As you likely noticed, yesterday, Mandiant lost control of this X account which had 2FA enabled. Currently, there are no indications of malicious activity beyond the impacted X account, which is back under our control. We'll share our investigation findings once concluded.
Mandiant (part of Google Cloud)
9,604 posts
We’re determined to make organizations secure against cyber threats and confident in their readiness.
Joined April 2009
- We are excited to announce that we've signed an agreement to join the @googlecloud family — bringing together some of the best minds in security! Read more here: mandiant.com/company/press-…
- Google completed its acquisition of Mandiant today. We’re excited to get started on our shared mission to create a comprehensive and best-in-class cyber security solution for customers and partners. Read more here: mandiant.com/company/press-…
- We have finished our investigation into last week's Mandiant X account takeover and determined it was likely a brute force password attack, limited to this single account.
- One compromised Microsoft Entra ID or Azure account can lead to a full tenant takeover. Our new framework ranks roles by risk and adds strong MFA + secure admin workstations to protect the most critical accounts. Read the whitepaper: bit.ly/47GbPTU
- Google Threat Intelligence Group details the ways threat actors are misusing AI tools, including how they are generating and executing AI-enabled malware. 🔗 Read this latest report on our blog: bit.ly/47EzWCq
- New: North Korea has taken a page out of China's cyber playbook to reorganize and consolidate its threat groups within the government - making them “extremely mobile now that they’ve consolidated.” Here's a first look at their new org structure 👇 mandiant.com/resources/mapp…
- Mandiant Intelligence has been tracking several ways in which Chinese cyber espionage activity has increasingly leveraged initial access and post-compromise strategies intended to minimize opportunities for detection. Learn more in our analysis: mndt.info/3rrmIaC
- Linux is becoming a prime target as it is used as the operating system for basic household items up to critical infrastructure. View our latest white paper for guidance on protecting Linux endpoints against malware and destructive attacks. ➡️ mndt.info/3NmBINx
- Listen to this week’s #ThreatTrends episode feat. Mandiant’s Yihao Lim who joined to discuss the trends he sees in the threat landscape in APJ and how organizations in the region are approaching security. 🎧: mndt.info/3etmda1
00:00 - Today, the Mandiant Threat Intelligence team shared that it assesses with high confidence that #UNC1151 is linked to the Belarusian govt & that Belarus is likely at least partially responsible for the Ghostwriter IO campaign. Read more on our blog: mndt.info/30v7e7X
- North Korea threat actor UNC5342 is using EtherHiding, the first time we have observed a nation-state use this technique. 🚨 The TTP is being used in a social engineering campaign that leads to cryptocurrency heists and espionage. Read the blog post: bit.ly/497lvsO
- Attention malware analysts 💻 Our latest blog post delves into Time Travel Debugging (TTD). We introduce the basics of WinDbg and TTD to help you start incorporating TTD into your analysis. 📄: bit.ly/441J3vS










