Threat Intelligence
Expert analysis, curated IOCs, and emerging threat trends from our research team
Our Mission
We transform threat intelligence into impact. By accelerating attribution through infrastructure analysis, predictive models, and expert insights, we connect malicious activity to real-world actors faster. Our mission is simple: make cybercrime matter by ensuring defenders can anticipate threats, disrupt adversaries, and help bring criminals to justice.
What You'll Find Here
Threat Analysis
In-depth analysis of APT groups, malware families, and active campaigns
Emerging Trends
Early detection of new attack vectors and evolving adversary tactics
Actor Profiling
Detailed profiles of threat actors, motivations, and capabilities
Expert Discussion
Join discussions with security professionals and researchers
Latest Threat Intelligence
Stay ahead of emerging threats with our latest analysis and intelligence reports
Latest 6 posts
EvilTokens: Device Code Phishing Goes Industrial
We fed 95 EvilTokens campaign IPs into ClusterHawk and mapped the full infrastructure architecture: a Cloudflare CDN frontend, fragmented backend hosting with DocuSign lures and Exim mail servers, a bridge cluster with Google Trust Services certificates on compromised business domains, Cobalt Strike C2 via domain fronting, and an unreported IoT proxy layer of compromised Hikvision/Dahua surveillance cameras on Chinese telecom networks.
Profiling the Largest Identifiable Exposed AI Infrastructure on the Internet
Over 1,500 IPs from Shodan's exposed Ollama index were analyzed through ClusterHawk. After filtering 60% honeypots, 13 of 27 clusters pointed to a single operator — XRUI TECHNOLOGY LIMITED — running identical nginx/MySQL/Ollama stacks with unauthenticated qwen3-vl inference across 35+ hosts alongside a Chinese sports gambling site. This is the largest identifiable exposed AI infrastructure we've found in one operator's hands.
OVERCAST: Tracking 1,900 Nation-State RDP Nodes Across Cloudzy's C2P Ecosystem
We received 50 validated IPs linked to a suspected Russian state-sponsored APT. We profiled them through ClusterHawk and extracted a common fingerprint — then pivoted on that profile against internet scanning data and surfaced approximately 1,900 matching assets across 15 countries. We designate this infrastructure tracking effort OVERCAST.
The Pattern in the Noise: What 1,602 Exposed Modbus Systems Reveal About Industrial Security's Systemic Failures
Analyzing 1,602 internet-visible Modbus systems revealed not scattered misconfigurations but systematic patterns—95% shared TLS fingerprints, identical certificates, same CVEs across clusters. This isn't about individual negligence; it's how the entire ICS ecosystem deploys critical infrastructure in predictable, exploitable ways.
When Your Router Becomes Someone Else's Weapon: Uncovering a 800+ Proxy Network via KeeneticOS Router
Through infrastructure clustering analysis, we identified a proxy network containing 832 compromised KeeneticOS routers operating across Russian ISPs. This investigation reveals how consumer devices become weaponized infrastructure in the modern threat landscape.
SideWinder's Click Once campaign - independent validation with ClusterHawk
We confirm Trellix’s reporting on SideWinder’s PDF ClickOnce chain and targets, and we prove our methodology by deliberately injecting a broad VirusTotal communicated IPs pivot and then separating CDN/search noise (~85%) from a compact nginx micro-cluster (~15%) that’s worth watching. Below are ready-to-run hunts (SIEM/Sigma + Shodan/Censys) and cluster fingerprints you can use as predictive seeds.
Join the Discussion
Premium subscribers can participate in expert discussions, share insights, and collaborate with other security professionals.
Swift Eagle
Senior Security Analyst • 2 hours agoExcellent analysis of the APT28 infrastructure changes. We've observed similar patterns in our network monitoring. The shift to European hosting providers is particularly interesting...
Mystic Wolf
Threat Researcher • 1 hour agoAgreed! The geographic distribution shift suggests they're adapting to sanctions and regulatory pressure...
Unlock Premium Threat Intelligence
Access exclusive analysis, detailed IOCs, and expert discussions
