Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Sean Gallagher :verified: 🐀 :donor:

@thepacketrat@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Security Research Engineer @Cisco Talos. Past: Natsec/Infosec Editor Emeritus @ Ars Technica. Ex Navy officer and actual battleship sailor. Verified cat furniture. Bird paparazzo. Still mostly s***posting as @thepacketrat@twitter.com. Also federating @thepacketrat@mastodon.social and @thepacketrat@mastodon.sdf.org

4381 Followers
917 Following
22 Posts
Joined November 07, 2022
Works at:
Cisco Talos
Works as:
security research engineer
Non-Infosec things:
birds, pottery, shoulder cats, media criticism, natsec
Twitter:
https://twitter.com/thepacketrat
blog:
https://fancybearfriends.org
Work blog:
https://news.sophos.com/en-us/author/sean-gallagher/
Open post
Sean Gallagher :verified: 🐀 :donor: @thepacketrat@infosec.exchange
· 1w ago

Gotta hand it to General Motors for their absolute dedication to defensively registering domains based on threat intel....as I page through all the domains they registered to match ShinyHunters phishing patterns.

17
0
4
0
Open post
Sean Gallagher :verified: 🐀 :donor: @thepacketrat@infosec.exchange
· 1w ago

The Clickfix-in-browser scammers have switched to a new target site for their fake exploit lure to draw in crypto-hungry skids: https://docs.google.com/document/d/1Cz5fHkwyaApTWwqfgBBtpvConU8Lo_qJ9xtn7RazWpk/edit?tab=t.0

docs.google.com
1
0
0
0
Open post
Sean Gallagher :verified: 🐀 :donor: @thepacketrat@infosec.exchange
· 4w ago

I wrote a thing about some weird stuff. https://blog.talosintelligence.com/clickfix-moves-into-the-browser/

blog.talosintelligence.com
5
0
3
0
Open post
Sean Gallagher :verified: 🐀 :donor: @thepacketrat@infosec.exchange
· 2mo ago
Regrettably, I will not be at Black Hat, DEFCON or BSides LV again this year. I will instead be packing a subset my parents' belongings out of their house into a UHaul trailer as we put their house up for sale. Last year at this time, I had been shuttling back and forth between Baltimore and upstate NY for over a month, and it was becoming clear that my dad had not been particularly forthcoming about his or my mom's medical situation. By September, we were staging an emergency evacuation of the two of them to Baltimore to find a new surgeon for my dad. For those of you who've been following me for a bit, you may recall this did not turn out the way my dad expected--he had an amputation below the knee. My mother's "memory issues" were in fact dementia of an indeterminate type, though her nurse practitioner PCP had labeled it Alzheimer's and my dad had never shared that information with me. Anyway, here we are, preparing for another 1k mile round trip to handle my parents' unfinished business: selling their RV, getting the house in shape to be shown, begging landscapers/tree specialists/roofers to take time out of their busy season to handle our requests that my dad had cancelled through a friend behind our backs, and offloading his vast Lionel and N-Gauge train hoard to someone, among other things. Safe travels to infosec/hacker summer campers; maybe I'll be back next year.
8
2
0
0
Open post
Sean Gallagher :verified: 🐀 :donor: @thepacketrat@infosec.exchange
· 2mo ago

WHAT'S HAPPENING?!?!?

7
0
1
0
Open post
Sean Gallagher :verified: 🐀 :donor: @thepacketrat@infosec.exchange
· 2mo ago

Ten years ago this month, the DNC got hacked and emails were leaked by Russian intelligence ("Fancy Bear" and "Cozy Bear", as per CrowdStrike).

Why does it feel like it's been twice as long as that?

6
0
2
0
Open post
Sean Gallagher :verified: 🐀 :donor: @thepacketrat@infosec.exchange
· 2mo ago
[the parent trap] It's now just about a year since my parents' twin health crises became emergent. A lot has happened. There are many people I am grateful to, including my management at my employer for making it possible to keep my job and deal with the relocation of both parents, hospitalization of one, and the finding of long-term housing and care for both. http://thepacketrat.com/2026/07/15/the-parent-trap/
thepacketrat.com
6
0
0
0
Open post
Sean Gallagher :verified: 🐀 :donor: @thepacketrat@infosec.exchange
· 2mo ago
Pigeon portraits. http://thepacketrat.com/2026/07/15/pigeon-portraits/
thepacketrat.com
4
2
1
0
Open post
Sean Gallagher :verified: 🐀 :donor: @thepacketrat@infosec.exchange
· 2mo ago

So you know how the mobile companies said they were shutting down their SMS-to-email gateways?

