惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

罗磊的独立博客
I
InfoQ
雷峰网
雷峰网
Hugging Face - Blog
Hugging Face - Blog
IT之家
IT之家
云风的 BLOG
云风的 BLOG
有赞技术团队
有赞技术团队
Martin Fowler
Martin Fowler
MyScale Blog
MyScale Blog
The GitHub Blog
The GitHub Blog
博客园_首页
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
G
Google Developers Blog
WordPress大学
WordPress大学
B
Blog
人人都是产品经理
人人都是产品经理
小众软件
小众软件
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
量子位
Apple Machine Learning Research
Apple Machine Learning Research
N
Netflix TechBlog - Medium
Last Week in AI
Last Week in AI
博客园 - 聂微东
Jina AI
Jina AI

DomainTools Investigations

Lemmings: A Russian Industrialized Persona Provisioning And Management for Active Measures Campaigns Threat Intelligence Report: University Leak Exposes Russia’s Military Cyber Training Pipeline Chinese Malware Delivery Domains Part V Cybersecurity Reading List - Week of 2026-08-17 Hey Nineteen (Newsletters) Rainy Day Newsletter #12 (but not 35) SecuritySnack - Account Farmers and Sellers Intelligence Report: The Zedxion Corporate Nexus for Illicit Iranian Financial Funds Transfer for IRGC Entities. Scarcity Scams DomainTools Investigations | Threat Intelligence Report: The Pro-Iran Hacktivist Ecosystem 2026 Eighteen Newsletters and a Dozen Roses Threat Intelligence Report: Nation-State Targeting of Water Systems 2024–2026 The APT35 Dump Episode 4: Leaking The Backstage Pass To An Iranian Intelligence Operation Threat Intelligence Report: Russia, Router, DNS, and Messaging-Layer Collection Operations SecuritySnack - Hijacking Corporate Sessions Threat Intelligence Report: ZionSiphon OT Malware First Attempts? Psyops? Both? Threat Intelligence Report: The SDA / Structura / Doppelgänger, Influence Operations, Infrastructure, Reach, and Potential Edge of Seventeen (Newsletters) Cybersecurity Reading List - Week of 2026-06-01 Chinese Malware Delivery Domains Part II: Data Collection Cybersecurity Reading List - Week of 2026-05-04 Sixteen going on Seventeen Newsletters DPRK Contagious Interview: Developer Workflow Compromise The AI Frame Campaign Continues MOIS Linked MOIST GRASSHOPPER / Homeland Justice / KarmaBelow80 / Handala Hackers / Campaigns and Evolution Fifteen (Newsletters) On A Skateboard Handala: MOIS Linked Cyber Influence Ecosystem Threat Intelligence Assessment Cybersecurity Reading List - Week of 2026-04-06 DPRK Malware Modularity: Diversity and Functional Specialization SecuritySnack - OpenAI Anti-Ads Malware
Twenty Flight Newsletter
DomainTools · 2026-09-19 · via DomainTools Investigations

August has come and gone, and my team and I have finally recovered from the excessive Las Vegas heat we had to endure during Hacker Summer Camp. However, August ending in Seattle also means we have roughly only six more weeks before the sun takes a break from the Pacific Northwest, and the eternal gray sets in until next April. And let’s be real, that six week estimation is a generous one - Take your vitamin D supplements, people!  While the sun may be setting earlier, the threats have been shining plenty bright to keep my team busy. 

Today, let’s start with what we published at the end of the month: My team got ahold of leaked internal documents from Bauman Moscow State Technical University, and we spent a good chunk of August combing through the files. We published the findings from our analysis of the leak, and it is one heck of an investigation. Most public reporting covered the GRU Hacker School aspect of the leak, but the documents revealed so much more. 

We also published part five of our series tracking a “super-cluster” of malware delivery domains linked to the Silver Fox threat actor group that’s targeting Chinese-speaking users. If you haven’t been following this investigation so far, we’ve been tracking this cluster since January 2025, Late last year we published Part 4 of the series, which included our agentic-AI powered security analysis. Finally, we started the month with a bite-sized investigation into markets for stolen and fraudulent accounts. 

 Now, let's dive in (reverse) and get you up to speed! 

Hot Off the Presses 

Threat Intelligence Report: University Leak Exposes Russia’s Military Cyber Training Pipeline

To close out August, the DTI team reviewed the leaked internal documents from Bauman Moscow State Technical University’s Department No. 4. While public reporting focused on the “GRU Hacker School” angle, our researchers took a deep dive into the documents to analyze the curriculum, training groups, personnel and assignments, and training materials included in the leak. Most reporting focused on only one of the three training groups revealed in the leak, the Special Intelligence Service group, because it provided the clearest link to military intelligence. However, two other groups focused on cyber operational effects and secure communications and technologies. Our research covered the curriculum and training for all three groups, as well as an underreported financial systems program included in the training for the Special Intelligence Services group. 

