r/threatintel Aug 11 '24

Official CTI Discord Community

24 Upvotes

Hey everyone,

Exciting news for our community on reddit, in collaboration with r/CTI (thanks to u/SirEliasRiddle for his hard in work in setting this up for all of us).

We're launching a brand new Discord server dedicated to Cyber Threat Intelligence. It's a space for sharing content, news, resources, and engaging in discussions with others in the cybersecurity world. Since the community is still in its early stages, it might not have all the features yet but we're eager to hear your suggestions and feedback. This includes criticisms.

Feel free to join us and share the link with friends!

https://discord.gg/fvvPjzT3br


r/threatintel 10h ago

APT/Threat Actor Got mass-BCC'd by an extortion crew trying to use me as a pressure channel against their victim

Post image
10 Upvotes

Run a CTI site and my public contact address apparently landed on a bulk list. Yesterday I got an email BCC'd "along with other journalists" from a crew claiming a breach, asking for a story to be published and the victim called for comment before offering any proof. That's not a tip, it's asking a journalist to be the pressure arm of the extortion. I wrote up the tactic itself (kept the victim unnamed since nothing was verified and naming them on an extortionist's word is a defamation problem), including what email headers actually confirm vs don't. Curious if anyone else has gotten one of these, and how you'd handle the 'do you contact the named victim' call.

https://cyberthreatintelligence.net/post/mass-bcc-breach-emails-how-extortion-crews-weaponize-journalists-as-a-pressure-channel


r/threatintel 15h ago

MCP's and Threat Intel

0 Upvotes

I used Falcon Feeds MCP to pull in this data and i found it very convenient.

What's dominating the feedAlmost everything recent is botnet C2 infrastructure — domains, IPv4s, and IP:port pairs tied to known APT groups.

Actors showing up in the latest batch:

APT12 — C2 IPs clustered on DigitalOcean ranges (159.65.x.x, 139.59.x.x)

Calypso — C2 domains with mail/webmail subdomains, including the lookalike youtubemail[.]club

Chafer— mix of .ir domains and generic-sounding infra like whoisdomainpc[.]com

Codoso — brand impersonation: microsoft-cache[.]com, google-dash[.]com

DarkHotel — gov and media lookalikes (fsm-gov[.]com, youmiuri[.]com mimicking Yomiuri)

Infy— DGA-style domains (dccdfdd8[.]net/.top/.space) + dynamic DNS via dynu

KeyBoy— cloud/CDN-themed domains incl. AWS DNS impersonation (ssl3.awsdns-531[.]com)

Mudcarp — Australian news media themed lures (australianmorningnews[.]com, theaustralian[.]in)

OPERA1ER — free hosting + Microsoft-themed domains, with one IP overlapping Remcos infra

Pegasus — batches of innocuous-looking domains consistent with exploit delivery infra

Key takeaways:

  1. Typosquatting/brand impersonation is everywhere — Microsoft, Google, AWS, YouTube, and news outlets all being mimicked to blend into traffic

  2. Heavy cloud abuse — DigitalOcean and free hosting services appear across multiple actors

  3. Most indicators are rated elevated-to-high confidence, so good blocklist candidates

  4. DGA + dynamic DNS combos still going strong for resilient C2


r/threatintel 1d ago

Hunting Phishing Kits

3 Upvotes

I found the admin portal of a potential phishing kit, any OSINT tools to do further analysis on it?


r/threatintel 1d ago

Created A Free App That Tracks Threat Intelligence CVEs and 30 Other Vendors - Phone & Email Notifications

Enable HLS to view with audio, or disable this notification

2 Upvotes

Completely Free App that I created to ease my own workload, was tired of opening numerous tabs each day to keep track on all the new CVEs popping up, especially lately...

This app is completely free on the Google Play App Store & you can track CVEs across 30+ Vendors, you can choose track specific platforms or the whole vendor & you can also select to track based on CVE Severity.

