#HarfangLab
📣 Thank you HarfangLab for being #PIVOTcon25 Bronze Sponsor 🎉

Read more about them: harfanglab.io

HarfangLab is a cybersecurity company that has developed a suite of solutions to prevent, detect, and block cyberattacks.

Our sponsors: pivotcon.org/sponsors

#CTI #ThreatIntel #ThreatResearch
April 2, 2025 at 1:25 PM
Merci à nos 4 sponsors "silver" : Brest Métropole, BZHunt, Crédit Mutuel Arkéa et HarfangLab pour leur confiance et pour nous permettre d'organiser cette 10e édition de #UYBHYS !

#UYBHYS25
October 17, 2025 at 8:12 PM
Merci à #Harfanglab pour son engagement à nos côtés lors de #UYBHYS25 !

Votre soutien est essentiel pour faire vivre un événement qui place la cybersécurité, la transmission et la passion au cœur de son ADN. 🔐❤️

#UYBHYS
November 10, 2025 at 5:28 PM
September 21, 2026 at 1:10 PM
Vous l'attendiez tous... la billetterie 2026 est ouverte pour les "early birds".
pretix.eu/cantine/UYBH...
Le programme et la billetterie des ateliers arrivent très bientôt.
#UYBHYS #UYBHYS26
#BZHunt @cmarkea.bsky.social #HarfangLab
September 14, 2026 at 9:27 AM
#UYBHYS25 Bienvenue à HarfangLab, sponsor silver de Unlock your Brain, Harden Your System.
Merci pour la confiance renouvelée, et pour nous permettre de fêter les 10 ans de l'événement !
June 5, 2025 at 3:00 PM
September 21, 2026 at 1:10 PM
We updated the 𝐄𝐃𝐑 𝐭𝐞𝐥𝐞𝐦𝐞𝐭𝐫𝐲 𝐩𝐫𝐨𝐣𝐞𝐜𝐭 over the weekend, specifically the Windows table!👇

➤ Some great telemetry additions from 𝐇𝐚𝐫𝐟𝐚𝐧𝐠𝐋𝐚𝐛 and 𝐄𝐒𝐄𝐓!
➤ Added 𝐏𝐫𝐨𝐜𝐞𝐬𝐬 𝐂𝐚𝐥𝐥 𝐒𝐭𝐚𝐜𝐤𝐬 subcategory! (𝘛𝘩𝘢𝘯𝘬𝘴 𝘵𝘰 @𝘫𝘥𝘶2600)
March 10, 2025 at 4:49 PM
Recently, our team at HarfangLab had a look at samples of archives containing weaponized XLS spreadsheets which drop C# and C++ downloaders, and likely intended to be delivered to targets in Ukraine and in Poland.
August 20, 2025 at 12:38 PM
Un « super antivirus » made in France reconnu à sa juste valeur a destination des entreprises #cybersécurité #antivirus
Un premier EDR, sorte de super antivirus, vient d'être "qualifié" par l'autorité cyber française : les explications
L'entreprise française HarfangLab a accueilli une excellente nouvelle : son EDR (Endpoint Detection and Response) devient le premier à obtenir la qualification de l'ANSSI. Il s'agit d'un vrai gage de ...
www.clubic.com
January 19, 2025 at 9:12 AM
Harfanglab researchers describe exploitation of Ivanti CSA vulnerabilities, which started in Q4 2024 & led to webshell deployments, and detail malicious activities conducted by a threat actor within an organization following Ivanti CSA device compromise. harfanglab.io/insidethelab...
February 11, 2025 at 11:45 AM
HarfangLab reports RedKitten, a new campaign seen in early January 2026 targeting Iranian interests, including NGOs & people documenting abuses. It uses GitHub and Google Drive for config/modules and Telegram for C2, with signs of LLM-assisted development. harfanglab.io/insidethelab...
January 30, 2026 at 9:45 AM
Cyber, le fossé entre la prise de conscience des dirigeants et la prise de responsabilité au comité de direction - IT SOCIAL itsocial.fr/cybersecurit...
Cyber, le fossé entre la prise de conscience des dirigeants et la prise de responsabilité au comité de direction - IT SOCIAL
Une étude européenne commandée par l’éditeur HarfangLab mesure un écart persistant entre la conscience du risque cyber et son appropriation par les dirigeants. En France, 46 % des entreprises constate...
itsocial.fr
June 23, 2026 at 5:52 AM
Enquête et analyse de la société de sécurité informatique française Harfanglab concernant l'opération de désinformation et polarisation des populations occidentales "Doppelgänger".

