-Even more research on Twitter/X algorithm manipulation
-Russia turns on Telegram
-Texas sues TP-Link
-West Virginia sues Apple
-US does dumb things, part 332737232
-Spain arrests hotel hacker
-Nigerian hacker sentenced to 8 years
-651 cybercrime arrests in Africa
-GrayCharlie profile
20.02.2026 10:41
π 5
π 3
π¬ 2
π 0
CastleLoader in the wild! Four distinct activity clusters, sector-specific targeting of logistics, and high-end tooling like Matanbuchus and CastleRAT.
09.12.2025 15:43
π 3
π 2
π¬ 0
π 0
Recorded Futureβs Insikt Group uncovered four GrayBravo activity clusters. TAG-160 impersonates logistics firms, while TAG-161 impersonates Booking.com, employing ClickFix to deliver CastleLoader and Matanbuchus. www.recordedfuture.com/research/gra...
09.12.2025 11:25
π 6
π 5
π¬ 0
π 0
2/ Our latest analysis uncovered four distinct activity clusters within GrayBravoβs ecosystem, all leveraging the groupβs #CastleLoader malware. Each cluster uses different tactics, techniques, and targets, reinforcing the assessment that GrayBravo runs a #MaaS model.
09.12.2025 08:24
π 3
π 1
π¬ 1
π 0
GrayBravoβs CastleLoader Activity Clusters Target Multiple Industries
1/ @whoisnt.bsky.social, Marius, and I just published a report on #GrayBravo (formerly TAG-150), a highly adaptive, sophisticated threat actor that we first identified in Sept 2025. It uses a multi-layered infrastructure and responds quickly to exposure: www.recordedfuture.com/research/gra...
09.12.2025 08:24
π 10
π 6
π¬ 1
π 1
A good piece highlighting the EU's continued inaction following recent sanctions, essentially allowing these enablers to continue their operations.
05.12.2025 19:35
π 1
π 0
π¬ 0
π 0
π¨ - New report by Haaretz, Inside Story, Inside-IT and Amnesty International release the Intellexa Leaks. Which exposes Intellexa support staff had access through Teamviewer to customer deployments and confirms found IOC's in the past by civil society. π§΅π
04.12.2025 11:37
π 9
π 16
π¬ 1
π 3
Intellexaβs Global Corporate Web
1/ Today we release a new report exposing previously undisclosed entities connected to the wider #Intellexa ecosystem as well as newly identified activity clusters in Iraq and indications of activity in Pakistan: www.recordedfuture.com/research/int...
04.12.2025 04:17
π 26
π 18
π¬ 2
π 4
3/ As long as the same LIRs and the same bad actors are able to maintain control of their RIPE resources, the problem will never stop.
26.11.2025 14:12
π 0
π 0
π¬ 0
π 0
2/ The case of fraud relating to metaspinner GmbH really does spell out the severity of the problem...
26.11.2025 14:11
π 0
π 0
π¬ 1
π 0
βNeutralβ internet governance enables sanctions evasion
Internet service providers and hosting companies enable cybercrime and cyber operations. Why donβt sanctions stop them?
1/ It's nice to see the topic of bulletproof hosters and Threat Activity Enablers gaining more mainstream attention; however, a bigger problem than endless shell companies exists, and that is RIPE RIR policy. bindinghook.com/neutral-inte...
26.11.2025 14:11
π 2
π 1
π¬ 1
π 1
NSA Joins CISA and Others to Release Guidance on Mitigating Malicious Activity from Bulletproof Hosting Provider Infrastructure
November 19, 2025, NSA/CSS
www.nsa.gov/Press-Room/P...
20.11.2025 12:03
π 4
π 3
π¬ 1
π 0
3/
19.11.2025 17:19
π 2
π 0
π¬ 0
π 0
1/ United States, Australia, and United Kingdom sanction Russian threat activity enabler Media Land (Yalishanda) and follow up on recent designations targeting Aeza. ofac.treasury.gov/recent-actio...
19.11.2025 17:17
π 3
π 3
π¬ 1
π 0
This is highly likely CrazyRDP :)
16.11.2025 19:58
π 2
π 0
π¬ 0
π 0
3/ metaspinner net GmbH (Hamburg, Germany) has no affiliation with #AS209800, Virtualine Technologies, or any related malicious activity associated with that network.
12.11.2025 21:52
π 0
π 0
π¬ 0
π 0
2/ A falsified RIPE end-user agreement provided to Insikt Group highlights how a basic verification check against publicly accessible company registration documents could have prevented the fraudulent registration.
12.11.2025 21:52
π 0
π 0
π¬ 1
π 0
1/ [UPDATE] As of November 10, 2025, metaspinner net GmbH has provided substantial evidence confirming Insikt Groupβs original assessment that their identity was unlawfully and fraudulently used in the registration of #AS209800.
12.11.2025 21:51
π 2
π 1
π¬ 1
π 0
Malicious Infrastructure Finds Stability with aurologic GmbH
Malicious Infrastructure Finds Stability with aurologic GmbH
07.11.2025 11:24
π 1
π 1
π¬ 0
π 0
German ISP Aurologic GmbH has Become a Central Nexus for Hosting Malicious Infrastructure
German ISP Aurologic GmbH has Become a Central Nexus for Hosting Malicious Infrastructure
08.11.2025 00:41
π 2
π 3
π¬ 0
π 0