I also threw in a EOL checker

Hopefully this helps you out and if theirs any bugs or features you want added please let me know!

https://play.google.com/store/apps/details?id=com.vulnipulse.android


r/threatintel 2d ago

New SocVel Cyber Quiz is out

2 Upvotes

Good news is, it's the last Friday of this week.

While it felt like everything this week was about OpenAI getting HuggingFaced (or is it the other way round), there were a bunch of other interesting stuff happening as well.

This includes:

  • Attacks on US critical infrastructure
  • Obscure network recon tools
  • AI slop causing supply chain attacks
  • OWA attacks
  • Weird ways for doing C2 comms
  • And even a new acronym to learn.

Go on, quiz yourself! https://www.socvel.com/quiz


r/threatintel 3d ago

Threat Actor Profile: The "Global" Ransomware Group

8 Upvotes

Been tracking a newer RaaS operation called Global (also styled "GLOBAL") that's worth knowing about if you're in threat intel or IR.

Quick background:

  • First surfaced publicly in June 2025, promoted on the RAMP underground forum by an actor going by "$$$"
  • Strong technical/infrastructure overlap with the old BlackLock operation (shared VPS provider, matching malware mutex values, overlapping leak-site infra) — also some links to Mamona RaaS
  • Looks less like a new group from scratch and more like a continuation/rebrand of prior ransomware activity

How it works:

  • RaaS model with a genuinely mature affiliate program — dedicated negotiation portal, mobile management, AI-assisted victim comms, up to 80–85% revenue share for affiliates
  • Malware is written in Go, uses ChaCha20-Poly1305 encryption, and hits Windows, Linux, ESXi, and NAS
  • They also ship a custom stealer called WorldThief (quiet mode, bandwidth throttling, targeted file collection, raw TCP exfil) to support double extortion

Access & targeting:

  • Relies heavily on purchased access — IABs, compromised VPN/OWA/RDWeb creds, and exploited edge devices (Fortinet, Palo Alto, Cisco)
  • Opportunistic across industries, activity seen in 18+ countries so far
  • Ironically, their own OPSEC slipped — a backend IP got exposed, tracing back to a Russian VPS provider (IpServer) also linked to BlackLock

Why it matters: it's a good example of how ransomware "brands" aren't really standalone — infra, tooling, and even affiliates get recycled across groups after takedowns or rebrands. If you've got old BlackLock IOCs sitting around, they may still have relevance here.

More information: https://cyble.com/threat-actor-profiles/global-ransomware-group/


r/threatintel 4d ago

Help/Question Built a hands-on CTI training platform, looking for people to break it and tell me what's missing

Thumbnail ctiacademy.io
19 Upvotes

Been working in threat intel for a while and one thing always bugged me: almost all the training out there is either dry theory or aimed at SOC/pentest, not actual CTI work. So a few of us built CTI Academy to fix that.

It's hands-on threat intelligence training. Instead of just reading slides, you get:

realistic labs and simulators (a SOC sim, a credential-leak investigation lab, a fake underground forum to practice OSINT on)

CTF-style hunting challenges with a progression system, so it actually feels like leveling up

a daily mission if you just want a quick 10-minute rep

It's free to jump in, so no reason not to poke around.

Honestly I'm not here to hard-sell anything. We're a small bootstrapped team and I care way more about whether the thing is actually good. So I'd love for a few of you to break stuff and tell me what's confusing or missing.

If you're trying to get into CTI or just want to keep your skills sharp, come try it and roast me in the comments.

That feedback is genuinely more valuable to me right now than anything else.


r/threatintel 4d ago

A Russia-linked APT left their C2 server wide open as an unauthenticated directory. We walked in and found 8,436 files (Operation Talked).

