π·πΊ French NGO Reporters Without Borders targeted by #Calisto in recent campaign
Sekoia #TDR analysed a recent #Calisto (aka #ColdRiver #Star Blizzard) spear-phishing campaign aimed at Reporters sans frontières and other #Ukraine-supporting organisations.
blog.sekoia.io/ngo-reporter...
04.12.2025 08:26
π 5
π 4
π¬ 1
π 0
#TDR analysts dig into a modus operandi targeting the hospitality industry and the related cybercrime ecosystem that facilitates #phishing and #fraud campaigns.
blog.sekoia.io/phishing-cam...
06.11.2025 10:27
π 5
π 3
π¬ 1
π 0
After our initial #PolarEdge #botnet write-up, weβre happy to announce the second part: βDefrosting PolarEdgeβs Backdoor,β a full technical deep-dive into its TLS-based implant.
blog.sekoia.io/polaredge-ba...
14.10.2025 13:35
π 2
π 3
π¬ 1
π 0
Technical Threat Researcher β Sekoia.io β Permanent contract β Fully-remote
Sekoia.io is looking for a Technical Threat Researcher!
Je recherche un Threat Researcher pour lβΓ©quipe TDR de @sekoia.io !
Vous aimez faire des rΓ¨gles #Sigma et #Yara ? Vous adorez pivoter et traquer les infrastructures (C2) dβattaques des cybercriminels ?
Alors cette offre dβemploi est faite pour vous !
www.welcometothejungle.com/en/companies...
06.10.2025 17:26
π 2
π 1
π¬ 0
π 0
Key takeaways:
βοΈ API exploitation: attackers leverage an exposed /cgi endpoint to push malicious SMS without authentication
π Scale of exposure: over 18,000 routers accessible on the internet; 572 confirmed vulnerable
02.10.2025 13:56
π 1
π 1
π¬ 1
π 0
π± Silent Smishing: The Hidden Abuse of Cellular Router APIs
Our latest #CTI investigation from Sekoia #TDR team uncovers a novel #smishing vector abusing Milesight industrial cellular router APIs to send phishing #SMS at scale.
blog.sekoia.io/silent-smish...
02.10.2025 13:56
π 6
π 4
π¬ 1
π 0
π» #APT28 β Operation Phantom Net Voxel: deep-dive into the latest spear-phishing campaign targeting Ukrainian military administrative staff.
blog.sekoia.io/apt28-operat...
16.09.2025 12:59
π 2
π 2
π¬ 1
π 1
[Threat investigation alert π¨] Predators for Hire: A Global Overview of Commercial Surveillance Vendors
β‘οΈ blog.sekoia.io/predators-fo...
02.09.2025 09:55
π 2
π 4
π¬ 1
π 0
π₯ Hot summer, sizzling crypto... and scammers turning up the heat π₯
Back in March, Sekoia #TDR team published a deep-dive report on a #Lazarus cluster we dubbed #ClickFake Interview, leveraging the #ClickFix technique in their #ContagiousInterview campaign.
21.07.2025 14:40
π 1
π 1
π¬ 1
π 0
You can find the phishing kit sheets on our blog: blog.sekoia.io/global-analy...
And on our Community GitHub: github.com/SEKOIA-IO/Co...
08.07.2025 07:53
π 1
π 2
π¬ 0
π 0
These sheets aim to assist SOC analysts in detecting and investigating #AitM #phishing compromises by offering context, technical details, infrastructure overview, detection opportunities, and more.
All are available in the PDF report and our Community GitHub.
08.07.2025 07:53
π 1
π 2
π¬ 1
π 0
A few weeks ago, we published our global analysis of Adversary-in-the-Middle #phishing threats, providing actionable intelligence on multiple #AitM phishing kits.
This report includes 11 sheets covering the most widespread #AitM phishing kits as of Q1 2025.
08.07.2025 07:53
π 5
π 2
π¬ 1
π 0
π Our latest #TDR report delivers an in-depth analysis of Adversary-in-the-Middle (#AitM) #phishing threats - targeting Microsoft 365 and Google accounts - and their ecosystem.
This report shares actionable intelligence to help analysts detect and investigate AitM phishing.