The research also covered a malware-analysis and cyber threat intelligence program, including a 2023 Bauman Military Training Center conference volume: “Current Issues Concerning the State and Prospects for the Development of Weapons, Military, and Special Equipment of the Aerospace Forces”. 

Bauman Staff and Graduates Dept 4

Read the investigation here 


Chinese Malware Delivery Domains Part V

In Part V of our series investigating a domain super-cluster tied to the Silver Fox threat actor group, our researchers analyzed continued activity around the cluster despite arrests by Chinese authorities of individuals associated with Silver Fox. In Part IV of the series, our researchers proposed the hypothesis that the malware delivery "super-cluster" operates as a decentralized Malware-as-a-Service (MaaS) platform. In Part V, we identify three distinct operational profiles that continued active following the arrests and break down the variations across the infrastructure and lures associated with the cluster. 

Our team also analyzed samples from this recent activity cluster that all point to an obfuscated variant of Gh0stRAT. Despite variations in the initial lures used, for the samples reviewed in this campaign, the technical execution chain, obfuscation methods, and final payload structure are nearly identical. 

Gh0stRAT Malware Execution Chain

Read Part V of the series here


SecuritySnack - Account Farmers and Sellers

To kick off August, my team published a security snack on fraudulent account reseller markets. The push for user-base growth by major email providers is often paired with minimal fraud prevention, shielded from legal consequences with boilerplate disclaimers in the SEC filings. This means actors can easily create fraudulent emails that subsequently serve as the gateway for spam, malicious infrastructure, bot networks and fraudulent accounts across all manner of other services. Our investigation surveyed some of the most recent sites alleging to sell such accounts.

Screenshot of thepaygate[.]store

Read the snack here


What We’re Reading 

In case you’re behind on your cybersecurity reading homework, DTI team member Ian Campbell’s monthly recommended reading list has returned and will get you up to speed! 

‍📚See the full reading list here

Where We’ll Be

  • BSides NoVa, Arlington, VA, 30-31 October

Final Thoughts

As always, thank you to my returning readers! If you’re new, I hope you found this newsletter informational, helpful, and worthy of sharing with your peers. And of course I hope you will be coming back to read future editions!

We share this newsletter via email as well - if you’d prefer to get it to your inbox, sign up here.

If you missed last month's content, here are some quick links:

Thanks for reading & see you next month!

-Daniel

https://www.linkedin.com/in/schwalbe/

https://infosec.exchange/@danonsecurity

Twenty Flight Newsletter

August has come and gone, and my team and I have finally recovered from the excessive Las Vegas heat we had to endure during Hacker Summer Camp. However, August ending in Seattle also means we have roughly only six more weeks before the sun takes a break from the Pacific Northwest, and the eternal gray sets in until next April. And let’s be real, that six week estimation is a generous one - Take your vitamin D supplements, people!  While the sun may be setting earlier, the threats have been shining plenty bright to keep my team busy.

August has come and gone, and my team and I have finally recovered from the excessive Las Vegas heat we had to endure during Hacker Summer Camp. However, August ending in Seattle also means we have roughly only six more weeks before the sun takes a break from the Pacific Northwest, and the eternal gray sets in until next April. And let’s be real, that six week estimation is a generous one - Take your vitamin D supplements, people!  While the sun may be setting earlier, the threats have been shining plenty bright to keep my team busy. 

Today, let’s start with what we published at the end of the month: My team got ahold of leaked internal documents from Bauman Moscow State Technical University, and we spent a good chunk of August combing through the files. We published the findings from our analysis of the leak, and it is one heck of an investigation. Most public reporting covered the GRU Hacker School aspect of the leak, but the documents revealed so much more. 

We also published part five of our series tracking a “super-cluster” of malware delivery domains linked to the Silver Fox threat actor group that’s targeting Chinese-speaking users. If you haven’t been following this investigation so far, we’ve been tracking this cluster since January 2025, Late last year we published Part 4 of the series, which included our agentic-AI powered security analysis. Finally, we started the month with a bite-sized investigation into markets for stolen and fraudulent accounts. 

 Now, let's dive in (reverse) and get you up to speed! 

