Senior Threat Intel Advisor @TeamCymru Co-founder @CuratedIntel Co-author @SANSForensics FOR589 Co-founder @BSidesBournemth #126: REvil @darknetdiaries

🇬🇧
Pinned Tweet
📝 Looking to get into infrastructure analysis for CTI? I recommend studying the following aspects/topics in-depth: PDNS WHOIS Records BGP Peers HTTP Titles, Response Headers & ETags X509 Cert Issuers & Subjects & JA4X JARM SSH Host Keys & HASSH Favicon Hashes OpenDirs
1
19
163
7,160
📝 Looking to get into infrastructure analysis for CTI? I recommend studying the following aspects/topics in-depth: PDNS WHOIS Records BGP Peers HTTP Titles, Response Headers & ETags X509 Cert Issuers & Subjects & JA4X JARM SSH Host Keys & HASSH Favicon Hashes OpenDirs
1
19
163
7,160
New Blog 🇬🇧 UK Cybercrime Journal: Manchester Airport Group Breached by FulcrumSec 🔗 blog.bushidotoken.net/2026/0…
5
1,323
Real
Putin casts online vote in Russia’s State Duma elections.
Made with AI
1
3
39
5,691
Very interesting Blockchain Dead Drop (BDD) for C2 infrastructure TTP shift documented by @chainalysis chainalysis.com/blog/etherhi…
9
13
1,974
I am very glad to finally share publicly some interesting research I’ve been doing into ransomware infrastructure TTPs. This has been a long-running collaboration with a trusted partner who we can’t name but deeply appreciate their support. Read it here 👇 team-cymru.com/post/ransomwa…
2
38
121
11,896
True global internet intelligence 👇
INTEL BRIEF The fastest way to move a hunt forward is knowing what an IP is before you chase it. Total Insights informational tags do exactly that. They describe the infrastructure and context behind an address so you can filter the noise and spend your time on what is actually huntable. Built by a team of analysts that know this pain intimately. List of interesting informational context tag categories: TAG # of IPs Residential - 172M VPS - 140M CGNAT - 89M Router - 12.3M SOCKS - 7.6M CDN - 7.5M IoT - 5.3M Proxy - 1.3M Scanner - 1.25M Shared-host - 1.06M Bogon - 300K The real value is at the model level. Router resolves to 261 device-model tags across 58 vendors, IoT breaks into 56 device types, and ICS into 97 device families. When you can see the exact make and model, both attribution and filtering get sharper and hunts become more efficient (looking at you ORBs 😉). For threat hunting this is the difference between chasing and clearing. Bogon, sinkhole, honeypot, top-site, and CDN let you drop non-actionable addresses fast. CGNAT and shared-host warn you that one IP maps to many users, so you weight it accordingly. VPS, router, and IoT tell you what you are actually looking at before you spend a cycle on it. #TotalInsights #ThreatIntel #ThreatHunting #DFIR team-cymru.com/total-insight…
1
16
5,566
Team Cymru tracks 1,021,627 IPs tied to IPIDEA 👇
INTEL BRIEF A January 2026 disruption knocked down IPIDEA's proxy network (excellent work GTIG,Cloudflare,Lumen,Spur). We watched the operators rebuild from near-zero starting in April 2026 and climb back to near-full operation by August 2026. Team Cymru tracks 1,021,627 IPs tied to IPIDEA today. We also see backconnect/Tier2 controllers for the IPIDEA network that is used to manage the nodes. This backonnect/Tier2 is almost entirely Chinese hyperscale cloud providers. The re-built backconnect layer is nearing it's pre-takedown size, going from 7,400 active tier-2 controllers before the disruption to over 6,713 currently. Backconnect controllers by country location: Singapore 6,477 Hong Kong 194 United States 86 China 53 Seychelles 11 Sample backconnect controllers already carrying an open SOCKS proxy in Total Insights: 43.130.39.236 socks + vps 43.135.179.24 socks + vps 170.106.143.236 socks + vps 43.173.74.230 socks + vps 43.173.85.38 socks + vps Any sufficiently motivated proxy-as-infrastructure provider is likely going to reconstitute after its controllers are seized, often larger than before, on fresh backconnect nodes. Catching and defending means tracking the network infrastructure layer, via a detection engineering process, and tagging nodes in near real-time. It also means inspecting device types that are typically abused by similar proxy networks. Expect this to a be an enduring norm. #TotalInsights #ThreatIntel #ResidentialProxy team-cymru.com/total-insight…
12
2,604
New Blog! 🇬🇧 UK Cybercrime Journal: ExfilSquad Emerges - ExfilSquad’s extortion campaign targets UK public sector orgs, education, and law enforcement - ExfilSquad's primary attack vector involves exploiting CRM platforms and Microsoft Power Pages 🔗 blog.bushidotoken.net/2026/0…
10
23
2,822
Many Orgs are still getting rocked by Mobile-focused phishing & social eng. it is much harder to defend against compared to traditional Win/Mac endpoints. No EDR, no Proxy, and no Content Scanning Gateways for SMS, Messaging Apps, and other in-app messages. Tough one to prevent.
1
1
17
2,123
Definitely check this BGP Hijack incident out… “a small number of Virtualizor installations received a malicious update package while their traffic was diverted” 👀
9
14
4,629
You already know the types of groups to use FRP 🇨🇳👇
INTEL DROP FRP tunnels in our Total Insights detection pipeline. 40,708 FRP-tagged hosts right now, 2,712 of them rated malicious across 216 ASNs, concentrated in China, the US, Hong Kong, and Singapore. FRP (Fast Reverse Proxy) is an open-source reverse-proxy tunneler that crews use to pivot into networks and front their C2. Coexisting + FRP: 138.124.53.170 proxy:frp + bph 79.137.204.191 proxy:frp + bph + kev-vulnerable 45.8.113.127 proxy:frp + malware-hosting + kev-vulnerable 51.75.31.123 proxy:frp + phishing + open-dir 128.1.211.110 proxy:frp + scanner + brute-force 47.87.80.23 proxy:frp + open-dir 45.145.229.183 proxy:frp + risknet 183.250.89.44 proxy:frp + gen-ai:new-api + gitlab 152.136.59.90 proxy:frp + iot:crestron + ipsec 104.239.66.54 proxy:frp + risknet + kev-vulnerable 213.21.254.149 proxy:frp + bph 185.221.196.112 proxy:frp + bph + kev-vulnerable 138.124.14.123 proxy:frp + bph Some FRP nodes double as C2 on the same host: 192.210.193.156 proxy:frp + controller:vshell 111.231.59.28 proxy:frp + controller:vshell 117.72.72.254 proxy:frp + controller:supershell #TotalInsights #ThreatIntel #FRP team-cymru.com/total-insight…
2
12
3,102
Suddenly nostalgic for 2021-era malware botnets… the success of #OpEndgame is clear
Waiting for botnets to spin up and to start seeing loaders to pour in after orthodox holidays. What will come first? #Zloader? #Hancitor? #Emotet? #TA505? #Gozi? #QuakBot? #IcedID? #Dridex? #TrickBot-family? Place your bets!

