Tommy Madjar
@ffforward.bsky.social
Threat Researcher @ Proofpoint. Opinions are my own etc
Reposted by Tommy Madjar
Since 14 October, we’ve tracked a high volume XWorm campaign targeting Germany. The activity is attributed to TA584, a sophisticated #cybercrime group tracked since 2020.
Messages are sent from hundreds of compromised sender accounts impersonating ELSTER and contain malicious URLs.
Messages are sent from hundreds of compromised sender accounts impersonating ELSTER and contain malicious URLs.
October 20, 2025 at 9:31 PM
Since 14 October, we’ve tracked a high volume XWorm campaign targeting Germany. The activity is attributed to TA584, a sophisticated #cybercrime group tracked since 2020.
Messages are sent from hundreds of compromised sender accounts impersonating ELSTER and contain malicious URLs.
Messages are sent from hundreds of compromised sender accounts impersonating ELSTER and contain malicious URLs.
Reposted by Tommy Madjar
New ecrime insights:
TA4557, known for distributing More_eggs malware, notably expanded to an international audience in recent campaigns.
Per our data, the recruiter-focused TA was seen targeting orgs in France, England & Ireland, in addition to typical North America-targeted threats.
TA4557, known for distributing More_eggs malware, notably expanded to an international audience in recent campaigns.
Per our data, the recruiter-focused TA was seen targeting orgs in France, England & Ireland, in addition to typical North America-targeted threats.
June 16, 2025 at 3:09 PM
New ecrime insights:
TA4557, known for distributing More_eggs malware, notably expanded to an international audience in recent campaigns.
Per our data, the recruiter-focused TA was seen targeting orgs in France, England & Ireland, in addition to typical North America-targeted threats.
TA4557, known for distributing More_eggs malware, notably expanded to an international audience in recent campaigns.
Per our data, the recruiter-focused TA was seen targeting orgs in France, England & Ireland, in addition to typical North America-targeted threats.
This article that starts getting traction claims that the official RVTools website was distributing a malicious installer leading to Bumblebee. I see zero evidence of this actually being the case.
1/2
1/2
May 19, 2025 at 3:47 PM
This article that starts getting traction claims that the official RVTools website was distributing a malicious installer leading to Bumblebee. I see zero evidence of this actually being the case.
1/2
1/2
Reposted by Tommy Madjar
Proofpoint also recently observed this activity delivering GootLoader. Google Ads for a fake document creation app (lawliner[.]com) led to a malicious document creation website, on which users are directed to enter their email address.
⚠️ New TTPs detected for #Gootloader ⚠️
Out are the PDF conversions and back in are legal document lurs. They are still using #malvertising, not SEO poisoning.
gootloader.wordpress.com/2025/03/31/g...
Out are the PDF conversions and back in are legal document lurs. They are still using #malvertising, not SEO poisoning.
gootloader.wordpress.com/2025/03/31/g...
🚨Gootloader Returns: Malware Hidden in Google Ads for Legal Documents
The threat actor behind the Gootloader malware has once again changed their tactics, but also reverted to some of their old ways. Just like with the previous infection method, we are seeing Google …
gootloader.wordpress.com
March 31, 2025 at 4:43 PM
Proofpoint also recently observed this activity delivering GootLoader. Google Ads for a fake document creation app (lawliner[.]com) led to a malicious document creation website, on which users are directed to enter their email address.
Great research on that #GootLoader is now including email in their delivery chain. Please don't download NDAs and other contract templates from free sites without any history.
⚠️ New TTPs detected for #Gootloader ⚠️
Out are the PDF conversions and back in are legal document lurs. They are still using #malvertising, not SEO poisoning.
gootloader.wordpress.com/2025/03/31/g...
Out are the PDF conversions and back in are legal document lurs. They are still using #malvertising, not SEO poisoning.
gootloader.wordpress.com/2025/03/31/g...
🚨Gootloader Returns: Malware Hidden in Google Ads for Legal Documents
The threat actor behind the Gootloader malware has once again changed their tactics, but also reverted to some of their old ways. Just like with the previous infection method, we are seeing Google …
gootloader.wordpress.com
March 31, 2025 at 2:42 PM
Great research on that #GootLoader is now including email in their delivery chain. Please don't download NDAs and other contract templates from free sites without any history.
New blog drop with @selenalarson.bsky.social and the rest of the team. This one covers a lot of threats using the #ClickFix technique to lure targets to infect themselves by pasting malicious CMD/PS code. My "fave" is the chumbox #malvertising on major tech sites.
www.proofpoint.com/us/blog/thre...
www.proofpoint.com/us/blog/thre...
November 18, 2024 at 12:44 PM
New blog drop with @selenalarson.bsky.social and the rest of the team. This one covers a lot of threats using the #ClickFix technique to lure targets to infect themselves by pasting malicious CMD/PS code. My "fave" is the chumbox #malvertising on major tech sites.
www.proofpoint.com/us/blog/thre...
www.proofpoint.com/us/blog/thre...
Well I guess it's time to try this platform too 😅
November 16, 2024 at 1:53 PM
Well I guess it's time to try this platform too 😅