Ariel Jungheit Profile picture
Life under the sea was so much easier | Threat Research @harfanglab | Maker | Tweets are my own
Jun 16 4 tweets 2 min read
Dropping new research - this time on recent #XDSpy operations. Out of hundreds of LNK files leveraging ZDI-CAN-25373, we isolated a tiny cluster using an additional LNK parsing trick, leading us to uncover a multi-stage infection chain actively targeting government entities Image Through hunting and pivoting, we identified the likely payload: XDigo, XDSpy's Go based malware deployed against a governmental target in Belarus. We also mapped additional infrastructure showing multiple connections and ties across past campaigns Image
Oct 19, 2023 8 tweets 2 min read
Some context on #WeRedEvils, an Israeli hacktivist group that recently made headlines by disrupting Tehran's power supply: 🧵 (1/8) Image #WeRedEvils, led by an individual known as 'Vlad,' boasts a diverse background. Vlad specialised in disrupting gambling, betting, and drugs services who reportedly defrauded people of their money, by crippling their online and social media presence. (2/8)