Log inSign up
Expel
4,203 posts
Expel profile banner
@ExpelSecurity

Expel

@ExpelSecurity
The leader in agentic MDR.
expel.com
Joined August 2016
281
Following
12.8K
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • @ExpelSecurity
    Expel
    @ExpelSecurity
    Aug 20
    On August 18, we caught a malware loader we believe to be novel. Entry point: a threat actor phished a client’s user through Microsoft Teams, posing as the IT help desk. We named it SynkLoader. (1/7)
    2
  • @ExpelSecurity
    Expel
    @ExpelSecurity
    Aug 6
    Based on our analysis, GoldenEyeDog has separate teams with dedicated resources and targets, and these separate teams can be distinguished based on code-signing certificate usage and tactics. 1/2
    Image
    1
  • @ExpelSecurity
    Expel
    @ExpelSecurity
    Aug 6
    In this version, CylindricalCanine still downloads the second stage from a text file hosted in the CDN. However, the files don't have normal extensions anymore. Looking in the directory shared by @elasticseclabs, we found two new certificates of interest. 🧵1/5
    Image
    Image
    @elasticseclabs
    Elastic Security Labs
    @elasticseclabs
    Aug 5
    Elastic Security Labs is tracking Golden Gh0st RAT targeting Western companies, expanding beyond its previously documented targeting of financial organizations in the Asia-Pacific region. Same TTPs as @ExpelSecurity CylindricalCanine research post: go.es.io/3TEZ0G6 The
    1
  • @ExpelSecurity
    Expel
    @ExpelSecurity
    Aug 4
    A self-propagating npm supply chain worm compromised keyv, cacheable, flat-cache, file-entry-cache, and 800+ downstream packages—stealing CI/CD, cloud, and API credentials along the way. (1/6)
    1
  • @ExpelSecurity
    Expel
    @ExpelSecurity
    Jul 15
    In April 2026, a Chinese cybercrime group accessed a support rep's device at DigiCert—then used that access to steal code-signing certificates meant for DigiCert customers. We're calling the actors CylindricalCanine. 🧵 1/4
    Image
    1
Advertisement
Advertisement