Kris McConkey Profile picture
Feb 22 7 tweets 3 min read Read on X
In September 2022, attendees at the inaugural @labscon_io heard about an actor I described then as "one of the most prolific, most deeply connected, and most technically advanced actors around". Events this week were a reminder that the video never went out, so here it is 👇
Information contained in the recent leaks overlaps directly with the actor we track as Red Scylla, plus a few adjacent clusters, such as DeepCliff and Poison Carp, which I talk about here, along with their use of #plugx, #winnti & #shadowpad: #threatintelsentinelone.com/labs/labscon-r…
"There is literally no threat actor we track in 2022 that appears to have a more global remit". We attributed intrusions in at least 35 countries to Red Scylla. @bkMSFT nailed it here:
Image
Leaked information also validates the same set of sectors we often saw them target, with a big focus on telecommunications: Image
The Chengdu scene is one of the most well established and historic locations of the infosec scene - it's no surprise that many founders have shared 15+ years of relationships. Image
These relationships, technical indicators, and related public reporting from @TrendMicroRSRCH @RecordedFuture and others, drew many links to i-Soon, and painted a picture of them as one of the most pervasive, capable China-based actors in recent history. Image
@TrendMicroRSRCH @RecordedFuture Direct video link:

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Kris McConkey

Kris McConkey Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @smoothimpact

Apr 23, 2019
Only about two months later than I originally planned, but here we go. I'll summarise areas we are hiring into in the thread 👇, along with a steer on experience and location where possible (all UK, but happy to make introductions elsewhere).
We have space for a mix of junior and experienced folks in most roles, and there is also a mix of location and partial remote working options depending on the role, so please DM to ask clarification questions or to ask about applying :) A little background on the team:
Cyber Threat Operations is PwC's front-line technical security services group, responsible for a portfolio of blue & red team services to global clients. Blue includes subscription & bespoke #threatintel & research services, short-term & managed endpoint/network threat hunting,
Read 18 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(