Corsin
banner
cocaman.ch
Corsin
@cocaman.ch
it security & cyber guy, research @ https://ecrime.ch, friendly, swiss | Opinions are my own
Sextortion emails dropped from 7,868 → 3,245 in August, but the number of distinct BTC wallets in use nearly doubled (14 → 26).
99.7% still spoof your own address as the sender. Volume down ≠ threat down - operators are just diversifying. 🧵
galileosignals.com/research/202...
Sextortion Bitcoin Ransom Campaign: August 2026
August 2026 brought a smaller but wallet-diverse sextortion wave: 3,245 wallet-bearing messages, near-universal visible From/To spoofing, and 26 checksum-valid BTC wallets.
galileosignals.com
September 1, 2026 at 3:49 PM
Reposted by Corsin
New claim on the shame-site for #ransomware / #datatheft group #Anubis.

Organization: fairlife, LLC
Location: #UnitedStates
Industry: #FoodAndBeverageServices
Staff: 1,001-5,000 employees

Learn more: https://ecrime.ch/
July 20, 2026 at 1:35 PM
Thanks AI, it converted the area41.io agenda into an importable .ics for your favorite calendar app.
Get it here:
gist.github.com/cocaman/f85e...
area41_2026_agenda.ics
GitHub Gist: instantly share code, notes, and snippets.
gist.github.com
May 2, 2026 at 8:37 AM
Reposted by Corsin
Thank you @ecrime.ch for being #PIVOTcon26 Silver Sponsor🥳
Read more about: @ecrime.ch here: ecrime.ch

They detect extortion threats, stolen data, and brand exposure before attackers escalate - with verified intelligence.

Our sponsors: pivotcon.org/sponsors
February 24, 2026 at 2:11 PM
Reposted by Corsin
I've waited 3 years to make this post
December 30, 2025 at 3:14 PM
Reposted by Corsin
#PIVOTcon2026 call for papers is open!

Remember, it's #PIVOTcon for a reason - your proposal should give insight into techniques and methodology, not just "what my favorite threat group did last summer". 😎

Bring on those proposals! #CFP
December 1, 2025 at 3:57 PM
Reposted by Corsin
Our annual review is out covering technical highlights such as

- Engineering resilience against critical loss
- Passkeys
- The future of digital identity
- Post quantum crypt transition
- Our Initiate r&d program with industry
- Radical transparency in technology

.. and more
It’s time to act

Today we’ve published our 2025 Annual Review, revealing that cyber threats facing the UK are accelerating rapidly. We must take action.
October 14, 2025 at 6:23 AM
Reposted by Corsin
You know you want to speak at Disobey 2026. And now is your chance to do that!

Our CfP is open at: cfp.disobey.fi/disobey-2026/

Check the guidelines from the link and send your proposal by Sep 30th!
August 5, 2025 at 2:52 PM
Reposted by Corsin
Tap in to the stream this week for some YARA fun, highlighting some crazy rules, how I think about learning yara (or anything) as a mid-career professional, and more!
🔥 Ready for this week's live stream with Greg Lesnewich...

youtube.com/live/JIxbM82...
July 21, 2025 at 5:06 PM
Well, where else do you get fresh Yara rules?
cc @stvemillertime.bsky.social @greg-l.bsky.social
July 15, 2025 at 5:34 PM
Finally a new template for a phishing email.

Sender IP: 45.138.48[.]158
Subject: Your email quarantine summary!!!

URLscan: urlscan.io/result/01980...

Phishing URL reported and blocked by Google Safe Browsing already.
July 14, 2025 at 11:43 AM
Reposted by Corsin
@greg-l.bsky.social drops knowledge on TA406 (Konni) as North Korea shows new interest in Ukraine, likely to keep tabs on the progress of the war and Russia's ability to keep pace on the battlefield www.proofpoint.com/us/blog/thre...
TA406 Pivots to the Front | Proofpoint US
What happened  In February 2025, TA406 began targeting government entities in Ukraine, delivering both credential harvesting and malware in its phishing campaigns. The aim of these
www.proofpoint.com
May 13, 2025 at 9:53 AM
Reposted by Corsin
Incidents impacting retailers – recommendations from the NCSC

www.ncsc.gov.uk/blog-post/in...
Incidents impacting retailers – recommendations from the NCSC
A joint blog post by the NCSC’s National Resilience Director, Jonathon Ellison, and Chief Technology Officer, Ollie Whitehouse.
www.ncsc.gov.uk
May 4, 2025 at 6:20 PM
Reposted by Corsin
amazing work from Palo Alto and Wired today on TraderTraitor (aka SlowPisces, UNK_MachoMan, UNC something or other, Jade Sleet)

unit42.paloaltonetworks.com/slow-pisces-...

