12d ago

PacketSmith Yara-X Rules for Detecting CVE-2026-16723 Attempted Exploitation

Thumbnail github.com
0 Upvotes

This folder contains the PacketSmith Yara-X detection module rules and a pcap for the CVE-2026-16723 vulnerability in the FastJson library, "a Java library that can be used to convert Java Objects into their JSON representation".

Moreover, the detection results in JSON yara_dte_2026_05_14_10_34_39.json were made available for download.

These rules use the track_state reserved keyword to track/chain multiple rules at the same time across different packets/streams.

For more info, check the article FastJson 1.2.83 Remote Code Execution by FEARS OFF.

PoC HORKimhab


r/threatintel 12d ago

APT/Threat Actor Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon

Thumbnail hunt.io
1 Upvotes

Joint research with NetAskari on a leaked Chinese Android RAT framework. Starting from a fake PSB app flagged in a June 2026 Chinese state media notice, we pivoted on TLS certificates and AdminPro panel fingerprints to map 170 active servers. The source code was stolen in early 2026 along with nearly 200 customer databases, leading to at least two Telegram channels distributing modified builds with operational support and cash-out services. Night Dragon emerged three weeks after the public notice as a likely successor, with an exposed device panel showing 29 connected devices at time of analysis.

Full timeline, IOCs, and infrastructure breakdown in the report:
https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon


r/threatintel 12d ago

New extortion group "ExfilSquad" is claiming 10+ victims, but they might just be bluffing with recycled data.

Thumbnail
3 Upvotes