Historical OSINT – Massive Blackhat SEO Campaign Courtesy of the Koobface Gang Spotted in the Wild

It’s 2010 and I’ve recently stumbled upon yet another massive blackhat SEO campaign courtesy of the Koobface gang successfully exposing hundreds of thousands of users to a multi-tude of malicious software.

In this post I’ll provide actionable intellig… Continue reading Historical OSINT – Massive Blackhat SEO Campaign Courtesy of the Koobface Gang Spotted in the Wild

HIstorical OSINT – PhishTube Twitter Broadcast Impersonated Scareware Serving Twitter Accounts Circulating

It’s 2010 and I’ve recently intercepted a currently circulating malicious and fraudulent malware-serving spam campaign successfully enticing hundreds of thousands of users globally into interacting with the rogue and malicious software found on the com… Continue reading HIstorical OSINT – PhishTube Twitter Broadcast Impersonated Scareware Serving Twitter Accounts Circulating

Historical OSINT – Chinese Government Sites Serving Malware

It’s 2008 and I’m stumbling upon yet another decent portfolio of compromised malware-serving Chinese government Web sites. In this post I’ll discuss in-depth the campaign and provide actionable intelligence on the infrastructure behind it.

Compromised… Continue reading Historical OSINT – Chinese Government Sites Serving Malware

Historical OSINT – Calling Zeus Home

Remember ZeuS? The infamous crimeware-in-the-middle exploitation kit? In this post I’ll provide historical OSINT on various ZeuS-themed malicious and fraudulent campaigns intercepted throughout 2008 and provide actionable intelligence on the infrastruc… Continue reading Historical OSINT – Calling Zeus Home

Historical OSINT – A Diverse Portfolio of Fake Security Software

In this post I’ll profile a currently circulating circa 2008 malicious and fraudulent scareware-serving campaign successfully enticing users into interacting with rogue and fraudulent fake security software with the cybercriminals behind the campaign s… Continue reading Historical OSINT – A Diverse Portfolio of Fake Security Software

Dancho Danchev’s 2010 Disappearance – An Elaboration – Part Two

UPDATE: I can be reached at dancho.danchev@hush.com or at +359 87 68 93 890 in case of an emergency.

UPDATE: It appears that recently a car belonging to local police department (hxxp://troyan-police.com; police_troyan@abv.bg) was stopped somewhere aro… Continue reading Dancho Danchev’s 2010 Disappearance – An Elaboration – Part Two