/
Navigation
C
Chronicles
Browse all articles
C
E
Explore
Semantic exploration
E
R
Research
Entity momentum
R
N
Nexus
Correlations & relationships
N
~
Story Arc
Topic evolution
S
Drift Map
Semantic trajectory animation
D
P
Posts
Analysis & commentary
P
Browse
@
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
?
Concept Search
Semantic similarity search
!
High Impact Stories
Top coverage by position
+
Sentiment Analysis
Positive/negative coverage
*
Anomaly Detection
Unusual coverage patterns
Analysis
vs
Rivalry Report
Compare two entities head-to-head
/\
Semantic Pivots
Narrative discontinuities
!!
Crisis Response
Event recovery patterns
Connected
Nav: C E R N
Search: /
Command: ⌘K
Embeddings: large
VOICE ARCHIVE

Raphael Satter

@razhael
63 posts
2022-06-30
APT40 is gobbling up so much exfil they're recruiting unwitting college graduates to help translate it all, per this @FT story. https://www.ft.com/...
2022-06-30 View on X
Financial Times

An investigation details an operation by Chinese hacking group APT40 to lure graduates who studied English into translating stolen documents via a front company

Thursday, June 30, 2022 // (IG): BB //Weekly Sponsor: Dataminr Tweets: Max Seddon / @maxseddon : “Chinese students have been lured to work at a secretive technology company that ma...

These hack-for-hire groups have long been tracked by big tech firms, threat intel shops & the sharp-eyed folks @citizenlab. Lately, researchers have become bolder about calling them out — among them those @Google, who're publishing a blog post today: https://blog.google/...
2022-06-30 View on X
Reuters

An investigation details an Indian hacking-for-hire scheme to obtain documents in legal cases, starting in 2013 and targeting 100+ US and European organizations

A trove of thousands of email records uncovered by Reuters reveals Indian cyber mercenaries hacking parties involved …

But what's been largely missing from the discussion of hack-for-hire is a solid grasp on the business model(s) of cyber mercenary actors. We hope this story will begin to provide an answer, for example by tracing the alleged cash flow from client to spy: https://www.reuters.com/... https://twitter.com/...
2022-06-30 View on X
Reuters

An investigation details an Indian hacking-for-hire scheme to obtain documents in legal cases, starting in 2013 and targeting 100+ US and European organizations

A trove of thousands of email records uncovered by Reuters reveals Indian cyber mercenaries hacking parties involved …

For at least a decade, an interlocking set of Indian APT groups has been hacking lawyers & litigants on behalf of Western private eyes. Their goal? Winning lawsuits & arbitration battles. @specialreports takes a look at India's cyber mercenary industry. https://www.reuters.com/...
2022-06-30 View on X
Reuters

An investigation details an Indian hacking-for-hire scheme to obtain documents in legal cases, starting in 2013 and targeting 100+ US and European organizations

A trove of thousands of email records uncovered by Reuters reveals Indian cyber mercenaries hacking parties involved …

2022-06-07
“Do everything to increase our market share, and nothing else.” Powerful @Reuters investigation into how @binance became a hub for hackers, including North Korea's Lazarus Group. By @AABerwick & @tomwilson1983 https://www.reuters.com/...
2022-06-07 View on X
Bloomberg

Sources: the SEC is probing Binance and its 2017 ICO of BNB, now the world's fifth biggest token, on whether BNB is a security that should have been registered

US regulators are investigating whether Binance Holdings Ltd. broke securities rules by selling digital tokens just as the crypto exchange …

2022-04-11
New: Senior European Union officials — including the bloc's top justice official — were targeted using powerful phone hacking tools, @Bing_Chris and I have learned. https://www.reuters.com/...
2022-04-11 View on X
Reuters

Sources and leaked docs: senior EU officials were targeted last year with Israeli spyware, including Belgian statesman Didier Reynders; NSO denies involvement

Senior officials at the European Commission were targeted last year with spy software designed by an Israeli surveillance firm …

2022-04-05
This @AP piece gets at what I've seen others saying: Russia may be struggling to get its narrative across in English, or in Europe, but audiences further afield may be more receptive to the story Moscow is selling. By @DavidKlepper & @AmandaSeitz https://apnews.com/...
2022-04-05 View on X
Associated Press

Research: RT en Español is the third-most shared site on Twitter for Spanish-language info about Russia's invasion and in March saw a boost in Facebook likes

Associated Press : Tweets: @alirogin , @eliothiggins , @abcpolitics , @nickknudsenus , and @razhael Tweets: Ali Rogin / @alirogin : Fascinating, and scary: Russia is focusing its ...

