xorJosh Profile Banner
Josh Profile
Josh

@xorJosh

Followers
1K
Following
1K
Statuses
267

SOC Analyst @HuntressLabs

UK
Joined September 2022
Don't wanna be here? Send us removal request.
@xorJosh
Josh
6 hours
RT @avery_town: Dissecting a Discord malware bot out of boredom & curiosity. #malware #Discord #Infosec #CyberSec
0
1
0
@xorJosh
Josh
13 hours
RT @EncapsulateJ: Fake Zoom updates lead to rouge RMM installation and hands on threat actor activity
Tweet media one
0
5
0
@xorJosh
Josh
9 days
RT @CyberRaiju: I frequently get asked is "what skills do I need need to excel as an analyst", so I figure this is a good opportunity to sh…
0
19
0
@xorJosh
Josh
11 days
RT @dipotwb: Suspected initial access malware spreading via fake captcha, utilising trycloudflare domains
Tweet media one
0
20
0
@xorJosh
Josh
14 days
RT @0xffaraday: @HuntressLabs SOC is seeing a newly suspected KoiLoader/KoiStealer attack chain. Details below:
0
4
0
@xorJosh
Josh
15 days
@mthcht reminds me of @mrd0x similar project:
1
1
8
@xorJosh
Josh
17 days
RT @HuntressLabs: ⚠️ Remote Support Software “SimpleHelp” is vulnerable to multiple CVEs that can be leveraged for full compromise. ⚠️ Pat…
0
7
0
@xorJosh
Josh
19 days
RT @0xffaraday: @HuntressLabs SOC is seeing further malicious activity from SimpleHelp RMM. Please update your SimpleHelp instance to its l…
0
2
0
@xorJosh
Josh
19 days
0
0
2
@xorJosh
Josh
20 days
RT @CyberRaiju: This is really big at the moment and you should absolutely be looking at your M365 logs to identify this activity. https:/…
0
94
0
@xorJosh
Josh
21 days
RT @Limitlezz_Dream: We observed an interesting case via the process insights detections. These happen to be one of my favorite things to r…
0
5
0
@xorJosh
Josh
22 days
@birchb0y has an really amazing blog on similar activity he previously looked into:
@ryanchenkie
Ryan Chenkie
23 days
⚠️ Developers, please be careful when installing Homebrew. Google is serving sponsored links to a Homebrew site clone that has a cURL command to malware. The URL for this site is one letter different than the official site.
Tweet media one
Tweet media two
1
7
26
@xorJosh
Josh
25 days
hxxps://rosecloud-security[.]com/1-93248234/index.html?user_id= hxxps://cdn-general[.]cyou/o.txt hxxps://cdn-general[.]cyou/1-723628312/hope4583945834-16-1-25.zip hxxps://cdn-general[.]cyou/2-912381232/sendNotification.php
0
0
3
@xorJosh
Josh
26 days
Saw @polygonben comment on a LinkedIn post related to this and had to share...
Tweet media one
1
0
2
@xorJosh
Josh
1 month
RT @CyberRaiju: 👀 A threat actor has cloned the California Freights website, modified it, is gathering information, and trying to make it f…
0
7
0
@xorJosh
Josh
1 month
RT @nosecurething: New @huntress blog where @birchb0y @Laughing_Mantis and I tell the story of 🕵️and 🤜 ➡️🗑️ some cyber espionage activity i…
0
6
0
@xorJosh
Josh
1 month
RT @birchb0y: reminder to say happy new years to the russian espionage groups in ur network 🥰🇷🇺 @nosecurething (🐐), @Laughing_Mantis (🐐),…
0
38
0
@xorJosh
Josh
1 month
RT @patrickwardle: Interested in all the new macOS malware of 2024!? 🍎🐛 I've started my annual "The Mac Malware of <Insert Year>" report.…
0
95
0
@xorJosh
Josh
1 month
RT @pe4Chscreeching: 🔍 Recent IoC from a BianLian Investigation @HuntressLabs Scheduled task, 'SystemsUpdate', had been created containing…
0
9
0