ALT Mr Bean Waiting GIF

1
9
2,597
New Blog! 🇬🇧 UK Cybercrime Journal: ACRO Breach Report — Between July 2021 and June 2023, the UK Criminal Records Office had 3 separate breaches — It had an SQLi attack on its Kentico CMS followed by Mimikatz — 4x Trend Micro AV alerts were ignored 🔗 blog.bushidotoken.net/2026/0…
4
5
1,472
🚨 Gshell is not one to miss! Start hunting with some IOCs shared below 👇
INTEL DROP Gshell command-and-control cluster likely targeting Pakistani based orgs. Gshell is a China-aligned C2 framework observed being used against government and financial organizations. 103.112.97.64 103.112.97.163 103.112.97.199 134.122.204.46 134.122.204.86 134.122.204.106 207.56.28.60 207.56.28.82 The hosts group tightly into three back-to-back blocks: 103.112.97.0/24, 3 hosts 134.122.204.0/24, 3 hosts 207.56.28.0/24, 2 hosts One block runs more than Gshell. 134.122.204.0/24 also hosts CobaltStrike, Plugx, Supershell. credit Gshell discovery @huntio #TotalInsights #ThreatIntel #gshell team-cymru.com/total-insight…
4
23
3,422
North Korean live reaction to when the $1.5 billion crypto theft hits
🇰🇵 A video of North Korean workers dancing to Russian music is circulating online. In Vladivostok, workers from North Korea held a party on a construction site after their workday.
1
3
23
5,693
Manchester Airport Group told the BBC they refused to pay the ransom. So to all Cybercrime Underground watchers, be on the look out for the data of 8.7 million customers being offered or leaking soon… bbc.co.uk/news/articles/c7v4…
1
3
14
2,133
Even though cybercriminal extortions appear to be behind this one, the intelligence value of this data is pretty significant and would be prized by a hostile nation state. I also anticipate a hefty ICO fine for this one…
1
628
Watch out for those RMMs!
INTEL DROP Remote-management tools are the access layer for a lot of live intrusions. Right now we're tracking 1,123 malicious IPs running RMM software (AnyDesk, ScreenConnect, MeshCentral, RustDesk) across 307 ASNs, most of it in the US, the Netherlands, and Germany, with India and Russia rounding out the top five. RMM staging malware: 185.187.84.31 screen-connect + malware-hosting 91.92.240.17 screen-connect + malware-hosting 91.92.34.123 screen-connect + malware-hosting RMM co-located with C2: 102.165.14.23 anydesk + screen-connect + purerat 108.171.194.80 anydesk + venomrat 117.18.127.179 anydesk + xworm 91.92.42.118 meshcentral + cobaltstrike RMM with an open directory exposing malware or C2 config: 103.68.109.59 anydesk + open-dir + malware-hosting 129.80.196.225 meshcentral + open-dir + malware-hosting 51.79.134.41 anydesk + open-dir + xworm + malware-config 115.159.33.118 rustdesk + open-dir + cyberstrikeai + proxy:nps Bulletproof hosting + brute-force: 91.220.163.50 anydesk + bph 149.104.30.78 rustdesk + proxy:frp 68.64.183.125 komari + proxy:frp 210.212.136.3 anydesk + scanner:brute-force #TotalInsights #ThreatIntel #RMM #C2 team-cymru.com/total-insight…
1
2
52
9,470