Austin Larsen

Investigating the intrusions that make headlines. Nation-state threats, zero-days, and data extortion. Previously Mandiant.

// as featured in

Bloomberg Reuters Fortune Newsweek TechCrunch CyberScoop Krebs on Security BleepingComputer Dark Reading The Register 404 Media

Blog

Takedown: Disrupting the Netnut Residential Proxy Botnet

Google, the FBI, Lumen's Black Lotus Labs, Shadowserver, and other partners disrupted the Netnut residential proxy botnet, which hijacked over 2 million home devices. GTIG observed 316 distinct threat clusters using suspected Netnut exit nodes in a single week in June 2026.

REDACT Responds: What BlackFile's Rebuttal Actually Confirms

BlackFile, now operating as REDACT, publicly responded to my SLEUTHCON talk on their vanishing act. Their rogue-affiliate explanation is plausible, but it leaves the abandoned mid-negotiation ransoms and the suspicious timing of a rival group's callout unexplained.

STOCKSTAY: Turla's Modular Backdoor Hiding in Plain Sight

GTIG's new research on STOCKSTAY, a multi-component .NET backdoor attributed with high confidence to the Russia-nexus espionage actor Turla (Secret Blizzard, FSB Center 16). It disguises itself as everyday software while running modular espionage tooling against Ukrainian government, military, and European foreign ministries.

Klue Integration Compromise Fuels Icarus Data Theft Extortion

GTIG is tracking a widespread data theft extortion campaign stemming from the compromise of the Klue third-party integration service. A legacy GitHub PAT gave the actor access to exfiltrate OAuth credentials and pivot into hundreds of Salesforce and Gong customer environments, tied to the Icarus extortion group.

Research

Mandiant

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

Mandiant and GTIG attribute an active compromise and extortion campaign to UNC6240 (ShinyHunters) exploiting CVE-2026-35273, a zero-day RCE in Oracle PeopleSoft, against the higher education sector. Open attacker directories exposed MeshCentral C2 staging and a lateral movement defacement script.

GTIG

Welcome to BlackFile: Inside a Vishing Extortion Operation

UNC6671, operating under the BlackFile brand, runs a high-cadence vishing and SSO compromise campaign using AiTM techniques to bypass MFA and exfiltrate data from Microsoft 365 and Okta environments for extortion.

GTIG

Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever

How defenders should rebuild vulnerability management programs as AI models surface exploitable bugs faster than most organizations can triage them.

GTIG

North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack

DPRK-nexus actor UNC1069 compromised the widely used Axios npm package to stage payloads against downstream developers in a targeted supply chain attack.

GTIG

Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft

Tracking the expansion of ShinyHunters-branded vishing operations targeting SaaS platforms for data theft and downstream extortion.

GTIG

Multiple Threat Actors Exploit React2Shell (CVE-2025-55182)

Multiple threat clusters rapidly weaponized CVE-2025-55182 in React-based applications for initial access and command execution.

GTIG

Oracle E-Business Suite Zero-Day Exploited in Widespread Extortion Campaign

CL0P-linked actors exploited an Oracle E-Business Suite zero-day at scale to steal customer data and run a widespread extortion campaign.

GTIG

Widespread Data Theft Targets Salesforce Instances via Salesloft Drift

Attackers abused compromised Salesloft Drift OAuth tokens to pivot into hundreds of Salesforce instances and exfiltrate customer data at scale.

GTIG

UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion

UNC5537 leveraged stolen credentials to compromise Snowflake customer instances, stealing data from roughly 165 organizations in one of 2024 largest extortion campaigns.

Mandiant

Cutting Edge, Part 4: Ivanti Connect Secure VPN Post-Exploitation Lateral Movement Case Studies

Post-exploitation case studies from Ivanti Connect Secure intrusions showing how attackers pivoted from the VPN into full domain compromise.

Mandiant

Bringing Access Back — Initial Access Brokers Exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect

Initial access brokers chained CVE-2023-46747 in F5 BIG-IP and ScreenConnect vulnerabilities to establish footholds later handed off to ransomware operators.

Mandiant

Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts

China-nexus UNC5325 abused Ivanti Connect Secure zero-days to deploy novel malware and maintain persistence through factory resets and upgrades.

Mandiant

Assessed Cyber Structure and Alignments of North Korea in 2023

Assessed reorganization and alignments of North Korean cyber units in 2023, tying operations back to RGB, MSS, and MoD reporting structures.

Mandiant

Diving Deep into UNC4841 Operations Following Barracuda ESG Zero-Day Remediation (CVE-2023-2868)

Deep dive into UNC4841 operations following CVE-2023-2868 remediation, including new malware families and attempts to maintain access on patched appliances.

Mandiant

North Korea Leverages SaaS Provider in a Targeted Supply Chain Attack

DPRK actor compromised JumpCloud to reach a narrow set of downstream cryptocurrency customers, marking a deliberate and targeted supply chain operation.

Mandiant

Barracuda ESG Zero-Day Vulnerability (CVE-2023-2868) Exploited Globally by Aggressive and Skilled Actor, Suspected Links to China

Suspected China-nexus actor exploited CVE-2023-2868 in Barracuda ESG appliances globally for espionage, with activity dating back months before public disclosure.

Mandiant

SIM Swapping and Abuse of the Microsoft Azure Serial Console: Serial Is Part of a Well Balanced Attack

A threat actor combined SIM swapping with abuse of the Azure Serial Console to gain privileged access to cloud-hosted virtual machines.

Media