11.06.2025 08:32
π 10
π 7
π¬ 1
π 0
Our new report describes one of the latest observed infection chains (delivering #AsyncRAT) relying on the #Cloudflare tunnel infrastructure and the attackerβs #TTPs with a principal focus on detection opportunities.
blog.sekoia.io/detecting-mu...
23.04.2025 08:33
π 2
π 1
π¬ 0
π 0
Since the apparition of the #Interlock ransomware, the Sekoia #TDR team observed its operators evolving, improving their toolset (#LummaStealer and #BerserkStealer), and leveraging new techniques such as #ClickFix to deploy the ransomware payload.
blog.sekoia.io/interlock-ra...
16.04.2025 09:13
π 2
π 5
π¬ 0
π 1
π It's not about a CTI investigation or a Detection Engineering topic, but today we are happy to announce that Sekoia.io has raised β¬26m!
www.sekoia.io/en/presse/se...
09.04.2025 13:16
π 4
π 1
π¬ 0
π 0
Retrouvez moi toute la journΓ©e au Forum INCYBER Europe (#FIC2025) pour Sekoia.io ! Rendez-vous stand #A17 pour Γ©changer !
02.04.2025 07:30
π 2
π 0
π¬ 0
π 0
π°π΅ Sekoia #TDR team investigated a malicious campaign that employs fake job interview websites to deliver backdoors on Windows and macOS - #GolangGhost using #ClickFix tactic. Dubbed #ClickFake Interview, this campaign has been attributed to #Lazarus APT
blog.sekoia.io/clickfake-in...
31.03.2025 09:27
π 5
π 2
π¬ 0
π 0
The conclusion (part three) of our series on #DetectionEngineering is finally here! buff.ly/dijB0fy
10.03.2025 16:48
π 3
π 1
π¬ 0
π 0
#ClearFake variant is now spreading #Rhadamanthys Stealer via #Emmenhtal Loader.
cc @plebourhis.bsky.social @sekoia.io
1. ClearFake framework is injected on compromised WordPress and relies on EtherHiding
2. The #ClickFix lure uses a fake Cloudflare Turnstile with unusual web traffic
β¬οΈ
06.03.2025 10:50
π 3
π 2
π¬ 2
π 0
Using our #honeypots, we uncovered an unreported #botnet that has been operational since at least the end of November 2023. This #PolarEdge botnet has been focusing on #edge devices, particularly those made by #Cisco, #Asus, #QNAP, and #Synology.
https://buff.ly/4ibOEo8
25.02.2025 13:22
π 6
π 4
π¬ 0
π 0
Cyber threats impacting the financial sector: focus on the main actors
We're thrilled to announce the release of the latest strategic report by Sekoia #TDR. This analysis highlights key cyber threats to the #financial sector in 2024.
https://buff.ly/3D3IZl7
24.02.2025 09:27
π 5
π 2
π¬ 0
π 1
Detection engineering at scale: one step closer (part two)
Discover the power of detection engineering and how it can help scale your cybersecurity projects efficiently.
π Large-scale detection engineering: part two! π
In this article, we explore an innovative approach that transforms the execution of automated actions via CI/CD pipelines, enabling effective scaling and alignment with developer and DevOps practices.
04.02.2025 13:51
π 3
π 1
π¬ 0
π 0
Sr Technical Threat Researcher - Sekoia.io - CDI - TΓ©lΓ©travail total
Sekoia.io recrute un(e) Sr Technical Threat Researcher !
π¨To strengthen the #investigation and #detection capabilities of the Sekoia.io Threat Detection & Research (TDR) team, we are looking for a Senior Technical Threat Researcher!
www.welcometothejungle.com/fr/companies...
#CTI #DetectionEngineering
29.01.2025 13:59
π 5
π 4
π¬ 0
π 0
TDR analysts analysed the supply chain attack targeting Chrome browser extensions, which potentially affected hundreds of thousands of end users in December 2024.
https://buff.ly/4auQ0HN
22.01.2025 14:30
π 8
π 4
π¬ 1
π 1
Around 1,000 malicious domains are hosting webpages impersonating Reddit and WeTransfer, redirecting users to download password-protected archives
These archives contain an AutoIT dropper, we internally named #SelfAU3 Dropper at @sekoia.io, which executes #Lumma Stealer
IoCs β¬οΈ
20.01.2025 18:13
π 9
π 6
π¬ 2
π 0