Validin is a next generation internet intelligence platform.

Southeast USA
Pinned Tweet
For analysts and researchers: releasing a new advanced search query language and Search Sessions. Read the announcement: validin.com/blog/validin_int…
2
4,142
Validin retweeted
Coffee break - back soon! Thanks to our friends @ValidinLLC for keeping us all fueled.
1
7
422
Validin retweeted
H/t again to @ValidinLLC and @500mk500. We got some great pivots through banner hashes and bouncing finds off maltrail. Also some white glove assistance from @SreekarMad.
Hijacked YouTube channels are pushing an emerging infostealer. We're tracking #REVSTEALER: at least 17 compromised channels advertising free game cheats, funneling viewers to 2 malicious domains. The stealer itself is built for long-term operation: - Sandbox scoring: 10 weighted checks, self-terminates at a score of 7+ - App-Bound Encryption bypass: reads the decrypted key from browser memory under debugger control - EtherHiding: fallback C2 stored in a Polygon smart contract, swappable without touching the binary - Gaming focus: session cookies from Steam, Battlenet, and Roblox, feeding account resale markets - 4,700 related samples hit VirusTotal in the past year. Our team observed 4 follow-on modules that haven't been publicly documented until now. Full analysis, whitepaper, YARA rule, and an IDAPython string decryption tool by @k33b0i, @soolidsnakee and @DanielStepanic: Blog: go.es.io/4iJZRQe Whitepaper: go.es.io/4xcanmZ
1
3
6
630
Validin retweeted
🫡 A strong LABScon salute to our partners at Validin for their generous support of the conference! 🔬 Validin is an internet intelligence and threat-hunting platform that helps security teams uncover and track malicious infrastructure using DNS, host and certificate data. @ValidinLLC 👉 Explore: validin.com/platform
2
8
442
Researching 3 clusters recently reported by GTIG to find unreported fake banquet invitations, Google Drive links, and more. Inhospitable: Tracking Russian Cyber Espionage Infrastructure validin.com/blog/inhospitabl…
2
5
1,107
❤️
I've probably said it before, but @ValidinLLC is seriously one of the most useful and underrated threat intel tools out there.
3
1,115
Validin retweeted
A Security Conversations interview with Kenneth Kinion, CEO at threat-intelligence firm Validin @ValidinLLC open.spotify.com/episode/3ar…
2
6
13
1,448
Validin retweeted
7/16/26 packetwatch.com/resources/be… - This case study shows how to investigate malicious traffic and a threat actor's infrastructure, IP addresses, and domain indicators of compromise. #validin @ValidinLLC #threatfeed #threatintelligence #threathunting #cybersecurity #cyberincidents #cyberattack #dfir #networksecurity #informationsecurity #teamsixty43
2
2
806
PacketWatch, a network threat-hunting and managed cybersecurity company, has both a research workflow and direct product integration with Validin. See how @packetwatch helps protect their customers with Validin in our latest case study: validin.com/blog/packetwatch…
1
1,741
We have improved our Oracle E-Business Suite fingerprinting by adding domain based scans in collaboration with @ValidinLLC. Around 950 exposed instances now seen globally (no vulnerability assessment). CVE-2026-46817 attempts have been observed in the wild by @DefusedCyber
2
10
22
5,678
With the World Cup in full swing, we dug into the IoCs from @GroupIB's Ghost Stadium report and found 3,079 domains still active in the past 14 days. We've published the full list of 6,000+ suspected domains publicly. Full write-up below ⤵️ validin.com/blog/ghost_stadi…
1
1
4
1,875
Read their report, with more technical breakdown of the mechanics of the campaign, here: nitter.net/GroupIB/status/2059531…
1,162
Validin retweeted
1/ Just came across this using @ValidinLLC searching for "Launch Meeting - Zoom" domains hosting what looks like XSS > RCE > MS Signed > dropper.exe > miniplasma > more fun @astrarce @Gi7w0rm @RussianPanda9xx @SquiblydooBlog @MsftSecIntel @banthisguy9349 @_JohnHammond
3
7
11
2,489
Validin retweeted
Lets use this pivot point on @ValidinLLC Title: Zoom Client Update Reported to @abuse_ch Telegram info 'bot_url' "6366434554:AAFV0fUvPM4BdKKUvMt9aQwg1nQ8MsxCpXE" 'chat_id' "588250349"
⚠️Observed phishing URLs delivering RMM payload: Theme: Zoom RMM: ScreenConnect URL: hxxp://zoom.web-interviews[.]live VBS Download URL: hxxps://zoom.web-interviews.live/download.php SHA256:65208b731a5a0956a90d8cd415825123029712acdf240ab6d613154c4307c087 #ThreatIntel #Phishing #RMM
2
7
6
2,954
Validin retweeted
Validin's threat intelligence platform requires unfettered access to data, with affordable, high-performance storage, bandwidth, and scaling. They’ve found that with Vultr Bare Metal, Cloud Compute, and File System. See how @ValidinLLC wins with Vultr: blogs.vultr.com/validin-case…
2
1
1,652
Validin retweeted
New report revisiting Gamaredon, this time focusing on their phishing emails and first stage downloaders - GammaDrop and GammaLoad. Despite years of active campaigns, detailed public analysis of either has been lacking. So we fixed that. 1/5
2
9
26
5,000
✈️ We’re headed to Malaga, Spain for #PIVOTCon26! Our founder Kenneth Kinion and founding engineer Sreekar Madabushi will be attending.
1
1
609
We're looking forward to seeing you all at @pivot_con next week!
Countdown is real ⌛️ Next week‼️ #ThreatResearch community gathers in Málaga 🇪🇸 Time to remind our PIVOTcon song: soundcloud.com/argonix/pivot… But watch out — it's a banger! thx: @JReisdorffer #CTI #ThreatIntel #PIVOTcon26

ALT Animated GIF

1
2
488
Ok, real question: how many of you have mistyped regsvr32.exe too? New blog is out! Got a chance to take a peek at CastleLoader 🏰 and a .NET stealer we are calling CastleStealer (duh) Their launch_method 4 calls regsrv32.exe. Yes, regsrv32.exe. The devs typo'd a binary that's been shipping since the 90s and never noticed :C I also didn't forget to give @ValidinLLC a shoutout this time. Would you check out the blog, pretty please? huntress.com/blog/clickfix-c…
5
26
99
14,201