Bryan's Avatar

Bryan

@r00tx

DFIR | Threat Hunting | Security Analyst | Liverpool & FC Dallas

94
Followers
133
Following
5
Posts
02.06.2023
Joined
Posts Following

Latest posts by Bryan @r00tx

Post image Post image

what a terrible day to be literate

04.12.2024 16:03 πŸ‘ 32 πŸ” 3 πŸ’¬ 4 πŸ“Œ 1

Interesting, Bluesky gave me the notification saying you redeemed my invite code πŸ˜…
Anyways, was just cool to see another trance fan! πŸ™‚

20.07.2023 13:51 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Ayo that's wild. You snagged my invite posted on twitter and you're #trancefamily?! Crazy to see another trance fan lol
Welcome!

20.07.2023 02:00 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

Crazy how beavers build these

22.06.2023 14:15 πŸ‘ 910 πŸ” 126 πŸ’¬ 21 πŸ“Œ 5
Post image
08.06.2023 02:20 πŸ‘ 146 πŸ” 52 πŸ’¬ 7 πŸ“Œ 0

Was just talking with someone on how we thought Clop would handle the whole MOVEit thing if it truly was them. We called that they’d put it on the victims to contact them lol

Too many victims here for Clop to handle reaching out to each one.

07.06.2023 03:31 πŸ‘ 4 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

LOLBins illustrated...

04.06.2023 20:50 πŸ‘ 23 πŸ” 4 πŸ’¬ 1 πŸ“Œ 0

Progress (Moveit) sent out an email to their possibly affected clients today which lead to the couple I saw today. I believe right now it’s limited to only data exfil, not 100% since it’s still early.

Gonna be watching this one closely though to see if RW groups start using it.

02.06.2023 03:47 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Already seeing some cases come into IR from this and these aren’t even ransomware cases yet.

02.06.2023 02:25 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
New MOVEit Transfer zero-day mass-exploited in data theft attacks Hackers are actively exploiting a zero-day vulnerability in the MOVEit Transfer file transfer software to steal data from organizations.

This looks like it could be bad and could be the third mass-exploitation ransomware campaign of 2023.

https://www.bleepingcomputer.com/news/security/new-moveit-transfer-zero-day-mass-exploited-in-data-theft-attacks/

01.06.2023 15:36 πŸ‘ 5 πŸ” 2 πŸ’¬ 3 πŸ“Œ 1