Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

The DFIR Report

@TheDFIRReport@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Real Intrusions by Real Attackers, the Truth Behind the Intrusion.

Detections: http://github.com/The-DFIR-Report | Services: http://thedfirreport.com/services |

1347 Followers
0 Following
20 Posts
Joined November 10, 2022
Open post
The DFIR Report @TheDFIRReport@infosec.exchange
· 1w ago
"The privilege escalation tool the threat actors brought with them was written as a text file and then decoded using certutil into a binary file." Read the full report: https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver #DFIR #ThreatIntel
thedfirreport.com
3
1
0
1
Open post
The DFIR Report @TheDFIRReport@infosec.exchange
· 2w ago
🔎 We’re currently investigating an intrusion involving activity associated with the Iranian threat actor tracked as Peach Sandstorm / PULSAR KITTEN / Mirage Kitten. As part of the investigation, we’ve identified the following domains: healthy-handles[.]com healthyselfeducation[.]com Seeing similar activity or have additional context to share? We’d like to hear from you. Get in touch 👉 https://buff.ly/iBfNhIo
buff.ly
4
0
1
1
Open post
The DFIR Report @TheDFIRReport@infosec.exchange
· 1w ago
"Once the encryption process was complete a file called RecoveryManual.html was left across the filesystem with the instructions on how to contact the threat actors for the ransom negotiations." Read the full report: https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours #DFIR #ThreatIntel
thedfirreport.com
2
0
0
0
Open post
The DFIR Report @TheDFIRReport@infosec.exchange
· 1w ago
🚨 It's here! The DFIR Labs Digital Forensics Challenge runs today. One real intrusion, 4 hours in Splunk or Elastic, 20+ questions, with live support in our Discord the whole way. It's not too late, sign up now 👉 https://dfirlabs.thedfirreport.com/dfirchallenge
dfirlabs.thedfirreport.com

DFIR Labs - Digital Forensics Challenge

1
0
1
0
Open post
The DFIR Report @TheDFIRReport@infosec.exchange
· 3w ago
🛡️ Let the attackers tell you what they're after. Active Defense Threat Insights deploys strategic decoys that attract adversaries and capture their moves 24/7, turning real interactions into high-fidelity IOCs and mapped TTPs specific to your organization. Understand adversaries before they reach your core systems. Learn more 👉 https://thedfirreport.com/products/active-defense/
thedfirreport.com
1
1
0
0
Open post
The DFIR Report @TheDFIRReport@infosec.exchange
· 6mo ago

We’re seeing a “Missing Font” ClickFix chain in the wild.

Flow:
1️⃣ Fake “Missing Font” prompt
2️⃣ Leads to a BSOD-style recovery screen
3️⃣ Prompts users to open Terminal/PowerShell directly (skipping the Run dialog) and execute commands

This variant leans into a more convincing multi-step user flow compared to typical ClickFix lures.

Curious if others are seeing similar activity?

#infosec #DFIR #threatintel

infosec.exchange

Infosec Exchange

7
2
9
0
Open post
The DFIR Report @TheDFIRReport@infosec.exchange
· 5mo ago

We identified an exposed server that provided unusual visibility into a large-scale, multi-victim exploitation and collection operation. Artifacts on the host showed that Claude Code and OpenClaw were embedded in the operator's day-to-day workflow, supporting troubleshooting, orchestration, and refinement of the collection pipeline. Logs indicated more than 900 confirmed compromises...

Read the full report: https://thedfirreport.com/2026/04/22/bissa-scanner-exposed-ai-assisted-mass-exploitation-and-credential-harvesting/

thedfirreport.com
2
0
5
0
Open post
The DFIR Report @TheDFIRReport@infosec.exchange
· 3mo ago
➡️ New report out today by Jake, Dino, Ahmed Farouk, @MittenSec, @angelo_violetti, and @r3nzsec. From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira 🔎 A user searching for ManageEngine OpManager was led to a fake download site and installed a trojanized MSI. 🐝 That install launched BumbleBee, which brought in AdaptixC2 and gave the threat actor a foothold in the network. https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira
thedfirreport.com
0
0
0
0
Open post
The DFIR Report @TheDFIRReport@infosec.exchange
· 3mo ago
"From network traffic recorded during the second round of exploitation, we saw the ActiveMQ Server process downloading the malicious XML file containing the commands to be run in the command-line interface: " Report: https://thedfirreport.com/2026/02/23/apache-activemq-exploit-leads-to-lockbit-ransomware/
thedfirreport.com
0
0
0
0
Open post
The DFIR Report @TheDFIRReport@infosec.exchange
· 2mo ago

🚨 Investigation & Collaboration Request

We are currently investigating malicious activity associated with the following LNK file:

1b3089a761da4a9b7a1bfb485cc857969346ce61 — Employment_Verification_Details.lnk

We observed command-and-control communications with:

🌐 work[.]officialm[.]com — VT Score: 0/91 🌐 31[.]192[.]107[.]162:443 — VT Score: 0/91

If you have observed related activity and/or possess additional intelligence, and would like to collaborate, please reach out!

