PRODAFT Profile Banner
PRODAFT Profile
PRODAFT

@PRODAFT

Followers
9K
Following
95
Media
546
Statuses
894

Proactive Defense Against Future Threats | Pioneering #CyberSec and #ThreatIntelligence in Europe & MENA since ’12. CTI Platform: #USTA Risk Intel: #BLINDSPOT

Europe
Joined July 2012
Don't wanna be here? Send us removal request.
@PRODAFT
PRODAFT
5 months
🚨 BIG NEWS: THE SYS INITIATIVE 🚨. For years, cyber criminals have hidden in the shadows of forums. They operated behind fake names, encrypted channels, and closed communities. Reputation and trust were their most valuable currencies. Now is the time to shift from defense to
7
21
83
@PRODAFT
PRODAFT
10 days
Our Ravens monitor every move of cybercriminals and intervene when necessary. Support them with the SYS Initiative:. #CyberSecurity #ThreatIntelligence #ReportCyberCrime #CyberCrime #IOC
0
1
3
@grok
Grok
2 days
Join millions who have switched to Grok.
47
86
635
@PRODAFT
PRODAFT
17 days
🚀 We've shared an IDA Pro decryption script for Matanbuchus 3.0, capable of decrypting ChaCha20 strings & resolving APIs/modules/syscalls using MurmurHash3. Fresh IOCs also available! . 👉Check it out: #threatintel #malware #IOC
Tweet media one
0
13
70
@PRODAFT
PRODAFT
24 days
🇮🇷 Iran-nexus espionage group Subtle Snail (UNC1549, TA455) linked to Charming Kitten is ramping up European ops, infecting telecom organizations and exfiltrating sensitive documents. They've impacted 10 organizations in the last week. Victim notification is ongoing. Do not skip
Tweet media one
1
22
52
@PRODAFT
PRODAFT
1 month
⚠️ Did you know? While St. Paul announced their cyberattack now, BLINDSPOT detected Neferious Mantis (a.k.a. Interlock) precursor activity 10 days ago! 🕵️‍♀️ Gain a crucial advantage & avoid being a victim. Public news: 🔗 . #threatintel #ransomware
Tweet media one
1
4
20
@PRODAFT
PRODAFT
1 month
Seriously? 🤯 Supernatural Cockroach (a.k.a. National Hazard Agency) exploiting basic default credentials on Fortinet, Palo Alto, Cisco & others…and deploying ransomware. Are we still seeing this in 2025? . 📄Report (subscribed users only):
Tweet media one
11
7
15
@PRODAFT
PRODAFT
1 month
Ransomware group���s internal news exposes management’s plans and decisions. Highlights from Qilin: . 🔒 Mandated 50% minimum ransom price .📰 Journalists engaged for the blog .🚫 Restrictions on BRICS attacks.⚖️Lawyer service. and more…. #Ransomware #Cybersecurity #ThreatIntel
Tweet media one
2
0
17
@PRODAFT
PRODAFT
1 month
RT @TheHackersNews: 🚨 New malware CastleLoader is hijacking systems through fake GitHub repos and phishing sites—469 confirmed infections.….
Tweet card summary image
thehackernews.com
CastleLoader malware infected 469 devices via ClickFix, GitHub, and phishing since May 2025. Malware delivery is evolving fast.
0
34
0
@PRODAFT
PRODAFT
1 month
🚨 CastleLoader: An emerging loader malware using phishing & fake GitHub repos to deploy RATs & stealers. Now targeting enterprise users via fake Zscaler Client & more. 📄 Read the report: 🔍IOCs: . #ThreatIntel #Malware
Tweet media one
8
8
57
@PRODAFT
PRODAFT
1 month
Catch the unknowns. 🕵️‍♂️ Understand the attackers. Be ready. 🛡️ . CATALYST delivers fresh IOCs & never-before-seen TTPs, linked to threat clusters. Level up your threat intel! . 👉 Try it: #ThreatIntel #Malware #IOCs #TTPs
