Resources

Blog

Get our latest research in your inbox

New threat intelligence, detection engineering, and red team write-ups, delivered when we publish.

Featured Research
More Posts

Browsing Outlook As You: Inside an Unreported ARToken / EvilTokens Phishing Tenant

We captured and reverse-engineered the client build of ARToken, an operator panel for a Microsoft 365 / Entra ID token-theft operation. It phishes the device-code authentication flow, steals access, refresh, and Primary Refresh Tokens, and drives the victim tenant from a dashboard with 80+ API endpoints. Cisco Talos ties ARToken to the EvilTokens phishing-as-a-service ecosystem. The tenant we analysed is not in Talos's published IOCs, so it is a previously-unreported deployment, complete with a bundled anti-detect browser for offline session replay.

One Token, 88 Repos: Reading the Accenture PwnForums Listing

A threat actor named 888 is selling roughly 35GB of alleged Accenture data on PwnForums: source code, RSA/SSH keys, Azure Personal Access Tokens, and Azure Storage keys, pulled from an Azure DevOps organization called LISTeamRepos. We read the listing directly and cross-referenced it against the six-million-line directory manifest the actor posted as proof. The access method is confirmed, a valid Personal Access Token used exactly as intended. How that token leaked is not.

The Credential Nobody Deleted: How Icarus Raided Salesforce Through a Forgotten Klue Integration

A dormant service account nobody decommissioned let the Icarus extortion group push malicious code into Klue's integration layer, harvest OAuth tokens, and quietly drain Salesforce CRM data from downstream victims over a 24-hour window. Here is how the supply chain attack unfolded and what the forensic artifacts reveal.

From One Hash to a Russian MaaS Empire: Hunting MuddyWater's DenoDoor

A single VirusTotal hash led us to the full deobfuscation of MuddyWater's DenoDoor backdoor, 40 plus active C2 nodes across two bulletproof ASNs, a second live DenoDoor cluster delivering zero-detection AI-themed lures, and confirmation that Iranian state actors are renting infrastructure from a Russian criminal Malware-as-a-Service operation.

The Full Account: TeamPCP's Mini Shai-Hulud Supply Chain Campaign, Waves 1 & 2

Complete forensic analysis of TeamPCP's supply chain attack: 2,650+ compromised GitHub repos, 16+ MB credential theft, and undetected Rust RAT deployment.

Bluekit PhaaS: The White-Label Supply Chain the Newswire Missed

Bluekit is not just another Phishing-as-a-Service platform. It is a multi-tenant white-label PhaaS engine, and buried inside a JavaScript bundle we pulled from its Tor hidden service is the configuration for a second brand, SnagX, a Chinese-market reseller charging 2.8x Bluekit's prices to a completely separate operator base.

Hunting a PhaaS Operator: From Phishing Email to Lagos, Nigeria

A phishing email landed in an employee's inbox. SPF passed. DKIM passed. DMARC passed. Spam score: 0.085/1.0. What started as a routine triage turned into a multi-day offensive hunt.

Bybit Hack Considerations

Analysis of the cryptocurrency exchange breach, highlighting supply chain security and browser-based attack vulnerabilities.

threat intelligence

APT38's New Game: Targeting Devs with Fake Coding Challenges

North Korean threat actors are leveraging GitHub to target software developers through fake job opportunities and technical interviews.

detection engineering

Conversion from Sigma Community to KQL That Works

Our functional Sigma-to-KQL conversion utility compatible with the Sigma Community repository.

Managing Threat Hunting Content via APIs in Microsoft Sentinel

API tools designed to streamline content management for threat hunting operations within Microsoft Sentinel.