JAMESWT (@jameswt_wt) 's Twitter Profile
JAMESWT

@jameswt_wt

#Independent #Malware #Hunter

#CyberSecurity #InfoSec

virustotal.com/gui/user/james…

ID: 3433210978

calendar_today20-08-2015 19:05:01

52,52K Tweet

36,36K Followers

487 Following

Garante Privacy (@gpdp_it) 's Twitter Profile Photo

#DataBreach #GarantePrivacy Verifiche sulle violazioni dei sistemi informatici di alcune strutture ricettive che avrebbero provocato la sottrazione di migliaia di scansioni dei documenti di riconoscimento utilizzati dai clienti al momento del check-in ➡️ gpdp.it/home/docweb/-/…

#DataBreach #GarantePrivacy Verifiche sulle violazioni dei sistemi informatici di alcune strutture ricettive che avrebbero provocato la sottrazione di migliaia di scansioni dei documenti di riconoscimento utilizzati dai clienti al momento del check-in ➡️ gpdp.it/home/docweb/-/…
Karsten Hahn (@struppigel) 's Twitter Profile Photo

🔍New Blog: JustAskJacky -- AI brings back classical trojan horse malware 🔗gdatasoftware.com/blog/2025/08/3… #GDATA G DATA Global #GDATATechblog

The Hacker News (@thehackersnews) 's Twitter Profile Photo

⚡ Japan’s cyber watchdog caught hackers using CrossC2—a Cobalt Strike spin-off that hijacks Linux, macOS, and Windows—to breach networks across multiple countries. They loaded custom malware entirely in memory—and may be tied to Black Basta ransomware crews. Details →

⚡ Japan’s cyber watchdog caught hackers using CrossC2—a Cobalt Strike spin-off that hijacks Linux, macOS, and Windows—to breach networks across multiple countries.

They loaded custom malware entirely in memory—and may be tied to Black Basta ransomware crews.

Details →
HackManac (@h4ckmanac) 's Twitter Profile Photo

🚨Cyber Attack Alert‼️ 🇮🇹Italy - Studio Legale Casali Angeleri Gentilini Avvocati Associati Dire Wolf hacking group claims to have breached the law firm Studio Legale Casali Angeleri Gentilini Avvocati Associati, exfiltrating 173 GB of data. The stolen files allegedly include

🚨Cyber Attack Alert‼️

🇮🇹Italy - Studio Legale Casali Angeleri Gentilini Avvocati Associati

Dire Wolf hacking group claims to have breached the law firm Studio Legale Casali Angeleri Gentilini Avvocati Associati, exfiltrating 173 GB of data. 

The stolen files allegedly include
TomU | I'm still here... til the end 🕊️🇨🇭 (@c_apt_ure) 's Twitter Profile Photo

𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 JAMESWT Andrea (Drego) Draghetti 👨🏻‍💻 🎣 Claudia Gianni Amato TG Soft Germán Fernández Ne0ne | Igal proxylife ShadowOpCode Simplicio Sam L. ANY.RUN Thanks for sharing Erik! I think there are some more C2 IPs connected to this TA: (via pDNS & SMB NetBIOS) virustotal.com/gui/domain/esp… 2025-08-08 - 94.26.90[.245 2025-07-02 - 45.74.10[.38 2025-06-22 - 74.208.226[.175 2025-03-26 - 176.65.144[.162 #AsyncRAT #ResolverRAT #server60929

<a href="/netresec/">𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲</a> <a href="/JAMESWT_WT/">JAMESWT</a> <a href="/AndreaDraghetti/">Andrea (Drego) Draghetti 👨🏻‍💻 🎣</a> <a href="/signorina37H/">Claudia</a> <a href="/guelfoweb/">Gianni Amato</a> <a href="/VirITeXplorer/">TG Soft</a> <a href="/1ZRR4H/">Germán Fernández</a> <a href="/0xToxin/">Ne0ne | Igal</a> <a href="/pr0xylife/">proxylife</a> <a href="/ShadowOpCode/">ShadowOpCode</a> <a href="/marsomx_/">Simplicio Sam L.</a> <a href="/anyrun_app/">ANY.RUN</a> Thanks for sharing Erik!

I think there are some more C2 IPs connected to this TA:
(via pDNS &amp; SMB NetBIOS)

virustotal.com/gui/domain/esp…
2025-08-08 - 94.26.90[.245
2025-07-02 - 45.74.10[.38
2025-06-22 - 74.208.226[.175
2025-03-26 - 176.65.144[.162

#AsyncRAT
#ResolverRAT
#server60929
JAMESWT (@jameswt_wt) 's Twitter Profile Photo

#compromised #italy mtecommerce.]it #Phishing pdf #fakecaptcha ASN AS39729 REGISTER-AS REGISTER S.P.A., IT (registered Apr 18, 2006)Register

#compromised #italy
mtecommerce.]it
#Phishing pdf #fakecaptcha 

ASN AS39729 REGISTER-AS REGISTER S.P.A., IT (registered Apr 18, 2006)<a href="/registerit/">Register</a>
ransomNews (@ransomnews) 's Twitter Profile Photo

🚨 nuova rivendicazione #ransomware Italia 🚨 🏴‍☠️ gruppo #Qilin 🧬 LIA Liberi Imprenditori Associati | Bergamo 🎯 settore: consulenze 🔗 liabergamo.it 🗓️ 15 agosto 2025 📄 sample: sì ▪️ dati esfiltrati dichiarati: - ▪️ dati esfiltrati pubblicati: - ⏲️ scadenza: -