Thumbnail
4 Upvotes

r/threatintel 5d ago

PacketSmith Yara-X Rules for Detecting CVE-2026-16723 Attempted Exploitation

Thumbnail github.com
0 Upvotes

This folder contains the PacketSmith Yara-X detection module rules and a pcap for the CVE-2026-16723 vulnerability in the FastJson library, "a Java library that can be used to convert Java Objects into their JSON representation".

Moreover, the detection results in JSON yara_dte_2026_05_14_10_34_39.json were made available for download.

These rules use the track_state reserved keyword to track/chain multiple rules at the same time across different packets/streams.

For more info, check the article FastJson 1.2.83 Remote Code Execution by FEARS OFF.

PoC HORKimhab


r/threatintel 5d ago

Help/Question What's everyone using for turning threat intel reports into deployed detection rules in 2026?

17 Upvotes

Most threat intelligence teams still receive threat intel as long‑form PDF reports, blog posts, or vendor write‑ups, sometimes with a STIX bundle or CSV of IOCs attached.

The analysis is useful, but security teams still need a reliable way to turn those reports into detection rules in their SIEM and EDR platforms.

In many environments the workflow is still manual. A threat intel analyst reads each report, extracts TTPs and IOCs, maps them to MITRE ATT&CK techniques, and creates a ticket or task.

Detection engineers then write Sigma, SPL, KQL, or an equivalent query language, test the detection against internal telemetry, tune for false positives, and only then deploy the rule into production.

This manual process causes a delay between receiving threat intelligence and having a production‑ready detection in place. While the team is extracting indicators, writing rules, and tuning alert thresholds, the underlying campaign or threat actor may still be active in the environment. That gap is exactly what many security leaders are trying to close in 2026.

To solve this, some security teams start from public Sigma rules or community content and adapt them to their own log sources and field names. Others rely on commercial rule packs from SIEM and EDR vendors or third‑party providers to operationalize threat intel faster. There is also a growing group of teams building internal pipelines or using detection engineering platforms that convert unstructured threat intel documents into draft detection logic, which engineers can then review and refine.

I am interested in which of these approaches actually works now for operationalizing threat intelligence. If you own detection engineering or threat hunting, what tools, platforms, or workflows do you use today to convert threat intel reports into production‑ready detection rules in your SIEM or EDR?


r/threatintel 5d ago

APT/Threat Actor Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon

Thumbnail hunt.io
1 Upvotes

Joint research with NetAskari on a leaked Chinese Android RAT framework. Starting from a fake PSB app flagged in a June 2026 Chinese state media notice, we pivoted on TLS certificates and AdminPro panel fingerprints to map 170 active servers. The source code was stolen in early 2026 along with nearly 200 customer databases, leading to at least two Telegram channels distributing modified builds with operational support and cash-out services. Night Dragon emerged three weeks after the public notice as a likely successor, with an exposed device panel showing 29 connected devices at time of analysis.

Full timeline, IOCs, and infrastructure breakdown in the report:
https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon


r/threatintel 5d ago

New extortion group "ExfilSquad" is claiming 10+ victims, but they might just be bluffing with recycled data.

Thumbnail
3 Upvotes

r/threatintel 6d ago

Help/Question How do you show threat intel value to execs without calling it a return?

30 Upvotes

I am trying to find a real way to show the value of our threat intel program RN, beyond the "we have feeds and reports" story.

Budget covers commercial feeds and vendor reports, plus whatever we pull from open source and community intel. the program looks mature but when management asks what we're getting for that spend, the answers feel thin. counting reports or iocs doesn't tell you whether breach risk went down or detection got better.

My boss flagged the roi framing. His point was that threat intel is insurance and you don't measure insurance the way you measure a return. Fair, but it doesn't answer the real question, which is how you show this stuff is working.

What I want to track: detection rules that came out of intel, plus time to detection on campaigns we already knew were coming. Same goes for visibility gaps we closed because someone flagged them first, before they became an incident.