Hot Off the Presses 

Threat Intelligence Report: University Leak Exposes Russia’s Military Cyber Training Pipeline

To close out August, the DTI team reviewed the leaked internal documents from Bauman Moscow State Technical University’s Department No. 4. While public reporting focused on the “GRU Hacker School” angle, our researchers took a deep dive into the documents to analyze the curriculum, training groups, personnel and assignments, and training materials included in the leak. Most reporting focused on only one of the three training groups revealed in the leak, the Special Intelligence Service group, because it provided the clearest link to military intelligence. However, two other groups focused on cyber operational effects and secure communications and technologies. Our research covered the curriculum and training for all three groups, as well as an underreported financial systems program included in the training for the Special Intelligence Services group. 

The research also covered a malware-analysis and cyber threat intelligence program, including a 2023 Bauman Military Training Center conference volume: “Current Issues Concerning the State and Prospects for the Development of Weapons, Military, and Special Equipment of the Aerospace Forces”. 

Bauman Staff and Graduates Dept 4

Read the investigation here 


Chinese Malware Delivery Domains Part V

In Part V of our series investigating a domain super-cluster tied to the Silver Fox threat actor group, our researchers analyzed continued activity around the cluster despite arrests by Chinese authorities of individuals associated with Silver Fox. In Part IV of the series, our researchers proposed the hypothesis that the malware delivery "super-cluster" operates as a decentralized Malware-as-a-Service (MaaS) platform. In Part V, we identify three distinct operational profiles that continued active following the arrests and break down the variations across the infrastructure and lures associated with the cluster. 

Our team also analyzed samples from this recent activity cluster that all point to an obfuscated variant of Gh0stRAT. Despite variations in the initial lures used, for the samples reviewed in this campaign, the technical execution chain, obfuscation methods, and final payload structure are nearly identical. 

Gh0stRAT Malware Execution Chain

Read Part V of the series here


SecuritySnack - Account Farmers and Sellers

To kick off August, my team published a security snack on fraudulent account reseller markets. The push for user-base growth by major email providers is often paired with minimal fraud prevention, shielded from legal consequences with boilerplate disclaimers in the SEC filings. This means actors can easily create fraudulent emails that subsequently serve as the gateway for spam, malicious infrastructure, bot networks and fraudulent accounts across all manner of other services. Our investigation surveyed some of the most recent sites alleging to sell such accounts.

Screenshot of thepaygate[.]store

Read the snack here


What We’re Reading 

In case you’re behind on your cybersecurity reading homework, DTI team member Ian Campbell’s monthly recommended reading list has returned and will get you up to speed! 

‍📚See the full reading list here

Where We’ll Be

  • BSides NoVa, Arlington, VA, 30-31 October

Final Thoughts

As always, thank you to my returning readers! If you’re new, I hope you found this newsletter informational, helpful, and worthy of sharing with your peers. And of course I hope you will be coming back to read future editions!

We share this newsletter via email as well - if you’d prefer to get it to your inbox, sign up here.

If you missed last month's content, here are some quick links:

Thanks for reading & see you next month!

-Daniel

https://www.linkedin.com/in/schwalbe/

https://infosec.exchange/@danonsecurity

Hey Nineteen (Newsletters)

Heatwaves in Vegas, high AQI in Seattle, and fresh threat research. Inside this edition: Iran’s growing hacktivist network, Mexican document scarcity scams, and the layered crypto architecture powering IRGC financial transfers.

For once, I am *not* starting this newsletter by talking about the weather. The weather in Seattle that is, instead let’s talk about what passes for “ weather” in Las Vegas! Astute readers may notice that this edition of my newsletter is coming out a week later than usual. Vegas is the reason for that, more specifically, my team and I spent the first week of August at Hacker Summer Camp, where it stayed in the triple-digits for nearly 10 days straight, topping out at 115 F (46 C for my international readers!). Meanwhile, in Seattle, the AQI pm2.5 value was closing in on 200, which combined with 84 F (29 C) heat made for unpleasant days.

While the heat in Vegas was unpleasant to say the least, our team kept busy staying in the air conditioned spaces of BSides LV, BlackHat, DefCon, and various other hacker gatherings.  After a week of talking to our colleagues in the field, and hearing about the work they’ve been doing, we are back in Seattle where the temperature stays safely below the triple digits.

The whole of July was more than packing for Summer Camp though,and  my team kept up the pace publishing research on the Iranian hacktivist ecosystem and scarcity scams. I also had the chance to contribute an Expert Insight to our friends at Cyber Security News based on our research into the threat actors that make up Iran’s Hacktivist Ecosystem. To end the month, we published the findings of a year-long investigation into the ZedXion Cryptocurrency Exchange and the network of affiliated entities used by the IRGC to evade sanctions. Now, let’s dive in and get you up to speed.

