Crossed wires: a case study of Iranian espionage and attribution | Proofpoint US
Proofpoint would like to thank Josh Miller for his initial research on UNK_SmudgedSerpent and contribution to this report. Key findings Between June and August 2025,
New Iran drop from me tracking an attribution nightmare - UNK_SmudgedSerpent! A little Charming, a little Muddy, and a lot C5. Targeting policy experts with benign conversation starters, health-themed infra, OnlyOffice spoofs, and RMMs. Check out the full story www.proofpoint.com/us/blog/thre...
05.11.2025 13:37
👍 18
🔁 12
💬 2
📌 0
APT: Android, Phishing, microsoft
A South Asian APT has been persistently targeting Sri Lanka, Bangladesh, Pakistan, and Turkey. This post walks through infrastructure and malware pivots to expose novel tooling that compromised the p...
A South Asian APT has been persistently targeting Sri Lanka, Bangladesh, Pakistan, and Turkey. This post walks through how to pivot from the well-publicized phishing infrastructure to expose APK tooling that compromised members of the military of Asian countries.
strikeready.com/blog/apt-and...
19.08.2025 10:45
👍 4
🔁 3
💬 0
📌 0
Appreciate it!
04.06.2025 17:10
👍 0
🔁 0
💬 0
📌 0
Is the era of the “named actor” done?
As the OG adversary sets diverge, get promoted, or move on
actors dispersing across the kill chain based on specialized skills increases (ORBs, criminal underground)
AND the CTI models maturing…
APTs ⬇️⬇️
UNCs ⬆️⬆️
21.05.2025 20:15
👍 28
🔁 8
💬 7
📌 0
It’s low volume.
18.12.2024 08:35
👍 1
🔁 0
💬 0
📌 0
In December 11 and 12, 2024, a spearphishing campaign targeted at least 20 Autonomous System (AS) owners, predominantly Internet Service Providers (ISPs), and purported to come from the Network Operations Center (NOC) of a prominent European ISP.
🧵⤵️
12.12.2024 21:18
👍 17
🔁 11
💬 1
📌 5
I’m a little excited for this one
19.11.2024 23:21
👍 1
🔁 0
💬 0
📌 0
two men are standing next to each other with the words " we open it up " on the screen
ALT: two men are standing next to each other with the words " we open it up " on the screen
#PIVOTcon25 registration is now OPEN 🤟📥📥📥
pivotcon.org
#CTI #ThreatResearch #ThreatIntel
Please read carefully the whole 🧵 for the rules about invite -> registration (1/5)
19.11.2024 14:00
👍 42
🔁 22
💬 2
📌 11