Intrinsec Profile Banner
Intrinsec Profile
Intrinsec

@Intrinsec

Followers
2K
Following
118
Media
357
Statuses
1K

Notre métier ? Protéger le vôtre ! Management des risques, Évaluation, Cyber Threat Intelligence, Détection, Réponse (CERT), Innovation.

Courbevoie, France
Joined March 2013
Don't wanna be here? Send us removal request.
@Intrinsec
Intrinsec
3 months
🧵9/📕Our report: #CyberWar #ThreatIntel #APT.
0
1
2
@Intrinsec
Intrinsec
3 months
🧵7/🧩 The full picture: A vast network of Russian-aligned intrusion sets leveraging global bulletproof hosting, fake shell corps, and recycled ransomware infrastructure to target Ukraine & its allies on multiple fronts. 📉 Espionage 💣 PsyOps 🪓 Ransomware #UAC0050 #UAC0006.
1
1
2
@Intrinsec
Intrinsec
3 months
🧵6/🇺🇸 The U.S. Treasury sanctioned Zservers(Seychelles 🇸🇨 BPH provider) for aiding #LockBit. Same 2 officers are listed as managing this newer infra too. 🔀 IPv4 prefixes from Zservers were moved to new Russia-based or offshore networks:.#AS213194.#AS61336.#AS213010.
1
1
2
@Intrinsec
Intrinsec
3 months
🧵5/📌 IPs from have been previously used by ransomware groups like:.#BlackBast🦹‍♂️.#Cactus🌵.#RansomHub 🏴.👁 Impressive overlap between PsOps, espionage and ransomware infrastructure.
1
1
3
@Intrinsec
Intrinsec
3 months
🧵4/ For #UAC0006: 🌐 IPs from Global Connectivity Solutions LLP (AS215540 - UK) routed through Stark Industries (AS44477) .⬅️ May be tied to 🇷🇺 Global Internet Solutions LLC (AS207713) .Both serve as legal fronts for bulletproof hoster 4vps[.]su 🛡️.
1
1
4
@Intrinsec
Intrinsec
3 months
🧵3/ Since Jan 2025, #UAC0050 adopted NetSupport Manager for malware delivery. 🕵️‍♂️ Used Ukrainian IPs managed by:.- Karina Rashkovska.- Virtualine (AS215789 & AS214943) 🏢 Virtualine hosted infra via shell company Railnet LLC (in Kentucky 🇺🇸), linked to White Label Networks.
1
3
2
@Intrinsec
Intrinsec
3 months
🧵2/🧠 Psychological ops (#PsyOps) were key: .📩 Emails mimicking terrorist & bomb threats sent to 🇺🇦 and allies 🇨🇭🇩🇪🇵🇱🇫🇷 throughout Dec 2024. 🔎 Strong similarities with UAC-0050’s “Fire Cells Group” activities. #InfoOps #CyberThreats.
1
1
3
@Intrinsec
Intrinsec
3 months
🧵1/ In Jan & Feb 2025, both groups ramped up espionage & financially-motivated spam campaigns. 📌 Focus: global targets, but heavily centered on Ukraine. 🎯 Targets:.- Govt entities.- Defense, energy & gas sectors.- Journalists.- NGOs involved in the Ukraine war.
1
1
2
@Intrinsec
Intrinsec
3 months
🔎 [THREAD] – New analysis by Intrinsec Cyber Threat Intelligence on the latest operations by Russian-aligned intrusion sets #UAC0050 & #UAC0006📢 . 🔗 Our Report:
2
28
72
@Intrinsec
Intrinsec
4 months
8/8 – Read the report here: 👉 .Stay vigilant! 🔍.#Disinformation #CyberThreats #Infowar #Doppelganger #OSINT.
1
1
2
@Intrinsec
Intrinsec
4 months
7/8 – Why is this alarming? .⚠️ These campaigns undermine trust in institutions and seek to influence major policy decisions in Europe. 🛑 The use of bulletproof hosting services makes combating this type of manipulation increasingly difficult.
1
1
2
@Intrinsec
Intrinsec
4 months
6/8 – Who is behind this?.In 2022, Meta attributed Doppelgänger to 2 Russian entities:.📌 Structura National Technologies .📌 Social Design Agency .🔎 The report confirms that these activities have evolved, with infrastructure designed to evade detection and blocking mechanisms.
1
1
2
@Intrinsec
Intrinsec
4 months
5/8 – What narratives are being spread? .📢 Core message: Western leaders neglect domestic issues in favor of supporting Ukraine, despite economic and political crises at home. 🎯 Objective: Polarize public debate and weaken European support for Ukraine.
1
1
2
@Intrinsec
Intrinsec
4 months
4/8 – Why now? .📅 The campaign aligns with a crucial geopolitical moment in Europe: .✔️ Return of Donald Trump 🇺🇸 .✔️ Political crisis in France 🇫🇷 .✔️ German federal elections in February 2025 🇩🇪 .✔️ EU reaffirming its support for Ukraine 🇺🇦.
1
1
2
@Intrinsec
Intrinsec
4 months
3/8 – Who are the targets? .The campaign primarily targets 📢 France, Germany, Italy, Ukraine, and Israel. 🎯 The goal is to fuel societal divisions, amplify misinformation, and manipulate political discourse within these nations.
1
1
3
@Intrinsec
Intrinsec
4 months
2/8 – How does this campaign operate?.📌 Creation of fake websites mimicking influential media.📌 Automated spreading of misleading articles via bot networks on X .📌 Use of Kehr[.]io, a redirection service leveraging bulletproof hosting providers to evade detection and takedowns.
1
1
2
@Intrinsec
Intrinsec
4 months
1/8 – What is Doppelgänger? .Doppelgänger is an intrusion set engaged in large-scale disinformation campaigns, spreading false narratives via bot accounts on platforms like X (Twitter). 🎯 Goal: Manipulate public opinion by exploiting social and geopolitical tensions.
1
1
2
@Intrinsec
Intrinsec
4 months
🔎 [THREAD] – Doppelgänger: A New Disinformation Campaign Spreading on Social Media 📢.📄 A newly released report sheds light on the tactics used by this Russian-linked network to target multiple Western countries. ⬇️.
1
7
12