the grugq's newsletter

Subscribe
Archives
June 1, 2025

June 1, 2025

June 1, 2025

Hidden Bear: The GRU hackers of Russia’s most notorious kill squad

Russian GRU Unit 29155 is best known for its long list of murder and sabotage ops, which include the Salisbury poisonings in England, arms depot explosions in Czechia, and an attempted coup d’etat in Montenegro. But its activities in cyberspace remained in the shadows — until now. After reviewing a trove of hidden data, The Insider can report that the Kremlin’s most notorious black ops squad also fielded a team of hackers — one that attempted to destabilize Ukraine in the months before Russia’s ...

NEW: We've anatomized the entire Unit 29155 hacking team, including its founder, who was previously indicted in the U.S. for cyber crimes unrelated to espionage. Here be sex, lies, and server logs, all of which we obtained. Plus a Bulgarian journalist recruited to peddle… pic.twitter.com/CwGRiqIvv1

— Michael Weiss (@michaeldweiss) May 31, 2025


https://www.openwall.com/lists/oss-security/2025/05/29/3


8,000+ Asus routers popped in 'advanced' mystery botnet plot

According to the report, these commands were used to enable SSH, bind it to TCP/53282, and add an attacker-controlled public key, affording them exclusive SSH access. … “Because it's configured through official Asus settings, the backdoor persists in NVRAM even after patching. No malware dropped, logging disabled = nearly invisible," Rudis added.

I like the use of existing tools for hacking, rather than using custom tools that can be easily detected.

https://www.theregister.com/2025/05/29/8000_asus_routers_popped_in/


Mysterious leaker outs Conti ransomware kingpins

https://www.theregister.com/2025/05/31/gangexposed_coni_ransomware_leaks/


U.S. Sanctions Cloud Provider ‘Funnull’ as Top Source of ‘Pig Butchering’ Scams – Krebs on Security

The U.S. government today imposed economic sanctions on Funnull Technology Inc., a Philippines-based company that provides computer infrastructure for hundreds of thousands of websites involved in virtual currency investment scams, commonly known as “pig butchering." In January 2025, KrebsOnSecurity detailed…


#SpyNews - week 22 (May 25-31):
A summary of 72 espionage-related stories from week 22 coming from 🇨🇳🇺🇸🇬🇧🇮🇳🇵🇰🇹🇷🇮🇱🇵🇸🇮🇷🇺🇦🇷🇺🇳🇿🇸🇪🇵🇱🇧🇾🇰🇭🇫🇷🇲🇲🇰🇵🇰🇷🇩🇪🇧🇪🇭🇺🇫🇮🇪🇸🇯🇵🇨🇿🇬🇷🇦🇲🇬🇪🇸🇾🇦🇷🇷🇸🇨🇦🇱🇧🇹🇼🇦🇹🇰🇿🇲🇪 https://t.co/l5ElUAPMxN#OSINT #SIGINT #HUMINT #espionage #spy

— Spy Collection (@SpyCollection1) June 1, 2025


Fascinating interview with a private drone designer for the RU military. His knowledge of UKR & Western drones is limited and should be taken with some skepticism but he still presents a quite candid picture into the current state of unmanned warfare:🧵https://t.co/VC0QBKg9Hu

— Dmitri Alperovitch (@DAlperovitch) May 31, 2025

Thread by @DAlperovitch on Thread Reader App – Thread Reader App

@DAlperovitch: Fascinating interview with a private drone designer for the RU military. His knowledge of UKR & Western drones is limited and should be taken with some skepticism but he still presents a quite candid ...…


Don't miss what's next. Subscribe to the grugq's newsletter:
X