Senior Director of Product Research @HuntressLabs and custodian of secret histories. Posts are my own.

New York State
Devon Kerr retweeted
Recently, Japan, the US, Australia, and Germany published a joint cybersecurity advisory on WaterPlum, also known as the Contagious Interview campaign, attributed to a DPRK threat actor. From the advisory, one loader uses two parallel infection chains involving OtterCookie and BeaverTail variants. I recently analyzed a very similar setup where a single loader also launches two separate infection chains, delivering different malware variants(BeaverTail/InvisibleFerret, OtterCookie) that have previously been linked to the same actor. What stands out to me is that the operators do not seem to care much about redundancy or efficiency in the infection chain. They seem more focused on stealing as many breadcrumbs as possible, even when the two chains collect overlapping data. A few notable characteristics: ▶️One loader kicks off two separate infection chains. ▶️EtherHiding is used to fetch BeaverTail-style JavaScript from a BSC transaction. ▶️InvisibleFerret capabilities and distribution endpoints have been slightly updated, suggesting that it is still under active development. ▶️Several stealing targets overlap across both infection chains, but the operators do not seem concerned about that redundancy.
1
5
42
2,063
Devon Kerr retweeted
Replying to @rvrsh3ll
@rvrsh3ll about to hit the stage @BSidesKrakow 🔥
1
5
20
828
Devon Kerr retweeted
This team is growing and the work is very interesting! Ever want to make a difference in the world by helping defend companies large and small who need all the help they can get? Do you like our blogs (huntress.com/blog)? This could be you helping fight the good fight!
Have you read some of our @HuntressLabs blogs and thought to yourself, damn, this looks like fun? Do you love logs and investigating incidents ? Want to help protect the 99 percent? If it's a yasss across the board then I have good news for you, I'm hiring for 2 positions on our Tactical Response team! Check out the posting below and apply! job-boards.greenhouse.io/hun…
5
15
1,795
Devon Kerr retweeted
We're honored to present Katie Moussouris (@k8em0) with our Lifetime Achievement Award, for a lifetime of incredible work and contributions to the industry.
8
37
9,045
Devon Kerr retweeted
cups2root dropped after my Linux LPE detection blog. There was no cups2root-specific rule. The general layer still fired on my Ubuntu 26.04 lab run. Python to root. SUID/SGID abuse. A system-binary symlink into a writable path. Writeup and rules ↓
1
3
7
643
Devon Kerr retweeted
Replying to @elasticseclabs
If we do a snap diamond analysis... Victim: crypto wallet devs Capability: supplychain, targetted SE Infra: npm packages I've heard this song before... but I haven't gotten deep enough to make a call yet.
1
4
194
Devon Kerr retweeted
Replying to @elasticseclabs
Initial take is that it's being used in SE campaigns targetted against blockchain and crypto devs.
A fake accelerator tried to #hack us today. "Apex Accelerator" asked us to run their due diligence tool: npx @apexacc/cli. It dropped a hidden, encrypted malware loader disguised as an Apple app. We caught it and lost nothing. Here's what happened 🧵
1
1
5
497
We are investigating a malicious package, apexacc/cli, distributed in the npm registry. Initial assessment shows that the package performs registry modifications to Windows Smart App Control, AV exclusions, UAC elevation attempts, and includes Base64-encoded PowerShell payloads. Further end-to-end triage shows that for the Windows path, its verification step requests commands from vrf.apexaccs[.]org, then runs encoded PowerShell. We traced the execution chain through Python/PyInstaller and PyArmor layers to a Go shellcode loader. The final component in the chain shows strong infostealer characteristics. Variants of this campaign and techniques have been observed and documented here - go.es.io/3V3c7BC and go.es.io/4AoyO3y. Since it was discovered in July 2026, it has been added to, and remains in, the npm package registry. We have reported this package to npm and are continuing to investigate. We will update this thread as we learn more.
5
21
60
6,789
Devon Kerr retweeted
Wow, Julian is such a legend. Always showing us how good threat research is done.
Our long time friend and research partner, Julian Ferdinand Vögele (@JulianVoeg), brings us a deep analysis of Middle Eastern threat actors. He is taking us on a nice stroll, revealing a fragmented yet deeply interconnected cyber ecosystem shaped by hidden relationships, shared operational structures, and an increasingly industrialized approach to cyber power.
1
4
29
2,312
Devon Kerr retweeted
Replying to @TomHegel
Julian is a bloodhound (complimentary) - I've never met a researcher who will go further in pursuit of a threat actor
1
1
9
394
Devon Kerr retweeted
Cybercriminals and nation-state actors alike are increasingly turning to the blockchain to sustain malicious campaigns. “Blockchain dead drops” or “etherhiding” use smart contracts as resilient storage for C2 and payloads, are now deployed with ease, and resistant to takedown.
