Ashley Shen Profile
Ashley Shen

@ashl3y_shen

Followers
3,433
Following
967
Media
41
Statuses
690

Security researcher @TalosSecurity / Ex-Googler / Black Hat & HITCON Review Board / Organizer of @rhacklette41 . These tweets are my own not my employer's.

Zurich, Switzerland
Joined March 2012
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@ashl3y_shen
Ashley Shen
21 days
🚨 We discovered that some versions of WeChat were vulnerable to CVE-2023-3420 due to the outdated V8 engine in Xweb. We reported this to the vendor in April. WeChat users should update to the latest version to stay secure. More details in #vulnerability
0
25
49
@ashl3y_shen
Ashley Shen
1 year
After 3 years at Google TAG, I'm delighted to announce an exciting new chapter in my career. I'm joining @TalosSecurity to conduct threat intelligence research and counter threat actors. Looking forward to collaborating with brilliant minds and growing in this new adventure.
18
7
220
@ashl3y_shen
Ashley Shen
5 months
It was such a honor to present at the first ever @pivot_con ! Also proud of myself for doing the panel ❤️ I had an amazing time there, perfect location, high quality talks and "my people"!! shoutout to the organizer team!! Thank you for the incredible job! #pivotcon24
Tweet media one
@pivot_con
PIVOTcon
5 months
🎙️ @ashl3y_shen talks about her research on Chinese mercenary group #PoisonCarp #EvilEye . There is everything from tracking malware, C2 infra to rabbit holes and analytical mysteries 🥰 #PIVOTcon24 #CTI #ThreatIntel
Tweet media one
0
7
24
6
15
140
@ashl3y_shen
Ashley Shen
7 years
I will present a talk about malwares, exploits and attack incidents from DPRK this week at HITB GSEC! Stay tuned!
Tweet media one
7
50
132
@ashl3y_shen
Ashley Shen
2 years
The Chrome 0day (CVE-2022-2856) that me and @0xbadcafe1 found ITW is patched in the latest release. Update your Chrome to make sure you are protected.
1
41
120
@ashl3y_shen
Ashley Shen
2 years
Just received some cool swags. I was struggling between hoodie and toilet paper 😅 Thanks @GoogleVRP #BugBounty
Tweet media one
5
4
112
@ashl3y_shen
Ashley Shen
3 years
Cookie theft is still a common account hijacking technique adopted by criminal groups. Have been tracking & disrupting this group with multiple security teams since I joined Google. Happy to share our results and finding in this blog.
4
27
103
@ashl3y_shen
Ashley Shen
1 year
So excited for the talk Alice in Kernel Land: Lessons Learned From the eBPF Rabbit Hole from @scannell_simon @chompie1337 @thatjiaozi #BHASIA
Tweet media one
0
13
90
@ashl3y_shen
Ashley Shen
1 year
Its hard to find a talk that’s novel, technical and inspiring at the same time but @orange_8361 can always accomplish that. Definitely one of the best talk I have ever attended. @hexacon_fr
Tweet media one
0
4
90
@ashl3y_shen
Ashley Shen
6 years
Another great plugin released by Flare team. Recovering Stackstrings Using Emulation with ironstrings.
1
11
43
@ashl3y_shen
Ashley Shen
5 years
Finally our search is out. Spear phishing campaign targets Ukraine government. We reveals information about the suspected actor behind RATVERMIN.
0
20
42
@ashl3y_shen
Ashley Shen
5 months
My 9th year attending @BlackHatEvents #BHASIA24 ! Looking forward to all the great talks!!
Tweet media one
0
0
39
@ashl3y_shen
Ashley Shen
5 years
I’m honored to be recognized as one of the "32 Influential Malware Research Professionals" in the new ebook of . Thank you @Peerlyst , @chihebchebbi201 and to everyone who have supported me!
1
6
38
@ashl3y_shen
Ashley Shen
1 year
It was great to see everyone at the CTF crash course of @rhacklette41 last night! Hopefully everyone learned something useful about reverse engineering! Looking forward to see you again in our next one and solve some challenges together 😃!
