Will T
banner
bushidotoken.net
Will T
@bushidotoken.net
🇬🇧 | Senior Threat Intelligence Advisor at Team Cymru | Co-author SANS FOR589 | Co-founder Curated Intel
I am very glad to finally share publicly some interesting research I’ve been doing into ransomware infrastructure TTPs. This has been a long-running collaboration with a trusted partner who we can’t name but deeply appreciate their support. Read it here 👇
www.team-cymru.com/post/ransomw...
Ransomware Incident Response: Infrastructure Analysis
A year of incident response data reveals how Akira, DragonForce & Clop build ransomware infrastructure — and how defenders can hunt it.
www.team-cymru.com
September 15, 2026 at 9:30 PM
New Blog! 🇬🇧 UK Cybercrime Journal: ExfilSquad Emerges

- ExfilSquad’s extortion campaign targets UK public sector orgs, education, and law enforcement
- ExfilSquad's primary attack vector involves exploiting CRM platforms and Microsoft Power Pages

🔗 blog.bushidotoken.net/2026/09/uk-c...
UK Cybercrime Journal: ExfilSquad Emerges
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
blog.bushidotoken.net
September 3, 2026 at 5:35 AM
New Blog! 🇬🇧 UK Cybercrime Journal: ACRO Breach Report

— Between July 2021 and June 2023, the UK Criminal Records Office had 3 separate breaches
— It had an SQLi attack on its Kentico CMS followed by Mimikatz
— 4x Trend Micro AV alerts were ignored

🔗 blog.bushidotoken.net/2026/08/uk-c...
UK Cybercrime Journal: ACRO Breach Report
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
blog.bushidotoken.net
August 28, 2026 at 5:49 PM
New Blog! 🇬🇧 UK Cybercrime Journal: Carding Tactics & Youth Money Muling

- UK law enforcement exposed domestic carding networks and the growing threat of teenage money mules recruited via Snapchat, Instagram, and online gaming services

🔗 blog.bushidotoken.net/2026/08/uk-c...
UK Cybercrime Journal: Carding Tactics & Youth Money Muling
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
blog.bushidotoken.net
August 22, 2026 at 8:27 AM
New Blog! 🇬🇧 UK Cybercrime Journal: Evolution of Courier Fraud Campaigns

🔗 blog.bushidotoken.net/2026/08/uk-c...
UK Cybercrime Journal: Evolution of Courier Fraud Campaigns
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
blog.bushidotoken.net
August 12, 2026 at 9:05 AM
New Blog! 🇬🇧 UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026

- In H1 2026, Qilin averaged 8 UK victims per month, 37 in total
- Most victims are Small/Medium Enterprises (SMEs)
- Salford City College appeared on Qilin & DragonForce’s DLSs

🔗 blog.bushidotoken.net/2026/07/uk-c...
UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
blog.bushidotoken.net
August 9, 2026 at 6:31 PM
New Blog! 🇬🇧 UK Cybercrime Journal: H1 2026 Social Media Fraud Trends

- HMRC Warns TikTok Users
- Lloyds Bank says 66% of Fraud Cases Started on Meta 
- UK Finance Recorded £221.5m Lost to Investment Scams
- Fraudsters arrested in Nigeria by the NCA

🔗 blog.bushidotoken.net/2026/07/uk-c...
UK Cybercrime Journal: H1 2026 Social Media Fraud Trends
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
blog.bushidotoken.net
July 29, 2026 at 5:19 PM
🔮 New CTI Resource Announcement! 🔮

Project ORBITAL (Operational Relay Box Intelligence, Tracking, & Analysis Lexicon) is the latest open source intelligence (OSINT) collection I’ve created to help educate the industry about ORB Networks.

🔗 blog.bushidotoken.net/2026/07/proj...
July 25, 2026 at 10:14 AM
New Blog! 🇬🇧 UK Cybercrime Journal: H1 2026 Dark Web Seizures & Arrests

- Nemesis Dark Web Drug Dealers Arrested
- AEGIS Dark Web Drug Market Seizure
- Online Killers Marketplace (OKM) Admins Arrested

🔗 blog.bushidotoken.net/2026/07/uk-c...
UK Cybercrime Journal: H1 2026 Dark Web Seizures & Arrests
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
blog.bushidotoken.net
July 22, 2026 at 8:55 AM
New Blog! 🇬🇧 UK Cybercrime Journal: University of Nottingham Breached by ShinyHunters

The education sector in the UK has suffered repeated, significant data breaches in recent years, but ShinyHunters campaign has been one of the worst yet.

🔗 blog.bushidotoken.net/2026/07/uk-c...
UK Cybercrime Journal: University of Nottingham Breached by ShinyHunters
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
blog.bushidotoken.net
July 16, 2026 at 1:00 PM
New Blog! 🇬🇧 UK Cybercrime Journal: SMS Blaster Gang Convicted

- New details emerge about the use of an SMS Blaster device to send fraudulent text messages as part of an organised criminal operation in London

🔗 blog.bushidotoken.net/2026/07/uk-c...
UK Cybercrime Journal: SMS Blaster Gang Convicted
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
blog.bushidotoken.net
July 8, 2026 at 11:51 AM
New Phishing Campaign: Fake Interviews Offered at Top Brands to harvest Gmail creds, IOCs inside
gist.github.com/BushidoUK/57...
GmailPhishingAlert.md
GitHub Gist: instantly share code, notes, and snippets.
gist.github.com
July 5, 2026 at 6:10 PM
New Blog! 🇬🇧 UK Cybercrime Journal: Argos Account Takeover Fraud

- Cybercriminals are using leaked credentials to hijack Argos user accounts
- They then order and then collect the goods in-person at a physical store and pay with stolen credit cards

🔗 blog.bushidotoken.net/2026/07/uk-c...
UK Cybercrime Journal: Argos Account Takeover Fraud
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
blog.bushidotoken.net
July 2, 2026 at 6:29 AM
New Blog! 🇬🇧 UK Cybercrime Journal: Hargreaves Landsdown Extortion Attempt by Bashe

It appears Bashe weaponised HL’s recent, IT outages & glitches (in Sept 2025 and March 2026) to construct a plausible, but false, narrative of a successful hack.