2022-03-24
New: Authentication firm Okta says up to 366 customers were potentially affected by Lapsus$ gang intrusion. One executive calls the count a “worst case scenario.” https://www.reuters.com/...
2022-03-24 View on X
Bloomberg

Security researchers say a 16-year-old from England is the Lapsus$ group's mastermind; source: researchers identified seven unique accounts tied to Lapsus$

Cybersecurity researchers investigating a string of hacks against technology companies, including Microsoft Corp. and Nvidia Corp. …

2022-03-23
New: Authentication firm Okta says up to 366 customers were potentially affected by Lapsus$ gang intrusion. One executive calls the count a “worst case scenario.” https://www.reuters.com/...
2022-03-23 View on X
Wired

Okta confirms an attacker accessed an engineer's laptop in January consistent with posted screenshots by Lapsus$, as customers struggle to grasp their exposure

Authentication firm Okta's statements on the Lapsus$ breach fails to answer key questions.  —  The digital extortion group Lapsus$ threw …

New: Authentication firm Okta says up to 366 customers were potentially affected by Lapsus$ gang intrusion. One executive calls the count a “worst case scenario.” https://www.reuters.com/...
2022-03-23 View on X
Reuters

Okta says the “maximum potential impact” of its security breach was to 366 customers, out of 15K+, whose data was accessed by contractor Sitel; Okta is down 5%+

Hundreds of customers of digital authentication firm Okta Inc have possibly been affected by a security breach caused …

2022-03-22
Our story: Okta is looking into a reported breach after hackers post screenshots of what they claim is its internal environment. @BillDemirkapi says the images look real. @viss says Okta's customers should be on their toes. https://www.reuters.com/... https://twitter.com/...
2022-03-22 View on X
Reuters

Okta is investigating reports of a breach after Lapsus$ group posted alleged internal system screenshots; CEO says they could be related to a January incident

Authentication services provider Okta Inc (OKTA.O) is investigating a report of a digital breach, the company said on Tuesday … Source: @toddmckinnon and @toddmckinnon .

2022-03-13
Salutary reminder that the same tech companies who today are pulling the plug on RT and its ilk were yesterday censoring the Russian opposition for fear of upsetting Moscow. https://twitter.com/...
2022-03-13 View on X
Washington Post

Sources: Apple and Google removed Kremlin critic Navalny's app in September after FSB agents came to top executives' homes and threatened to take them to prison

Russian agents came to the home of Google's top executive in Moscow to deliver a frightening ultimatum last September …

2022-03-12
Salutary reminder that the same tech companies who today are pulling the plug on RT and its ilk were yesterday censoring the Russian opposition for fear of upsetting Moscow. https://twitter.com/...
2022-03-12 View on X
Washington Post

Sources: Apple and Google removed Kremlin critic Navalny's app in September after FSB agents came to top executives' homes and threatened to take them to prison

Russian agents came to the home of Google's top executive in Moscow to deliver a frightening ultimatum last September …

2022-03-10
The @FT goes into some detail about America's last-minute efforts to secure the networks of the Ukrainian railways & the Ukrainian police. https://www.ft.com/... https://twitter.com/...
2022-03-10 View on X
Financial Times

Sources describe how the US has bolstered Ukraine's cyber defenses with soldiers and cybersecurity experts, working with Ukraine years before Russia's attack

Most cyberattacks in Ukraine continue … Tweets: Raphael Satter / @razhael : The @FT goes into some detail about America's last-minute efforts to secure the networks of the Ukrainia...

2022-03-08
APT28 is back at it (again) using malicious blogspot domains to redirect Ukrainian targets to credential harvesting pages. https://blog.google/... This kind of tactic dates back almost five years. https://threatconnect.com/... https://twitter.com/...
2022-03-08 View on X
Washington Post

Google: Russia's Fancy Bear launched phishing campaigns against Ukrainians before the invasion and Belarus' Ghostwriter targeted Ukrainian and Polish militaries

Belarus conducted widespread phishing attacks against members of the Polish military as well as Ukrainian officials …

2022-03-02
Ukrainians tilting at digital windmills here, but no one will criticise them for lack of creativity. https://twitter.com/...
2022-03-02 View on X
The Verge

Web host Namecheap ends services for users registered in Russia over Russia's “war crimes”, with exceptions for anti-regime media, protest resources, and expats

2021-12-18
Thread by @jsrailton here on the previously obscure Cytrox ↘️ https://twitter.com/...
2021-12-18 View on X
The Citizen Lab

Two Egyptians living in exile had their iPhones compromised in June 2021 using Predator spyware built by North Macedonian developer Cytrox

Thread by @jsrailton here on the previously obscure Cytrox ↘️ https://twitter.com/...
2021-12-18 View on X
TechCrunch

Meta bans seven surveillance-for-hire groups, including Cytrox, removing over 1,500 Facebook and Instagram accounts and alerting 50K users who were targeted

Cytrox is one of seven surveillance companies now banned from Meta's platforms  —  While NSO Group was taking flak for hacking …

2021-12-17
Thread by @jsrailton here on the previously obscure Cytrox ↘️ https://twitter.com/...
2021-12-17 View on X
The Citizen Lab

Two Egyptians living in exile had their iPhones compromised in June 2021 using Predator spyware built by North Macedonian developer Cytrox

Key Findings  — Two Egyptians—exiled politician Ayman Nour and the host of a popular news program (who wishes to remain anonymous) …

2021-09-06
This is what several employees of the former Afghan government saw Friday morning when they tried to log in to their official Google Workspace accounts, per a source on the ground. My story from Friday: https://www.reuters.com/... https://twitter.com/...
2021-09-06 View on X
Reuters

Source: Google has temporarily locked an unspecified number of Afghan government email accounts, as the Taliban seeks to acquire former officials' emails