Tweet media one
0
4
38
@ashl3y_shen
Ashley Shen
5 months
Here I am!! Ready for all the fun at @pivot_con #PIVOTcon24 #malaga
Tweet media one
0
1
33
@ashl3y_shen
Ashley Shen
1 year
Having HITCON FOMO. It’s my honour to join the review board this year and I was impressed by the quality of submissions! Enjoy the conference! #HITCONCommunity2023 #HITCONCMT2023 #HITCON
0
5
31
@ashl3y_shen
Ashley Shen
5 years
Attended my first @Blackhoodie_RE workshop and had a wonderful Android reversing training from @maddiestone . Also gave a lightening talk about "From Threat Intelligence to Pokemon Master". Thank you for everyone who make this weekend awesome!
Tweet media one
1
6
31
@ashl3y_shen
Ashley Shen
3 months
@craghuprasad and I published 2 new blogs about the Sugargh0st campaigns. We are tracking the group as Sneakychef, and named the new RAT found in the campaign SpiceRAT. The group is targeting a wider scope of government entities in EMEA and Asia. #sugargh0st #sneakychef
@TalosSecurity
Cisco Talos Intelligence Group
3 months
A Chinese-speaking threat actor has already targeted more than a dozen government agencies across the globe. More on #SneakyChef here
Tweet media one
11
16
46
2
7
31
@ashl3y_shen
Ashley Shen
3 years
This is what we do in TAG and I'm proud of it.
@googleeurope
Google Europe
3 years
Our threat intel teams continue to look out for and disrupt disinfo campaigns, hacking, and financially motivated abuse, and are working with other companies and relevant government bodies to address these threats.
8
37
250
0
1
31
@ashl3y_shen
Ashley Shen
7 years
We are getting on stage!!!! #BHEU
Tweet media one
2
0
28
@ashl3y_shen
Ashley Shen
5 years
Happy to have a chance to join this conference and present my research about the ICEFOG apt :)
3
3
30
@ashl3y_shen
Ashley Shen
11 months
Of course there are tons of snacks at the HITCON CTF final. 😍 #HITCON2023
Tweet media one
Tweet media two
0
0
28
@ashl3y_shen
Ashley Shen
1 year
So happy to join the blackhoodie training and seeing everyone again! 🥳 Thanks @pinkflawd @SynapticRewrite for giving the reverse engineering training! @Blackhoodie_RE @reconmtl
Tweet media one
3
1
28
@ashl3y_shen
Ashley Shen
6 years
This talk is awesome!!!! My fav talk this yaer at BlackHat / Defcon.
Tweet media one
Tweet media two
Tweet media three
2
6
25
@ashl3y_shen
Ashley Shen
1 year
I have the honor of giving away two passes to the @BlackHatEvents Black Hat Asia conference! Priority goes to students and anyone who needs support to attend. PM me if interested. #BHASIA
1
10
28
@ashl3y_shen
Ashley Shen
6 years
Its finally out. #FireEye #APT38
0
7
23
@ashl3y_shen
Ashley Shen
7 months
So excited and honoured to have this chance to share my research at the very first #PIVOTcon24 in May!! Thank you to all the crews for organising! Looking forward to seeing all the brilliant people and research!
@pivot_con
PIVOTcon
7 months
📢 Yes. It’s here. Absolutely mind blowing. The highlights of the #PIVOTcon24 #agenda . You have goosebumps all over your bodies? Drrrrrrrrumrrrrrrrroll.. 🥁🥁🥁 Go ahead and check them out! We still have some tickets😉 #ThreatIntel #CTI 🧵1/15
1
27
57
0
0
25
@ashl3y_shen
Ashley Shen
7 years
Thanks for everyone’s attention! Our slides is released, feel free to contact if there are any questions!
2
13
22
@ashl3y_shen
Ashley Shen
5 months
Just got back from my trip to #BHASIA and a vacation in Sabah 🏝️☀️ Met so many old and new friends and the talks were amazing! Thanks for everyone who came to our session it was such a heartwarming gathering and I’ve learned from you too! See you all next year!