🔗 blog.bushidotoken.net/2026/06/uk-c...
UK Cybercrime Journal: Hargreaves Landsdown Extortion Attempt by Bashe
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
blog.bushidotoken.net
June 24, 2026 at 8:42 AM
Two of my fav 🇬🇧 🇨🇦 experts when it comes to discussing cyber warfare, Philip Ingram and Ian Thornton-Trump, released an interview reviewing in detail the threat landscape of 🇷🇺 Russian cyber operations in the context of the ongoing war in 🇺🇦 Ukraine.

🔗 youtu.be/p1vl5t4fVWA
How Russia’s cyber propaganda machine is backfiring on the frontline | Ian Thornton-Trump
YouTube video by Frontline
youtu.be
June 24, 2026 at 7:54 AM
New Blog! 🇬🇧 UK Cybercrime Journal: Sustained DragonForce Campaign

Throughout May 2026, the DragonForce RaaS operation claimed seven UK-based companies as its victims by posting them on their Tor data leak site.

🔗 blog.bushidotoken.net/2026/06/uk-c...
UK Cybercrime Journal: Sustained DragonForce Campaign
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
blog.bushidotoken.net
June 21, 2026 at 11:07 AM
New Blog! Ransomware Tool Matrix Project Updates: Three Groups To Track 🔒🛠️

🔗 blog.bushidotoken.net/2026/06/rans...
Ransomware Tool Matrix Project Updates: Three Groups To Track
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
blog.bushidotoken.net
June 15, 2026 at 3:08 PM
I recently experimented with turning one of my blogs from back in 2020 (the pre-AI era!) into an AI-generated video via @NotebookLM and was surprised with the result.

🎥 Video: The Law of the Jungle 🐍 🦁 🦈 🦀
youtu.be/gb1aOjXly7E

Original blog: blog.bushidotoken.net/2020/05/cybe...
The Law of the Jungle: A Cybersecurity Awareness Video made with NotebookLM
YouTube video by BushidoToken
youtu.be
June 14, 2026 at 11:45 AM
New 🇬🇧 UK Cybercrime Journal Entry: Arup Group Breached by FulcrumSec

What do AWS DCs, Disneyland, Wembley Football Stadium, HS2 and HS1 Channel Tunnel Rail Link network, and the Eden Project all have in common? They were engineered by Arup Group 👀

blog.bushidotoken.net/2026/06/uk-c...
UK Cybercrime Journal: Arup Group Breached by FulcrumSec
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
blog.bushidotoken.net
June 10, 2026 at 11:58 AM
New 🇬🇧 UK Cybercrime Journal Entry: British Universities Struck by ShinyHunters Before Exam Season

blog.bushidotoken.net/2026/05/uk-c...
blog.bushidotoken.net
June 3, 2026 at 7:04 PM
New 🇬🇧 UK Cybercrime Journal Entry: £102 million Lost to Scams in 2025

blog.bushidotoken.net/2026/05/uk-c...
UK Cybercrime Journal: £102 million Lost to Scams in 2025
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
blog.bushidotoken.net
May 27, 2026 at 8:54 PM
📣 I have been wanting to write more regularly for my site blog.bushidotoken.net and have made a new series: The UK Cybercrime Journal.

These are short UK cybercrime incident reports with a BLUF, Analyst Comment, and Defensive Takeaways.

Starting here: blog.bushidotoken.net/2026/05/uk-c...
UK Cybercrime Journal: Inside the Cl0p attack on South Staffs Water
CTI, threat intelligence, OSINT, malware, APT, threat hunting, threat analysis, CTF, cybersecurity, security
blog.bushidotoken.net
May 24, 2026 at 12:16 PM
New Blog! Stranger Strings: Yurei Ransomware Operator Toolkit Exposed

Through my research with Team Cymru’s data, we have discovered another ransomware operator’s server with Stranger Things-themed tools, check it out👇

www.team-cymru.com/post/yurei-d...
Yurei Double Extortion Ransomware: Operator Toolkit and Analysis
Analyze the Yurei double extortion ransomware campaign, including its toolkit, attack lifecycle, and key tactics used by operators.
www.team-cymru.com
April 1, 2026 at 11:31 AM
New Blog! The Beast Returns: Analysis of a Beast Ransomware Server 👹

In March 2026, Team Cymru detected a Beast operator’s server that enabled us to understand the flow of their attacks from start, to middle, to the end, including ransomware binaries.

www.team-cymru.com/post/beast-r...
Beast Ransomware Toolkit: A Proactive Threat Intelligence Report
Explore our latest threat intelligence report on Beast Ransomware. See the exact incident response tools and TTPs used by operators to bypass EDR and delete backups.
www.team-cymru.com
March 18, 2026 at 11:12 AM