dadamitis Profile Banner
Danny 🌻 Profile
Danny 🌻

@dadamitis

Followers
630
Following
268
Media
176
Statuses
2K

Security Researcher @ Lumen, black coffee connoisseur, dog lover, follower of sea turtles, SHU 13, my thoughts are my own. (he/him)

Baltimore, MD
Joined January 2010
Don't wanna be here? Send us removal request.
@dadamitis
Danny 🌻
2 years
My job today is beach.
0
0
3
@dadamitis
Danny 🌻
2 years
Happy tortured poets society day to everyone!!!
0
0
1
@4A4133
John Althouse
2 years
Pivoting on the JDY C2 proxy cert hash in https://t.co/C2j3umgWeI shows an IP, 45.76.67.43, that was not listed in Lumen's IOC list. Though it looks like it was only active for 2 days and has since been recycled back into Vultr.
1
4
5
@labscon_io
LABScon 2026
3 years
#LABScon23 is here! Sep 20-23, 2023 in Scottsdale, Arizona Head to https://t.co/q1msQScycV for all the details!
0
26
49
@Dave_Maynor
David Maynor
3 years
https://t.co/HYyKDnSiWu the base for a repo for low power tracker research. Expect more to be added. Great research sponsored by @cybraryIT! #flipperzero #ble #airtag
github.com
Contribute to Cybrary/CTIG_FlipOFF development by creating an account on GitHub.
1
6
9
@LabsSentinel
SentinelLabs
3 years
soon.
@juanandres_gs
J. A. Guerrero-Saade
3 years
Thank you, #LABScon22 fam. See you next year ;)
0
6
14
@LabsSentinel
SentinelLabs
3 years
New Research -- "Tainted Love" APT Operation ✴️Targeting Middle East telecom. ✴️ Likely connected to a Chinese groups in the nexus of Gallium and APT41. Full Report: https://t.co/SWnqTXiAKk By @milenkowski @juanandres_gs @joeychen @QTrust
Tweet card summary image
sentinelone.com
Cyber espionage actor deploys custom credential theft malware in new campaign targeting the telecoms sector.
1
12
19
@dadamitis
Danny 🌻
3 years
0
0
4
@dadamitis
Danny 🌻
3 years
Side note: I didn’t actually create this meme. Someone else on the internet did, so I just reposted it because it made me chuckle.
1
0
0
@dadamitis
Danny 🌻
3 years
To get all the details check out the blog here https://t.co/qfuUaK9Qgl with IOCs found here
Tweet card summary image
blog.lumen.com
0
4
15
@dadamitis
Danny 🌻
3 years
Oh and one more thing that caught my eye, when we looked at the embedded config file the malware identified itself as version 1.5. So while this latest campaign goes back to July 2022. This activity cluster almost certainly preceded that date.
1
0
9
@dadamitis
Danny 🌻
3 years
The actor also had some interesting prebuilt functions, two of which that caught our eye were tcp_forward and SOCKS5 which would allow the threat actor to tunnel commands/exfil through the router
1
0
5
@dadamitis
Danny 🌻
3 years
A couple interesting tidbits, does the threat actor behind this campaign seemed to have a strong interest in gathering email data as it transmitted through the device. Once the pcap was collected it would periodically get upload to the C2.
1
0
9
@dadamitis
Danny 🌻
3 years
Today we’re releasing research on brand new activity cluster we’re calling Hiatus. This actor has an affinity for target routers, to gather pcap and use as covert infrastructure.
2
45
124
@dadamitis
Danny 🌻
3 years
New blog dropping at 10am this morning , check it out here https://t.co/vjEt7I9Zvu
2
3
10
@dadamitis
Danny 🌻
3 years
Setting up an account on the elephant app, hit me up there dadamitis@infosec.change. Don’t worry I’ll continue to provide the same threat intel, salty comments, and spicy memes as before.
0
0
2
@securityledger
securityledger
3 years
Our latest #podcast is out with an interview with @dadamitis of @BlackLotusLabs about #ZuoRAT #malware targeting SOHO routers and home networks with #APT-style tools. Recorded at #LabsCon22. https://t.co/sRWsiHUD66 #sponsored by @ReversingLabs https://t.co/sRWsiHUD66
1
2
4
@dadamitis
Danny 🌻
3 years
Bold strategy to have your campaign outed and then ramp up operations. Let’s see how this one plays out for them.
@BlackLotusLabs
Black Lotus Labs
3 years
The Chaos #DDoS and cryptomining botnet continues to grow… We’ve identified 125 new certificates in the last month:
0
0
3
@DakotaInDC
Dakota Cary
3 years
Love this quote. When talking about paying for an on-going lawsuit to harass the victims, one agent said: "[It] really is a drop in the bucket for a country to spend $1 billion or $0.8 billion to meet the political task assigned by the Central Government." IE. $ is no object.
1
6
10