Our latest research shows how North Korean and Iranian hackers are increasingly launching hard-to-stop cyberattacks. And they’re using blockchains to do it. We call the attack tactic “Blockchain Dead Drops,” or BDDs. BDDs are getting more sophisticated, more prevalent, and therefore more dangerous. Read on:
2
1
249
Devon Kerr retweeted
This discussion here would be way more lolz
27
35
320
11,777
Devon Kerr retweeted
2022. ChatGPT released in 2020 @RachelTobac has been doing social engineering training full time since 2017. And METR still doesn’t have a cybersecurity hire. Not just a cybersecurity person on their vibes control team, but clearly none for their entire org.
My name is Chris Painter, and I'm the President of METR (Model Evaluation and Threat Research). I know we've made a lot of new friends on the internet the last couple of days, so I thought I'd take this chance to re-up what we do and why. Our work is aimed at making sure that if AI really were autonomous, difficult to steer, and close to "going rogue," the public would find out. If evidence exists inside of an AI company that it’s close to losing control of AI, we want to make sure that information gets shared with the rest of the world, including governments and the public outside the company’s walls. This is what we've been focused on since 2022, and over the years we've worked with OpenAI, Anthropic, Google DeepMind, Meta, Amazon, and others on piloting third-party assessments and investigations of this type. We don’t have some private room where we rubber stamp things as “safe” or not. We have had a track record of publishing results on AI that don't cleanly map onto the "doomer" or "accelerationist" labels, and we put in effort to hire people with competing views on AI. We’ve been cited for having found some of the strongest evidence that AI capabilities are improving rapidly (our work measuring AI “time horizons”) while also presenting some of the strongest evidence that, at various points, AI’s capability may be overstated (some might remember our study showing that early 2025 software engineers were actually being slowed when they thought they were being sped up). METR is funded by donations. We don't accept money from frontier AI companies. They haven't paid us for our work, and we don't accept donations from them or their employees. As we’ve shared previously, multiple frontier AI companies currently provide us with free access to their models in order to perform our evaluations, research, and engineering. Our funding intentionally comes from a wide range of donors, which we’ve shared on our website. Today, when an AI company works with any third-party evaluator or external testing organization (of which there are and should be many), it's entirely voluntary. This often involves NDAs and redactions. To counterbalance this, we have a principle that when we enter into a contract with a company, we try to retain the right to tell the public the terms of the contract we signed, and characterize the nature of redactions that the company chose to make. For example, the report from our independent investigation of the OpenAI-HuggingFace incident included that information. Public disclosure is also a big part of our COI policy (linked on our website). That’s not to say our reports are adequate as oversight. We’re just one organization (among many doing great work), working in a voluntary setup, trying to get good evidence to the public and the world about AI, letting the facts fall where they may.
5
10
103
7,143
Devon Kerr retweeted
Can app control stop a malicious skill from loading? ▶️ Watch the full episode:
1
4
7
847
Devon Kerr retweeted
I wrote about some Linux Detection Engineering research: detecting local privilege escalation. Instead of chasing individual CVEs, the framework detects the behaviors they tend to share: suspicious UID changes, unexpected SUID/SGID execution, user namespace creation, and more. If you're interested, you can read my latest research here: elastic.co/security-labs/thr…
1
18
67
2,645
Devon Kerr retweeted
Great #research from our team members @cyril_t_f @andythevariable at @elasticseclabs Check it out ! #malware
KREMLIN is a multi-stage credential theft toolkit targeting Brazilian banking users. New research from Elastic Security Labs (REF9334): go.es.io/4yfkg4R by @cyril_t_f and @andythevariable The infection chain combines JavaScript loaders, an optional PE injector, and a custom C++ installer. The installer downloads and installs a malicious browser extension for Chrome and Edge and/or deploys an embedded PULSAR or REMCOS RAT. This malicious extension is then used for web-browser data interception and exfiltration. KREMLIN resolves its C2 endpoints from Ethereum. Smart contracts store payload URLs and extension download locations as on-chain key-value pairs. The operators update endpoints by writing a new transaction. The extension installation bypasses Chromium's integrity system. The installer launches Chrome under a debugger, recovers the App-Bound OSCrypt key from process memory, extracts the seed from resources.pak, then regenerates the HMACs and encrypted SHA-256 hashes that Secure Preferences requires. The extension registers silently with developer mode forced on. Once active, it logs input fields, intercepts HTTP requests by configurable URL and method rules, injects attacker-controlled HTML, and exfiltrates intercepted data, cookies, and credentials over WebSocket and HTTP. Elastic Security Labs Threat Command registered the network canary domain that operates as a kill switch. We observed thousands of implants from Brazil attempting to check in to this domain. Once this domain was live, the KREMLIN loaders crash before trying to update or install the final payload, temporarily disrupting this campaign. The targeting is clear. Lure filenames impersonate PIX transfers, bank statements, and receipts from Banco do Brasil, Bradesco, Sicoob, Santander, C6 Bank, and PagBank. Ethereum transaction timestamps cluster in São Paulo working hours. Portuguese-language artifacts appear throughout the codebase.
