Threat Intel & Attribution
Analyzing malware, campaigns, and actors, and the open-source signals behind attribution.
-
US Military Smartphones Targeted via Roaming and Ad Tech
2026-07-19
Citizen Lab documents SS7 roaming exploitation and ad tech surveillance against US military personnel. Here's what the attack surface actually demands from security teams.
-
Who Runs The Gentlemen Ransomware Group?
2026-06-15
OSINT tradecraft and threat intelligence takeaways from Krebs's attribution investigation into The Gentlemen ransomware group—now second by victim count.
-
Influence Operation Analytic Signatures: A DFRLab-Anchored Method
2026-06-01
How DFRLab structures influence operation attribution: narrative cloning, cluster topology, temporal anomalies, and confidence framing for working analysts.
-
SS7 and Diameter: Mobile Network Espionage Tradecraft
2026-06-01
Citizen Lab and HPI's exchange on telecom-layer surveillance maps real SS7/Diameter attack patterns. Here's what it means for red teamers, defenders, and OSINT practitioners.