In September 2022, attendees at the inaugural @labscon_io heard about an actor I described then as "one of the most prolific, most deeply connected, and most technically advanced actors around". Events this week were a reminder that the video never went out, so here it is 👇
Information contained in the recent leaks overlaps directly with the actor we track as Red Scylla, plus a few adjacent clusters, such as DeepCliff and Poison Carp, which I talk about here, along with their use of #plugx, #winnti & #shadowpad: #threatintelsentinelone.com/labs/labscon-r…
"There is literally no threat actor we track in 2022 that appears to have a more global remit". We attributed intrusions in at least 35 countries to Red Scylla. @bkMSFT nailed it here:
Leaked information also validates the same set of sectors we often saw them target, with a big focus on telecommunications:
The Chengdu scene is one of the most well established and historic locations of the infosec scene - it's no surprise that many founders have shared 15+ years of relationships.
These relationships, technical indicators, and related public reporting from @TrendMicroRSRCH @RecordedFuture and others, drew many links to i-Soon, and painted a picture of them as one of the most pervasive, capable China-based actors in recent history.
@TrendMicroRSRCH @RecordedFuture Direct video link:
• • •
Missing some Tweet in this thread? You can try to
force a refresh
Only about two months later than I originally planned, but here we go. I'll summarise areas we are hiring into in the thread 👇, along with a steer on experience and location where possible (all UK, but happy to make introductions elsewhere).
We have space for a mix of junior and experienced folks in most roles, and there is also a mix of location and partial remote working options depending on the role, so please DM to ask clarification questions or to ask about applying :) A little background on the team:
Cyber Threat Operations is PwC's front-line technical security services group, responsible for a portfolio of blue & red team services to global clients. Blue includes subscription & bespoke #threatintel & research services, short-term & managed endpoint/network threat hunting,