ICSNick
@IcsNick
Followers
1K
Following
2K
Media
99
Statuses
550
Time to leave this platform. If you like to contact me professionally, find me on LinkedIn.
Stockholm, Sverige
Joined March 2019
Time to leave this platform. If you like to contact me professionally, find me on LinkedIn
0
0
1
Hope to see you virtual there!
Join us at #CTISummit when @IcsNick and Mattias Wåhlén will discuss: 🦗 The rise of Cicada 3301 #ransomware 🔗 Links to the notorious BlackCat group 🔍 TTPs and infrastructure uncovered ➡️ Learn More & Save Your Spot: https://t.co/lHG68IgpY0
#ThreatIntel #CTI #MalwareAnalysis
0
0
4
Did a 10 minute lightning talk at @SEC_T_org analyzing the an ESXi ransomware from the new group Cicada 3301 and how we see links to the debunked RaaS BlackCat. https://t.co/HI16XAQpT0
0
0
1
I am glad and humble that @BleepinComputer picked up the analysis I did with @WahlenPMattias regarding Cicada 3301 ransomware and possible connections to AlphV/BlackCat.
Cicada3301 ransomware’s Linux encryptor targets VMware ESXi systems - @billtoulas
https://t.co/RZ9hibsOEP
https://t.co/RZ9hibsOEP
1
1
5
CrowdStrike pushes the ultimate security update. All computers become unhackable.
0
1
2
So LockBit = Booger Toilet Sniffer BlackBasta = Lumpy Toilet Head Play Ransomware = Doofus Gizzard Tush So @SwiftOnSecurity @GossiTheDog @rj_chap @TheDFIRReport @thegrugq @BushidoToken @cyb3rops as being CTI though leaders. Are you with me on silly mission?
2
0
3
So, Threat Intel community. I think we should change the way we name threat actors, from sound as villains to a more appropriate convention showing their true colors. My suggestion is that we turn to Captain Underpants “Professor Poopypants name change-o-chart 2000”
1
0
6
@rj_chap might be of your interest ;) @TheQueenofELF thanks for giving inspiration and laying the groundwork with your amazing talk on the subject matter.
1
0
2
Anders Olsson’s and my talk from Security Fest. Get insights how VMware/ESXi ransomware works, how to recover, how to do incident response and how to protect for it. Also how Captain Underpants can assist in Threat Intelligence. https://t.co/CRXTMIMQpe
#Truesec
1
5
16
It is a first for me to be featured in @BleepinComputer , so I am very to announce that @nordenlund and my work was featured there today. https://t.co/yYTIWOjpeF
bleepingcomputer.com
A new phishing campaign is abusing Microsoft Teams messages to send malicious attachments that install the DarkGate Loader malware.
1
5
20
Did an investigation regarding DarkGate delivered by Teams together with my fantastic colleague Jakob Nordenlund at @Truesec. A lot of good IoC for all defenders! https://t.co/lyJtDYZFnh
truesec.com
Malspam campaigns involving DarkGate Loader have been on the rise since its author started advertising it as a Malware-as-a-Service offering on popular cybercrime forums in June 2023. Until now...
2
25
66
Jag beklagar djupt Nobelstiftelsens beslut från igår att bjuda in Rysslands och Vitrysslands ambassadörer till den kommande Nobelprisutdelningen den 10 december 2023. Jag har flera frågor till den ansedda Nobelstiftelsen – vad har förändrats sedan förra året, när er organisation
150
582
3K
New blog post based on a recent intrusion I observed with #Ursnif as the initial infection! Topics include: ✅ Detection opportunities ✅ TAs clipboard data ✅ Post-exploitation and more! The artifacts for this case: https://t.co/jTDVVL3pLp The blog:
5
75
192
All good things most unfortunately come to an end. I have decided to retire from @TheDFIRReport to focus on other things. It has been an awesome time and I love what @TheDFIRReport do for the community. Thank you for everything!
0
0
26
Time for a quick visit on the #DarkWeb? 💻 Join our #ThreatIntelligence specialists @cstromblad and Jolina Pettersson for our webinar to learn about: ✔️ Infostealers: how they work ✔️ Demo: Dark Web marketplace ✔️ Signs to predict #cyberattacks Sign up: https://t.co/N2fGhbUxDH
0
4
5
I had the absolute pleasure to speak at the SANS CTI Summit about cracking ransomware tooling. It is now available at SANS DFIR YouTube channel. https://t.co/G5N55RDKqp
@sansforensics
0
2
11
Best read of the day! Amazing report with a lot of great insight for all defenders out there.
2022 Year in Review ➡️Most common TTPs we saw in 2022 ➡️Trends around IAB's ➡️Top detections ➡️Ransomware propagation methods ➡️and more! https://t.co/KT7u22VHFc
0
2
6
Anonymous Sudan: most likely Russia disrupting Swedens🇸🇪 NATO-application. Today, Truesec’s #ThreatIntelligence Unit released a report which explains how the "Anonymous Sudan" has nothing to do with the online activists collectively known as Anonymous. https://t.co/eYZ1ymyaa1
0
17
25
Behold the latest addition to the Marvel cinematic universe: IRQL_NOT_LESS_OR_EQUAL man
17
120
740