/
Navigation
C
Chronicles
Browse all articles
C
E
Explore
Semantic exploration
E
R
Research
Entity momentum
R
N
Nexus
Correlations & relationships
N
~
Story Arc
Topic evolution
S
Drift Map
Semantic trajectory animation
D
P
Posts
Analysis & commentary
P
Browse
@
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
?
Concept Search
Semantic similarity search
!
High Impact Stories
Top coverage by position
+
Sentiment Analysis
Positive/negative coverage
*
Anomaly Detection
Unusual coverage patterns
Analysis
vs
Rivalry Report
Compare two entities head-to-head
/\
Semantic Pivots
Narrative discontinuities
!!
Crisis Response
Event recovery patterns
Connected
Nav: C E R N
Search: /
Command: ⌘K
Embeddings: large
VOICE ARCHIVE

Jack Stubbs

@jc_stubbs
11 posts
2020-12-12
🇻🇳 Today in APT attribution news: Investigators at Facebook have tracked OceanLotus, a suspected Vietnamese state-backed hacking operation, to an IT firm called CyberOne Group in Ho Chi Minh City. Story with @pearswick and @razhael https://www.reuters.com/...
2020-12-12 View on X
ZDNet

Facebook identifies individuals behind APT32 and suspends their accounts, linking one of the most active state-sponsored hacking groups to an IT firm in Vietnam

one operating in Vietnam, and the other in Bangladesh. https://about.fb.com/... Alon Gal / @underthebreach : Idk if Facebook made the right move by doxxing APT32 publicly prior to ...

A fun sub-plot to this story. While investigating CyberOne Group this week we found an old version of their website which linked to a Facebook page run by some Vietnamese infosec bloggers https://twitter.com/...
2020-12-12 View on X
ZDNet

Facebook identifies individuals behind APT32 and suspends their accounts, linking one of the most active state-sponsored hacking groups to an IT firm in Vietnam

one operating in Vietnam, and the other in Bangladesh. https://about.fb.com/... Alon Gal / @underthebreach : Idk if Facebook made the right move by doxxing APT32 publicly prior to ...

2020-08-04
After the ransom was paid, the attackers even provided some bonus security advice! https://twitter.com/...
2020-08-04 View on X
@jc_stubbs

[Thread] A look at the correspondence between a hacked US travel management firm, CWT, and the ransomware attackers, who were paid $4.5M in BTC to decrypt files

Jack Stubbs / @jc_stubbs : Tweets: @jc_stubbs , @jc_stubbs , @codybrown , and @jc_stubbs Tweets: Jack Stubbs / @jc_stubbs : After the ransom was paid, the attackers even provided ...

But the online chat room where the ransom negotiations took place was left online, giving a rare and *incredibly* interesting insight into how these things actually go down https://twitter.com/...
2020-08-04 View on X
@jc_stubbs

[Thread] A look at the correspondence between a hacked US travel management firm, CWT, and the ransomware attackers, who were paid $4.5M in BTC to decrypt files

Jack Stubbs / @jc_stubbs : Tweets: @jc_stubbs , @jc_stubbs , @codybrown , and @jc_stubbs Tweets: Jack Stubbs / @jc_stubbs : After the ransom was paid, the attackers even provided ...

Personally I was surprised at how professional and collegial the whole conversation was. From beginning to end, this was treated a business transaction for both parties https://twitter.com/...
2020-08-04 View on X
@jc_stubbs

[Thread] A look at the correspondence between a hacked US travel management firm, CWT, and the ransomware attackers, who were paid $4.5M in BTC to decrypt files

Jack Stubbs / @jc_stubbs : Tweets: @jc_stubbs , @jc_stubbs , @codybrown , and @jc_stubbs Tweets: Jack Stubbs / @jc_stubbs : After the ransom was paid, the attackers even provided ...

2020-06-10
Researchers at @citizenlab have also spent more than 2 years tracking this activity and say they have high confidence that BellTroX employees were behind the campaign. Per @jsrailton: “This is one of the largest spy-for-hire operations ever exposed.” https://citizenlab.ca/...
2020-06-10 View on X
Reuters

An obscure Indian firm provided hacking services to help spy on 10K+ email accounts over seven years, in one of the largest spy-for-hire operations ever exposed

New report from @citizenlab uncovering Dark Basin, a hack-for-hire group that has targeted thousands of individuals on six continents. Targets include advocacy groups and journalis...

NEW: Little-known Indian cyber firm BellTroX InfoTech Services has been acting as an international hacking shop, helping clients spy on at least 10,000 email accounts belonging to politicians, investors, journalists and activists worldwide https://uk.reuters.com/...
2020-06-10 View on X
Reuters

An obscure Indian firm provided hacking services to help spy on 10K+ email accounts over seven years, in one of the largest spy-for-hire operations ever exposed

New report from @citizenlab uncovering Dark Basin, a hack-for-hire group that has targeted thousands of individuals on six continents. Targets include advocacy groups and journalis...

2020-06-09
NEW: Little-known Indian cyber firm BellTroX InfoTech Services has been acting as an international hacking shop, helping clients spy on at least 10,000 email accounts belonging to politicians, investors, journalists and activists worldwide https://uk.reuters.com/...
2020-06-09 View on X
Reuters

An obscure Indian firm provided hacking services to help spy on 10K+ email accounts over seven years, in one of the largest spy-for-hire operations ever exposed

LONDON/WASHINGTON (Reuters) - A little-known Indian IT firm offered its hacking services to help clients spy …

Researchers at @citizenlab have also spent more than 2 years tracking this activity and say they have high confidence that BellTroX employees were behind the campaign. Per @jsrailton: “This is one of the largest spy-for-hire operations ever exposed.” https://citizenlab.ca/...
2020-06-09 View on X
Reuters

An obscure Indian firm provided hacking services to help spy on 10K+ email accounts over seven years, in one of the largest spy-for-hire operations ever exposed

LONDON/WASHINGTON (Reuters) - A little-known Indian IT firm offered its hacking services to help clients spy …

2020-05-11
Exclusive - Hackers linked to Iran have targeted staff at Gilead Sciences in recent weeks, the U.S. pharma giant whose antiviral drug remdesivir is the only treatment so far proven to help patients infected with COVID-19 https://www.reuters.com/...
2020-05-11 View on X
New York Times

Sources: the FBI and DHS are preparing to accuse China of attempting to hack vaccine data from academic and private laboratories

New York Times :

2020-04-29
NEW: Company documents reviewed by Reuters show at least 8 cyber-intelligence firms, better known for selling hacking and surveillance tools, are now pitching coronavirus-tracking products to governments around the world https://www.reuters.com/... with @joel_schectman @Bing_Chris
2020-04-29 View on X
Reuters

A deep dive on pitches to governments from cyber-intel firms like Cellebrite, NSO Group, and Intellexa to use their spy tools to trace the coronavirus