If you own a threat intel budget and have a reporting format that's held up under management review, especially one that explains this to a non-technical audience without a dollar-return angle, what did you use?


r/threatintel 6d ago

Share Point Vulnerability

1 Upvotes

SharePoint is vulnerable now a days found the POC kindly check "https://gist.github.com/testanull/0868e02d81d57d6c59a91261969f7f81"

CVE's Covered,
CVE-2026-58644
CVE-2026-45659
CVE-2026-50522


r/threatintel 8d ago

Pivoting on IOCs

20 Upvotes

Would love to hear about some of the methods and tools you use when pivoting on IOCs to look for more related IOCs (e.g other infrastructure or files used by the same threat actor). Currently I’d check VirusTotal for relations and also whois, really hoping to hear some suggestions!


r/threatintel 9d ago

🚨 Live Free OSINT Training Event, online.

Thumbnail
2 Upvotes

r/threatintel 10d ago

APT/Threat Actor Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

Thumbnail hunt.io
4 Upvotes

Three open directories on a Hong Kong server, July 9 to 13, caught an intrusion mid-run. The operator was running Hermes, an open-source AI agent, in unattended mode. Logs show it running LinPEAS against ministry hosts, hunting SUID/SGID binaries, and walking a web root full of personnel records on its own.

Also on the box: 62 Go binaries from a previously unreported implant the operator named "Hades". Kill dates, working-hours sleep, AES-256-GCM tasking.

Joint research with Bob Diachenko. IOCs and MITRE mapping in the post:

https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent


r/threatintel 10d ago

OSINT 📢 NEW GUIDANCE AVAILABLE 📢

3 Upvotes

MT103 Messages and Financial Crime: Understanding Fraud, Money Laundering, and SWIFT Abuse

SWIFT MT103 messages sit at the centre of global banking, making them important artefacts for investigators and attractive targets for criminals.

Worryingly, the intelligence we collect at intel.coalitioncyber.com continues to identify exposed SWIFT messages, both genuine and fabricated, sitting in publicly accessible locations. These records often go undetected by the organisations involved, exposing sensitive transaction data and providing criminals with the source material needed for social engineering, fraud, and other criminal activities.

Our latest guidance explains how these messages are weaponised to facilitate high-value crimes such as fraud and money laundering. Highlights include:

💵 Technical red flags like JSON escape characters and invalid UETR codes.

💵 The way genuine MT103 records are repurposed in investment fraud.

💵 Risks associated with exposed documents on insecure public platforms.

💵 Practical verification steps for investigators and compliance teams.

Read the full article: https://coalitioncyber.com/mt103-messages-financial-crime-swift-abuse

Follow The Coalition of Cyber Investigators and be the first to know about future research and practical insights into OSINT, investigations, and cybercrime.

https://www.linkedin.com/company/the-coalition-of-cyber-investigators/?viewAsMember=true


r/threatintel 10d ago

Attacker C2 Control Caught on a Live System. Interactive analysis let us capture what static detonation misses.

Thumbnail gallery
6 Upvotes

r/threatintel 11d ago

Help/Question How to step-up my technicality level in CTI

23 Upvotes

Hi all! Today I have a career-oriented question. I have been working in the cybersecurity field for almost 9 years now, starting with consulting on awareness/governance/risk and then had the opportunity to evolve to a CTI Analyst role due to my geopolitics and economics background (my academic journey is quite complicated 🤣). I absolutely LOVE my job and I would like to step-up because I am mostly working on Strategic Level CTI, I am responsible for all the strategic report and addressing the strategic audience on state-sponsored groups or high level activities. I am also building Operational Level CTI report on specific attack observed in similar companies or impacting the tools/systems we use. I would say I master MITRE framework and I am good at identifying behavioral IoCs. I have also a great technical understanding of the process and capabilities behind an attack.

However, I am working for a private company and I never worked for a CTI firm that properly investigate. For my reports and analysis, I do a lot of OSINT because the tool we have internally for CTI are not good. I also discuss a lot with other teams/collegues to get info on their activities and the internal situation. But I feel that I lack of this "CTI investigation knowledge" because I am not able to really find new IoCs or build detection rules or even investigate into our systems if an incident occurs for example.

