#Prodaft
An unidentified individual has leaked the internal chats of the BlackBasta ransomware group

x.com/PRODAFT/stat...
February 20, 2025 at 4:11 PM
Prodaft has published a technical analysis of Anubis, a new Python-based backdoor linked to Savage Ladybug (FIN7) operations

catalyst.prodaft.com/public/repor...
March 16, 2025 at 10:39 AM
An Iranian cyber-espionage group is using fake LinkedIn jobs to target employees of EU telcos and defense organizations.

According to security firm Prodaft, one of the group's most recent campaigns has infected 34 devices across 11 organizations.

catalyst.prodaft.com/public/repor...
September 21, 2025 at 1:31 PM
Modus Operandi of Subtle Snail Espionage Group
PRODAFT CATALYST
catalyst.prodaft.com
September 21, 2026 at 2:28 PM
🕵️‍♂️ Cyber firm Prodaft is buying #hacker forum accounts to spy on cybercriminals.

The “Sell Your Source” initiative aims to infiltrate & gather intel
Pro-level threat intel.

#ransomNews #cybersecurity #threatintel #darkweb #infosec #OSINT
April 17, 2025 at 11:37 AM
Swiss cybersecurity firm Prodaft has launched a new initiative called 'Sell your Source' where the company purchases verified and aged accounts on hacking forums to to spy on cybercriminals. #CyberDefence www.bleepingcomputer.com/news/securit...
Cybersecurity firm buying hacker forum accounts to spy on cybercriminals
Swiss cybersecurity firm Prodaft has launched a new initiative called 'Sell your Source' where the company purchases verified and aged accounts on hacking forums to to spy on cybercriminals.
www.bleepingcomputer.com
April 14, 2025 at 8:55 PM
Swiss cybersecurity firm Prodaft buys verified hacking forum accounts (XSS, Exploit.in, RAMP4U, Verified, Breachforums) pre-dating Dec 2022, with no prior activity, to gather intel on cybercriminals. Cryptocurrency payment.#ProdaftCyberIntel
April 14, 2025 at 8:05 PM
Prodaft has published a profile on LARVA-208 (EncryptHub), a known affiliate of the RansomHub and Blacksuit ransomware operations.

The group is known to run phishing pages targeting enterprise VPN login pages.

catalyst.prodaft.com/public/repor...
February 25, 2025 at 2:29 PM
🇷🇺 hackers spied on NATO structures for years

A 🇷🇺 hacker group spied on NATO structures and government institutions for several years using malicious software and a sophisticated cyber infrastructure, according to a report by the cyber intelligence firm PRODAFT

odessa-journal.com/russian-hack...
Russian Hacker Group Spied on NATO Using Sophisticated Malware - Oj
PRODAFT reveals Russian-speaking group Nebulous Mantis spied on NATO using advanced malware, phishing, and bulletproof hosting to evade detection.
odessa-journal.com
May 6, 2025 at 4:26 PM
Let me teach you something about Suricata that took me most of an afternoon to re-figure out and unfuck a rule that I was trying to make for a CVE that was four years old.

This blog post got on my mastodon feed: www.forescout.com/blog/draytek...

and there was a fucking HUGE list of draytek CVEs.
DrayTek Routers Exploited in Massive Ransomware Campaign - Forescout
Forescout analyzes ransomware campaigns with DrayTek routers as entry points for attacks. Threat intelligence was also provided by PRODAFT.
www.forescout.com
December 17, 2024 at 4:07 AM
PRODAFT detects high-severity flaws in mySCADA myPRO Manager, warns of industrial network breaches
PRODAFT detects high-severity flaws in mySCADA myPRO Manager, warns of industrial network breaches
PRODAFT detects high-severity flaws in mySCADA myPRO Manager, and warns organizations of industrial network breaches.
buff.ly
March 22, 2025 at 10:42 AM
Swiss cybersecurity firm Prodaft has launched a new initiative called 'Sell your Source' where the company purchases verified and aged accounts on cybercrime forums to conduct threat intelligence operations.
Cybersecurity firm buying hacker forum accounts to spy on cybercriminals
Swiss cybersecurity firm Prodaft has launched a new initiative called 'Sell your Source' where the company purchases verified and aged accounts on cybercrime forums to conduct threat intelligence operations.
www.bleepingcomputer.com
April 14, 2025 at 7:36 PM
It's my last day before more surgery, so I'm getting some work done. By me @forbes.com: Chinese smartphone farm attack. The farm, not the smartphones, although...