Tweet media one
Tweet media two
Tweet media three
Tweet media four
0
1
23
@ashl3y_shen
Ashley Shen
6 years
Not a new tool but I just recently spent some time to fix the code and get it run. A very nice plugin.
Tweet media one
1
4
21
@ashl3y_shen
Ashley Shen
6 years
First time in BlathatIL and Isreal. Both are awesome! Great talks and great people! #BlueHatIL
Tweet media one
1
1
21
@ashl3y_shen
Ashley Shen
5 months
Can’t believe it’s been 20 years 😬 we are calling for papers for both HITCON CMT in August and the Enterprise in October this time. Looking forward to see all the brilliant submissions! #HITCON #HITCONCommunity2024 #HITCONCMT2024
@HacksInTaiwan
HITCON
5 months
HITCON Community 2024 - Call for Paper Theme: 20 Years of HITCON: Mind Meld Hacker Spirit from Human to AI HITCON is celebrating its 20th anniversary this year, marking the evolution from underground gatherings to a renowned hacker conference over the past two decades. The
Tweet media one
0
12
26
0
2
20
@ashl3y_shen
Ashley Shen
7 years
Thanks for all the support!!! @krNeoTra and I will present “A Deep Dive into the Digital Weapons of the North Korean Cyber Army” @HITBGSEC
0
12
18
@ashl3y_shen
Ashley Shen
8 years
Monnappa KA talking about Evasive Hollow Process Injection, surprise to see Taidoor in the slide! #BHASIA
Tweet media one
1
9
17
@ashl3y_shen
Ashley Shen
5 years
Our research is finally out! So excited! Check out the report and visit our booth at #BHUSA to learn more about APT41!
1
2
19
@ashl3y_shen
Ashley Shen
6 years
I will be joining and sharing my experience of founding a women security community at the Women in Security Meet Up in Black Hat Asia on March 29. Welcome everyone to join! #BHASIA
0
3
17
@ashl3y_shen
Ashley Shen
4 years
New research from TAG. Thats why I ignored a lot of messages from strangers.
@ShaneHuntley
Shane Huntley
4 years
New blog post from TAG with details of a North Korean campaign targeting security researchers working on vulnerability research and development. Stay safe out there everyone!
33
1K
2K
1
0
18
@ashl3y_shen
Ashley Shen
4 months
The mastermind of exploit hunting @_clem1 is going to speak at @hexacon_fr 🤩! so looking forward!! #HEXACON2024
@hexacon_fr
Hexacon
4 months
Why bother looking for vulnerabilities when you can just peer over the actor's shoulder beside you? 🤓 @_clem1 is infamously known for being able to track APT's exploit toolkits and we are extremely grateful to have him talk about it as our opening keynote! #HEXACON2024
Tweet media one
2
21
78
0
1
18
@ashl3y_shen
Ashley Shen
4 years
Sharing the slides @ReinforceMagic and I presented for the Threat Hunting and Campaign tracking 101 session during HITCON 2020 CTI Village Workshop. The talk was only 65 mins but we tried to cover some interesting cases and insights.
3
5
18
@ashl3y_shen
Ashley Shen
1 year
This is finally happening 🥳! So proud to be part of the Rhacklette! Looking forward to all the upcoming events!
@rhacklette41
rhacklette
1 year
WoSec ZH becomes Rhacklette! In March we have officially joined @defconch . We are a group of FINTA people in security with the goal to create a protected space for gender minorities in the security industry in Switzerland. We look forward to meeting you in upcoming events.
2
7
12
2
1
17
@ashl3y_shen
Ashley Shen
6 months
Black Hat Asia is around 10 days away! I have the honor of giving away two Live Event- Briefings Only or Virtual-Only- Briefings Only passes to the conference! Priority goes to students and anyone who needs support to attend. PM me if interested. #BHASIA @BlackHatEvents
0
10
17
@ashl3y_shen
Ashley Shen
5 months
Join me, @cyberMeeks , @Marmusha and @pink_tangent at the “Crush It In Cyber: The Debugging Odysseys of Women in CyberSecurity” today at 12:55 pm in Business hall theatre A! We are going to share our journeys and the challenges we faced! #BHASIA24 @BlackHatEvents
0
2
16
@ashl3y_shen
Ashley Shen
1 year
Come join our CTF training program and grow together! We will make sure this is fun for everyone with different levels of CTF experience!
