Our new blog post is here! Learn how to improve forensics readiness in your Windows environment by configuring built-in logs and artifacts. This guide is perfect for IT and security teams looking to enhance incident response and breach detection using native Windows tools.
Check it out and boost your security posture today!
https://profero.io/blog/microsoft-windows-endpoint-forensics-readiness-booster
Check it out and boost your security posture today!
https://profero.io/blog/microsoft-windows-endpoint-forensics-readiness-booster
Profero | Rapid-IR
Microsoft Windows Endpoint Forensics Readiness Booster
This short blog post will run through a few ways the IT/Security teams can configure their existing Windows environment in order to improve forensics readiness using existing operating system capabili
Infostealer - A Threat on the Rise:
Last year, an employee of the Israeli National Cyber Directorate learned a harsh lesson. His private workstation was mysteriously infected, and his details leaked to the internet, including screenshots of his desktop and other details.
The researcher was hit by "Stealer malware" (aka Infostealer) called Redline. This is THE most trending kind of malware currently – even more prevalent than ransomware – so allow me to elaborate:
Stealer malware is designed to steal information from a PC. The attack vectors are numerous – including phishing, software bundles, browser plugins, and more. Once the victim downloads the rogue software, the virus steals all sorts of data: browser cookies, passwords, crypto wallets, files, and more.
As the software doesn't need to encrypt files, the attack fingerprint is minimal, and the malware is hard to detect. According to Specops, hundreds of millions of passwords have already leaked online, and it is estimated that millions of devices are infected worldwide.
The journey of the stolen files is fascinating. First-hand – the OGs – they skim the cream after evaluating the data and gain access to large wallets, lucrative bank accounts, etc. They then sell the dump with all the data on the dark web or Telegram. The buyers are usually cybercriminals who use this bulk of stolen usernames and passwords to gain access to organizations' networks (this practice is called Credential Stuffing). This is how Uber was breached.
We're not done yet because eventually, the data typically leaks onto the web, where strategic players lurk for diamonds. This is presumably how the details of the Israeli gov employee got out. The data changes hands and is exploited multiple times; you've got to admire the scavenging.
Two weeks ago, law enforcement agencies from 6 countries managed to take down the infrastructure of Redline – the most notorious stealer malware gang. This is great news, but you know, there is no checkmate in cyber defense. The game is on.
So, what can individuals and organizations do to avoid stealer malware?
• It is wise to protect employees' personal assets as well – as they are the weakest link in the network. However, privacy issues must be considered.
• Strict access management is critical, under Zero-Trust assumptions. No BOYD should be allowed in.
• Two-factor authentication across all sensitive assets is always wise, also as protection for this kind of attack.
· Make sure SSO is implemented in every SaaS and on-prem.
· Avoid dual users accounts in any cost, leave no generic users such as “support” or similar used by multiple people and teams.
· Make sure to implemented credential breach monitoring.
If you have any thoughts or battle-earned experience with this kind of threat – you're invited to comment and share your knowledge for the benefit of all parties. Be Breach Ready!
Last year, an employee of the Israeli National Cyber Directorate learned a harsh lesson. His private workstation was mysteriously infected, and his details leaked to the internet, including screenshots of his desktop and other details.
The researcher was hit by "Stealer malware" (aka Infostealer) called Redline. This is THE most trending kind of malware currently – even more prevalent than ransomware – so allow me to elaborate:
Stealer malware is designed to steal information from a PC. The attack vectors are numerous – including phishing, software bundles, browser plugins, and more. Once the victim downloads the rogue software, the virus steals all sorts of data: browser cookies, passwords, crypto wallets, files, and more.
As the software doesn't need to encrypt files, the attack fingerprint is minimal, and the malware is hard to detect. According to Specops, hundreds of millions of passwords have already leaked online, and it is estimated that millions of devices are infected worldwide.
The journey of the stolen files is fascinating. First-hand – the OGs – they skim the cream after evaluating the data and gain access to large wallets, lucrative bank accounts, etc. They then sell the dump with all the data on the dark web or Telegram. The buyers are usually cybercriminals who use this bulk of stolen usernames and passwords to gain access to organizations' networks (this practice is called Credential Stuffing). This is how Uber was breached.
