P.E.M.B LAB RESEARCH

Menu

  • Home
  • About
  • Contact Me
  • Home
  • About
  • Contact Me
Search
1 post tagged

CyberAwareness

Unmasking the Threat∶ A Deep Dive into a Phishing Campaign Targeting Corporate and Educational Emails
3 min read Feb 17, 2025

Unmasking the Threat∶ A Deep Dive into a Phishing Campaign Targeting Corporate and Educational Emails

Massive campaign targets over 27,000+ emails across across 14,000 domains from corporate and education. A threat actor by the name of "Armandabors" on github initially made a commit to github to update the massive list of emails used for one of the phihing domains.

in Phishing ThreatIntel EmailSecurity StaySafeOnline CyberAwareness
1 post tagged

EmailSecurity

Unmasking the Threat∶ A Deep Dive into a Phishing Campaign Targeting Corporate and Educational Emails
3 min read Feb 17, 2025

Unmasking the Threat∶ A Deep Dive into a Phishing Campaign Targeting Corporate and Educational Emails

Massive campaign targets over 27,000+ emails across across 14,000 domains from corporate and education. A threat actor by the name of "Armandabors" on github initially made a commit to github to update the massive list of emails used for one of the phihing domains.

in Phishing ThreatIntel EmailSecurity StaySafeOnline CyberAwareness
2 posts tagged

Phishing

Unmasking the Threat∶ Telegram OSINT and Attempt at Attribution
8 min read Mar 1, 2025

Unmasking the Threat∶ Telegram OSINT and Attempt at Attribution

Last time on part 1 we made a deep dive into the overal campaign infrastructure operation revealing multiple indicators and targeted groups. This time Ia am going to focus on the findings related to the odd one, referering to the unique phishing page, I uncovered during the investigation...

in Phishing ThreatIntel telegram osint bot attribution
Unmasking the Threat∶ A Deep Dive into a Phishing Campaign Targeting Corporate and Educational Emails
3 min read Feb 17, 2025

Unmasking the Threat∶ A Deep Dive into a Phishing Campaign Targeting Corporate and Educational Emails

Massive campaign targets over 27,000+ emails across across 14,000 domains from corporate and education. A threat actor by the name of "Armandabors" on github initially made a commit to github to update the massive list of emails used for one of the phihing domains.

in Phishing ThreatIntel EmailSecurity StaySafeOnline CyberAwareness
1 post tagged

StaySafeOnline

Unmasking the Threat∶ A Deep Dive into a Phishing Campaign Targeting Corporate and Educational Emails
3 min read Feb 17, 2025

Unmasking the Threat∶ A Deep Dive into a Phishing Campaign Targeting Corporate and Educational Emails

Massive campaign targets over 27,000+ emails across across 14,000 domains from corporate and education. A threat actor by the name of "Armandabors" on github initially made a commit to github to update the massive list of emails used for one of the phihing domains.

in Phishing ThreatIntel EmailSecurity StaySafeOnline CyberAwareness
2 posts tagged

ThreatIntel

Unmasking the Threat∶ Telegram OSINT and Attempt at Attribution
8 min read Mar 1, 2025

Unmasking the Threat∶ Telegram OSINT and Attempt at Attribution

Last time on part 1 we made a deep dive into the overal campaign infrastructure operation revealing multiple indicators and targeted groups. This time Ia am going to focus on the findings related to the odd one, referering to the unique phishing page, I uncovered during the investigation...

in Phishing ThreatIntel telegram osint bot attribution
Unmasking the Threat∶ A Deep Dive into a Phishing Campaign Targeting Corporate and Educational Emails
3 min read Feb 17, 2025

Unmasking the Threat∶ A Deep Dive into a Phishing Campaign Targeting Corporate and Educational Emails

Massive campaign targets over 27,000+ emails across across 14,000 domains from corporate and education. A threat actor by the name of "Armandabors" on github initially made a commit to github to update the massive list of emails used for one of the phihing domains.

in Phishing ThreatIntel EmailSecurity StaySafeOnline CyberAwareness
1 post tagged

analysis

Static Malware Analysis∶ to string or to floss that is the question
2 min read Mar 22, 2024

Static Malware Analysis∶ to string or to floss that is the question

Every analyst has one or two methodologies for analyzing malware and perhaps even different approaches based on the malware type being analyzed. Regardless of many ways you can analyze malware we all do static analysis and look into strings at some point.

in malware static analysis
1 post tagged

attribution

Unmasking the Threat∶ Telegram OSINT and Attempt at Attribution
8 min read Mar 1, 2025

Unmasking the Threat∶ Telegram OSINT and Attempt at Attribution

Last time on part 1 we made a deep dive into the overal campaign infrastructure operation revealing multiple indicators and targeted groups. This time Ia am going to focus on the findings related to the odd one, referering to the unique phishing page, I uncovered during the investigation...

in Phishing ThreatIntel telegram osint bot attribution
1 post tagged

bot

Unmasking the Threat∶ Telegram OSINT and Attempt at Attribution
8 min read Mar 1, 2025

