Nick Attfield
@nickattfield.bsky.social
📤 121
📥 175
📝 5
Threat Researcher @ Proofpoint | Views are my own.
reposted by
Nick Attfield
ThreatInsight
about 2 months ago
Proofpoint has directly observed a targeted email campaign that delivers DarkSword RCE, and we attribute the messages to Russian FSB threat actor TA446 with high confidence. 🧵
1
18
15
reposted by
Nick Attfield
ThreatInsight
2 months ago
Proofpoint identified a targeted campaign against operations personnel at energy firms linked to projects in Pakistan. The messages were sent on 18 March 2026, and mimicked invitations to the upcoming Pakistan Energy Exhibition & Conference (PEEC). We track the activity as UNK_VaporVibes. 1/8
1
10
6
reposted by
Nick Attfield
ThreatInsight
3 months ago
Conflict in Iran is accelerating cyber espionage across the Middle East. Since the start of Operation Epic Fury on February 28, 2026, Proofpoint researchers have observed heightened cyber activity against Middle East targets tied to the war. Details:
brnw.ch/21x0EJi
.
loading . . .
Iran conflict drives heightened espionage activity against Middle East targets | Proofpoint US
Analyst note: Proofpoint uses the UNK_ designator to define clusters of activity that are still developing and have not been observed for long enough to receive a numerical TA designation.
https://brnw.ch/21x0EJi
1
3
5
reposted by
Nick Attfield
Saher
7 months ago
New Iran drop from me tracking an attribution nightmare - UNK_SmudgedSerpent! A little Charming, a little Muddy, and a lot C5. Targeting policy experts with benign conversation starters, health-themed infra, OnlyOffice spoofs, and RMMs. Check out the full story
www.proofpoint.com/us/blog/thre...
loading . . .
Crossed wires: a case study of Iranian espionage and attribution | Proofpoint US
Proofpoint would like to thank Josh Miller for his initial research on UNK_SmudgedSerpent and contribution to this report. Key findings Between June and August 2025,
https://www.proofpoint.com/us/blog/threat-insight/crossed-wires-case-study-iranian-espionage-and-attribution
2
18
12
reposted by
Nick Attfield
StrikeReady Labs
9 months ago
A South Asian APT has been persistently targeting Sri Lanka, Bangladesh, Pakistan, and Turkey. This post walks through how to pivot from the well-publicized phishing infrastructure to expose APK tooling that compromised members of the military of Asian countries.
strikeready.com/blog/apt-and...
loading . . .
APT: Android, Phishing, microsoft
A South Asian APT has been persistently targeting Sri Lanka, Bangladesh, Pakistan, and Turkey. This post walks through infrastructure and malware pivots to expose novel tooling that compromised the p...
https://strikeready.com/blog/apt-android-phishing-microsoft/
0
4
3
reposted by
Nick Attfield
AJ Vicens
10 months ago
New: A handful of Chinese-linked cyber espionage groups are stepping up targeting of Taiwanese semiconductor companies, per new analysis from
@proofpoint.com
. Campaigns include targeting of financial analysts focused on the sector as well:
www.reuters.com/sustainabili...
loading . . .
Exclusive: China-linked hackers target Taiwan's chip industry with increasing attacks, researchers say
Chinese-linked hackers are targeting the Taiwanese semiconductor industry and investment analysts as part of a string of cyber espionage campaigns, researchers said on Wednesday.
https://www.reuters.com/sustainability/boards-policy-regulation/china-linked-hackers-target-taiwans-chip-industry-with-increasing-attacks-2025-07-16/
1
15
9
reposted by
Nick Attfield
ThreatInsight
12 months ago
Just published: A two-part blog series in collaboration with
@threatray.bsky.social
, which aims to substantiate the claim that
#TA397
(Bitter) is an espionage-focused, state-backed threat actor with interests aligned to the Indian state. Part 1:
brnw.ch/21wT9A5
Part 2:
brnw.ch/21wT9Ad
.
loading . . .
The Bitter End: Unraveling Eight Years of Espionage Antics—Part One | Proofpoint US
This is a two-part blog series, detailing research undertaken in collaboration with Threatray. Part two of this blog series can be found on their website here. Analyst note: Throughout
https://brnw.ch/21wT9A5
1
3
3
Dropping some joint research today with Threatray on TA397/Bitter 🔍 We dive into the confluence of signals that led us to our attribution of the threat actor 🎯 Shoutout to
@konstantinklinger.bsky.social
and Threatray for collaborating on this research.
www.proofpoint.com/us/blog/thre...
loading . . .
