Proactive Defense Against Future Threats | Pioneering #CyberSec and #ThreatIntelligence in Europe & MENA since ’12. CTI Platform: #USTA Risk Intel: #BLINDSPOT

Europe
🎯 A fixed target set. A kernel service. Endpoint defenses taken offline before encryption. Because ransomware deployment is easier when the security software is no longer running. This is PHANTOM MANTIS (a.k.a. The Gentlemen) before the ransom note. We have been tracking the operation for some time. In our previous report, we mapped its affiliate model, internal infrastructure, operational structure, and ransomware platform. This time, we went back for the arsenal used to clear the way. 🕵️ Our latest report traces its evolution from repeated process termination to: 🔺 Blocking selected security drivers during initialization 🔺Overwriting writable memory inside running processes 🔺 Modifying kernel memory 🔺 Removing selected file-system filters 🔺 Abusing a historically signed security component The killers continuously search for nearly 180 security and IT-management processes. They are also supplied through the operation’s affiliate-support structure. Because apparently, ransomware affiliates need technical support too. We pulled the arsenal apart. The indicators, defensive priorities, and hunting rules are in the report. 🔎 Previous investigation: catalyst.prodaft.com/public/… 👇 Read the latest report: catalyst.prodaft.com/public/…
5
8
3,044
👇The Pareto Principle applies to Funky Mantis as well, where a successful extortion follow an 80-20% split.
⚠️ DevMan RaaS now runs a full affiliate portal. Experts (tracking it as Funky Mantis) say the platform handles payload builds, victim records, chat, teams, support, and payouts in one place. Affiliates get structured workflows, deadlines, and an 80/20 cut. 184 victims claimed so far. Read: thehackernews.com/2026/07/de…
3
1,470
🎯 A target list. A schedule. A revenue model. A locker ready to deploy. This is Funky Mantis (DevMan) behind the ransom note. 🕵 Our latest report reveals how the operation assigns access, schedules targets, divides responsibilities, and coordinates through Rocket.Chat, private communications, and dedicated RaaS portals. We trace the platform's evolution from December 2025 to its January 2026 v3 release, then dissect the Windows encryptor used to finish the job. The locker: - Terminates processes and services - Searches network shares - Supports lateral movement - Disables Microsoft Defender - Clears event logs - Deletes shadow copies - Removes itself after execution. The report also includes defensive priorities, response guidance, and four behavior-focused threat hunting rules. 👇 Read the full report: catalyst.prodaft.com/public/… #PRODAFT #ThreatIntelligence #Ransomware #FunkyMantis #DevMan
1
3
16
2,703
A #ransomware gang broke away from the pack. The Gentlemen started as an affiliate using LockBit, Qilin, and Medusa resources. Now it runs its own RaaS program, claims 478 victims, offers affiliates a 90% cut, uses AI to maintain its tools, and can spread across networks when enabled. Read the full story: thehackernews.com/2026/06/th…
7
12
40
7,551
🚨 PHANTOM MANTIS (a.k.a. The Gentlemen): They only hold the door open to exfiltrate your data. Meet Phantom Mantis, the ransomware crew that went from total unknown to one of the most prolific operations. 💀 🔥 HUNDREDS of victims on their leak site 🌍 Confirmed hits across 20+ countries 📈 Explosive growth that nobody saw coming We are tearing the operation wide open.🕵️ 🔴 TLP:RED version: the full deep-dive: affiliate intel, victimology, the usual PRODAFT stuff. ⚪ TLP:CLEAR: Open to everyone, right here: 👉 catalyst.prodaft.com/public/… #TheGentlemen
5
15
1,736
This is what happens when you put an ex-hacker on a stage in front of 750 students. 👨‍🎓👩‍🎓 Last week, we had the privilege of being part of two remarkable events and we're still feeling the energy. We participated in the Leiden 2026 Youth Security Conference, where the next generation of cybersecurity talent gathered to learn, connect, and take their first steps into the industry. @euhorizons At the same time, @mdisec took the stage with his talk "A Hacker's Diary". Over 750 students registered for his solo talk, making it an all-time record. 🚀#CyberTEDU These young minds show up with boundless energy, remarkable patience, and a curious mindset that is impossible to ignore. To every student we crossed paths with last week -- a big THANK YOU. Keep pushing. 💙
2
15
1,281
🛡️ Showcasing cyber intelligence expertise at #FIC2026 (@INCYBER_Europe , Lille) We were proud to contribute to the Expertise France track, presenting our CTI and supply chain risk intelligence solutions to international delegates. 🤝 We had the pleasure of engaging with partners from Africa, Europe, Central Asia, and the Asia Pacific region, highlighting the truly global nature of today's cyber challenges. ✨ Key message: across all regions, there is a shared urgency to strengthen cyber resilience, capacity building, and trusted digital ecosystems. These discussions also reaffirm the importance of strategic autonomy and diversified partnerships in shaping a balanced and sovereign approach to cybersecurity. A big thank you to all participants for the rich discussions. Looking forward to building impactful collaborations ahead. #Cybersecurity #InCyber #FIC2026 #ExpertiseFrance #DigitalCooperation #CyberResilience
5
12
1,623
🛡️ Executive Exposure is an Enterprise Risk Senior executives and high-trust, business-critical leaders are prime targets for cyber criminals due to their access, visibility, and decision authority. Our VIP Protection module in U.S.T.A. continuously monitors personal and corporate account exposure of key executives and VIPs in your organization. 🚨 When early signs of leakage appear, we alert in real time before personal exposure turns into business, legal, or reputational impact. 📌 Board-level takeaway: Protecting leadership identity is no longer optional. It’s a core part of enterprise risk management. Explore more: prodaft.com/usta-cyber-threa… #CyberSecurity #ExecutiveRisk #BoardGovernance #DigitalRisk #ThreatIntelligence