🚨 nuova rivendicazione #ransomware Italia 🚨 

🏴‍☠️ gruppo #Qilin
🧬 LIA Liberi Imprenditori Associati | Bergamo
🎯 settore: consulenze
🔗 liabergamo.it
🗓️ 15 agosto 2025

📄 sample: sì
▪️ dati esfiltrati dichiarati: -
▪️ dati esfiltrati pubblicati: -
⏲️ scadenza: -
ransomNews (@ransomnews) 's Twitter Profile Photo

🚨 UPDATE rivendicazione #ransomware Italia 🚨 🏴‍☠️ gruppo #Sarcoma 🧬 Maselli Misure SPA | Parma 🎯 settore: manifattura 🔗 maselli.com 🗓️ 15 agosto 2025 📄 sample: sì ▪️ dati esfiltrati dichiarati: - ▪️ dati esfiltrati pubblicati: 49.50GB ⏲️ scadenza: -

ransomNews (@ransomnews) 's Twitter Profile Photo

⚠️ Remove your data from the reborn “National Public Data” site The relaunched National Public Data site now allows free access to sensitive personal info: addresses, phone numbers, birthdates, criminal records, and more. You can still submit an opt-out request to remove your

⚠️ Remove your data from the reborn “National Public Data” site

The relaunched National Public Data site now allows free access to sensitive personal info: addresses, phone numbers, birthdates, criminal records, and more.

You can still submit an opt-out request to remove your
Squiblydoo (@squiblydooblog) 's Twitter Profile Photo

Amazing reflection on trojans from Karsten Hahn . JustAskJacky was using a code-signing certificate we reported last week "App Interplace LLC", they were running a few other campaigns too: AskBettyHow, DailyChefly, GoCookMate, etc. JustAskJacky C2: api[.]vtqgo0729ilnmyxs9q[.]com

Amazing reflection on trojans from <a href="/struppigel/">Karsten Hahn</a> .

JustAskJacky was using a code-signing certificate we reported last week "App Interplace LLC", they were running a few other campaigns too:
AskBettyHow, DailyChefly, GoCookMate, etc.

JustAskJacky C2: api[.]vtqgo0729ilnmyxs9q[.]com
Squiblydoo (@squiblydooblog) 's Twitter Profile Photo

CertCentral is proud to announce partnership with #malcat (Malcat ). One essential function it plays today is we use it headlessly to enrich our database... The most obvious use of malcat is its GUI, but malcat can also be installed and ran as a python package. 🧵 1/6

CertCentral is proud to announce partnership with #malcat (<a href="/malcat4ever/">Malcat</a> ).

One essential function it plays today is we use it headlessly to enrich our database... The most obvious use of malcat is its GUI, but malcat can also be installed and ran as a python package. 🧵
1/6
Claudio (@sonoclaudio) 's Twitter Profile Photo

Vulnerabilità cuffie e auricolari #Bluetooth basati su #Airoha Claudia ed io, lo avevamo già segnalato a giugno. Se volere approfondire, maggiori dettagli, qui: 🔗 insinuator.net/2025/06/airoha…

Vulnerabilità cuffie e auricolari #Bluetooth basati su #Airoha
<a href="/signorina37H/">Claudia</a> ed io, lo avevamo già segnalato a giugno.
Se volere approfondire, maggiori dettagli, qui:
🔗 insinuator.net/2025/06/airoha…
Claudia (@signorina37h) 's Twitter Profile Photo

C'avete i giga illimitati per commentare le peggio cose, per instagrammare tutto quello che mangiate e per fare i voyeur sugli stati degli altri. Ma non riuscite a resistere al fascino del WiFi gratuito. Con aggravante QR code.

ransomNews (@ransomnews) 's Twitter Profile Photo

🚨 BREAKING: Peggy Sage under Datacarry’s shadow French beauty giant Peggy Sage has been hit by the emerging #DATACARRY ransomware. Attackers exfiltrated 11.3 GB of sensitive data and released it in a ZIP archive. #ransomNews #ransomware #beauty

🚨 BREAKING: Peggy Sage under Datacarry’s shadow

French beauty giant Peggy Sage has been hit by the emerging #DATACARRY ransomware.

Attackers exfiltrated 11.3 GB of sensitive data and released it in a ZIP archive.

#ransomNews #ransomware #beauty
JAMESWT (@jameswt_wt) 's Twitter Profile Photo

#spam #Italy #RemcosRAT "CONFERMA DELL'ESECUZIONE DELLA TRANSAZIONE.docx" 👇 bazaar.abuse.ch/browse/tag/car… ⛔️172.96.172.]174 ⛔️carljas.duckdns.]org

#spam #Italy #RemcosRAT
"CONFERMA DELL'ESECUZIONE DELLA TRANSAZIONE.docx"
👇
bazaar.abuse.ch/browse/tag/car…

⛔️172.96.172.]174
⛔️carljas.duckdns.]org
ransomNews (@ransomnews) 's Twitter Profile Photo

🥷🏻 Crypto24 toolkit revealed A Trend Micro report reveals #Crypto24, a sophisticated ransomware operation that blends legitimate admin tools (like PSExec, AnyDesk) with custom malware to infiltrate, persist, steal via Google Drive, disable EDRs, and deploy ransomware during

🥷🏻 Crypto24 toolkit revealed

A Trend Micro report reveals #Crypto24, a sophisticated ransomware operation that blends legitimate admin tools (like PSExec, AnyDesk) with custom malware to infiltrate, persist, steal via Google Drive, disable EDRs, and deploy ransomware during