@rhacklette41
rhacklette
1 year
🚀 Join us in Zurich for an exciting CTF training program! Boost your cybersecurity skills, solve challenges, and dive into the world of cybersecurity. Open to FINTA individuals in Rhacklette, all skill levels welcome! Register now by writing at rhacklette @defcon -switzerland.org
1
11
14
1
1
16
@ashl3y_shen
Ashley Shen
1 year
Thanks @TrenchantARC for the amazing party last night! Love the ideas for cocktails!
Tweet media one
Tweet media two
0
0
16
@ashl3y_shen
Ashley Shen
7 years
My first time presenting at #sectorca Don’t know much people here but it was fun! Thanks for evryone who came to my talk today! :)
Tweet media one
0
0
14
@ashl3y_shen
Ashley Shen
11 months
Time to submit your research to #BHASIA ! The conference will be on April 16-19 in Singapore again! Looking forward to see your submission! 😊
@BlackHatEvents
Black Hat
11 months
The #BHASIA 2024 Call for Tools is now open. Submit your tool proposal by Thursday, December 14 to be considered >>
0
1
1
0
1
14
@ashl3y_shen
Ashley Shen
1 year
Congratulations @_clem1 for winning the epic achievement at the @PwnieAwards ! The best exploit hunter I’ve known.
@dcuthbert
Daniel Cuthbert
1 year
Winner is
Tweet media one
0
1
10
0
1
14
@ashl3y_shen
Ashley Shen
7 years
I was the first women in my company, where I do malware analysis to identify the attackers and help to defend against them. 🇹🇼  #WITBragDay
0
2
14
@ashl3y_shen
Ashley Shen
3 months
Great find!! The target regions of both campaigns also have overlap (UZ, KZ). Definitely worth to research on more potential connections between xCaon and SpiceRAT. #spicerat #sneakychef #xcaon
@greglesnewich
Greg Lesnewich
3 months
Following the excellent work from @TalosSecurity @ashl3y_shen , we ( @threatinsight @Myrtus0x0 @ozuriexv ) observed some similarities between #SpiceRAT and #xCaon , a backdoor found by @_CPResearch_ linked to IndigoZebra active in the same regions as SneakyChef/UNK_SweetSpecter
2
17
63
1
2
14
@ashl3y_shen
Ashley Shen
7 years
HITCON wins 2nd place at #DEFCON CTF. Congratulations @magicienchao @h4ck47 @0xddaa @mehqq_ @seanwupi !!!
2
0
13
@ashl3y_shen
Ashley Shen
6 years
Will be my first time speaking in Poland :)
@CONFidenceConf
confidenceconf
6 years
#SPEAKER ANNOUNCEMENT 📢 @ashley_shen_920 from @FireEye Specializes in threat hunting, malware analysis, reverse engineering, and targeted attacks research. Co-founded “HITCON GIRLS” – the first security community for women in Taiwan. Full agenda here
Tweet media one
0
0
3
0
0
12
@ashl3y_shen
Ashley Shen
5 years
Will be speaking about my ICEFOG research in RESET conference next week in London! #RESET2019
0
2
13
@ashl3y_shen
Ashley Shen
5 years
Want to solve some smart contract challenges? Come to see us at #HITB2019AMS
@hitcongirls
HITCON GIRLS
5 years
HITCON GIRLS will be holding a smart contract challenge at #HITB2019AMS . We will be in Hapox at beurs van berlage during May 9 and 10. Try to solve the challenge and win some coins with us!
0
7
14
0
7
11
@ashl3y_shen
Ashley Shen
5 years
Just finished my talk in @CONFidenceConf ! Slide will release soon. Conference in the Polish aviation museum. Really cool!