Tweet media one
4
4
19
@PRODAFT
PRODAFT
1 month
Did you play Chemia on Steam? 🎮 Then you should be worried. LARVA-208’s modification of the game to distribute Fickle Stealer, HijackLoader and Vidar demonstrates a concerning trend. ➡️Check the IOCs now: . #threatintel #cybersecurity #malware #IOC
Tweet media one
2
21
61
@PRODAFT
PRODAFT
1 month
Starting from Monday, we will no longer be accepting any accounts of XSS[.]is. Thank you for consistently providing accounts over the past months. We appreciate your business !. #SYSInitiative #SYS #PRODAFT #XMR
Tweet media one
@Europol
Europol
1 month
🚨 Suspected admin of a top Russian-speaking cybercrime forum, was arrested in Ukraine. The suspect, active for nearly 20 years, allegedly made €7M facilitating cybercrime. 🇫🇷🇺🇦🇪🇺 Operation led by France with Europol support.
Tweet media one
3
6
43
@PRODAFT
PRODAFT
1 month
RT @TheHackersNews: 🚨 Web3 devs targeted with fake AI job interviews — to steal your crypto. Hackers lure victims with sites like “Norlax….
Tweet card summary image
thehackernews.com
Hackers target Web3 developers using fake AI tools and malware to steal crypto wallets and credentials.
0
40
0
@PRODAFT
PRODAFT
1 month
🚨 LARVA-208 is back! . Now targeting Web3 developers via fake AI platforms with job offers & portfolio reviews. Malware disguised as a Realtek HD Audio Driver is deployed during interviews. 📄 Read the full report: 🔍 IOCs:
Tweet media one
2
10
22
@PRODAFT
PRODAFT
1 month
Spoiler: DDoSing is bad, kids.
@Europol
Europol
1 month
🚨 Operation Eastwood targets pro-Russian cybercrime network NoName057(16) and shuts down over one hundred criminal servers in global operation. Read more in our press release ⤵️.
Tweet media one
1
2
7
@PRODAFT
PRODAFT
1 month
🚨 AI is supercharging phishing! . Cybercriminals now use LLMs to auto-generate realistic sites, lowering the barrier to attack. They define detailed personas & use AI to build convincing pages. Are we ready to fight AI-powered phishing? . #phishing #threatintel #LLMs #AI
Tweet media one
0
5
19
@PRODAFT
PRODAFT
2 months
➡️ Fresh IOCs on Matanbuchus 3.0: . #malware #threatintel #IOC.
Tweet card summary image
github.com
This repository contains indicators of compromise (IOCs) of our various investigations. - prodaft/malware-ioc
@PRODAFT
PRODAFT
2 months
🚨Matanbuchus 3.0 is here!. Threat actors are already buzzing about this completely rewritten loader. DNS/HTTPS C2, in-memory execution, reverse shell/WMI, morphing builds & a multitenant panel. Priced at $10K–$15K/month. Stay informed. #threatintelligence #cybersecurity
Tweet media one
Tweet media two
Tweet media three
Tweet media four
0
9
32
@PRODAFT
PRODAFT
2 months
🚨Matanbuchus 3.0 is here!. Threat actors are already buzzing about this completely rewritten loader. DNS/HTTPS C2, in-memory execution, reverse shell/WMI, morphing builds & a multitenant panel. Priced at $10K–$15K/month. Stay informed. #threatintelligence #cybersecurity
Tweet media one
Tweet media two
Tweet media three
Tweet media four
1
11
43
@PRODAFT
PRODAFT
2 months
CoreSecThree spotted! 🔍 . Exploiting Cloudflare Workers to deliver ClickFix & operate through a network of 5000+ compromised websites. Now a cybercrime "as-a-service." 🤯. Get IOCs: Report (subscriber only):
Tweet media one
0
11
41