Opens profile photo
Follow
Stefan Soesanto
@iiyonite
Senior Cyber Defence Researcher // Former Fellow & // all cyber op flavors, EU cyber diplo toolbox, IW, CEMA, space 🃔
Zurich (Switzerland)Joined October 2013

Stefan Soesanto’s Tweets

FYI: I don't have a position on whether this op is acceptable behavior or not. All I know is that what is happening in Ukrainian and Russian cyberspace will not stay there.
1
1
Show this thread
I mean ... it's one thing to screw with a Russian company. It's quite another for a Ukrainian government sponsored group to target 1.5k Russian users with a fake app and then leak their names and emails.
6
1
5
Show this thread

Topics to follow

Sign up to get Tweets about the Topics you follow in your Home timeline.

Carousel

The IT Army claims to have breached a database of Rossgram beta sign-ups (Russian Instagram clone), then created a fake Rossgram app, send invites to said beta users, then pushed notifications out to those users that Rossgram was hacked and then leaked the data of the beta users
Embedded video
1:36
3.4K views
1
19
35
Show this thread
What has the world come to when you can't even trust murder-for-hire groups to not scam you on the dark web.
Consequences Keanu Reeves GIF
GIF
Quote Tweet
Image
Romanian law enforcement has searched the homes and detained five members of a criminal group who ran murder-for-hire websites on the dark web Romanian authorities intervened at the behest of US agencies to detain the group diicot.ro/mass-media/349
Show this thread
1
1
I still don't understand what is counting. Would be good if they could explain what incidents/vectors are included in the 198 number.
Quote Tweet
According to the @dsszzi analysis, the top 5 branches that suffer from #cyberattacks are central and local governments, the security and defense sector, commercial organizations, the financial sector, and telecom #Ukraine #WARINUKRAINE
Image
1
Show this thread
The IT Army has been defacing gazprom sites with pictures of Bucha. (I rarely see the IT Army using defacements as their tactic of choice as the impact is too short lived and miniscule. They only makes sense as a content mean to rally IT Army support)
Image
1
2
👀
Quote Tweet
Взломали �?еть ро�?�?ий�?ких �?ертификационных агент�?тв и и�?пытательных лабораторий. Разрушили инфра�?труктуру, удалили 46ТБ данных включа�? бекапы, выгрузили в�?е данные из локальной CRM �?и�?темы, задефей�?или �?айты. #UkraineWar #UkraineWillResist #OpRussia #HackersAgainstPutin
Show this thread
Image
2
“We provided remote analytic support to Ukraine & conducted network defense activities aligned to critical networks from outside Ukraine — directly in support of mission partners,�? said in testimony to the Senate Armed Services Committee.
1
12
17
Show this thread
🤣😆
Quote Tweet
Let's talk about #Liberator the #DDoS tool going around. We took a look at the tool and intercepted some traffic going out of the tool, we came to a highly suspicious VPS Server. Read the thread to see how uneducated the devs are #Ukraine #Russia #UkraineRussiaWar #RussianWar
Show this thread
According to the IT Army, Clearview identified 582 abandoned RU corpses through which they contacted relatives and friends. From a Russian view, one could argue that Clearview directly supports UKR information warfare operations.
Image
1
2
1
Show this thread
The IT Army published a YT vid today in their Telegram channel. I won't link the vid cause it shows POWs. In it the IT Army shows the use of Clearview to identify dead RU soldiers, and how they go to the social media to send relatives and friends pics of the dead body & ID
1
Show this thread
The IT Army channel is steadily losing subscribers. First sign of disillusionment, repetitive tasking, boredom?
Image
Image
Image
1
The Stoprussiachannel picked up the news. It describes the Bandera Hackers as a "Ukrainian cyber group." (For context: According to the Ukrainian Ministry of Internal Affairs, the Stoprussiachannel was created by the Ukrainian Cyberpolice on Feb 26.)
Image
Image
Image
Show this thread
Interesting approach. For my taste though too limited in reach and easily debunked. Ops might want to deface multiple site with legit looking information at the same time. Usually it's always better to create the illusion of a group conspiracy.
Quote Tweet
Russia 🇷🇺 : the #Sukhoi website was hit by a #cyberattack on April 2. A false statement was published on the site, in which the CEO of the UAC group, of which Sukhoi is a part, announced his resignation in protest against the war in #Ukraine. #Defacement #OpRussia Via Kommersant
Show this thread
Image
3
For those interested in the Belarusian Cyber Partisans. Maybe I've missed it before, but they seem to acknowledge here for the first time that they there are not only Belarusian members in the group.
Image
Image
1
2
Show this thread