Un peut technique mais très intéressant.

harfanglab.io/en/insidethe...
Mid-year Doppelgänger information operations in Europe and the US
Identifier: TRR240701. Summary This report delves into Doppelgänger information operations conducted by Russian actors, focusing on their activities from early June to late-July 2024. Our investigatio...
harfanglab.io
August 6, 2024 at 1:20 PM
Iran-Linked Hackers Target Human Rights Groups in Redkitten Malware Campaign #Campaign #Iranhackers #Iranianstate
Iran-Linked Hackers Target Human Rights Groups in Redkitten Malware Campaign
A Farsi-speaking threat actor believed to be aligned with Iranian state interests is suspected of carrying out a new cyber campaign targeting non-governmental organizations and individuals documenting recent human rights abuses in Iran, according to a report by HarfangLab.  The activity, tracked in January 2026 and codenamed RedKitten, appears to coincide with nationwide unrest that erupted in Iran in late 2025 over soaring inflation, rising food prices, and currency depreciation. The protests were followed by a severe security crackdown, mass casualties, and an internet blackout.  “The malware relies on GitHub and Google Drive for configuration and modular payload retrieval, and uses Telegram for command-and-control,” HarfangLab said.  Researchers said the campaign is notable for its apparent use of large language models to help develop and coordinate its tooling. The attack chain begins with a 7-Zip archive bearing a Farsi filename, which contains malicious Microsoft Excel files embedded with macros.  The XLSM spreadsheets purport to list details of protesters who died in Tehran between Dec. 22, 2025, and Jan. 20, 2026. Instead, the files deploy a malicious VBA macro that acts as a dropper for a C# implant known as AppVStreamingUX_Multi_User.dll using a technique called AppDomainManager injection. HarfangLab said the VBA code itself shows signs of being generated by an LLM, citing its structure, variable naming patterns, and comments such as “PART 5: Report the result and schedule if successful.”  Investigators believe the campaign exploits the emotional distress of people searching for information about missing or deceased protesters. Analysis of the spreadsheet data found inconsistencies such as mismatched ages and birthdates, suggesting the content was fabricated. The implanted backdoor, dubbed SloppyMIO, uses GitHub as a dead drop resolver to obtain Google Drive links hosting images that conceal configuration data using steganography. This data includes Telegram bot tokens, chat IDs, and links to additional modules.  The malware supports multiple modules that allow attackers to run commands, collect and exfiltrate files, establish persistence through scheduled tasks, and launch processes on infected systems. “The malware can fetch and cache multiple modules from remote storage, run arbitrary commands, collect and exfiltrate files and deploy further malware with persistence via scheduled tasks,” HarfangLab said. “SloppyMIO beacons status messages, polls for commands and sends exfiltrated files over to a specified operator leveraging the Telegram Bot API for command-and-control.”  Attribution to Iranian-linked actors is based on the use of Farsi-language artifacts, protest-themed lures, and tactical overlaps with earlier operations, including campaigns associated with Tortoiseshell, which previously used malicious Excel documents and AppDomainManager injection techniques. The use of GitHub as part of the command infrastructure mirrors earlier Iranian-linked operations. In 2022, Secureworks, now part of Sophos, documented a campaign by a sub-group of Nemesis Kitten that also leveraged GitHub to distribute malware.  HarfangLab noted that reliance on widely used platforms such as GitHub, Google Drive, and Telegram complicates traditional infrastructure-based attribution but can also expose operational metadata that poses risks to the attackers themselves. The findings follow recent disclosures by U.K.-based Iranian activist and cyber investigator Nariman Gharib, who detailed a separate phishing campaign using a fake WhatsApp Web login page to hijack victims’ accounts.  “The page polls the attacker’s server every second,” Gharib said. “This lets the attacker serve a live QR code from their own WhatsApp Web session directly to the victim.” That phishing infrastructure was also designed to request access to a victim’s camera, microphone, and location, effectively turning the page into a surveillance tool. The identity and motive of the operators behind that campaign remain unclear.  Separately, TechCrunch reporter Zack Whittaker reported that related activity also targeted Gmail credentials using fake login pages, impacting around 50 victims across the Kurdish community, academia, government, and business sectors. The disclosures come amid growing scrutiny of Iranian-linked cyber groups following a major data leak affecting Charming Kitten, which exposed details about its operations and a surveillance platform known as Kashef. Gharib has also highlighted leaked records tied to Ravin Academy, a cybersecurity school linked to Iran’s Ministry of Intelligence and Security, which was sanctioned by the United States in 2022.
dlvr.it
February 2, 2026 at 5:48 PM
HarfangLab étend sa détection aux identités en l'adossant à son EDR - IT SOCIAL itsocial.fr/cybersecurit...
HarfangLab étend sa détection aux identités en l'adossant à son EDR - IT SOCIAL
HarfangLab lance offre de détection et de réponse sur les identités, au moment où les comptes d'agents détournés servent de porte d'entrée aux attaques contre l'administration française. L'éditeur eur...
itsocial.fr
September 10, 2026 at 12:35 PM
HarfangLab breidt detectie en respons uit naar identiteitsaanvallen met nieuwe ITDR-oplossing

Nieuwe oplossing detecteert onder meer accountmisbruik, ongebruikelijke inlogpogingen en pogingen om hogere toegangsrechten te verkrijgen

#Persbericht #Cybersecurity #Cyberaanvallen #Beveiligingsoplos
September 8, 2026 at 8:07 AM
Dat gezegd zijnde: HarfangLab EDR is een uitstekend product, en nu spreek ik uit ervaring.
September 1, 2026 at 3:38 PM