Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • About Bonfire
Ian Campbell 馃彺
Ian Campbell 馃彺
@neurovagrant@masto.deoan.org  路  activity timestamp 2 days ago

Happy Friday, folks! New research from us:

THE KNOWNSEC LEAK: Yet Another Leak of China鈥檚 Contractor-Driven Cyber-Espionage Ecosystem

DTI researchers have been ripping apart 60+ sample screenshots from the Knownsec dump since November.

What emerged were deep technical details about Knownsec's platform and capabilities.

#threatintel

https://dti.domaintools.com/the-knownsec-leak-yet-another-leak-of-chinas-contractor-driven-cyber-espionage-ecosystem/

DomainTools Investigations | DTI

THE KNOWNSEC LEAK: Yet Another Leak of China鈥檚 Contractor-Driven Cyber-Espionage Ecosystem - DomainTools Investigations | DTI

Leaked Knownsec documents reveal China鈥檚 cyberespionage ecosystem. Analyze TargetDB, GhostX, and 404 Lab鈥檚 role in global reconnaissance and critical infrastructure targeting.
  • Copy link
  • Flag this post
  • Block
Ian Campbell 馃彺
Ian Campbell 馃彺
@neurovagrant@masto.deoan.org replied  路  activity timestamp 2 days ago

Knownsec tends to portray itself as a vanilla bug bounty/defense/pentest outfit.

But internal documents show they're a deeply sophisticated surveillance and offensive operations firm.

Their global crawler ZoomEye aggregates along with a target database and a vast datalake to enable targeting, compromise, and deeper surveillance of people, places, and institutions.

  • Copy link
  • Flag this comment
  • Block
Ian Campbell 馃彺
Ian Campbell 馃彺
@neurovagrant@masto.deoan.org replied  路  activity timestamp 2 days ago

Their PassiveRadar product allows them to feed multiple sources including PCAPs into a network environment enumerator, which raises the stakes on things like packet interception.

It's a completely passive way to build up a picture of the network environment in order to figure out how to best compromise it.

  • Copy link
  • Flag this comment
  • Block
Ian Campbell 馃彺
Ian Campbell 馃彺
@neurovagrant@masto.deoan.org replied  路  activity timestamp 2 days ago

As stated in our analysis, Resecurity's recent writeup definitely fleshed out targeting data much more, so it's very worth reading: https://www.resecurity.com/blog/article/knownsec-data-breach-a-trove-of-espionage-tradecraft-with-an-insider-narrative

That said, I really like how deeply we went on the technicals, and how much we were able to pull just from 65 screenshots.

Resecurity | Knownsec Data Breach: A Trove of Espionage Tradecraft with an Insider Narrative

  • Copy link
  • Flag this comment
  • Block

BT Free Social

BT Free is a non-profit organization founded by @ozoned@btfree.social . It's goal is for digital privacy rights, advocacy and consulting. This goal will be attained by hosting open platforms to allow others to seamlessly join the Fediverse on moderated instances or by helping others join the Fediverse.

BT Free Social: About 路 Code of conduct 路 Privacy 路
Bonfire social 路 1.0.1-beta.22 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Code of Conduct