techieStef's profile picture. Senior Intelligence Analyst @RedCanary! Former DFIR @Mandiant, former @NetworkDefense intern. Psychology nerd. When I am not computering, I go outside and play!

Stef Rand

@techieStef

Senior Intelligence Analyst @RedCanary! Former DFIR @Mandiant, former @NetworkDefense intern. Psychology nerd. When I am not computering, I go outside and play!

置頂

Super excited to introduce Tangerine Turkey! Tangerine Turkey is @redcanary's name for a VBS worm that is delivered via an infected USB and uses a printui DLL hijack to deliver a cryptomining payload. This was a fascinating rabbit hole to go down! redcanary.com/blog/threat-in…


Stef Rand 已轉發

📈 After ranking first for the whole year in our newly released Threat Detection Report, SocGholish takes the number one spot in our 10 top threat list for the month as well. Learn more about fake browser updates and worms in this month's edition of Intelligence Insights.…


Stef Rand 已轉發

📣 The 2025 Threat Detection Report is here! Dive into our analysis of 93,000 threats our customers' security controls missed, with actionable guidance on every page. Read the ungated report here: redcanary.com/threat-detecti…


Stef Rand 已轉發

🆕 Two emerging threats make their debuts in our top 10 list: Infrared Ibis and Saffron Starling Get detection opportunities and more in this month's edition of Intelligence Insights. redcanary.com/blog/threat-in…


Exciting update to our blog! As part of our ongoing research we identified some public Github repos being leveraged that, I'm happy to say, are no longer active! More details--plus some IOCs for still-active sites--in the update.

🗞️ Just in, from Red Canary Intel: After discovering that Tangerine Turkey’s operators pull down miner configuration files from remote resources, we reported some of their public GitHub repos, which have now been taken down. Read our updated blog for IOCs and more.…



Stef Rand 已轉發

HijackLoader—a newcomer to our monthly top 10 list—is fond of renaming executables, which presents a detection opportunity. Learn more in this month's edition of Intelligence Insights. redcanary.com/blog/threat-in…


Stef Rand 已轉發

📈 We've seen a spike in LummaC2 stealer activity over the last two months. Get detection guidance and more in this month's edition of Intelligence Insights. redcanary.com/blog/threat-in…

redcanary's tweet image. 📈  We've seen a spike in LummaC2 stealer activity over the last two months. Get detection guidance and more in this month's edition of Intelligence Insights. redcanary.com/blog/threat-in…

Stef Rand 已轉發

ChromeLoader and SocGholish remained our top threats in September, but a new technique stood out, tricking users into copying a PowerShell script, pasting it into Windows Run, and executing malicious code that leads to LummaC2: redcanary.com/blog/threat-in…


Stef Rand 已轉發

Removal Complete! Salmon can now access much more cold water habitat and excellent spawning grounds… oregonlive.com/native-america…


Stef Rand 已轉發

At the end of August 2024, Red Canary observed ransomware incidents that leveraged VPNs both as an initial access vector and to facilitate further access within organizations. redcanary.com/blog/threat-in…


Stef Rand 已轉發

Keep tabs on ChromeLoader and other browser-related threats in this month's edition of Intelligence Insights. redcanary.com/blog/threat-in…


Stef Rand 已轉發

This month's newcomers: 🏵️ Amber Albatross, which starts with a potentially unwanted program and ultimately leads to a pyInstaller executable with stealer capabilities 💸 dllFake, a malware family that primarily targets browsers and crypto wallets redcanary.com/blog/threat-in…


Stef Rand 已轉發

It's Koi phishing season! Red Canary Intel has been tracking an activity cluster that drops Koi Loader and a final payload of a .NET stealer. redcanary.com/blog/threat-in…


Stef Rand 已轉發

Keeping up with threats and trends can feel like navigating a labyrinth in the dark. @techieStef & @ForensicITGuy explore topics from our 2024 Threat Detection Report, including initial access tradecraft, cloud abuse, identity attacks, and more. 🎬 🍿 youtu.be/4HTd6boLPDc

redcanary's tweet card. Defenders on Defenders | Red Canary

youtube.com

YouTube

Defenders on Defenders | Red Canary


Stef Rand 已轉發

Tax season springs financially-themed phishing lures on users, and vulnerabilities continue to sprout up in this month’s edition of Intelligence Insights. redcanary.com/blog/intellige…

redcanary's tweet image. Tax season springs financially-themed phishing lures on users, and vulnerabilities continue to sprout up in this month’s edition of Intelligence Insights. redcanary.com/blog/intellige…

I do not have words for how much this delights me. These loud little birds are one of my favorite things in the world. Look ye upon this glorious wrendering that captures their noisy bossy chaos. Absolutely wonderful, @thepacketrat

此推文已無法使用。

TDR Day 🥳🎉 also means it’s Threat Sounds release day!!! Vol. 4 has dropped and it’s epic, y’all! 🔥 redcanary.com/threat-sounds/


It’s TDR Day wooooo! 🥳🎉

The 2024 Threat Detection Report is out! Featuring actionable insights for the most prevalent cyber threats and ATT&CK techniques your security team is likely to encounter. Read the full report now: redcanary.com/threat-detecti…

redcanary's tweet image. The 2024 Threat Detection Report is out! Featuring actionable insights for the most prevalent cyber threats and ATT&CK techniques your security team is likely to encounter. Read the full report now: redcanary.com/threat-detecti…


Stef Rand 已轉發

🚨 On February 26th and 27th Telekom Security and Bayern-CERT observed threat actor #TA577 phishing campaigns. This time the actor is not spreading malware, but apparently uses NTLMv2 handshakes to steal user credentials/hashes. 🧵1/7


Loading...

Something went wrong.


Something went wrong.