We're not done yet because eventually, the data typically leaks onto the web, where strategic players lurk for diamonds. This is presumably how the details of the Israeli gov employee got out. The data changes hands and is exploited multiple times; you've got to admire the scavenging.
Two weeks ago, law enforcement agencies from 6 countries managed to take down the infrastructure of Redline – the most notorious stealer malware gang. This is great news, but you know, there is no checkmate in cyber defense. The game is on.
So, what can individuals and organizations do to avoid stealer malware?
• It is wise to protect employees' personal assets as well – as they are the weakest link in the network. However, privacy issues must be considered.
• Strict access management is critical, under Zero-Trust assumptions. No BOYD should be allowed in.
• Two-factor authentication across all sensitive assets is always wise, also as protection for this kind of attack.
· Make sure SSO is implemented in every SaaS and on-prem.
· Avoid dual users accounts in any cost, leave no generic users such as “support” or similar used by multiple people and teams.
· Make sure to implemented credential breach monitoring.
If you have any thoughts or battle-earned experience with this kind of threat – you're invited to comment and share your knowledge for the benefit of all parties. Be Breach Ready!
Ever wondered what infostealers are and why they're a growing concern in the cybersecurity world?
Dive into this insightful article by our Co-Founder and CEO, @GelosSnake on @geektime and discover what steps you can take to protect yourself.
https://www.geektime.co.il/what-the-f-are-infostealers/
Dive into this insightful article by our Co-Founder and CEO, @GelosSnake on @geektime and discover what steps you can take to protect yourself.
https://www.geektime.co.il/what-the-f-are-infostealers/
גיקטיים
נראה שאחרי תוכנות הכופר, ההאקרים מצאו מטרה יותר מעניינת | גיקטיים
מאת: עמרי שגב מויאל לפני כשנה, עובד של מערך הסייבר הישראלי למד שיעור כואב. המחשב הפרטי שלו בבית הודבק על ידי פוגען מסתורי, ופרטים אישיים שלו זלגו לרשת,
Forwarded from גיקטיים Geektime - ערוץ חדשות הטכנולוגיה וההייטק של ישראל
ספר הג'ונגל של הסייבר: מה אני כל-כך אוהב ב-MITRE ATT&CK
https://www.geektime.co.il/meet-mitra-attck/
https://www.geektime.co.il/meet-mitra-attck/
This isn't a drill - this is reality!
See real-world proof that creative incident response can outmaneuver ransomware math in our latest blogpost.
Walk through our investigation workflow, cryptographic analysis, and end-to-end data-recovery strategy, proving that "encrypted" doesn't always mean "unrecoverable."
Read more: https://profero.io/blog/from-drone-strike-to-file-recovery-outsmarting-a-nation-state
See real-world proof that creative incident response can outmaneuver ransomware math in our latest blogpost.
Walk through our investigation workflow, cryptographic analysis, and end-to-end data-recovery strategy, proving that "encrypted" doesn't always mean "unrecoverable."
Read more: https://profero.io/blog/from-drone-strike-to-file-recovery-outsmarting-a-nation-state
Profero | Rapid-IR
From Drone Strike to File Recovery: Outsmarting a Nation State
On January 28, 2023, an ammunition factory belonging to the Iranian Defence Ministry in Isfahan was attacked by three drones. Iran later claimed that the drones had caused only minor damage to a build
Disinformation alert: A Telegram narrative claims to reveal doxxing data and breach material against Iranian institutions and APT35. Our OSINT review shows mixed signals; credible data interwoven with fabrication.
Verify sources, not every "intel" is a trust source, sometimes it's just an influence operation.
https://profero.io/blog/p4tr-0t3ch-channel-doxxing-disinfo-assessment
Verify sources, not every "intel" is a trust source, sometimes it's just an influence operation.
https://profero.io/blog/p4tr-0t3ch-channel-doxxing-disinfo-assessment
profero.io
P4Tr!0T3CH Channel Doxxing & Disinfo Assessment
A Telegram post claimed doxxing targeting Iranian judiciary and APT35; Profero OSINT flags it as an influence operation, mixing real data with fabrication
Profero IRT identified a supply chain compromise involving the AppsFlyer Web SDK, where obfuscated JavaScript was silently replacing cryptocurrency wallet addresses in user sessions. The payload targeted Bitcoin, Ethereum, Solana, Ripple, and TRON wallets, with built-in fallback infrastructure and wallet rotation capabilities. AppsFlyer is embedded across thousands of websites and apps globally. Full advisory with IOCs and detection guidance on our blog.
