SEAL exists because security experts chose to share knowledge instead of hoarding it. Your donation keeps that infrastructure running: securityalliance.org/donate
4
6
31
17,520
Not only DPRK. A vibe-coded phishing frontend for Microsoft Teams, found in the wild. With the proliferation of capable, unrestricted LLMs, we often observe unaffiliated threat actors deploying fully vibe-coded malware infrastructure. In this example, an endpoint misconfiguration exposed the phishing kit's assets along with the LLM's comments. Interestingly, the threat actor most likely framed the task as a benign development job - a custom video conferencing platform called "Lassy Meet" - traces of which can also be found on the suspicious GitHub organization that also appears to be LLM-automated. However, the comments reveal the intent. IOCs: 223.165.6[.]141 netwitz.zoom01[.]us teams.mlcrosoff[.]com github[.]com/altosecteam-org
1
5
21
2,726
SEAL weekly stats, 15-22 Sep: This week we responded to 62 incidents. Reported losses by category: 1) Protocol compromise $13.71M 2) Other $953k 3) Malware $530k 4) Pig butchering $500k 5) Fake ads $270k 6) Seed compromise $263k + 1.7 BTC and 14.2 ETH (DPRK) Read below for details.
2
7
41
2,698
ClickFix: 10 new domains, $530k. Six used mshta: 5843-cf[.]com 9898-cf[.]com anthropicrbh[.]com gmecoinrbh[.]com nectarbnb[.]com thebitcounfoundation[.]com Never paste what a website tells you to.
1
3
277
@SEAL_911 is free to anyone who needs it, and stays that way because people fund it. If this week's numbers are useful to you, fund the next one here: securityalliance.org/donate If you require a direct and more detailed data feed from @SEAL_Intel contact us on our website (link in bio).
3
243
Welcome @Quantstamp to the SEAL Certifications program! They’re now undergoing accreditation and taking on certification engagements. Details on SEAL Certifications: securityalliance.org/our-wor…
6
5
21
4,680
#DPRK intrusions this week: Contagious Interview - $1.9M IT worker hired onto the team - $500k SINT-01 (Konni) - $480k All three successful intrusions happened months before the theft occurred. DPRK actors persisted on developers' devices and infrastructure for an extended period. In the case of the DPRK IT worker, an insider leveraged his access to critical infrastructure and withdrew funds to his wallet.. #UNC1069 - a single incident with $0 loss IOCs: texmslives[.]com tezmlives[.]com tevmslives[.]com microteamscall[.]com usonliues[.]us 365lineup[.]com
1
1
8
2,352
Misc fake meeting campaigns that could not be attributed. gogglemeets[.]com us04-web-zoom[.]us workspace-zoommeeting[.]us meetinglinvite[.]com zoom[.]com[.]im
1
1
5
450
@SEAL_911 is free to anyone who needs it, and stays that way because people fund it. If this week's numbers are useful to you, fund the next one. If you require a direct and more detailed data feed from @SEAL_Intel - talk to us. securityalliance.org/donate
1
4
371
SEAL weekly stats, 8-14 Sep: 61 incidents we dealt with. Reported losses by category: Seed compromise $9.39M Protocol compromise $3.94M DPRK intrusion $2.9M Escrow scam $1.68M Malware $960k Social engineering $192k Plus 132.5 ETH lost - distributed across all categories.
1
8
34
2,981
17 of 61 incidents this week involved compromised seed phrases or private keys. Root causes typically include: a compromised device, re-typing the seed into a fake wallet app, or exposing the seed to third-party storage. The largest loss - $5.4M: a seed kept in cloud storage.
1
3
203
What we collected: 3,192 phishing domains 3,226 indicators published 74 wallets Ledger was impersonated 277 times. Last week it was 29.
1
4
1,220
Welcome @Cyfrin to the SEAL Certifications program! They’re now undergoing accreditation and taking on certification engagements. Details on SEAL Certifications: securityalliance.org/our-wor…
6
38
2,957
15 firms are undergoing accreditation with SEAL Certifications and taking on audit engagements right now — smart contracts, incident response, treasury security, multisig ops, and more! If your protocol hasn't scoped an audit yet, reach out directly to a Certification Partner today: securityalliance.org/our-wor… @AdevarLabs @audit_wizard @BlockSecTeam @chain_security @Composable_Sec @ConsensysAudits @DefiSafety @hackenclub @HackenProof @SecurityOak @opsek_io @sigp_io @Wonderland @zellic_io @zeroshadow_io
7
8
64
8,924
Doh! We tagged the wrong @nft_dreww. 🙈 Deleted it. Corrected: The Discord account management guide (Community Management Framework) was updated to match Discord's recent settings redesign, so the steps now match what you'll see in the app. Thanks @nft_dreww for the update.
2
1
6
282
Another tagging correction: DevSecOps Framework has a new Policy as Code section covering how to enforce build policy through the CI/CD pipeline (commit > merge > build > release > deploy > runtime). frameworks.securityalliance.… Credit to @S1ns3nz0S71060 for this contribution.
1
1
4
266