Hot Off the Presses 

Threat Intelligence Report: The Pro-Iran Hacktivist Ecosystem 2026

To kick off July, the DTI team broke down the threat actor ecosystem supporting Iranian interests in 2026. The current pro-Iran“Axis of Resistance” is decentralized, blending hacktivist groups, ideological cyber militias, influence operators, and jihadist cyber propagandists, functioning as a loose knit cyber mobilization network. DTI researchers analyzed the individual actors in the ecosystem, assessing their capabilities and tradecraft as part of the larger collective. The groups’ behavior shows how modern cyber conflict is moving beyond traditional espionage toward more influence operations. Much of their activity is built for wartime influence by leveraging public visibility for asymmetric pressure against perceived enemies.

Our research found that most of the actors rely on basic tradecraft, including DDoS attacks, defacements, credential reuse, recycled breach data, public claims, and propaganda amplification to effect. These methods are often low-end but still create real impact when many groups act at once during geopolitical escalation. The main defensive challenge is not only intrusion prevention, but also managing disruption, reputational risk, and alert fatigue across public-facing systems.

Read the breakdown here

Scarcity Scams

When government backlogs create scarcity, scammers step in. DTI analysts exposed the mechanics of these "scarcity scams", from replica portals to weaponized session-recording tools, in July’s security snack. We uncovered a years-long campaign targeting Mexican citizens with a scam themed as a fast track service for government documents they branded as “Mexican Cita Express” or “Cita Express SRE México”. This scam alleges there is a fast track service to process government documents. Based on this investigation, our team expanded the investigation to hunt for similar scams based on shared conditions and methods. 

Read the snack here

Intelligence Report: The Zedxion Corporate Nexus for Illicit Iranian Financial Funds Transfer for IRGC Entities

In July 2025, DomainTools Investigations began investigating the Zedxion Cryptocurrency Exchange after an external partner came to us with the question “Does anything look strange about this domain?” Our researchers continued the investigation into the Zedxion Exchange in partnership with TRM Labs who first published their own research on the Exchange in January 2026. Signals point to Zedxion, and the BZ Group, as part of a larger constellation of entities tied to the IRGC moving towards establishing regional banking app(s) spanning the United Kingdom and the United Arab Emirates in order to more effectively obscure their transactions and mitigate disruption or takedown. When examined holistically, the constellation does not resemble a conventional cryptocurrency enterprise. Instead, it presents as a layered financial architecture in which legal entities, branding assets, governance actors, and digital infrastructure perform distinct and compartmentalized functions.

At the corporate level, the UK serves as a recurring incorporation platform. Companies are formed with high nominal capitalization, frequently £1,000,000, yet file dormant or non-trading accounts and exhibit no verifiable operating revenue. These entities are restructured, mirrored, or dissolved as exposure increases. ZEDXION EXCHANGE LTD and ZEDCEX EXCHANGE LTD reflect this pattern: structurally similar exchange vehicles, one absorbing litigation and regulatory pressure while the other preserves brand continuity and operational optionality. The dissolution of BZ BROKER LIMITED and the short lifecycle of BZ DIAMOND LTD reinforce the conclusion that UK entities function primarily as disposable regulatory interfaces rather than durable operating companies.

Read the investigation here 

Where We’ll Be

  • ‍Boston Security Meetup, Boston, MA, 20 August

Final Thoughts

As always, thank you to my returning readers! If you’re new, I hope you found this newsletter informational, helpful, and worthy of sharing with your peers. And of course I hope you will be coming back to read future editions!

We share this newsletter via email as well - if you’d prefer to get it to your inbox, sign up here.

If you missed last month's content, here are some quick links:

Thanks for reading & see you next month!

-Daniel

https://www.linkedin.com/in/schwalbe/

https://infosec.exchange/@danonsecurity

Eighteen Newsletters and a Dozen Roses

June’s roundup of research - from cyberattacks on water infrastructure OT and ICS to DNS hijacking and an AiTM campaign targeting Microsoft365 users. 

June was unusually warm here in Seattle, which for a region that claims “June-uary” as a Season, is noteworthy. We made the best of it by watching Team USA defeat the Socceroos in a 2-0 victory at our beloved “Seattle Stadium” - Did you hear we have been ranked the #1 World Cup stadium this time around?. Of course it all came to an end yesterday, when the Belgian “Red Devils” (who have claimed that name for longer than Manchester United) gave the Team USA a soccer lesson they won’t soon forget. That 4-1 defeat stung, especially since it was the last game Seattle hosted this time around. Well, there are always the Mariners.

