Security Research for the Community

Recently Added

Research
MOIS Linked MOIST GRASSHOPPER / Homeland Justice / KarmaBelow80 / Handala Hackers / Campaigns and Evolution

Explore the evolution of MOIS-linked actors Homeland Justice, Karma, and Handala. Analysis of destructive malware, surveillance integration, and the 2026 Stryker incident.

2026-04-15
2026-04-06
2026-04-01
SecuritySnacks
Cybersecurity Reading List - Week of 2026-05-04

Systems thinking, biolistics, and the danger of mop-up science in infosec — plus this month's reading on ransomware, RPKI exploits, cPanel, and LLM pollution.

2026-05-07
SecuritySnacks
DPRK Contagious Interview: Developer Workflow Compromise

Analyze the DPRK "Contagious Interview" campaign targeting developers. Get technical deep-dives into VS Code task abuse, Node.js malware obfuscation, and a full Sigma/EDR detection pack to defend your CI/CD pipeline and identity perimeter.

2026-04-30
Newsletters
Sixteen going on Seventeen Newsletters
DPRK's modular malware portfolio, Iran's MOIS-linked Handala/Homeland Justice/Karma persona ecosystem, and a fake Authenticator Chrome extension dissected.
Learn More
2026-05-07
Newsletters
Fifteen (Newsletters) On A Skateboard
DTI's March newsletter covers Doppelgänger disinformation infrastructure analysis, Cloudflare-abusing phishing campaigns, a TLS private key exposure in Qihoo 360's AI platform, and a malicious ChatGPT ad blocker Chrome extension stealing user conversations.
Learn More
2026-04-10
Podcast episodes
How Russian Disinformation Campaigns Exploit Domain Registrars and AI
The Breaking Badness Cybersecurity Podcast discusses research from the DomainTools Investigations team on Russian Disinformation
Learn More
2025-04-16
Podcast episodes
Book Club with Dmitri Alperovitch
Discussing Dmitri's new book, World on the Brink: How America Can Beat China in the Race for the 21st Century.
Learn More
2024-05-01

Research

View All
Research
Handala: MOIS Linked Cyber Influence Ecosystem Threat Intelligence Assessment

Discover how Handala, Homeland Justice, and Karma function as a unified MOIS-linked cyber influence ecosystem. This threat intelligence assessment reveals how Iran uses "hack-and-leak" operations to weaponize perception over technical complexity.

Learn More

SecuritySnacks

View All
SecuritySnacks
Cybersecurity Reading List - Week of 2026-05-04

Systems thinking, biolistics, and the danger of mop-up science in infosec — plus this month's reading on ransomware, RPKI exploits, cPanel, and LLM pollution.

Learn More
SecuritySnacks
DPRK Contagious Interview: Developer Workflow Compromise

Analyze the DPRK "Contagious Interview" campaign targeting developers. Get technical deep-dives into VS Code task abuse, Node.js malware obfuscation, and a full Sigma/EDR detection pack to defend your CI/CD pipeline and identity perimeter.

Learn More
SecuritySnacks
The AI Frame Campaign Continues

Analysis of the persistent AIFrame campaign: A fake Google Authenticator Chrome extension and 6+ related apps use "deploy clean, update dirty" tactics to steal 2FA credentials and inject malicious iframes. Learn how this operation bypasses Google’s security reviews.

Learn More

Newsletters

View All
Newsletters
Sixteen going on Seventeen Newsletters
DPRK's modular malware portfolio, Iran's MOIS-linked Handala/Homeland Justice/Karma persona ecosystem, and a fake Authenticator Chrome extension dissected.
Learn More
Newsletters
Fifteen (Newsletters) On A Skateboard
DTI's March newsletter covers Doppelgänger disinformation infrastructure analysis, Cloudflare-abusing phishing campaigns, a TLS private key exposure in Qihoo 360's AI platform, and a malicious ChatGPT ad blocker Chrome extension stealing user conversations.
Learn More
Newsletters
Fourteen Newsletters and Fifteen Winters
Learn how Lotus Blossom (G0030) weaponized Notepad++ updates. Plus, a deep dive into 250+ crypto scam domains and upcoming BSides San Francisco sessions.
Learn More

Podcast Episodes

View All
Podcast episodes
How Russian Disinformation Campaigns Exploit Domain Registrars and AI
The Breaking Badness Cybersecurity Podcast discusses research from the DomainTools Investigations team on Russian Disinformation
Learn More
Podcast episodes
Book Club with Dmitri Alperovitch
Discussing Dmitri's new book, World on the Brink: How America Can Beat China in the Race for the 21st Century.
Learn More
Podcast episodes
Call to ARMs
Palo Alto’s latest findings on Bifrost along with the rise of laid off tech workers turning to cybercrime.
Learn More