Bias in CTI attribution is harder to shake than you think.
The DPRK/cybercrime boundary has always been blurry, but today I got a personal reminder of just how biased I still am.
Here's what happened:
1⃣ First look: I encountered a compiled AppleScript malware (Zoom Audio SDK Update.scpt, MD5: 743f60f02d352201e2df36805f1ec00d). I suspected a link to `APT38` due to their known use of similar social engineering lures, including ClickFix techniques.
2⃣ Deeper dive: I checked the 2nd and 3rd stage payloads. I told myself they'd just changed their tradecraft. Still convinced it was DPRK.
3⃣ Final payload: The last-stage AppleScript was focused on stealing a wide range of sensitive data from the victim. Something felt off. I ran it through my IOC search bot. Result: `SHub Infostealer`, known crimeware, nothing to do with DPRK. DataDog published a solid write-up on it: 🔗 securitylabs.datadoghq.com/articles/tech-…
If I had stopped at stage 1 or 2, I would have published a completely wrong attribution. Attribution requires full context. Our prior knowledge is a lens that helps us work faster, but it's also a blindfold. The more deeply you specialize in one actor, the more you'll see that actor everywhere. Stay humble. Follow the evidence to the end.
Infrastructure pivots have identified a high-confidence link to DPRK-nexus activity (#TA444).
The #Axios C2 shares a unique ETag with 23.254.167[.]216 also hosted on Hostwinds AS54290. This specific IP is a documented artifact of the "JustJoin" campaigns from @Huntio.
the commit that introduced the ci/cd vuln—used as the initial access vector in the s1ngularity attack—was co-authored by claude! first real incident from insecure ai-written code? gpt-5 and even 4o flagged it instantly, but somehow it slipped past their ai code review 🤔
What a PR github.com/nrwl/nx/pull/3… by @NxDevTools
This one was written by AI and introduces a critical PR title injection that could allow anyone to steal their NPM token with a little privesc.
How is stuff like this still shipping?
#Odyssey new macOS malware #Stealer 🍎
- Just another #AMOS fork. 🤔
- C2: poseidon[.]cool
- Saves stolen data in `/tmp/pizda/`
- More structured Apple Notes exfiltration
- Uses AppleScript (`osascript`) instead of pure shell.
@osint_barbie@bing FYI I’ve also observed distribution via Facebook Advertisements (mostly targeting LLM apps). I found you can Meta exposes all their ads which is great for finding more distributions
facebook.com/ads/library/
New #macOS#stealer with 0 VT hits
Written in C++, it gathers info about the system, collects keychain data, browser data & crypto wallets (Chrome & Brave)
Cool things:
1. Uses uploadcare.com to exfiltrate data
2. Please put your psw to access XSS forum (??!!?)
@UK_Daniel_Card I looked at these briefly and noted some hosting providers that looked like small internet gateways, so it may be worth checking those. It is a little annoying when people provide Mullvad VPN IoCs without disclaiming them as such
176 Followers 3K FollowingSecurity Engineer - Incident Response @StarknetFndn | All views here are my own. #DFIR Ex - @Mozilla, @Livenation, @Ticketmaster
3K Followers 555 FollowingIncident Responder & @TheDFIRReport Member • Hunting and dissecting smart creatures called malware, doing forensics between whiles…
225K Followers 953 FollowingResearcher and a best-selling author. Keynote talks at RSA, Black Hat & DEF CON. TED Speaker. Chief Research Officer at Sensofusion.
205K Followers 12 FollowingFollow what the CEOs and other executives from tech companies do on X. DMs open for feedback and requests. Powered by @Kalshi
353 Followers 34 FollowingCharting the technical roadmap to SL5 optionality for frontier AI labs. A multistakeholder initiative uniting AI labs, national security leaders & engineers.
6K Followers 297 Followingp/hd | Big RL energy | RS @ big company (not speaking for the company though) | Prev. {Meta FAIR; Gym(nasium)} | Glory to Mankind
35K Followers 403 FollowingHead of Policy @AIPolicyNetwork. Ohioan. World champion forecaster. Former data scientist. Protecting liberty and prosperity in the age of superintelligence.
40K Followers 3K FollowingLead Engineer at @AIPRMcorp (https://t.co/fepyWfV4kA) and @lrt_co (https://t.co/p7LEvIKduG), building AIPRM for ChatGPT & Claude. Signal @ btibor.91
558K Followers 200 FollowingThoughts triggering thoughts. No label required. Learning on the go. Novel in progress. Public feed: general musing. Private feed: Tokyo diary.
2K Followers 322 FollowingInfostealer hunter by night, threat actors’ headache 24/7. I track C2s, ruin botnets, and make cybercriminals rethink their life choices