#kudos Prodaft

#infosecurity

www.forbes.com/sites/daveyw...
Warning As Smartphone Farm Used In 100,000 Android, iPhone Attacks
A massive smartphone hacking campaign is underway using device farms to attack hundreds of thousands of iPhone and Android users.
www.forbes.com
April 1, 2025 at 8:12 AM
Russian-linked Nebulous Mantis targets NATO, critical infrastructure with RomCom RAT buff.ly/epXgq15
Russian-linked Nebulous Mantis targets NATO, critical infrastructure with RomCom RAT
PRODAFT researchers detail Russian-linked Nebulous Mantis that targets NATO, critical infrastructure with RomCom RAT.
buff.ly
May 6, 2025 at 2:42 PM
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage va…
#hackernews #news
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. Swiss cybersecurity company PRODAFT is tracking the centrally administered RaaS operation under the name Funky Mantis. "The portal combined build generation, finance,
thehackernews.com
July 26, 2026 at 1:12 PM
Threat Intel Firm Offers Crypto in Exchange for Dark Web Accounts
www.darkreading.com/threat-intel...
Threat Intel Firm Offers Crypto for Dark Web Accounts
Prodaft is currently buying accounts from five Dark Web forums and offers to pay extra for administrator or moderator accounts. The idea is to infiltrate forums to boost its threat intelligence.
www.darkreading.com
April 16, 2025 at 11:17 AM
By me @forbes.com: Got an old hacker forum account and want to make some cash? Prodaft wants to hear from you and has crypto waiting.

#infosec

Read the full article here:

www.forbes.com/sites/daveyw...
Sell Us Your Hacker Account, Admins Paid Extra — SYS Initiative Says
Hacker forum accounts sought to spy on crime forums in return for crypto.
www.forbes.com
April 18, 2025 at 1:30 PM
I've seen one report that it's the same group as Prodaft's "Phantom Mantis," but that's a misidentification of another group that has been an affiliate of Qilin, Embargo, LockBit, Medusa, and BlackRock, per Prodaft, and operates "The Gentlemen" ransomware.
January 3, 2026 at 11:11 PM
-BlackBasta developed custom firewall/VPN brute-forcing tool
-New Anubis and Emmenthal versions
-Ruby-SAML auth bypass
-Picklescan vulnerabilities blind scanners to malware
-Edimax zero-day exploited for months
-Uber CSO conviction upheld
-Prodaft open-sources Cradle threat-sharing platform
March 17, 2025 at 8:04 AM
I went looking for a managed-Postgres provider. Instead, I found a vulnerability in a 4-star PostgreSQL extension available everywhere! and turned it into code execution at NeonDB, Supabase, Xata and many other PostgreSQL service companies
Part 1/6 | Systemic Risks in the Managed PostgreSQL Industry: Extension Risks Are Real! Exploiting PostGis Memory Corruption Bug at NeonDB, SupaBase and Many More - Mehmet Ince @mdisec - Vulnerability Researcher | Building security products | Security Advisor | Amateur Muay Thai fighter
Back in April, I was talking with our system and software engineering teams at PRODAFT about the possibilities of using a managed database service. Due to the nature of our business, we simply cannot start using managed services right away. I told my team, “Alright, I will have a look at a few companies and […]
mehmetince.net
August 14, 2026 at 7:58 PM
🌀 Glitch in the Matrix

Steam Early Access game ‘Chemia’ found bundled with multiple infostealers
Researchers found Fickle, Vidar stealers and HijackLoader inside a Steam game, used to propagate malware via trusted platform.
🔗 Read more: Tom’s Hardware / Prodaft
TechRadar+3Tom's Hardware+3
July 28, 2025 at 12:32 PM
Nebulous Mantis’s sophisticated cyberattacks on NATO is a stark reminder that we are under siege. AZ-07 needs federal leadership to bolster cybersecurity. This isn’t just about tech, it’s about economic security and ethical governance.
#CyberSecurity #Arizona7 #Tucson #UofA #NATO
Prodaft CATALYST
catalyst.prodaft.com
April 30, 2025 at 7:03 PM