Unmasking the Threat∶ Telegram OSINT and Attempt at Attribution

Last time on part 1 we made a deep dive into the overal campaign infrastructure operation revealing multiple indicators and targeted groups. This time Ia am going to focus on the findings related to the odd one, referering to the unique phishing page, I uncovered during the investigation...

in Phishing ThreatIntel telegram osint bot attribution
1 post tagged

breach

Post Patch Threat Hunting
2 min read Apr 19, 2024

Post Patch Threat Hunting

Earlier today MITRE went public stating that a state-backed hacking group breached its systems using two Ivanti VPN zero-days back in January 2024.

in breach threat hunting patch ivanti mitre
1 post tagged

dropper

Powershell Dropper
2 min read May 30, 2023

Powershell Dropper

I found an interesting PowerShell script uploaded today on Malware Bazaar uploaded at 2023-05-31 02:06 (UTC) then turns out to be a dropper...

in malware dropper
1 post tagged

ivanti

Post Patch Threat Hunting
2 min read Apr 19, 2024

Post Patch Threat Hunting

Earlier today MITRE went public stating that a state-backed hacking group breached its systems using two Ivanti VPN zero-days back in January 2024.

in breach threat hunting patch ivanti mitre
2 posts tagged

malware

Static Malware Analysis∶ to string or to floss that is the question
2 min read Mar 22, 2024

Static Malware Analysis∶ to string or to floss that is the question

Every analyst has one or two methodologies for analyzing malware and perhaps even different approaches based on the malware type being analyzed. Regardless of many ways you can analyze malware we all do static analysis and look into strings at some point.

in malware static analysis
Powershell Dropper
2 min read May 30, 2023

Powershell Dropper

I found an interesting PowerShell script uploaded today on Malware Bazaar uploaded at 2023-05-31 02:06 (UTC) then turns out to be a dropper...

in malware dropper
1 post tagged

mitre

Post Patch Threat Hunting
2 min read Apr 19, 2024

Post Patch Threat Hunting

Earlier today MITRE went public stating that a state-backed hacking group breached its systems using two Ivanti VPN zero-days back in January 2024.

in breach threat hunting patch ivanti mitre
1 post tagged

osint

Unmasking the Threat∶ Telegram OSINT and Attempt at Attribution
8 min read Mar 1, 2025

Unmasking the Threat∶ Telegram OSINT and Attempt at Attribution

Last time on part 1 we made a deep dive into the overal campaign infrastructure operation revealing multiple indicators and targeted groups. This time Ia am going to focus on the findings related to the odd one, referering to the unique phishing page, I uncovered during the investigation...

in Phishing ThreatIntel telegram osint bot attribution
1 post tagged

patch

Post Patch Threat Hunting
2 min read Apr 19, 2024

Post Patch Threat Hunting

Earlier today MITRE went public stating that a state-backed hacking group breached its systems using two Ivanti VPN zero-days back in January 2024.

in breach threat hunting patch ivanti mitre
1 post tagged

static

Static Malware Analysis∶ to string or to floss that is the question
2 min read Mar 22, 2024

Static Malware Analysis∶ to string or to floss that is the question

Every analyst has one or two methodologies for analyzing malware and perhaps even different approaches based on the malware type being analyzed. Regardless of many ways you can analyze malware we all do static analysis and look into strings at some point.

in malware static analysis
1 post tagged

telegram

Unmasking the Threat∶ Telegram OSINT and Attempt at Attribution
8 min read Mar 1, 2025

Unmasking the Threat∶ Telegram OSINT and Attempt at Attribution

Last time on part 1 we made a deep dive into the overal campaign infrastructure operation revealing multiple indicators and targeted groups. This time Ia am going to focus on the findings related to the odd one, referering to the unique phishing page, I uncovered during the investigation...

in Phishing ThreatIntel telegram osint bot attribution
1 post tagged

threat hunting

Post Patch Threat Hunting
2 min read Apr 19, 2024

Post Patch Threat Hunting

Earlier today MITRE went public stating that a state-backed hacking group breached its systems using two Ivanti VPN zero-days back in January 2024.

in breach threat hunting patch ivanti mitre

Latest Posts

Unmasking the Threat∶ Telegram OSINT and Attempt at Attribution
8 min read Mar 1, 2025

Unmasking the Threat∶ Telegram OSINT and Attempt at Attribution

PEMB's Picture
PEMB
Unmasking the Threat∶ A Deep Dive into a Phishing Campaign Targeting Corporate and Educational Emails
3 min read Feb 17, 2025

Unmasking the Threat∶ A Deep Dive into a Phishing Campaign Targeting Corporate and Educational Emails

PEMB's Picture
PEMB

Explore Tags

CyberAwareness EmailSecurity Phishing StaySafeOnline ThreatIntel analysis attribution bot breach dropper ivanti malware mitre osint patch static telegram threat hunting
2025 © P.E.M.B LAB RESEARCH