IcsNick Profile Banner
ICSNick Profile
ICSNick

@IcsNick

Followers
1K
Following
2K
Media
99
Statuses
550

Time to leave this platform. If you like to contact me professionally, find me on LinkedIn.

Stockholm, Sverige
Joined March 2019
Don't wanna be here? Send us removal request.
@IcsNick
ICSNick
11 months
Time to leave this platform. If you like to contact me professionally, find me on LinkedIn
0
0
1
@IcsNick
ICSNick
1 year
Hope to see you virtual there!
@sansforensics
SANS DFIR
1 year
Join us at #CTISummit when @IcsNick and Mattias Wåhlén will discuss: 🦗 The rise of Cicada 3301 #ransomware 🔗 Links to the notorious BlackCat group 🔍 TTPs and infrastructure uncovered ➡️ Learn More & Save Your Spot: https://t.co/lHG68IgpY0 #ThreatIntel #CTI #MalwareAnalysis
0
0
4
@IcsNick
ICSNick
1 year
Did a 10 minute lightning talk at @SEC_T_org analyzing the an ESXi ransomware from the new group Cicada 3301 and how we see links to the debunked RaaS BlackCat. https://t.co/HI16XAQpT0
0
0
1
@IcsNick
ICSNick
1 year
I am glad and humble that @BleepinComputer picked up the analysis I did with @WahlenPMattias regarding Cicada 3301 ransomware and possible connections to AlphV/BlackCat.
@BleepinComputer
BleepingComputer
1 year
Cicada3301 ransomware’s Linux encryptor targets VMware ESXi systems - @billtoulas https://t.co/RZ9hibsOEP https://t.co/RZ9hibsOEP
1
1
5
@IcsNick
ICSNick
1 year
CrowdStrike pushes the ultimate security update. All computers become unhackable.
0
1
2
@IcsNick
ICSNick
1 year
So LockBit = Booger Toilet Sniffer BlackBasta = Lumpy Toilet Head Play Ransomware = Doofus Gizzard Tush So @SwiftOnSecurity @GossiTheDog @rj_chap @TheDFIRReport @thegrugq @BushidoToken @cyb3rops as being CTI though leaders. Are you with me on silly mission?
2
0
3
@IcsNick
ICSNick
1 year
So, Threat Intel community. I think we should change the way we name threat actors, from sound as villains to a more appropriate convention showing their true colors. My suggestion is that we turn to Captain Underpants “Professor Poopypants name change-o-chart 2000”
1
0
6
@IcsNick
ICSNick
1 year
@rj_chap might be of your interest ;) @TheQueenofELF thanks for giving inspiration and laying the groundwork with your amazing talk on the subject matter.
1
0
2
@IcsNick
ICSNick
1 year
Anders Olsson’s and my talk from Security Fest. Get insights how VMware/ESXi ransomware works, how to recover, how to do incident response and how to protect for it. Also how Captain Underpants can assist in Threat Intelligence. https://t.co/CRXTMIMQpe #Truesec
1
5
16
@IcsNick
ICSNick
2 years
Did an investigation regarding DarkGate delivered by Teams together with my fantastic colleague Jakob Nordenlund at @Truesec. A lot of good IoC for all defenders! https://t.co/lyJtDYZFnh
Tweet card summary image
truesec.com
Malspam campaigns involving DarkGate Loader have been on the rise since its author started advertising it as a Malware-as-a-Service offering on popular cybercrime forums in June 2023. Until now...
2
25
66
@a_plakhotniuk
Andrii Plakhotniuk
2 years
Jag beklagar djupt Nobelstiftelsens beslut från igår att bjuda in Rysslands och Vitrysslands ambassadörer till den kommande Nobelprisutdelningen den 10 december 2023. Jag har flera frågor till den ansedda Nobelstiftelsen – vad har förändrats sedan förra året, när er organisation
150
582
3K
@Kostastsale
Kostas
2 years
New blog post based on a recent intrusion I observed with #Ursnif as the initial infection! Topics include: ✅ Detection opportunities ✅ TAs clipboard data ✅ Post-exploitation and more! The artifacts for this case: https://t.co/jTDVVL3pLp The blog:
5
75
192
@IcsNick
ICSNick
3 years
All good things most unfortunately come to an end. I have decided to retire from @TheDFIRReport to focus on other things. It has been an awesome time and I love what @TheDFIRReport do for the community. Thank you for everything!
0
0
26
@Truesec
Truesec
3 years
Time for a quick visit on the #DarkWeb? 💻 Join our #ThreatIntelligence specialists @cstromblad and Jolina Pettersson for our webinar to learn about: ✔️ Infostealers: how they work ✔️ Demo: Dark Web marketplace ✔️ Signs to predict #cyberattacks Sign up: https://t.co/N2fGhbUxDH
0
4
5
@IcsNick
ICSNick
3 years
I had the absolute pleasure to speak at the SANS CTI Summit about cracking ransomware tooling. It is now available at SANS DFIR YouTube channel. https://t.co/G5N55RDKqp @sansforensics
0
2
11
@IcsNick
ICSNick
3 years
Best read of the day! Amazing report with a lot of great insight for all defenders out there.
@TheDFIRReport
The DFIR Report
3 years
2022 Year in Review ➡️Most common TTPs we saw in 2022 ➡️Trends around IAB's ➡️Top detections ➡️Ransomware propagation methods ➡️and more! https://t.co/KT7u22VHFc
0
2
6
@Truesec
Truesec
3 years
Anonymous Sudan: most likely Russia disrupting Swedens🇸🇪 NATO-application. Today, Truesec’s #ThreatIntelligence Unit released a report which explains how the "Anonymous Sudan" has nothing to do with the online activists collectively known as Anonymous. https://t.co/eYZ1ymyaa1
0
17
25
@vxunderground
vx-underground
3 years
Behold the latest addition to the Marvel cinematic universe: IRQL_NOT_LESS_OR_EQUAL man
17
120
740
@IcsNick
ICSNick
3 years
Thank you very much @TheDFIRReport ! Looks really awesome.
0
0
18