StrikeReady Labs
@strikereadylabs
Download live malware samples mentioned here: If you prefer marketing (our product is great!) subscribe to our main page @strikeready.com
#apt targeting the Indian gov a6f27d0a4844c725a9d3bf916b59df24c3f440a63c567329fda87c99f80529fb Indl Case List 2026.pdf.lnk 9ec2fcf125890ad69155a3343399f7e704ae0edb9873dcd38448415398ed81c5 Indl Case List 2026.rar a5a9b99066d1d27899506a2bf138da3289f9c33fc4dc5b8fd76be9c32c2bf90a powerpoint.bat
#apt 7d35283f975f9d7a2ff335706527771bf3d7e75f8b6c8762f6165adcfe8d2cf5 ASEAN Semiconductor Roadmap 2026_2030_Draft v0 (For Input)_for ATF-JCC.docx web-api.nrilsnalnrlne.workers[.]dev
these scams are pretty solid. they grab the list of applications from publicly hosted "construction permit" type city governments, and then send you a relatively small invoice to pay for "approval".
interesting #dailyphish using shopify's CDN for hosting payload cdn.shopify[.]com/s/files/1/0743/9509/1080/files/Document_for_your_review.pdf?v=1784829484
"send me money please" continues to be an effective scam with very little downside
41f221c65129e820ab85b578ca44651e8bda5eaa6df5bb4858566480518dcbc6 Certificate.pdf
f726dc8a5fd8026b16a5c3aa62a82ab7614247a5315c3a6c2a5c37b976b73775 214227.pdf
susp #unc1151 4ba59e9262c8023a2e365c7177de9dbeb3216ea446d1a399c0b458cd2c05d625 64_01_2026.pdf
Always interesting to see what a live phish from #unc1151 looks like 845474a60e029ac8b361a89edfee507d59318c52c6e48f36e6bd30626f09b3f0 Certificate.pdf
3152cb01dddc95ce5d14d45b9b0e33f5b107a4d3dce64f47efba24cbad406cfb CERTYFIKAT_Nr_312-05-2025.wsf #apt
edb3b8ef7949fad5a5c0b88f744e4e4a2acd40fe287bec8604ebe8dee9ab3a51 ASEAN 2026 Attendance Meeting (2).zip typical apt lure, but with ransomware filenames, makes this researcher call shenanigans
#malware #dailyopendir meetingszoom[.]com b91ca87a2ce64f025c27a4a7d58f4b61f7b9b043251abab0a138345b5cae322f zoom_meeting.zip
#apt #pk drive.usercontent[.]google[.]com/download?id=1FCv4gbtcpWYQo5GFVFRoMaJe0_YZVBk-&export=download&authuser=0 igkashmir8@gmail.com
this actor has sent an email like this to dozens of governments, every single day, for the past 15 years. it takes them a few weeks to get banned from outlook/gmail/yahoo/etc and they move to a new one #daily_notaphish_just_weird
#susp #dailyphish -> financeoperations1.github[.]io/ambulacecare/
#dailyphish targeting an insurance company ... a dinner invite leading to screenconnect. subscribezoominfo.screenconnect[.]com/Bin/ScreenConnect.ClientSetup.msi?e=Access&y=Guest
susp #redteam OSCE_Election_Security_Checklist_v2.pdf.exe 600710c6ad0e4260a3879d36c5455e71 66.234.147.10
"big game" invoice scammers switching from training invoices to infosec #dailyphish