BushidoToken Profile Banner
Will Profile
Will

@BushidoToken

Followers
36K
Following
36K
Media
2K
Statuses
12K

Senior Threat Intel Advisor @TeamCymru | Co-founder @CuratedIntel | Co-author @SANSForensics FOR589 | Co-founder @BSidesBournemth | @darknetdiaries #126: REvil

🇬🇧
Joined March 2013
Don't wanna be here? Send us removal request.
@BushidoToken
Will
13 hours
First we saw APT28 using an LLM to generate commands in their malware and now, a ransomware is using an LLM to start file system encryption 👀.
@ESETresearch
ESET Research
14 hours
#ESETResearch has discovered the first known AI-powered ransomware, which we named #PromptLock. The PromptLock malware uses the gpt-oss:20b model from OpenAI locally via the Ollama API to generate malicious Lua scripts on the fly, which it then executes 1/6
Tweet media one
3
21
105
@CPAC
CPAC
14 days
Zohran Mamdani: He votes for activists, not you
29
27
90
@BushidoToken
Will
3 days
For all UK 🇬🇧 folks working in CTI, @bletchleypark is a must visit! . The intelligence factory was a great reminder of the people and processes involved in this type of work (particularly the intelligence lifecycle). Easy to relate to modern day cybercrime intelligence! #FOR589
Tweet media one
1
1
36
@BushidoToken
Will
3 days
Tweet media one
0
2
13
@BushidoToken
Will
5 days
Was rifling through the Interlock advisory from last month and noticed this 'Sysmon.sys' file. It was familiar, looked on VT and saw the ThreatFire System Monitor in the description. I also saw it in this Sophos report on RansomHub ( . maybe an affiliate?
Tweet media one
Tweet media two
Tweet media three
@CISACyber
CISA Cyber
1 month
🛡️ Interlock ransomware is on the rise. Interlock actors are targeting businesses & #CriticalInfrastructure with double extortion ransomware attacks. Learn more and see our top recommended actions in our joint Cybersecurity Advisory. 👉 . #StopRansomware
Tweet media one
1
4
21
@BushidoToken
Will
5 days
ICYMI: Was just perusing the latest CrowdStrike 2025 Threat Hunting report ( and check this wild timeline for Scattered Spider - from account takeover to Entra ID bulk user export in <5 minutes 👀
Tweet media one
5
74
223
@BushidoToken
Will
5 days
RT @g0njxa: A Windows #Clickfix alternative seen in the wild on a mass-spreading malware campaign bypassing traditional Win+R shortcut rest….
0
59
0
@BushidoToken
Will
6 days
Follow-up 👇 .
@WhichbufferArda
Arda Büyükkaya
6 days
There is a lot of disinformation and counterintelligence activity circulating in Telegram channels. If you are a journalist or a CTI analyst, stay cautious, your role is to provide accurate information, not to amplify the hype.
Tweet media one
Tweet media two
0
1
8
@BushidoToken
Will
6 days
Interesting example of a cybercrime counterintelligence operation.
1
0
11
@BushidoToken
Will
6 days
Confirmed fake: @Europol told SecurityWeek that it’s a “scam” and the message does not come from the law enforcement agency.
Tweet card summary image
securityweek.com
A $50,000 reward from Europol for two members of the Qilin ransomware group is a ‘scam’, according to the law enforcement agency.
@DarkWebInformer
Dark Web Informer
11 days
Europol offering only $50,000 for Qilin admins. seems super low, but they are the feds.
Tweet media one
2
6
22
@BushidoToken
Will
6 days
RT @vmray: 🚨Alert: Internet Archive abused as hosting service for stealthy malware delivery. 🔍This delivery chain is another example of leg….
0
53
0
@barstoolsports
Barstool Sports
5 days
RT @PardonMyTake: Tuesday night max woke Big Cat up with a flashlight at 2am because he thought we were going to get sued. @forthepeople ht….
0
18
0
@BushidoToken
Will
6 days
RT @ExpelSecurity: 🚨 A NEW trojan on the block spotted by our threat intel team 👀. We saw files with the code-signing signature “GLINT SOF….
0
18
0
@BushidoToken
Will
7 days
RT @threatinsight: Proofpoint @threatinsight identified a unique attack chain leveraging GitHub notifications to deliver #Rhadamanthys. We….
0
27
0
@BushidoToken
Will
8 days
RT @inversecos: NEW LAB: Scattered Spider (UNC3944) 🕷️🕸️. Scattered Spider hits indie studio AB Projekt Blue, deploying ransomware and stea….
0
84
0
@BushidoToken
Will
8 days
Maltego CSV imports to brrrr.
@SttyK
SttyK✨💉👩‍⚕️(スティッキー)
12 days
Someone just dropped almost 1.4k email address list used by North Korean IT workers.
0
0
36
@BushidoToken
Will
10 days
Thank you everyone who was able to make it to @BSidesBournemth 2025! We had an amazing lineup of speakers, workshops, villages, and sponsors! The organisers have had some lovely feedback from everyone who enjoyed the day. Hope to see you all next year!
Tweet media one
Tweet media two
Tweet media three
Tweet media four
0
1
8
@BushidoToken
Will
10 days
RT @ollieatnowhere: We were in Britain's Venice beach for the inaugural @BSidesBournemth today. Thanks to @BushidoToken and team. Great….
0
3
0
@America1stLegal
America First Legal
1 month
WRECKED. Hirono: Has any court said that DEI is unconstitutional? Yes or no?. Hamilton: Yes. Hirono: Which court?. Hamilton: The United States Supreme Court. Hirono: I disagree with you…. Hamilton: You can go read it yourself. 🔥🔥🔥
2K
11K
51K
@BushidoToken
Will
13 days
Some people think the APTs are ahead of the Red Teamers, but in fact it’s often the other way around. The commercial offsec industry is ahead of many of the APTs… who are piggybacking off their research.
0
5
23
@BushidoToken
Will
13 days
Favourite sticker I saw at Defcon
Tweet media one
1
4
41
@BushidoToken
Will
13 days
Probably my favourite slide from the talk that’s sums up the whole trend nicely:
Tweet media one
@BushidoToken
Will
16 days
Thanks everyone for coming, was a packed room for my Defcon33 talk on Russian APT activity 🇷🇺🐻. Here's the slides and linked resources at the end.
1
12
71
@BushidoToken
Will
14 days
Seems the scammers have already been arrested… the Dubai Police don’t mess about:.
@DubaiPoliceHQ
Dubai Policeشرطة دبي
21 days
#News | Dubai Police Urge Public Caution Following Arrests Linked to ‘Traffic Fine Discount’ Fraud . Details: . #BewareOfFraud
Tweet media one
0
0
3