Austin Larsen

Investigating the intrusions that make headlines. Nation-state threats, zero-days, and data extortion. Previously Mandiant.

upcoming LABScon 2026 — Sep 16 Register →

// as featured in

Bloomberg Reuters Fortune Newsweek TechCrunch CyberScoop Krebs on Security BleepingComputer Dark Reading The Register 404 Media New York Post

Blog

TeamPCP Arrests: How Operational Security Failures Ended a Supply Chain Crime Spree

The Australian Federal Police, FBI, and Western Australia Police charged two alleged members of TeamPCP (tracked by GTIG as UNC6780) following a joint investigation into the group's global supply chain attacks, which compromised more than 1,000 organizations and exposed over 500,000 credentials.

UNC6671's Multi-Brand Vishing Empire: Redact, Pink, Helix, and Falcon

GTIG and Mandiant published new research tracking UNC6671, a data theft extortion group that has diversified across the Redact, Pink, Helix, and Falcon brands despite the announced BlackFile shutdown. I spoke with Reuters about the group's recent pivot to law firms, private equity, and financial services.

UNC5537's Connor Riley Moucka Pleads Guilty to Snowflake Extortion Campaign

Connor Riley Moucka, tracked as UNC5537, pleaded guilty to a hacking conspiracy involving the compromise of over 165 victim organizations and the theft of billions of customer records, in the case GTIG first detailed in our 2024 Snowflake data theft and extortion research.

Takedown: Disrupting the Netnut Residential Proxy Botnet

Google, the FBI, Lumen's Black Lotus Labs, Shadowserver, and other partners disrupted the Netnut residential proxy botnet, which hijacked over 2 million home devices. GTIG observed 316 distinct threat clusters using suspected Netnut exit nodes in a single week in June 2026.

Research

GTIG

UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

UNC6671 has diversified data theft extortion operations across the Redact, Pink, Helix, and Falcon brands despite the announced BlackFile retirement. Shared vishing infrastructure, phishing templates, and victim targeting overlaps link the brands, with recent activity shifting toward financial services, private equity, and professional services.

Mandiant

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

Mandiant and GTIG attribute an active compromise and extortion campaign to UNC6240 (ShinyHunters) exploiting CVE-2026-35273, a zero-day RCE in Oracle PeopleSoft, against the higher education sector. Open attacker directories exposed MeshCentral C2 staging and a lateral movement defacement script.

GTIG

Welcome to BlackFile: Inside a Vishing Extortion Operation

UNC6671, operating under the BlackFile brand, runs a high-cadence vishing and SSO compromise campaign using AiTM techniques to bypass MFA and exfiltrate data from Microsoft 365 and Okta environments for extortion.

GTIG

Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever

How defenders should rebuild vulnerability management programs as AI models surface exploitable bugs faster than most organizations can triage them.

GTIG

North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack

DPRK-nexus actor UNC1069 compromised the widely used Axios npm package to stage payloads against downstream developers in a targeted supply chain attack.

GTIG

Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft

Tracking the expansion of ShinyHunters-branded vishing operations targeting SaaS platforms for data theft and downstream extortion.

GTIG

Multiple Threat Actors Exploit React2Shell (CVE-2025-55182)

Multiple threat clusters rapidly weaponized CVE-2025-55182 in React-based applications for initial access and command execution.

GTIG

Oracle E-Business Suite Zero-Day Exploited in Widespread Extortion Campaign

CL0P-linked actors exploited an Oracle E-Business Suite zero-day at scale to steal customer data and run a widespread extortion campaign.

GTIG

Widespread Data Theft Targets Salesforce Instances via Salesloft Drift

Attackers abused compromised Salesloft Drift OAuth tokens to pivot into hundreds of Salesforce instances and exfiltrate customer data at scale.

GTIG

UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion

UNC5537 leveraged stolen credentials to compromise Snowflake customer instances, stealing data from roughly 165 organizations in one of 2024 largest extortion campaigns.

Mandiant

Cutting Edge, Part 4: Ivanti Connect Secure VPN Post-Exploitation Lateral Movement Case Studies

Post-exploitation case studies from Ivanti Connect Secure intrusions showing how attackers pivoted from the VPN into full domain compromise.

Mandiant

Bringing Access Back — Initial Access Brokers Exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect

Initial access brokers chained CVE-2023-46747 in F5 BIG-IP and ScreenConnect vulnerabilities to establish footholds later handed off to ransomware operators.

Mandiant

Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts

China-nexus UNC5325 abused Ivanti Connect Secure zero-days to deploy novel malware and maintain persistence through factory resets and upgrades.

Mandiant

Assessed Cyber Structure and Alignments of North Korea in 2023

Assessed reorganization and alignments of North Korean cyber units in 2023, tying operations back to RGB, MSS, and MoD reporting structures.

Mandiant

Diving Deep into UNC4841 Operations Following Barracuda ESG Zero-Day Remediation (CVE-2023-2868)

Deep dive into UNC4841 operations following CVE-2023-2868 remediation, including new malware families and attempts to maintain access on patched appliances.

Mandiant

North Korea Leverages SaaS Provider in a Targeted Supply Chain Attack

DPRK actor compromised JumpCloud to reach a narrow set of downstream cryptocurrency customers, marking a deliberate and targeted supply chain operation.

Mandiant

Barracuda ESG Zero-Day Vulnerability (CVE-2023-2868) Exploited Globally by Aggressive and Skilled Actor, Suspected Links to China

Suspected China-nexus actor exploited CVE-2023-2868 in Barracuda ESG appliances globally for espionage, with activity dating back months before public disclosure.

Mandiant

SIM Swapping and Abuse of the Microsoft Azure Serial Console: Serial Is Part of a Well Balanced Attack

A threat actor combined SIM swapping with abuse of the Azure Serial Console to gain privileged access to cloud-hosted virtual machines.

Media