
Ismael Valenzuela
@aboutsecurity
VP Threat Research & Intelligence @AWNetworks āŖļø Ex @Foundstone @Intel @McAfee @BlackBerryāŖļø SANS Senior Instructor GSE #132 āŖļø #SEC530 #SEC568 #ThinkRedActBlue
ID: 45917439
http://aboutsecurity.io/ 09-06-2009 19:23:40
6,6K Tweet
18,18K Followers
9,9K Following




Nothing too exciting by APT41 šØš³ here IMO, using Impacket, CobaltStrike, Mimikatz, Pillager, RawCopy, Neo-reGeorg Using a compromised SharePoint server for C2 is interesting I guess, especially with this new ToolShell exploit for SharePoint servers securelist.com/apt41-in-africā¦

#ZeroTrust is complex. #AI helps simplify implementation. SANSā Ismael Valenzuela (Ismael Valenzuela) breaks down predictive, generative & agentic AI in action. š Read on The Hacker News: thehackernews.com/2025/07/assessā¦


Right after disclosing financially motivated "Greedy Sponge's" campaign targeting organizations in #Mexico (arcticwolf.com/resources/blogā¦), our Arctic Wolf Labs team has identified a new campaign by cyber-espionage group #DroppingElephant targeting Turkish defense contractors,


Thanks for the report Arctic Wolf! Further connected infrastructure based on upstream traffic patterns: 2.56.127.158 - cypowertech[.]org 94.131.108.94 - techzcore[.]org (recent & potentially live campaign) All four IPs in the attached image were suspended THE.Hosting šš¤š¤
![Team Cymru Threat Research (@teamcymru_s2) on Twitter photo Thanks for the report <a href="/AWNetworks/">Arctic Wolf</a>!
Further connected infrastructure based on upstream traffic patterns:
2.56.127.158 - cypowertech[.]org
94.131.108.94 - techzcore[.]org (recent & potentially live campaign)
All four IPs in the attached image were suspended <a href="/the_hosting_/">THE.Hosting</a> šš¤š¤ Thanks for the report <a href="/AWNetworks/">Arctic Wolf</a>!
Further connected infrastructure based on upstream traffic patterns:
2.56.127.158 - cypowertech[.]org
94.131.108.94 - techzcore[.]org (recent & potentially live campaign)
All four IPs in the attached image were suspended <a href="/the_hosting_/">THE.Hosting</a> šš¤š¤](https://pbs.twimg.com/media/GwoO9tEWAAIwRG7.jpg)


My latest talk on the practical application of AI in #cyberdefense is now live! š youtube.com/watch?v=HT3f66⦠This presentation was part of the SANS Institute āSecure Your Fortressā event back in April 2025, with 4,000 registrations and over 1,200+ live views from 76 countries.



āThinking like a Red Teamer doesnāt mean becoming one, it means becoming a more dangerous defender.ā Thatās the heart of my #ThinkRedActBlue š“ šµ philosophy, and Iām proud to see how well Galen Gough captured it after taking SANS Institute #SEC530. In his recent article, Galen