Feel free to read, ask questions and share!
https://profero.io/blog/hijacked-at-the-source-a-trusted-marketing-appsflyers-sdk-distributes-a-crypto-stealer
Feel free to read, ask questions and share!
https://profero.io/blog/hijacked-at-the-source-a-trusted-marketing-appsflyers-sdk-distributes-a-crypto-stealer
Profero | Rapid-IR
Hijacked at the Source: AppsFlyer's Trusted Marketing SDK Distributes a Crypto Stealer
Profero IRT has uncovered a cryptocurrency wallet hijacking supply chain attack in the AppsFlyer Web SDK
Iranian APT targeting of U.S. organizations is expanding beyond government and defense into commercial sectors.
We've stopped these operators before they hit. In Operation Quicksand, we intercepted an IRGC-linked destructive campaign mid-deployment. When an Iranian state-sponsored group did get through, we reversed their ransomware, broke the encryption, and recovered the data they tried to destroy.
The technical breakdowns are on our site.
We're offering U.S. organizations a free Iranian APT Readiness session, exposure review, detection gap analysis, and hardening priorities, led by the responders who handled these operations.
DM for the booking link.
Know a CISO who should see this? Tag or share.
We've stopped these operators before they hit. In Operation Quicksand, we intercepted an IRGC-linked destructive campaign mid-deployment. When an Iranian state-sponsored group did get through, we reversed their ransomware, broke the encryption, and recovered the data they tried to destroy.
The technical breakdowns are on our site.
We're offering U.S. organizations a free Iranian APT Readiness session, exposure review, detection gap analysis, and hardening priorities, led by the responders who handled these operations.
DM for the booking link.
Know a CISO who should see this? Tag or share.
Russia's GRU built NotPetya. This week "Russian Legion" misspelled SharePoint in a fake nuclear breach screenshot. That gap is strategy, not decline. https://profero.io/blog/the-theater-of-cyber-war-cardinal-russian-legion/
Our IR team just published a deep teardown of "WindowsAudit.exe", a 101MB .NET RAT we've observed across multiple environments. It runs as LocalSystem, uses a private Discord guild as its primary C2 (with MQTT and Telegram as fallbacks), and ships with a complete post-exploitation kit: LSASS and DPAPI credential theft, full Active Directory takeover tooling, Hell's Gate syscalls, AMSI/ETW patching, targeted EDR removal for 15+ vendors, and WireGuard relay for pivoting. The build quality and breadth of capability suggest a crew positioning for ransomware. Detections, IOCs, and the full analysis: https://profero.io/blog/windowsaudit-backdoor/
New research from Profero: a malware campaign affecting 25+ organizations, several in Israel, brought down by the attacker’s own operational security failure.
The malware, WindowsAudit, runs as LocalSystem on compromised hosts and uses Discord for command and control. The Discord bot token was hardcoded in plaintext inside the binary, identical across every sample on every infected machine.
Our research team used the exposed token to:
• Authenticate to the attacker’s Discord and recover the full operation history
• Recover all data the attacker had exfiltrated from victims, including AD dumps, network maps, screenshots, and file listings
• Identify 25 distinct victim organizations
• Profile the attacker’s working hours and timezone in real time
• Automatically retrieve, analyze, and extract IOCs from every new build the attacker deployed
A flaw in the malware’s design compounded the issue. Every infected host runs the same binary, capable of both receiving commands from the operator and issuing commands to other infected hosts. No signing, no authentication. Anyone holding the token could push a single command and uninstall the malware across the entire botnet. An accidental kill switch.
We chose not to use it. Any command we sent would have appeared in the attacker’s own Discord and ended the monitoring operation.
Full technical writeup and IOCs available at the link below. Particularly relevant for organizations operating in Israel.
https://profero.io/blog/windowsaudit-backdoor/
The malware, WindowsAudit, runs as LocalSystem on compromised hosts and uses Discord for command and control. The Discord bot token was hardcoded in plaintext inside the binary, identical across every sample on every infected machine.
