Log inSign up
Alexis Dorais-Joncas (@adorais.bsky.social)
973 posts
@adorais

Alexis Dorais-Joncas (@adorais.bsky.social)

@adorais
Sr Manager, APT Threat Research @Proofpoint
Montréal, Québec
Joined March 2009
843
Following
1,675
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • Pinned
    @adorais
    Alexis Dorais-Joncas (@adorais.bsky.social)
    @adorais
    Dec 1, 2021
    Crunching reports by so many different researchers was a great learning experience. There is a lot of awesome knowledge out there! And to top it off, I got to work alongside the relentless @0xfmz. Mission accomplished!
    @ESETresearch
    ESET Research
    @ESETresearch
    Dec 1, 2021
    #ESETresearch has published a comprehensive whitepaper comparing all known malware frameworks designed to breach air-gapped networks. Read more: welivesecurity.com/2021/12/01/jum… @adorais @0xfmz 1/7
  • @adorais
    Alexis Dorais-Joncas (@adorais.bsky.social)
    @adorais
    May 29, 2025
    Vendors only have partial visibility on any campaign. What appears as highly targeted to one can be widespread to another. It is normal and expected - we all have visibility biases. Working together and combining our findings is the only way to get closer to the full picture 🤜🤛
    @threatinsight
    Threat Insight
    @threatinsight
    May 28, 2025
    Proofpoint also observed the activity reported by Trellix in email threat data targeting financial organizations and people in positions of leadership. Our researchers offer clarifying context below to supplement @TrellixARC’s technical analysis. 🧵
  • @adorais
    Alexis Dorais-Joncas (@adorais.bsky.social)
    @adorais
    Dec 12, 2024
    Developing story - attack against #BGP peers of a European telco. The malicious emails impersonated that same telco and included the ASN of each recipient in the subject line. The emails contained a password-protected RAR attachment with the malicious payload.
    @threatinsight
    Threat Insight
    @threatinsight
    Dec 12, 2024
    Between December 11 and 12, 2024, a spearphishing campaign targeted at least 20 Autonomous System (AS) owners, predominantly Internet Service Providers (ISPs), and purported to come from the Network Operations Center (NOC) of a prominent European ISP. All of the observed
    Image
  • @adorais
    Alexis Dorais-Joncas (@adorais.bsky.social)
    @adorais
    Dec 5, 2024
    Rare opportunity to work with an exceptional team!
    @ESETresearch
    ESET Research
    @ESETresearch
    Dec 4, 2024
    #ESETResearch is hiring a senior malware researcher for our 🇨🇦office. If you’d like to track some of the most impactful APTs/cybercrime campaigns, don’t wait and apply here 👇 jobs.eset.com/int/job-offer/… 1/3
  • @adorais
    Alexis Dorais-Joncas (@adorais.bsky.social)
    @adorais
    Nov 27, 2024
    Not everything is a ZERO DAY...
    @threatinsight
    Threat Insight
    @threatinsight
    Nov 27, 2024
    Proofpoint has tracked this technique since August 2024, and call it “brooxml”. Our researchers do not consider this a zero-day or vulnerability in general. We’ve released Emerging Threats and YARA signatures at the end of this thread.
Advertisement
Advertisement