
Will
@BushidoToken
Followers
36K
Following
36K
Media
2K
Statuses
12K
Senior Threat Intel Advisor @TeamCymru | Co-founder @CuratedIntel | Co-author @SANSForensics FOR589 | Co-founder @BSidesBournemth | @darknetdiaries #126: REvil
🇬🇧
Joined March 2013
Pleased to share my latest blog post for @TeamCymru all about identifying and tracking C2 infrastructure. 1/3 🧵 .
team-cymru.com
This blog is written for threat analysts, defenders, and CTI teams who use our Scout platform—but even if you’re not a user today, it offers practical insight into how advanced research teams...
2
14
89
First we saw APT28 using an LLM to generate commands in their malware and now, a ransomware is using an LLM to start file system encryption 👀.
#ESETResearch has discovered the first known AI-powered ransomware, which we named #PromptLock. The PromptLock malware uses the gpt-oss:20b model from OpenAI locally via the Ollama API to generate malicious Lua scripts on the fly, which it then executes 1/6
3
21
105
For all UK 🇬🇧 folks working in CTI, @bletchleypark is a must visit! . The intelligence factory was a great reminder of the people and processes involved in this type of work (particularly the intelligence lifecycle). Easy to relate to modern day cybercrime intelligence! #FOR589
1
1
36
Was rifling through the Interlock advisory from last month and noticed this 'Sysmon.sys' file. It was familiar, looked on VT and saw the ThreatFire System Monitor in the description. I also saw it in this Sophos report on RansomHub ( . maybe an affiliate?
🛡️ Interlock ransomware is on the rise. Interlock actors are targeting businesses & #CriticalInfrastructure with double extortion ransomware attacks. Learn more and see our top recommended actions in our joint Cybersecurity Advisory. 👉 . #StopRansomware
1
4
21
Confirmed fake: @Europol told SecurityWeek that it’s a “scam” and the message does not come from the law enforcement agency.
securityweek.com
A $50,000 reward from Europol for two members of the Qilin ransomware group is a ‘scam’, according to the law enforcement agency.
2
6
22
RT @vmray: 🚨Alert: Internet Archive abused as hosting service for stealthy malware delivery. 🔍This delivery chain is another example of leg….
0
53
0
RT @PardonMyTake: Tuesday night max woke Big Cat up with a flashlight at 2am because he thought we were going to get sued. @forthepeople ht….
0
18
0
RT @ExpelSecurity: 🚨 A NEW trojan on the block spotted by our threat intel team 👀. We saw files with the code-signing signature “GLINT SOF….
0
18
0
RT @threatinsight: Proofpoint @threatinsight identified a unique attack chain leveraging GitHub notifications to deliver #Rhadamanthys. We….
0
27
0
RT @inversecos: NEW LAB: Scattered Spider (UNC3944) 🕷️🕸️. Scattered Spider hits indie studio AB Projekt Blue, deploying ransomware and stea….
0
84
0
Thank you everyone who was able to make it to @BSidesBournemth 2025! We had an amazing lineup of speakers, workshops, villages, and sponsors! The organisers have had some lovely feedback from everyone who enjoyed the day. Hope to see you all next year!
0
1
8
RT @ollieatnowhere: We were in Britain's Venice beach for the inaugural @BSidesBournemth today. Thanks to @BushidoToken and team. Great….
0
3
0
Seems the scammers have already been arrested… the Dubai Police don’t mess about:.
#News | Dubai Police Urge Public Caution Following Arrests Linked to ‘Traffic Fine Discount’ Fraud . Details: . #BewareOfFraud
0
0
3