hunting russian apt cyber ops @Mandiant @GoogleCloud. views expressed here are mine, not my employer’s. she/her.

Joined October 2016
deactivating here, find me at bluesky @ gabr . bsky . social : ) I promise I will actually start posting there hehe
1
Verifying myself: I am gabbot on Keybase.io. VR8PFLwAl2Iiigqwc9gBmJ_Sz8u-XUnWnsgh / keybase.io/gabbot/sigs/VR8PF…
1
Gabby Roncone 🇺🇦 🇵🇸 retweeted
russia running the marxist stages of history in reverse by going from communism to capitalism to feudalism
In Russia, a war between Dagestan and Chechnya may break out: Kadyrov announced a blood feud against the Dagestan senator and oligarch Suleiman Kerimov. 📍In addition to Kerimov, Kadyrov also plans to announce a blood feud against State Duma deputies Bekhan Barakhoyev and Rizvan Kurbanov. Kadyrov stated that this trio ordered his murder. 📍The conflict began due to the situation around the Russian online store Wildberries (the Russian analogue of AMAZON). 📍On September 18, against the backdrop of the divorce of the Bakalchuks (owners of Wildberries), as well as the merger of the Wildberries company with the outdoor advertising operator Russ, which belongs to the oligarch, a shootout took place near the Wildberries Dagestan office Kerimov, in a company. 📍Meanwhile, the company is actually run by Tetyana Kim (formerly Bakalchuk), but her husband has also represented rights to the company since the beginning of the divorce. Vladyslav Bakalchuk admitted that he had known Kadyrov for eight years and was "friends" with him, and asked him for help in wresting business from his wife. 📍Chechens sent by Kadyrov to plunder Wildberries came to the office with Bakalchuk. It was there that the shooting began, during the conflict two Ingush guards were shot dead by Kadyrivs. In Ingushetia, because of this, some protests began with threats against Chechens. 📍It is interesting that the Wildberries office where the shooting took place is located not far from the Kremlin. After that, several Kadyrivians were arrested for killing guards. They are currently on trial. Kadyrov was very indignant about this, he thought he could do anything, but it turned out that Kerimov's administrative resources were more powerful than those of Don-Don. 📍 Suleiman Kerimov has long been friends with the Kremlin, all his problems are solved by the head of the Putin administration - Anton Vaina. There is also information that Kerimov, at Putin's request, financed the election campaign of a pro-Russian French official, Marine Le Pen. 📍Putin tried to attack Kadyrov and Kerimov, urging them to come to an agreement. It seemed to Kadyrov that the Bunker thus supported Kerimov's side, and the Don did not want to negotiate, spat on Putin's words and staged a shootout in the center of Moscow. 📍After it was not possible to occupy the office of Wildberries, and the people of Don-Don were detained, Kadyrov decided to announce bloody revenge on Kerimov and his entourage. In the Caucasus, this is taken seriously, these are not just words, but real deeds. Those who have declared blood feud cannot help but start killing. This is the law. There will be dozens of corpses. After that, Kerimov will also have to think about how to eliminate Kadyrov so that this clan war ends with his victory. 📍It will be very funny when the Putler's plan to "take over" the world fails due to a showdown between two hot Caucasians. Ukraine Telegram.
57
1,213
45
12,636
I enjoyed this report for many reasons. I really appreciate the authors' attention to factual detail rather than hyping operations. Also, as @RidT notes, loved reading notes about detection and investigation capabilities built-in at OpenAI.
This tweet is unavailable
16
experienced a voice to text tragedy while walking my dog this morning
14
Gabby Roncone 🇺🇦 🇵🇸 retweeted
never not thinking of eric adams 2011 pea on how to check your kid’s room for contraband
Gabby Roncone 🇺🇦 🇵🇸 retweeted
The most comprehensive blog on Gamaredon tooling you will find in miles.
By analyzing thousands of samples, #ESETresearch has conducted a comprehensive technical analysis of the toolset the 🇷🇺Russia-aligned #Gamaredon #APTgroup used in 2022 and 2023 to spy on Ukraine🇺🇦 . welivesecurity.com/en/eset-r… 1/9
3
17
Gabby Roncone 🇺🇦 🇵🇸 retweeted
Seriously @Cloudflare? IOCs in a image 🤦🏻‍♂️
2
27
207
Gabby Roncone 🇺🇦 🇵🇸 retweeted
coming soon ... the Interview Part II how does @aptwhatnow keep getting these guests???
1
2
26
Gabby Roncone 🇺🇦 🇵🇸 retweeted
DPRK's UNC5267 operations have expanded greatly over the past few years. It is essential to be proactive and detect them in your environment. These operations directly fund North Korea by diverting the paychecks they obtain back to the regime. cloud.google.com/blog/topics…
12
2
28
Gabby Roncone 🇺🇦 🇵🇸 retweeted
Gabby Roncone 🇺🇦 🇵🇸 retweeted
Gabby Roncone 🇺🇦 🇵🇸 retweeted
This must be the funniest Russian Intel failure I have seen. It's 'Allo 'allo level. The FBI read the Whatsapp (!) chats between FSB's Col. Popov and his asset Ionov, and indicted them. And the two continued to discuss the indictment...on Whatsapp!!!
FSB disinfo operations are tearing the US apart. rferl.org/a/russia-fsb-elect…
59
795
56
4,916
can't miss this talk if you're gonna be at @mWISEConference
“Malware distribution groups are tricky to look at as a collective, so let’s narrow it down to some of my *least* favorites…” See ya next week, @mWISEConference 🫶🏼 #mWISE2024
5
your daily reminder that -DOORs are meaningless do not name your malware with "-DOOR" thanks
Schools need to stop teaching kids malware is like, 'trojans', and 'worms', etc. It's not 1996 anymore. New malware types: - Ransomware - Loaders - Information Stealers - Piles of shit that doesn't work - RATs
2
11
Gabby Roncone 🇺🇦 🇵🇸 retweeted
Can't help myself.. Taking a look into some of these 32 domains sheds light on a few unmentioned Doppelganger domains still active and personas posting on Twitter. Quick 🧵
Yesterday, @TheJusticeDept seized 32 websites linked to the Russian influence operation (IO) network #Doppelganger. @USTreasury added to the SDN list individuals and entities involved in Russia-aligned IOs, including Doppelgänger. 🧵A few thoughts justice.gov/opa/pr/justice-d…
Gabby Roncone 🇺🇦 🇵🇸 retweeted
Five Russian GRU Officers and One Civilian Charged for Conspiring to Hack Ukrainian Government 🔗: justice.gov/opa/pr/five-russ…
Please note that UNC2589 != APT44. Two very different units.
1
2
9
Gabby Roncone 🇺🇦 🇵🇸 retweeted
The @FBI announce a $10 m award for information leading to the arrest of GRU Unit 29155 hackers who targeted Ukrainian gov't infrastructure at the start of the invasion. They are all familiar faces to us, will do a story on them in the next few days.
Intelligence agencies and FBI/DOJ have revealed that unit 29155 of Russia’s GRU—a unit responsible for coup attempts, assassinations, and bombings—is now engaged in brazen hacking operations with targets across the world, including in Ukraine and the US. wired.com/story/russia-gru-u…
30
736
33
1,210