Despite heat and soccer, we still spent the month investigating emerging threats, talking about our already emerged research, and preparing for Hacker Summer Camp. We started with an investigation into an attacker-in-the-middle credential-harvesting kit targeting Microsoft365 and EntraID identities. Next our team analyzed Russian-linked cyber operations targeting SOHO routers for DNS-hijacking and adversary-in-the-middle intelligence collection, as well as communications-layer collection from messaging platforms like Signal and WhatsApp. 

The team and I also attended SLEUTHCON in Arlington, VA; if you didn’t get a chance to say hi and grab a T-shirt, we will be in Las Vegas for Hacker Summer Camp next month with lots of swag. Ending the month, we published research on the targeting of water systems by Russian, Iranian, and PRC-aligned threat actors. As an added bonus, our friends at Dark Reading picked up the story and published their own article based on our research - I highly recommend giving it a read. I also had the pleasure of joining CyberWire’s Dave Bittner for an episode of his Research Saturday podcast talking about last month’s related research on the ZionSiphon OT malware sample. Now, let’s dive in and get you up to speed.  

Hot Off the Presses 

SecuritySnack - Hijacking Corporate Sessions

DTI researchers kicked off June with an investigation into a fully operational Adversary-in-the-Middle (AiTM) credential-harvesting kit targeting Microsoft 365 and Entra ID identities. The kit runs through a three-to-five stage funnel starting from financial, recruiting, and document related domain name themes. The funnels typically begin with an anti-analysis CAPTCHA gate to filter sandboxes, followed by a corporate email harvest stage that builds trust by dynamically rendering the victim's employer logo and filtering out personal email addresses. The final stage is a pixel-perfect, AiTM reverse proxy of the Microsoft sign-in page, which brokers the live authentication flow and successfully intercepts every credential, Multi-Factor Authentication (MFA) code (including Push, TOTP, and SMS), and post-authentication session cookie.

Read the snack here

Threat Intelligence Report: Russia, Router, DNS, and Messaging-Layer Collection Operations

The DTI team pivoted to an analysis of Russian-linked cyber operations targeting SOHO routers for DNS-hijacking and adversary-in-the-middle intelligence collection, as well as communications-layer collection from messaging platforms like Signal and WhatsApp. By targeting routers and bending DNS, Russian operators are able to watch traffic, steer chosen victims, and steal credentials without putting malware on the machine. Meanwhile, their work against Signal, WhatsApp, Telegram, and Microsoft 365 gives them access to messages, contacts, trusted names, and private conversations. 

Russia is increasingly treating edge infrastructure and messaging platforms as persistent intelligence-collection terrain. Router compromise provides GRU-linked operators with a passive upstream vantage point over victim traffic, while messaging-account compromise provides visibility into human networks, operational discussions, authentication workflows, and trusted social relationships. Together, these operations support long-duration intelligence collection, access persistence, credential interception, social-graph mapping, and pre-positioning for future contingency operations.

Read our full analysis here

Threat Intelligence Report: Nation-State Targeting of Water Systems 2024–2026

To wrap up the month, our researchers took a deep dive into the targeting of water systems by Russian, Iranian, and PRC-aligned threat actors. Recent activity targeting water systems includes Iranian IRGC-linked targeting of exposed programmable logic controllers (PLCs), Russian and pro-Russian access to municipal water-control environments, and PRC-linked pre-positioning in U.S. critical infrastructure, including water and wastewater systems. U.S. federal agencies, including CISA, FBI, NSA, and EPA, have warned that many utilities remain exposed through internet-facing human-machine interfaces (HMIs) and PLCs, weak credentials, shared accounts, legacy devices, limited monitoring, and poor IT/OT segmentation. 

While each nation uses a slightly different model for these operations, they all are used as shaping tools rather than destructive actions. Russia tends to pair infrastructure access with pressure and destabilization. Iran often blends symbolic retaliation, psychological signaling, and opportunistic disruption. In contrast, China places more emphasis on long-term pre-positioning and strategic persistence.

Read the breakdown here 

Where We’ll Be

  • ‍Hacker Summer Camp, Las Vegas, NV, 01-09 August

Final Thoughts

As always, thank you to my returning readers! If you’re new, I hope you found this newsletter informational, helpful, and worthy of sharing with your peers. And of course I hope you will be coming back to read future editions!

We share this newsletter via email as well - if you’d prefer to get it to your inbox, sign up here.

If you missed last month's content, here are some quick links:

Thanks for reading & see you next month!

-Daniel

https://www.linkedin.com/in/schwalbe/

https://infosec.exchange/@danonsecurity