www.wired.com/story/trader...

and a minor line item, only one mention of the L word is a major success
Slow Pisces Targets Developers With Coding Challenges and Introduces New Customized Python Malware
North Korean state-sponsored group Slow Pisces (Jade Sleet) targeted crypto developers with a social engineering campaign that included malicious coding challenges. North Korean state-sponsored group ...
unit42.paloaltonetworks.com
April 14, 2025 at 4:20 PM
Reposted by Corsin
Reposted by Corsin
Aaaaand we have just released the #PIVOTcon25 #agenda Again You will find there crème de la crème of #CTI #ThreatIntel #ThreatReserch Top researchers tracking both APTs and cybercriminals using very clever and effective PIVOTs 😎💪 Link and thank you ⬇️1/2
📣 Oops!... They did it again!!!
61 Talks submitted and so many too good that, once again, we had to increase a bit the number of accepted talks.🔥

#PIVOTcon25 Agenda is finally here, and the caliber is insane!!! Check it out➡️ pivotcon.org/agenda-2025/
#CTI #ThreatIntel
Talks and presenters in🧵⬇️ 1/18
March 7, 2025 at 3:12 PM
Reposted by Corsin
February 2025 was a high-volume month on data leak and ransomware sites. Our system picked up and enriched 705 events, the highest ever.

CL0p has been active posting victims from their December 2024 attack against vulnerable Cleo servers.

Get the full picture with our subscription at eCrime.ch
March 3, 2025 at 8:50 AM
Great job by police organisations around the globe to seize domains and arrest #ransomware operators of Phobos/#8BASE.

www.khaosodenglish.com/news/2025/02...
February 10, 2025 at 2:07 PM
Reposted by Corsin
A teen DOGE staffer recently given access to government systems worked at a startup known for hiring convicted hackers. Someone using a Telegram handle associated with him also solicited a cyberattack-for-hire service in 2022. All raising questions about his vetting. www.wired.com/story/edward...
DOGE Teen Owns ‘Tesla.Sexy LLC’ and Worked at Startup That Has Hired Convicted Hackers
Experts question whether Edward Coristine, a DOGE staffer who has gone by “Big Balls” online, would pass the background check typically required for access to sensitive US government systems.
www.wired.com
February 6, 2025 at 7:43 AM
Reposted by Corsin
Subscribing to WIRED should be mandatory for anyone who is concerned about what's happening and wants in-depth coverage from journalists who have been reporting on privacy, security, feds, and national security for years. Plus my besties @dell.bsky.social and @couts.bsky.social work there.
Exclusive: Federal workers have filed an emergency motion requesting a restraining order to disconnect the DOGE server that's being used to conduct Trump's "deferred resignation program." The workers had previously accused DOGE of illegally bypassing a mandated privacy audit.

By me at @wired.com:
Federal Workers Sue to Disconnect DOGE Server
Two federal workers, citing reports that Elon Musk’s associates are operating an illegally connected email server at OPM, seek a restraining order.
www.wired.com
February 4, 2025 at 6:22 PM
Reposted by Corsin
Interesting report from Twitter:
"Another certificate was acquired by this company and used to sign a malicious kernel driver. The driver injects an IIS module into w3wp.exe, embedding JS into webpages that redirects to a Chinese adult site, tricking users into downloading a spyware-like app."
January 18, 2025 at 12:23 PM
@benkoe.com Apple Intelligence seit heute in der Schweiz verfügbar?
January 14, 2025 at 9:21 AM
Reposted by Corsin
This year, we worked swiftly to save legacy media sites Vice.com and MTVNews before decades worth of valuable journalism could be erased. These sites are now searchable on the Wayback Machine!

Help us in saving these resources:: https://archive.org/donate/?origin=blsky-eoy2024
December 28, 2024 at 4:00 PM
Reposted by Corsin
The Annual Report for the National Cyber Security Centre is out

www.ncsc.gov.uk/collection/n...

Threat assessment:

www.ncsc.gov.uk/collection/n...
NCSC Annual Review 2024
Looking back at the National Cyber Security Centre's eighth year and its key developments and highlights, between 1 September 2023 and 31 August 2024.
www.ncsc.gov.uk
December 3, 2024 at 7:27 AM