xiu Profile
xiu

@osint_barbie

Followers
628
Following
2K
Statuses
561

OSINT enthusiast | malware researcher at @moonlock_lab | opinions and tweets are my own

Joined August 2023
Don't wanna be here? Send us removal request.
@osint_barbie
xiu
3 months
we all know our nerdy souls craved code snippets and juicy IOCs (they’re coming at the end of thread😉)
@moonlock_lab
Moonlock Lab
3 months
1/10: We got tagged by @NietzscheLab under a post about a suspicious PyPI package targeting macOS users. It led to an article exposing the “Meme-Token-Hunter-Bot” on GitHub. Naturally, we had to check it out and sketch the hidden attack flow ourselves. Here’s what we found 👇
Tweet media one
0
0
12
@osint_barbie
xiu
4 days
RT @bruce_k3tta: #Poseidon #stealer for #macos with low detections lol "poseidon[.]cool" domain points to its C2 saves zip in /tmp/pizd…
0
13
0
@osint_barbie
xiu
7 days
RT @vmray: 🚨 Alert: Fully undetected Shell Script dropping macOS Atomic Stealer📷 💻 A DMG file containing a malicious Shell Script used to…
0
21
0
@osint_barbie
xiu
7 days
@vmray great work! thank you for tagging me🩶 keep me in the loop if you find more macOS samples;)
0
0
2
@osint_barbie
xiu
7 days
AI was supposed to be the future of humanity🙈
0
0
1
@osint_barbie
xiu
7 days
@smica83
Szabolcs Schmidt
7 days
Possibly related (again) @abuse_ch @JAMESWT_MHT
0
1
9
@osint_barbie
xiu
8 days
Great analysis of macOS samples from @SentinelOne related to the campaign reported by @tayvano_ 👏💪 I was lucky enough to check out this interview myself, what a win to see it before it disappeared )🍀
Tweet media one
@SentinelOne
SentinelOne
8 days
🚨 Alert: New macOS Malware Variants, FlexibleFerret, Undetected by Apple’s XProtect 🚨 @LabsSentinel researchers @philofishal and @TomHegel have uncovered new variants, which slip past Apple's XProtect, of the DPRK-linked macOS malware, Ferret. Dive deeper into our findings to stay ahead of this sophisticated threat: Key Insights: 👉 Detailed analysis of the malware's capabilities, part of the ongoing Ferret family campaign. 👉 Comprehensive list of indicators for threat hunters and defenders to identify and mitigate the threat. 👉 Threat actors are dynamically adapting, moving from signed to unsigned applications to evade detection. 👉 Both targeted attacks and broader 'scatter gun' approaches via social media and platforms like GitHub. @LabsSentinel continues to track and publicize these activities to bolster community defenses. SentinelOne customers are protected from all known variants of the Ferret family.
Tweet media one
0
3
28
@osint_barbie
xiu
8 days
@jamieantisocial when I told my bestie about state-sponsored hackers, stuxnet, and MaaS, she looked at me like I had just escaped from a psych ward 🥲
1
0
5
@osint_barbie
xiu
9 days
if you don't feel like reading thread 😅ps there is many suspicious (phishing) pages related to AS41745 -
Tweet media one
0
0
8
@osint_barbie
xiu
10 days
woooow well done 💪👏
@patrickwardle
Patrick Wardle
11 days
Well this took all of January, but that's a wrap! Mahalo for following along 🙏🏽 I've just uploaded a (100 page+) PDF of the complete blog post: Also all samples in the report have been made available for download #SharingIsCaring 🍎👾🥰
Tweet media one
0
0
5
@osint_barbie
xiu
10 days
RT @KandjiOfficial: Infostealers targeting macOS are evolving rapidly, making continuous monitoring essential, which our team is always on…
0
14
0
@osint_barbie
xiu
10 days
RT @privacyis1st: Another Mac Appstore AI Scam. Fail OpenAI Scam App converted by the scammer in @deepseek_ai by impersonating the DeepSeek…
0
5
0
@osint_barbie
xiu
11 days
Tweet media one
0
0
2