@bumblebreaches
Security engineer + analyst who tracks network, commodity and botnet threats.
Full Publications
TodayZoo PhishKit Analysis
TodayZoo PhishKit Analysis
A phishing kit built using pieces of code copied from other kits, some available for sale through publicly accessible scam sellers or are reused and repackaged by other kit resellers, provides rich insight into the state of the economy that drives phishing and email threats today.
BulletProofLink PHaaS
BulletProofLink PHaaS
With over 100 available phishing templates that mimic known brands and services, the BulletProofLink operation is responsible for many of the phishing campaigns that impact enterprises today. We are sharing these findings so the broader community can build on them and use them to enhance email filtering rules as well as threat detection technologies like sandboxes to better catch these threats.
LemonDuck Evolution Part II
LemonDuck Evolution Part II
LemonDuck is an actively updated and robust malware primarily known for its botnet and cryptocurrency mining objectives. Today, beyond using resources for its traditional bot and mining activities, LemonDuck steals credentials, removes security controls, spreads via emails, moves laterally, and ultimately drops more tools for human-operated activity.
LemonDuck Evolution Part I
LemonDuck Evolution Part I
Phorpiex 2021 Analysis
Phorpiex 2021 Analysis
Tracking Email Infrastructure
Tracking Email Infrastructure
Sweeping research into massive attacker infrastructures, as well as our real-time monitoring of malware campaigns and attacker activity, directly inform Microsoft security solutions, allowing us to build or improve protections that block malware campaigns and other email threats, both current and future, as well as provide enterprises with the tools for investigating and responding to email campaigns in real-time.
Chrome Extension Network
Chrome Extension Network
Explore the Duo Blog for expert tips, security insights, and resources to stay updated on the latest in security and access management trends.
Tweet Threads
"Staff Request" CredPhish
"Staff Request" CredPhish
SolarMarker Abusing SEO
SolarMarker Abusing SEO
SNIP3 Targets Aviation
SNIP3 Targets Aviation
PhishKit with DoubleDot Lure
PhishKit with DoubleDot Lure
GraceWire Uses Captcha
GraceWire Uses Captcha
Presentations
Microsoft: Tracking Email Infrastructure
Microsoft: Tracking Email Infrastructure
Microsoft: SolarMarker
Microsoft: SolarMarker
B Sides 2020: Cheap Shot
B Sides 2020: Cheap Shot
Collection of presentations and other public works not directly related to any given project. - Bumblebreaches/PublicWorks
TAG NW 2020: Malvertising
TAG NW 2020: Malvertising
Collection of presentations and other public works not directly related to any given project. - Bumblebreaches/PublicWorks
B Sides 2019: MineMeld
B Sides 2019: MineMeld
Podcasts
Security Unlocked: Untangling Botnets
Security Unlocked: Untangling Botnets
Security Unlocked: Tracking Email Infrastructure
Security Unlocked: Tracking Email Infrastructure
If you use email, there is a good chance you’re familiar with email scams. Who hasn’t gotten a shady chain letter or suspicious offer in their inbox? Cybercriminals have been using email to spread malware for decades and today’s methods are more sophisticated than ever. In order to stop these attacks from ever hitting our inboxes in the first place, threat analysts have to always be one step ahead of these cybercriminals, deploying advanced and ever-evolving tactics to stop them.
Paywalled Publications
Tracking SNIP3 Loader
Tracking SNIP3 Loader
Learn about emerging threats and attack techniques and how to stop them. Assess their impact to your organization and evaluate your organizational resilience.
Tracking LoadGame
Tracking LoadGame
Learn about emerging threats and attack techniques and how to stop them. Assess their impact to your organization and evaluate your organizational resilience.
Tracking SolarMarker
Tracking SolarMarker
Learn about emerging threats and attack techniques and how to stop them. Assess their impact to your organization and evaluate your organizational resilience.
Tracking Qakbot 2021
Tracking Qakbot 2021
Learn about emerging threats and attack techniques and how to stop them. Assess their impact to your organization and evaluate your organizational resilience.
Tracking LemonDuck 2021
Tracking LemonDuck 2021
Learn about emerging threats and attack techniques and how to stop them. Assess their impact to your organization and evaluate your organizational resilience.
Tracking Phorpiex 2020-2021
Tracking Phorpiex 2020-2021
Learn about emerging threats and attack techniques and how to stop them. Assess their impact to your organization and evaluate your organizational resilience.
Tracking BazaLoader 2020
Tracking BazaLoader 2020
Tracking Egregor 2020
Tracking Egregor 2020
Tracking StrangeU in 2020
Tracking StrangeU in 2020
@bumblebreaches LinkedIn
@bumblebreaches LinkedIn
@bumblebreaches X
@bumblebreaches X
More from Linktree
Products
Link in bio + tools
Manage your social media
Grow and engage your audience
Monetize your following
Measure your success
Templates
Marketplace
Learn
Resources
How to use Linktree
Pricing
Link in bio + tools
Link in bio
Customize your Linktree
Link shortener
Create trackable, shareable short links
QR code generator
Turn links into scannable QR codes
Canva Background Editor
Import your custom designs from Canva into your profile
Linktree for every social platform
Grow and engage your audience everywhere
Instagram
TikTok
LinkedIn
X
Manage your social media
Schedule and auto-post
Hands-free, hassle-free social media planning
Instagram auto reply
Automated replies and DMs triggered by comments
AI content & caption generator
Instant AI-powered post ideas and captions
Hashtag generator
Trending hashtag suggestions for better reach
Social integration for every social platform
Plan, auto post, and share across all platforms
Instagram
TikTok
Facebook
Pinterest
LinkedIn
Threads
Youtube
Grow and engage your audience
Collect leads with contact forms
Turn visitors into subscribers
Manage and activate your audience
Organize, tag, and track contacts
Send contacts to email tools
Sync with Mailchimp, Klaviyo, Kit & more
Monetize your following
Earn with a Linktree Shop
Sell products and earn commission
Sell an online course
Create and sell your expertise easily
Host digital products
Sell digital products and build your email list
Earn by hosting sponsored links
Share brand offers and earn for every sign-up or sale
Get rewarded for growing your Linktree
Earn points, level up and unlock cash bonuses
Booked and paid, easily
Offer sessions and earn from your expertise
Measure your success
Social + link analytics
Track clicks, engagement and audience insights
Resources
Read our blog
All the latest tips, tricks and growth strategies
Success Stories
Real people, real results on Linktree
How to use Linktree
Linktree Help Centre
Get answers, guides and support