Blog

Security insights andplatform updates

Product updates, security research, and launch announcements from the team.

Turning IDN edge cases into typosquats
ResearchHomograph attacks

Turning IDN edge cases into typosquats

In 2017, Chromium began showing аррӏе.com, a Cyrillic lookalike of apple.com, as Punycode. Replacing its final е with ө produces аррӏө.com, which Chromium still displays in Unicode with no warning. This post explains why, covering Chromium's checks, the .com registry, and two webmail clients.

By Ian Muscat and Leanne Briffa
Inside Corp MDM, the Android spyware targeting logistics companies
Threat intelligenceMalware

Inside Corp MDM, the Android spyware targeting logistics companies

Fake Google Play pages branded as CEVA and TKW Logistics delivered a hidden Android implant that steals new SMS messages, redirects calls, persists across reboots, and accepts remote commands over cleartext HTTP.

By Ben Folland
Have I Been Squatted achieves SOC 2 Type II compliance
company

Have I Been Squatted achieves SOC 2 Type II compliance

Have I Been Squatted is now SOC 2 Type II compliant, with security controls independently assessed against recognized standards for protecting customer data.

By Have I Been Squatted
From GAPIUpdate to Odyssey Stealer: inside a macOS wallet-theft chain
Threat intelligenceMalware

From GAPIUpdate to Odyssey Stealer: inside a macOS wallet-theft chain

The macOS branch of a fake Web3 interview delivered GAPIUpdate.dmg, an Odyssey Stealer build that stole credentials, sessions, and wallets before installing remote tasks and replacing wallet applications.

By Cameron Coller and Ben Folland
Building certgrep.sh: a free certificate transparency search engine
EngineeringCertificate transparency

Building certgrep.sh: a free certificate transparency search engine

The engineering story behind certgrep.sh. An occurrence-only index over certificate transparency, a finite state transducer engine that ran in production for three months, the regex-latency wall that ended it, and the trigram pivot that made the whole thing cheap enough to give away.

By Juxhin D. Brigjaj
From fake interview to signed ClickOnce: inside a three-payload Windows chain
Threat intelligenceMalware

From fake interview to signed ClickOnce: inside a three-payload Windows chain

A fake Web3 interview delivered a signed ClickOnce stager on Windows that unpacked two credential stealers and a persistent Go RAT.

By Cameron Coller and Ben Folland
Announcing Site Canaries
productsite-canaries

Announcing Site Canaries

Site Canaries detect cloned and phishing copies of a production page with a small embedded script, then report flagged hostnames alongside domain findings.

By Have I Been Squatted
From typosquatting to macOS backdoor via ClickFix and blockchain C2
Threat intelligenceMalware

From typosquatting to macOS backdoor via ClickFix and blockchain C2

A macOS ClickFix campaign used typosquatting, clipboard-driven Terminal execution, persistent AppleScript, and a Polygon smart contract as a mutable C2 pointer for backdoor, stealer, RAT, and Ledger replacement modules.

By Ben Folland
When one RMM tool won't get the job done: inside a phishing operation's infrastructure
Threat intelligenceThreat actor

When one RMM tool won't get the job done: inside a phishing operation's infrastructure

A packed carrier-onboarding dropper pulls NetSupport Manager from commodity VPS infrastructure. The same operator box also runs SimpleHelp and ScreenConnect, rotates fresh builds daily, and pivots lures from US carriers to European freight within 24 hours.

By Charlie Kelly
Announcing Email Intelligence for Microsoft 365
microsoft 365email

Announcing Email Intelligence for Microsoft 365

Email Intelligence ingests domain threat signals from Microsoft 365 mail into Have I Been Squatted lookups. Watchdog adds sender domain blocks in the tenant.

By Have I Been Squatted
When a trusted trucking email delivers remote access
Threat intelligenceThreat actor

When a trusted trucking email delivers remote access

Attackers used what appears to be a compromised Microsoft 365 account at a US freight carrier, sent Bill of Lading phishing to business contacts, and used a PDF link to an S3-hosted EXE that silently installed a pre-configured N-able RMM agent.

By Charlie Kelly
Have I Been Squatted now integrates with Tines
integrationstines

Have I Been Squatted now integrates with Tines

Have I Been Squatted now integrates with Tines, so typosquat permutations, domain analysis data can run directly inside investigation stories.

By Have I Been Squatted