The Bitter End: Unraveling Eight Years of Espionage Antics—Part One | Proofpoint US
This is a two-part blog series, detailing research undertaken in collaboration with Threatray. Part two of this blog series can be found on their website here. Analyst note: Throughout
https://www.proofpoint.com/us/blog/threat-insight/bitter-end-unraveling-eight-years-espionage-antics-part-one
12 months ago
0
11
9
reposted by
Nick Attfield
Greg Lesnewich
about 1 year ago
Is the era of the “named actor” done? As the OG adversary sets diverge, get promoted, or move on actors dispersing across the kill chain based on specialized skills increases (ORBs, criminal underground) AND the CTI models maturing… APTs ⬇️⬇️ UNCs ⬆️⬆️
7
28
8
reposted by
Nick Attfield
Saher
about 1 year ago
@greg-l.bsky.social
drops knowledge on TA406 (Konni) as North Korea shows new interest in Ukraine, likely to keep tabs on the progress of the war and Russia's ability to keep pace on the battlefield
www.proofpoint.com/us/blog/thre...
loading . . .
TA406 Pivots to the Front | Proofpoint US
What happened In February 2025, TA406 began targeting government entities in Ukraine, delivering both credential harvesting and malware in its phishing campaigns. The aim of these
https://www.proofpoint.com/us/blog/threat-insight/ta406-pivots-front
1
15
14
reposted by
Nick Attfield
BogeyBackdoor
about 1 year ago
Introducing
#UNK_CraftyCamel
! Leveraged Trusted Business Relationship? ✅ Low Volume, highly targeted? ✅ Interesting technique? ✅ Overlaps with other IRGC clusters? ✅ Bonus: Infrastructure still up to watch how they respond to the blog? ✅
www.proofpoint.com/us/blog/thre...
loading . . .
Call It What You Want: Threat Actor Delivers Highly Targeted Multistage Polyglot Malware | Proofpoint US
Key findings Proofpoint researchers identified a highly targeted email-based campaign targeting fewer than five Proofpoint customers in the United Arab Emirates with a distinct
https://www.proofpoint.com/us/blog/threat-insight/call-it-what-you-want-threat-actor-delivers-highly-targeted-multistage-polyglot?utm_source=twitter&utm_medium=social_organic
0
7
5
Dropping some new research on TA397/Bitter 🚨 Hidden in Plain Sight | TA397’s New Attack Chain Delivers Espionage RATs Report:
www.proofpoint.com/us/blog/thre...
loading . . .
Hidden in Plain Sight: TA397’s New Attack Chain Delivers Espionage RATs | Proofpoint US
Key findings Proofpoint observed advanced persistent threat (APT) TA397 targeting a Turkish defense sector organization with a lure about public infrastructure projects in Madagascar. The attack...
https://www.proofpoint.com/us/blog/threat-insight/hidden-plain-sight-ta397s-new-attack-chain-delivers-espionage-rats
over 1 year ago
2
16
14
reposted by
Nick Attfield
ThreatInsight
over 1 year ago
In December 11 and 12, 2024, a spearphishing campaign targeted at least 20 Autonomous System (AS) owners, predominantly Internet Service Providers (ISPs), and purported to come from the Network Operations Center (NOC) of a prominent European ISP. 🧵⤵️
add a skeleton here at some point
1
17
16
I’m a little excited for this one
add a skeleton here at some point
over 1 year ago
0
1
0
reposted by
Nick Attfield
PIVOTcon
over 1 year ago
#PIVOTcon25
registration is now OPEN 🤟📥📥📥
pivotcon.org
#CTI
#ThreatResearch
#ThreatIntel
Please read carefully the whole 🧵 for the rules about invite -> registration (1/5)
2
42
33
reposted by
Nick Attfield
Catalin Cimpanu
over 1 year ago
Wait... did a Chinese security vendor just publish research on a suspected Chinese APT backdoor? 🙃 I need your thoughts here
@jags.bsky.social
blog.xlab.qianxin.com/analysis_of_...
loading . . .
New Zero-Detection Variant of Melofee Backdoor from Winnti Strikes RHEL 7.9
Background On July 27, 2024, XLab's Cyber Threat Insight and Analysis System(CTIA) detected an ELF file named pskt from IP address 45.92.156.166. Currently undetected on VirusTotal, the file trigger...
https://blog.xlab.qianxin.com/analysis_of_new_melofee_variant_en/
1
26
9
you reached the end!!
feeds!
log in