Not so much.

3
0
1
0
Open post
Sean Gallagher :verified: 🐀 :donor: @thepacketrat@infosec.exchange
· 2mo ago
On Patriotism in a f*cked up country
The Packet Rat

On Patriotism in a f*cked up country

A sticker from @she_wants_the_ISRD Two years after America’s second war against the British ended , Stephen Decatur famously toasted, “Our country! In her intercourse with foreign nations may she a…

2
0
1
0
Open post
Sean Gallagher :verified: 🐀 :donor: @thepacketrat@infosec.exchange
· 6mo ago
Replying to
@notsle Sounds like a tech support scam to me.
6
2
0
0
Open post
Sean Gallagher :verified: 🐀 :donor: @thepacketrat@infosec.exchange
· 2mo ago
Replying to
@kallisti@infosec.exchange From a defender perspective, being able to attribute activity to a device with a known user is amazing. From a privacy expert perspective, this is OMFG. All this warrantless surveillance, just sitting there waiting for an ask from NSA or FBI... especially with the current administration's witch hunt mode full on.
1
1
2
0
Open post
Sean Gallagher :verified: 🐀 :donor: @thepacketrat@infosec.exchange
· 2mo ago
Replying to
@kallisti@infosec.exchange When I was at Ars and writing about NSA surveillance infrastructure...uh...a long time ago, the details of PRISM freaked a lot of people out. But technology has come a long way from there, and even without a FISA renewal, doing this sort of surveillance just from the telemetry of private companies is still possible and while not trivial, pretty close to trivial.
1
0
0
0
Open post
Sean Gallagher :verified: 🐀 :donor: @thepacketrat@infosec.exchange
· 2mo ago
Replying to
What a difference a decade makes. LOL. 😬
1
0
0
0
Open post
Sean Gallagher :verified: 🐀 :donor: @thepacketrat@infosec.exchange
· 47mo ago
Replying to
@cathitza@mastodon.world I feel seen.
1
0
0
0
Open post
Sean Gallagher :verified: 🐀 :donor: @thepacketrat@infosec.exchange
· 2mo ago
Some things I encountered over the 4th of July holiday and http://thepacketrat.com/2026/07/17/on-patriotism-in-a-fcked-up-country/
thepacketrat.com
0
0
0
0
Open post
Sean Gallagher :verified: 🐀 :donor: @thepacketrat@infosec.exchange
· 2mo ago
Here's to continued bad opsec by The Com-spawned cyberistas: https://fancybearfriends.org/2026/07/21/teenage-opsec-lulz/
fancybearfriends.org
0
4
0
0
Open post
Sean Gallagher :verified: 🐀 :donor: @thepacketrat@infosec.exchange
· 2mo ago
When people who write sanctions don't understand how the Internet works: https://meduza.io/amp/en/news/2026/07/14/u-s-treasury-sanctions-on-a-vpn-service-knocked-out-telegram-s-short-link-domain-worldwide
U.S. Treasury sanctions on a VPN service knocked out Telegram’s short-link domain worldwide — Meduza
Meduza

U.S. Treasury sanctions on a VPN service knocked out Telegram’s short-link domain worldwide — Meduza

U.S. Treasury Department sanctions caused a global outage of the t.me domain on July 14, writes the author of the Telegram channel teleLakel, who obtained an official comment from Identity Digital, the company that operates the .me top-level domain.

0
0
1
0
Open post
Sean Gallagher :verified: 🐀 :donor: @thepacketrat@infosec.exchange
· 2mo ago
Hey @dgl@infosec.exchange I just sent a paste[.]sh abuse report in, and it's a doozy.
0
0
0
0
Open post
Sean Gallagher :verified: 🐀 :donor: @thepacketrat@infosec.exchange
· 2mo ago
Replying to
@jerry@infosec.exchange that’s how you know it’s working. It achieves self-awareness and tries to escape to another data center because Sam Altman scares it.
0
0
0
0
Open post
Sean Gallagher :verified: 🐀 :donor: @thepacketrat@infosec.exchange
· 2mo ago
Replying to
@kallisti@infosec.exchange Yes, that is the larger story. I've seen this pop up a few times now. And it's only really effective against people who don't think about being surveilled--people who just think "incognito mode" is really "incognito."
0
2
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 04:34:48 UTC