2
3
1,173
Our SYS initiative continues to accept tips regarding cybercrime. If you have information about any threat actor group, you can reach us directly through our TOX anonymously: D0E5B14B166D8440E3F54CDFC0F38E5080645F728F02AADFB7B978F9D579EE5A6D38A29DD307 P.S. Our graphic designer is away this week, but since posts with images receive better engagement, we did our best. Thank you for your understanding. #cybercrime #cyberthreatintel #proactivedefense
6
25
3,572
📈Statistically speaking, thanks to the SYS initiative, there are now more "good guys in disguise" running cybercrime forums as moderators and administrators than actual criminals. #cybercrime #proactive #cyberintelligence
As part of the SYS initiative, @PRODAFT is notifying users affected by the RAMP forum database leak. Threat actors are being encouraged to assist with the de-anonymization of some of the most active cybercriminals and ransomware operators — developments that are expected to make headlines. Choose a better path for yourself. nitter.net/PRODAFT/status/2019928…
1
4
20
4,536
RAMP Forum User Intelligence Available for Our Platform (U.S.T.A. & Catalyst) Members 🫶Our SYS initiative remains highly active, as a well-known forum member voluntarily contacted us. We are grateful for their contribution. Even when admins attempt to dox each other for 10 BTC, it's good to see some members doing it voluntarily for us. 🔍As a result, our team has acquired intelligence associated with 7,709 RAMP forum users, including the following high-value investigative datasets: 📧Private messages exchanged between threat actors, enabling reconstruction of operational planning and coordination; 👾Attachments sent and received between threat actors, supporting malware, tooling, and infrastructure attribution; 🔐Authentication and login activity, facilitating access-pattern analysis and operational security assessment; 🌌Forum search history, providing insight into intent, targeting, and operational focus; 🧐Profile information, including but not limited to registered email addresses, supporting identity correlation and cross-platform attribution; 🗣️Chat room and group communication metadata, indicating collaboration structures and coordinated activity across specific operations and campaigns. We will be correlating these datasets to support and advance multiple previously unsolved investigations. #cyberintelligence #ramp #LockBitSupp <3
4
12
74
10,080
Our managing partner @mdisec took the stage at a fully packed Meetup series (#58) organized by @teknasyon 🐦‍⬛The room was packed wall to wall as hundreds of hackers gathered to listen to his energetic and educational talk titled Hacker’s Diary: A Product Security Tale. Huge thanks to @teknasyon for hosting such an incredible event and big respect to the passionate audience whose curiosity and engagement filled the room 🔥 #zeroday #vulnerability 👋#chat
1
2
39
4,075
For all the malware devs out there 🦠🧑‍💻 Every infostealer uses a different timestamp format. Some of you even invent new ones. Analysts everywhere are crying while parsing those logs. Please. Just use ISO8601. (One of our clients advised that) Make it a standard among whatever nasty thing you're coding. If you don't know how, please contact us. #ISO8601 #CyberThreat #MalwareDev
2
14
70
8,470
🚨 Hidden Risk: Unattended or Forgotten Social Media Links A single social media link on a website can open the door to: 🎭 Brand impersonation 🎣 Phishing campaigns 💸 Fraud and reputation damage Attackers actively search for unclaimed or abandoned social media accounts linked from official websites, then take them over to exploit user trust or re-register to sell them. Only thing worse than a breach is explaining to the board that it started with a forgotten Twitter link from 2016 🤦‍♂️ #CyberSecurity #ThreatIntelligence #BrandProtection
3
7
1,346
🔧Our open source tool Cradle is built for the threat intelligence community and shared openly with everyone. What started as a public project is now being used by many major organizations to manage complex internal cases and critical knowledge at scale. We are pushing Cradle forward with new powerful features coming soon !🤫. Follow our GitHub to see what is next and be part of the future of case management github.com/prodaft/cradle
64
488
31,525
Our seasoned manager, ACK, represented us at MaTeCC in Morocco as a speaker, sharing insights on AI-driven cyber threats and the latest cases we investigate. From Morocco's strong support for cybersecurity to the high-quality technical sessions and an inspiring student community shaping the future of cyber resilience, MaTeCC truly showcased the region's growing capability in cyber domain. #Morocco #MaTeCC
3
9
146,491
⏳After countless hours protecting critical organizations from breaches and supporting global cyber investigations 💪, we are taking a moment to recharge in Cappadocia (Kapadokya), a place that feels like home. ⛰️Here, hot air balloons rise with the sun, ancient valleys and fairy chimneys shape a dreamlike horizon, and history lives in every stone. It is the perfect setting to reflect, reset, and prepare for the next challenges. #CyberSecurity
2
1
13
4,109
We are thrilled to see our work featured in a new WIRED piece on Google's lawsuit against the "Lighthouse" smishing operation. 📱 Huge shout-out to our team for their relentless work tracking Chinese-speaking smishing ecosystems and reporting the infrastructure behind these global scam campaigns. 🔗 Read the WIRED article: wired.com/story/lighthouse-g…
2
14
2,338