0
0
0
0
Open post
The DFIR Report @TheDFIRReport@infosec.exchange
· 2mo ago
On the Exchange email server, the threat actor used a legitimate Windows executable, SystemSettingsAdminFlows.exe, which allows users to customize or configure the system settings to user’s preference. This LOLBIN was used to disable Windows Defender settings on the server. Report: https://thedfirreport.com/2026/02/23/apache-activemq-exploit-leads-to-lockbit-ransomware/
thedfirreport.com
0
0
0
0
Open post
The DFIR Report @TheDFIRReport@infosec.exchange
· 2mo ago
🐱 Cat’s Got Your Files: Dive Into the Lynx Ransomware Incident! Check out our latest DFIR Report detailing how attackers abused valid credentials to compromise an environment, create persistent high-privilege accounts, and conduct environment mapping and exfiltration before deploying Lynx ransomware. Report: https://thedfirreport.com/2025/11/17/cats-got-your-files-lynx-ransomware/
thedfirreport.com
0
0
0
0
Open post
The DFIR Report @TheDFIRReport@infosec.exchange
· 2mo ago
🔒 Private DFIR Reports — From the Front Lines of Incident Response Go beyond high-level threat summaries. Our Private DFIR Reports deliver unredacted, evidence-based intrusion analysis drawn directly from real investigations. Each report provides a ground-truth view of how modern intrusions unfold with detailed timelines, command lines, file paths, and forensic artifacts. 📩 Contact us for details and examples. https://thedfirreport.com/products/threat-intel/private-dfir-reports/
thedfirreport.com
0
0
0
0
Open post
The DFIR Report @TheDFIRReport@infosec.exchange
· 2mo ago
RDP bitmap cache artifacts revealed the threat actor opening the Veeam Backup & Replication console, reviewing backup jobs, tape & storage infrastructure — and removing backups from the configuration database. Full report 👇 https://thedfirreport.com/2025/12/17/cats-got-your-files-lynx-ransomware/
thedfirreport.com
0
0
0
0
Open post
The DFIR Report @TheDFIRReport@infosec.exchange
· 2mo ago
Did you know you can get notified when we publish a new report? Subscribe to our mailing list and receive updates directly in your inbox: https://thedfirreport.com/subscribe/
thedfirreport.com
0
0
0
0
Open post
The DFIR Report @TheDFIRReport@infosec.exchange
· 2mo ago
Use DFIR Report’s Threat Feed to gain early, actionable insight into attacker infrastructure before it becomes mainstream. Check it out here 👉 https://thedfirreport.com/products/threat-feed/
thedfirreport.com
0
0
0
0
Open post
The DFIR Report @TheDFIRReport@infosec.exchange
· 2mo ago
From smaller data sets to complex cases, DFIR Labs has case studies you can work through at your own pace — from your first investigation all the way to expert level. Start digging in 👉 https://thedfirreport.com/products/dfir-labs/
thedfirreport.com
0
0
0
0
Open post
The DFIR Report @TheDFIRReport@infosec.exchange
· 2mo ago
EtherRAT brought blockchain-backed C2 into this intrusion. A malicious MSI masquerading as Sysinternals RAMMap deployed EtherRAT, which used EtherHiding to retrieve Ethereum-hosted C2 config updates before pivoting to TryCloudflare infrastructure. Full report: https://thedfirreport.com/2026/05/11/flash-alert-etherrat-and-tuktuk-c2-end-in-the-gentleman-ransomware/ #DFIR #ThreatIntel #DigitalForensics
thedfirreport.com
0
0
1
0
Open post
The DFIR Report @TheDFIRReport@infosec.exchange
· 2mo ago
👤 Analyst Spotlight: Mattie Schuch A cyber threat hunter and detection enthusiast with almost a decade in cyber, focused on building detections, tracking threat actors, and making sense of the chaos they leave behind. Explore their work on The DFIR Report: https://thedfirreport.com/analyst/mittensec/
thedfirreport.com
0
0
0
0
Open post
The DFIR Report @TheDFIRReport@infosec.exchange
· 2w ago
🏆 The DFIR Labs Digital Forensics Challenge is this Saturday, and here's the prize pool so far: 🎟️ Full-access ticket to HACKLU 2026 🛠️ Full Arsenal license 🎫 3 DeathCon online tickets 🔬 3 DFIR Labs Pro licenses 🏢 1 DFIR Labs Enterprise license A huge thank you to our sponsors for supporting the DFIR community! Compete solo, with team options available. Sign up 👉 https://dfirlabs.thedfirreport.com/dfirchallenge
dfirlabs.thedfirreport.com

DFIR Labs - Digital Forensics Challenge

0
0
1
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:41:00 UTC