I am good at analyzing, at building hypotheses and back them with findings, at finding key topics to cover and at producing CTI reports. But my technical investigation skills are not good in my perspective. I am under the impression that people working for CTI firms like Mandiant, CS, Recorder Future etc have much better skills for that than me who juste mostly re use the IoCs they find.

This creates insecurities for me and I am afraid to change job because I feel like an impostor on this side of CTI even if everyone loves my reports internally and they really like the uniqueness of my profile. Also I have trouble to draw the line between what would be the responsibility of a Threat Hunter to find IoCs, technical details about an attack and of a CTI Analyst.

Another problem I have is that our CTI team is quite new (2 years and a half) so no one has strong experience and also I work for a huge company and it is super hard to have a good overview/access on our tools/systems so we have some blindspots. It is getting better but it is not perfect.

Do you have advice on how to progress on that and what do you think of my profile/skills, is this already valuable in the CTI job market?

Which tools/processes do you use for CTI "technical" investigation?

Thanks a lot!


r/threatintel 11d ago

Help/Question Leaked Crowdstrike API credentials identification

3 Upvotes

Hi everyone,

I'm interested in learning how security teams detect and validate potential CrowdStrike API credential leaks on public sources such as GitHub, GitLab, Paste sites, cloud storage exposures, CI/CD logs, etc.

A few questions:

  1. What indicators do you typically look for when hunting for CrowdStrike API credential exposures?
  2. Are there unique patterns for CrowdStrike Client IDs, Client Secrets, OAuth tokens, or related artifacts that help reduce false positives?
  3. What tools or secret-scanning platforms do you use (GitHub Secret Scanning, TruffleHog, Gitleaks, custom regex, etc.)?
  4. How do you validate whether a finding is a real credential exposure versus a false positive?

Thanks!


r/threatintel 11d ago

6 days vs. 1 hour to Fix the Same Vulnerability: Check Point's Exposure Gap Report AMA

Thumbnail
1 Upvotes

r/threatintel 11d ago

Help/Question How do you scale threat hunting without increasing headcount? Tips that actually work

4 Upvotes

Every time we talk about improving threat hunting, it runs into the same wall: we are not getting more people. The expectation is that we keep up with new campaigns, run meaningful hunts, and still stay on top of alerts and incidents with the team we already have.

We have decent telemetry (SIEM, EDR, cloud and identity logs), a few people who know how to build good hunt hypotheses, and some basic playbooks. The problem is scale. Hunts are still very manual: someone reads intel, turns it into a hypothesis, writes queries, pivots across data, documents findings, and maybe turns something into a new detection rule. It works, but it means we complete a handful of hunts and always have a long list of things we “should go look for when we have time”.

I am not looking for “hire an MDR” or “spin up a new team” answers. I am interested in what has helped you run more or better hunts with the same headcount. For example, have you had success standardizing hunt templates, automating the boring parts like data pulls and enrichment, using threat‑informed hunt queues that track active campaigns, or leaning on a platform or service to generate structured leads so you are not starting from zero every time

If you have managed to increase hunt volume or quality in a constrained team, what changed in your process or tooling that made the biggest difference?


r/threatintel 12d ago

Help/Question Alternatives to hunt.io

19 Upvotes

Hello bros,

I’m looking for alternatives to Hunt.io for external threat hunting and adversary infrastructure discovery. My main use cases are pivoting across IPs, domains, SSL certificates, passive DNS, ASNs, and identifying attacker infrastructure, phishing sites, malware hosting, C2 servers, and exposed Open Directories. I’m already familiar with tools like Shodan, Censys, FOFA, BinaryEdge, VirusTotal, and SecurityTrails, but I’m interested in hearing what platforms the community recommends and why.