Tweet media one
0
2
13
@ashl3y_shen
Ashley Shen
1 year
The schedule for Black Hat Asia 2023 is now live! It's truly an honor to have served on the review board for 7 years now, and I'm blown away by the number of outstanding submissions we received this year! Check out the lineup of talks here: #BHAsia
0
0
12
@ashl3y_shen
Ashley Shen
4 years
very detailed comparison between Bindiff and Diaphora! great work @marcos_alvares !
@marcos_alvares
Marcos Alvares
4 years
"Comparative analysis between Bindiff and Diaphora - Patched Smokeloader Study Case" #smokeloader #bindiff #diaphora
Tweet media one
1
4
16
0
1
12
@ashl3y_shen
Ashley Shen
5 years
Love this pic!
@cglyer
Christopher Glyer
5 years
Next up is @ashley_shen_920 discussing ICEFOG (first reported by @kaspersky ) - is it a malware family? Is it a threat group? No public reporting since 2014 - what happened? #FireEyeSummit
Tweet media one
Tweet media two
1
3
23
1
0
12
@ashl3y_shen
Ashley Shen
5 years
Great presentation about mobile application traffic analysis from @verovaleros ! #RESET2019
Tweet media one
0
3
12
@ashl3y_shen
Ashley Shen
3 months
Read about SneakyChef espionage group targets government agencies with SugarGh0st and more infection techniques here #sneakychef #sugargh0st
0
2
11
@ashl3y_shen
Ashley Shen
1 year
Another amazing HITCON is happening this year! Looking forward to see all your outstanding submissions! Haven’t booked the flight but I will most likely be there! Feel free to reach out for a meetup 😊 #HITCON #HITCONENT2023
@HacksInTaiwan
HITCON
1 year
【HITCON Enterprise 2023 Call For Paper】 🚀HITCON ENT 2023 theme: Automation Security Ascendancy: Systematic Evolution to Maturity. Our CFP system is also available now. 🌐 #HITCON #HITCONENT2023
Tweet media one
0
2
1
0
0
11
@ashl3y_shen
Ashley Shen
5 years
Final stop of the ICEFOG word tour. Thank you #sector2019
Tweet media one
0
2
10
@ashl3y_shen
Ashley Shen
7 years
ESTsecurity discovered a spear-phishing campaign leveraging mobile app to target Korea cryptocurrency exchange users. #REAPER #APT37 #Geumseong121 #RedEYE #Group123
@cyberwar_15
CyberWar - 싸워
7 years
Tweet media one
0
3
6
1
4
10
@ashl3y_shen
Ashley Shen
4 months
Thanks for referencing our SugarGh0st blog! The target is indeed very interesting. It is also interesting that they kept using the old domain for months after we published the blog and only have a new domain for the recent campaign.
@threatinsight
Threat Insight
4 months
Artificial intelligence research is of high value to adversaries. @Proofpoint recently identified a SugarGh0st RAT campaign targeting US-based organizations involved in AI efforts, including those in academia, private industry, and gov't service. Brief: .
1
7
21
2
1
10
@ashl3y_shen
Ashley Shen
6 years
I enjoyed my time a lot at BlueHatIL so I’m really excited to join the CAB of BlueHat Shanghai. CFP is open until March 31. Dont miss your chance to speak at the very first BlueHat in Asia. #BlueHat
@msftsecresponse
Security Response
6 years
The CFP for #BlueHat Shanghai is now open! See our blog for details about the event and some topic suggestions from our CAB. @ashley_shen_920 @AsuNa_jp @csima @long123king @HuihuiG @epakskape @MJ0011 @zer0mem @vinnieliu @yongchuank @tinkerzf @lovesuae
1
16
29
0
0
10
@ashl3y_shen
Ashley Shen
6 years
Dear Black Hat Asia CFP submitters, my tip for beating 50% competitors is: DONT BE LAZY.
2
1
10
@ashl3y_shen
Ashley Shen
5 years
Yesterday I finally got a chance to join @wicca_NL . The CTF was a lot of fun. Thanks for holding this event.