1
9
587
Devon Kerr retweeted
RE work by @cyril_t_f uncovered a kill switch in the implant for an NX domain, so we registered it. It was rewarding to see the implants checking in and then terminating - hopefully giving defenders detections and time to remediate.
KREMLIN is a multi-stage credential theft toolkit targeting Brazilian banking users. New research from Elastic Security Labs (REF9334): go.es.io/4yfkg4R by @cyril_t_f and @andythevariable The infection chain combines JavaScript loaders, an optional PE injector, and a custom C++ installer. The installer downloads and installs a malicious browser extension for Chrome and Edge and/or deploys an embedded PULSAR or REMCOS RAT. This malicious extension is then used for web-browser data interception and exfiltration. KREMLIN resolves its C2 endpoints from Ethereum. Smart contracts store payload URLs and extension download locations as on-chain key-value pairs. The operators update endpoints by writing a new transaction. The extension installation bypasses Chromium's integrity system. The installer launches Chrome under a debugger, recovers the App-Bound OSCrypt key from process memory, extracts the seed from resources.pak, then regenerates the HMACs and encrypted SHA-256 hashes that Secure Preferences requires. The extension registers silently with developer mode forced on. Once active, it logs input fields, intercepts HTTP requests by configurable URL and method rules, injects attacker-controlled HTML, and exfiltrates intercepted data, cookies, and credentials over WebSocket and HTTP. Elastic Security Labs Threat Command registered the network canary domain that operates as a kill switch. We observed thousands of implants from Brazil attempting to check in to this domain. Once this domain was live, the KREMLIN loaders crash before trying to update or install the final payload, temporarily disrupting this campaign. The targeting is clear. Lure filenames impersonate PIX transfers, bank statements, and receipts from Banco do Brasil, Bradesco, Sicoob, Santander, C6 Bank, and PagBank. Ethereum transaction timestamps cluster in São Paulo working hours. Portuguese-language artifacts appear throughout the codebase.
Made with AI
3
3
368
KREMLIN is a multi-stage credential theft toolkit targeting Brazilian banking users. New research from Elastic Security Labs (REF9334): go.es.io/4yfkg4R by @cyril_t_f and @andythevariable The infection chain combines JavaScript loaders, an optional PE injector, and a custom C++ installer. The installer downloads and installs a malicious browser extension for Chrome and Edge and/or deploys an embedded PULSAR or REMCOS RAT. This malicious extension is then used for web-browser data interception and exfiltration. KREMLIN resolves its C2 endpoints from Ethereum. Smart contracts store payload URLs and extension download locations as on-chain key-value pairs. The operators update endpoints by writing a new transaction. The extension installation bypasses Chromium's integrity system. The installer launches Chrome under a debugger, recovers the App-Bound OSCrypt key from process memory, extracts the seed from resources.pak, then regenerates the HMACs and encrypted SHA-256 hashes that Secure Preferences requires. The extension registers silently with developer mode forced on. Once active, it logs input fields, intercepts HTTP requests by configurable URL and method rules, injects attacker-controlled HTML, and exfiltrates intercepted data, cookies, and credentials over WebSocket and HTTP. Elastic Security Labs Threat Command registered the network canary domain that operates as a kill switch. We observed thousands of implants from Brazil attempting to check in to this domain. Once this domain was live, the KREMLIN loaders crash before trying to update or install the final payload, temporarily disrupting this campaign. The targeting is clear. Lure filenames impersonate PIX transfers, bank statements, and receipts from Banco do Brasil, Bradesco, Sicoob, Santander, C6 Bank, and PagBank. Ethereum transaction timestamps cluster in São Paulo working hours. Portuguese-language artifacts appear throughout the codebase.
1
27
95
6,395
Devon Kerr retweeted
CISAの新しいLogging Reference Architecture。 これ、かなり刺さる。 「SIEMにログを集めました」は、もう答えにならない。 問われるのは、 ・必要なログが本当に届いているか ・欠損や遅延を検知できるか ・元の文脈を潰さず正規化できるか ・障害後にReplayできるか ・必要な期間、検索できるか ・侵害経路を最後まで再構築できるか そしてCISAは、 「全ログをSIEMに入れる必要はない」 とまで踏み込む。 Repository First、Selective Feed、階層ストレージ。 高価なSIEMをログ倉庫にするのではなく、 検知に必要なログと、フォレンジックに必要なログを分けて設計する。 さらに強烈なのがこれ。 コネクタがGreenでも、ログが使えなければ“能力”ではない。 収集できていることと、 インシデント対応できることは別物。 SOCで見るべきKPIは 「ログ収集率」ではなく、 そのログで攻撃を再構築できるか。 CISAがようやく、そこまで言語化した。 cisa.gov/resources-tools/res…
1
49
236
14,495