
Félix Aimé
@felixaime
Followers
6K
Following
3K
Media
663
Statuses
6K
Threat Intel. stakhanovite ⛏️ and proud dad. Former @Kaspersky & @CERT_FR. Principal CTI researcher at @sekoia_io, focused on state-sponsored / hybrid stuff.
🇫🇷
Joined February 2009
RT @wunderwuzzi23: AWS published an advisory for their compromised Amazon Q Developer VS Code Extension. You must update to version 1.85….
0
4
0
RT @sekoia_io: No OS left behind. It happily infects Windows, macOS, and Linux systems. Unlike before, they're not impersonating a real c….
0
2
0
RT @felixaime: @censysio @GreyNoiseIO ViciousTrap != PolarEdge, its another threat actor. Otherwise, we would have given it the same name.….
0
1
0
Our blogpost on this threat. Sad to not see any mention 😔
blog.sekoia.io
Discover ViciousTrap, a newly identified threat who turning edge devices into honeypots en masse targeting
2
0
4
#Ayysshush is #ViciousTrap a threat actor previously disclosed by @sekoia_io. Note that they are using their SSH access to drop and execute some bash script hosted on previously compromised #QNAP systems.
labs.greynoise.io
Using an AI powered network traffic analysis tool we built called SIFT, GreyNoise has caught multiple anomalous network payloads with zero-effort that are attempting to disable TrendMicro security...
1
2
11
Excited to see this paper finally published! Meet #ViciousTrap, a threat actor compromising and turning edge devices into honeypots! .
blog.sekoia.io
Discover ViciousTrap, a newly identified threat who turning edge devices into honeypots en masse targeting
1
10
21
RT @pentest_swissky: How I Got Hacked: A Warning about Malicious PoCs - @Chocapikk_ .
chocapikk.com
An in-depth forensic analysis of how a seemingly legitimate Proof-of-Concept (PoC) for CVE-2020-35489 turned out to be a cleverly disguised malware. This blog post details the attack vector, payload...
0
40
0
Our last blogpost on #ClickFake, yet another DPRK campaign. 🙃
blog.sekoia.io
Discover how Lazarus leverages fake job sites in the ClickFake Interview campaign targeting crypto firms using the ClickFix tactic.
0
1
12
RT @MrDanPerez: 🚨UNC3886 🇨🇳 Deploying Custom Malware to Juniper Junos OS Router🚨. 👀 and ensure you are keeping your devices up to date!.
0
5
0
RT @CartesDuMonde: France 🇫🇷 : CNEWS la voix de Moscou🧵. CNEWS se dit être le porte-voix de la liberté, d’être l’étendard des patriotes. En….
0
1K
0
D'utilité publique.
France 🇫🇷 : La Russie attaque la France🧵. Le Kremlin menace la France, que cela soit du feu nucléaire ou de l’extermination de son armée. Moscou multiplie la désinformation afin d'accroître les tensions afin de générer du chaos. Nous sommes à l’ère de la guerre hybride⤵️. 1/24
0
0
3