@wicca_NL
Women In Cybersecurity Community Association
5 years
What an awesome hack the bank CTF evening organised by @ingnl !! 🎉🤗 So great to meet so many amazing women! Thank you all for making this possible and see you next time!! ❤️ #infosec #womenintech
Tweet media one
2
8
24
0
4
9
@ashl3y_shen
Ashley Shen
7 years
How I Chained 4 vulnerabilities on GitHub Enterprise, From SSRF Execution Chain to RCE! @orange_8361 #TaiwanNo1
0
3
8
@ashl3y_shen
Ashley Shen
2 years
To those in the Switzerland, join our community event in Zurich on June 15th to listen amazing lighting talks from Google Women in Engineering group! (English talks will be in the afternoon!)
1
6
9
@ashl3y_shen
Ashley Shen
5 years
@cyb3rops Thanks Florian! Im glad it provides helpful information.
1
1
8
@ashl3y_shen
Ashley Shen
1 year
@_vventura and @hunterbr72 did an amazing research on reversing NIM binary and developed FLIRT signature to make our life easier. @reconmtl
Tweet media one
0
2
8
@ashl3y_shen
Ashley Shen
6 years
If you are at #BHASIA welcome to join us tomorrow
Tweet media one
0
1
7
@ashl3y_shen
Ashley Shen
2 years
Received my @Blackhoodie_RE t-shirt! Thank you 😊
Tweet media one
0
0
8
@ashl3y_shen
Ashley Shen
11 months
Spoiler alert! We will have another CTF training with @rhacklette41 this Sunday to solve some other reversing challenges on hack the box! This time we will be also doing medium level challenge with windows binary so have your VM ready!
@rhacklette41
rhacklette
1 year
🚀Join us and learn how to solve CTF challenges! 📚We will meet once a month and cover a variety of CTF topics, including but not limited to: Web security, RE, Binary exploitation, Forensics, Crypto. Each session will include a mix of lecture, hands-on exercises, and discussion.
1
8
13
0
2
8
@ashl3y_shen
Ashley Shen
7 years
Still love my design after 3 years :)
@apnic
APNIC
7 years
The HITCON GIRLS logo shows that not all hackers are men #TWSeries #womenintech #netsec
Tweet media one
0
2
5
1
0
7
@ashl3y_shen
Ashley Shen
5 years
Looking forward to speak at Code Blue again!
@M_Miho_JPN
Mihoko Matsubara 松原実穂子
5 years
An annual international cybersecurity conference @codeblue_jp is just around the corner! It’s held in Tokyo on October 29 and 30. The speakers include @andrewfutter @allanfriedman @SungtingTsai @ashley_shen_920 Hikohiro Y Lin.
0
2
4
0
1
7
@ashl3y_shen
Ashley Shen
1 year
We are going to have our first training event soon! So excited 🥳
@rhacklette41
rhacklette
1 year
Join us for our 2 trainings on Web App Pentest 101 on 6th and 10th July after work: How to do a Pentest and what are the challenges of a Security Consultant? Open to FINTA individuals. Register now by writing at rhacklette @defcon -switzerland.org
1
5
7
0
0
7
@ashl3y_shen
Ashley Shen
5 years
Thanks for the photo! Lol
@ale_sp_brazil
Alexandre Borges
5 years
In few minutes @CONFidenceConf starts here at Krakow (Poland) Ashley, from FireEye, is making a last minute checking at track 2. #confidence #conference #cybersecurity
Tweet media one
0
1
11
0
0
6
@ashl3y_shen
Ashley Shen
7 years
Thank you @apnic for the awesome article of HITCON GIRLS!