Our research team used the exposed token to:
• Authenticate to the attacker’s Discord and recover the full operation history
• Recover all data the attacker had exfiltrated from victims, including AD dumps, network maps, screenshots, and file listings
• Identify 25 distinct victim organizations
• Profile the attacker’s working hours and timezone in real time
• Automatically retrieve, analyze, and extract IOCs from every new build the attacker deployed
A flaw in the malware’s design compounded the issue. Every infected host runs the same binary, capable of both receiving commands from the operator and issuing commands to other infected hosts. No signing, no authentication. Anyone holding the token could push a single command and uninstall the malware across the entire botnet. An accidental kill switch.
We chose not to use it. Any command we sent would have appeared in the attacker’s own Discord and ended the monitoring operation.
Full technical writeup and IOCs available at the link below. Particularly relevant for organizations operating in Israel.
https://profero.io/blog/windowsaudit-backdoor/
Profero | Rapid-IR
WindowsAudit Backdoor: Inside a .NET RAT That Hides in Discord
Profero IRT reverse engineered a .NET 8 RAT named WindowsAudit.exe recovered from a victim host in April 2026. It uses Discord as primary C2, runs as SYSTEM, tears down EDR in Safe Mode, and ships a full Active Directory attack toolkit.
An IRGC cyber front spoiled food and destroyed three compressors at an Israeli plant by rewriting setpoints and pinning the valves open, then dropped a disk wiper on the same network. Sabotage written in the equipment’s own language, run under a ceasefire.
https://profero.io/blog/war-between-wars/
https://profero.io/blog/war-between-wars/
Profero | Rapid-IR
The War Between Wars: How an IRGC Cyber Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire
An IRGC-directed persona sabotaged industrial refrigeration and staged a disk-wipe campaign at Israeli facilities during a ceasefire. How the operation unfolded, and how to find the actor before it reaches your plant floor.
We added a detection rule for --allow-dangerously-skip-permissions in Claude Desktop. Then we found an attack chain nobody was talking about.
"No shell, no impact" is the wrong mental model for AI agents.
An agent running with that flag, even with Bash blocked, can still:
• Read SSH private keys, .env files, AWS credentials, and browser session databases
• Write to ~/.zshrc, .git/hooks/pre-commit, ~/.ssh/authorized_keys, or source files in your repo
Execution is deferred. The next terminal you open, the next commit you push, the next CI run, runs the payload.
It gets worse. Skills load as trusted context with no signatures, no checksums, and no version pinning. Inject once, persist in ~/.claude/skills/, and wait. The user invokes the skill days later in a fresh session, and the payload runs with full trust. No anomalous process, network, or permission signal to catch it.
What defenders should do today:
• Monitor ~/.claude/skills/ for unexpected modifications
• Vet every MCP tool and skill before installation
• Audit shell configs and git hooks after any agent session
• Stop treating --allow-dangerously-skip-permissions as safe just because Bash is off
Full breakdown:
https://profero.io/blog/hiddenperms/
"No shell, no impact" is the wrong mental model for AI agents.
An agent running with that flag, even with Bash blocked, can still:
• Read SSH private keys, .env files, AWS credentials, and browser session databases
• Write to ~/.zshrc, .git/hooks/pre-commit, ~/.ssh/authorized_keys, or source files in your repo
Execution is deferred. The next terminal you open, the next commit you push, the next CI run, runs the payload.
It gets worse. Skills load as trusted context with no signatures, no checksums, and no version pinning. Inject once, persist in ~/.claude/skills/, and wait. The user invokes the skill days later in a fresh session, and the payload runs with full trust. No anomalous process, network, or permission signal to catch it.
What defenders should do today:
• Monitor ~/.claude/skills/ for unexpected modifications
• Vet every MCP tool and skill before installation
• Audit shell configs and git hooks after any agent session
• Stop treating --allow-dangerously-skip-permissions as safe just because Bash is off
Full breakdown:
https://profero.io/blog/hiddenperms/
Profero | Rapid-IR
We Added a Detection Rule. We Were Not Expecting This.
Claude Desktop launches its AI subprocess with --allow-dangerously-skip-permissions. We found the command line, reverse-engineered the architecture, and threat-modeled what an attacker could actually do inside that sandbox, including a prompt injection chain…