@apnic
APNIC
7 years
Hacker communities like Taiwan's HITCON GIRLS r encouraging women to get into #CyberSecurity #TWSeries #womenintech
Tweet media one
0
13
15
0
2
6
@ashl3y_shen
Ashley Shen
2 months
Good to see Chrome is implementing more mitigation to the cookie theft attack. Although malware will still be able to do process injection to bypass the mitigation but pushing this to a more detectable behaviour is also a progress! #chrome #cookietheft
@parityzero
Will Harris
2 months
With Chrome 127 on Windows, we're introducing enhanced encryption to protect sensitive data, starting with your cookies🍪! This helps protect your personal information and keeps your online accounts secure from hackers. Read more about this protection:
Tweet media one
16
141
364
0
0
6
@ashl3y_shen
Ashley Shen
7 years
Thanks!
@TechJournalist
Sean Kerner
7 years
Amazing info from @ashley_shen_920 on how Lazarus group operates #SecTorCA @sectorca
Tweet media one
Tweet media two
0
2
10
0
2
6
@ashl3y_shen
Ashley Shen
5 years
Lol
@cyb3rops
Florian Roth
5 years
New Blog Post - How I forced a Chinese threat actor to help me with a campaign's attribution by adding it to a new "Taiwan" tab in my APT group mapping spreadsheet
Tweet media one
Tweet media two
37
203
698
1
1
6
@ashl3y_shen
Ashley Shen
6 years
It's always awkward to watch myself speaking.
@BlackHatEvents
Black Hat
6 years
VIDEO: Details of attacks targeting multiple banks, ATMs & Bitcoin services plus the malware, vulnerabilities discovered, and future mitigations presented at #BHASIA 2018
0
24
48
1
1
6
@ashl3y_shen
Ashley Shen
6 years
Taiwanから応援しています! #私たちは女性差別に怒っていい
0
0
6
@ashl3y_shen
Ashley Shen
5 years
Thanks Marcin :)
@siedlmar
⚛️ Marcin Siedlarz
5 years
. @ashley_shen_920 dropping a lot of knowledge about campaigns utilising ICEFOG malware
Tweet media one
0
5
15
0
0
6
@ashl3y_shen
Ashley Shen
2 months
The research began with detecting abnormal PowerShell commands downloading additional scripts and Cobalt Strike. Interestingly, the threat actor used the “quser” command to avoid operating with other users simultaneously. #APT41 #cobaltstrike
Tweet media one
1
1
6
@ashl3y_shen
Ashley Shen
5 years
Cool stuff, thanks
@silascutler
Silas Cutler (p1nk)
5 years
Interesting #Mirage / #MirageFox sample 🇨🇳: af8aa745ba47a4a85f513979cc9e2196 . Signed using fake @kaspersky cert. Compiled 30 Nov 2015 13:07:28 UTC Looks like an operator sets C2 at runtime ./sample.exe [C2 Server] [Port] (cc: @ashley_shen_920 )
Tweet media one
Tweet media two
2
22
51
0
0
5
@ashl3y_shen
Ashley Shen
1 year
@pstirparo So you pay for the indicators feed 😂
0
0
5
@ashl3y_shen
Ashley Shen
2 months
In addition to Bitdefender’s Crash Handler being abused by Shadowpad, we found Microsoft Office IME binary was also exploited. For privilege escalation, the threat actor crafted a custom loader to inject CVE-2018-0824 code. #exploit #shadowpad
Tweet media one
0
1
5
@ashl3y_shen
Ashley Shen
11 months
Really interesting research revealing the false flag campaign from #YoroTrooper !
@TalosSecurity
Cisco Talos Intelligence Group
11 months
Talos assesses with high confidence that the #YoroTrooper threat actor likely consists of individuals from Kazakhstan. But that hasn't stopped them from covering their tracks and disguising their origins. More on this threat actor in our latest blog
Tweet media one
1
8
16
0
1
5
@ashl3y_shen
Ashley Shen
6 years
Rule #0 : Waste a lot of time TRUE!!!!
0
3
5
@ashl3y_shen
Ashley Shen
8 years
Panda Poke, Panda Flight, Panda Sneeze. So Panda is "officially" representing China now. :) #Vault7 #YearZero #CIALeaks
Tweet media one
0
1
5
@ashl3y_shen
Ashley Shen
7 years
Awesome material for learning reverse engineering! I love all the GIF picture and the unicorn! :)
0
1
5