<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Investigations on Riga</title><link>https://riga.sh/investigations/</link><description>Recent content in Investigations on Riga</description><generator>Hugo 0.125.0</generator><language>en-us</language><lastBuildDate>Mon, 28 Oct 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://riga.sh/investigations/index.xml" rel="self" type="application/rss+xml"/><item><title> [OSINT/CTI] The Great Canadian Scammers</title><link>https://riga.sh/investigations/the-great-canadian-scammers/</link><pubDate>Mon, 28 Oct 2024 00:00:00 +0000</pubDate><guid>https://riga.sh/investigations/the-great-canadian-scammers/</guid><description>This article is made for educational purpose only, to show what&amp;rsquo;s going on behind the scenes of malicious actors and their digital platforms. Everything comes from open and legal sources.
I received an SMS asking me to log in to: auth-rbcroyalbank-online[.]com. Well, thanks to this scam, I was able to map a wide phishing network targeting Canadian institutions.
Key points:
⏺️ Mostly Russian and Chinese registrars/hosting providers (JSC Selectel, Nicenic&amp;hellip;) are involved.</description></item><item><title>[CTI] NoName057(16) mapping</title><link>https://riga.sh/investigations/noname05716/</link><pubDate>Sun, 21 Jul 2024 00:00:00 +0000</pubDate><guid>https://riga.sh/investigations/noname05716/</guid><description>NoName057(16) is a pro russian hacking group targeting multiple strategic organizations (by DOS/DDOS) associated with countries supporting Ukraine in the ongoing war. They also rely on Botnets (infected machines) to carry large scale attacks. They are very talkative on different platforms, sharing their assets and targets, so I&amp;rsquo;ll try to summarize all of this here.
NoName057(16) operates on two principal Telegram channels:
🇷🇺 https://t.me/noname0571
🇬🇧 https://t.me/noname05716eng
They mainly share news about their attacks: What makes NoName057(16) interesting, is their community implication where anyone can download their DOS/DDOS tools, ask questions and support their actions broadly.</description></item><item><title>[CTI] Phish me if you can</title><link>https://riga.sh/investigations/government-phishing/</link><pubDate>Wed, 20 Dec 2023 00:00:00 +0000</pubDate><guid>https://riga.sh/investigations/government-phishing/</guid><description>Recently, I received quite an unusual phishing email.
At first, it looks like a typical delivery phishing, but it came from&amp;hellip; a government address!
It came from the doctor appointment service from the Serbian Ministry of Health:
This domain has no DMARC policy in place, meaning it could be more easily beings used to spread malicious emails.
The email is simply an image rendered by HTML, and linked 2 fraudulent files:</description></item><item><title>[OSINT] Leveraging OSINT to identify potential misinformation</title><link>https://riga.sh/investigations/countermisinformation/</link><pubDate>Mon, 30 Oct 2023 00:00:00 +0000</pubDate><guid>https://riga.sh/investigations/countermisinformation/</guid><description>OSINT is about gathering technical and social elements to draw a narrative about a situation and communicate a clear thought. Sometimes, misinformation campaigns regain attention as they are shared a few years later, taking advantage of the mass of shared information to reuse old images when they are forgotten. It&amp;rsquo;s also worth pointing out that a tragic event appeals the emotions, making us less inclined to verify it.
So, I stumbled upon a tweet published in March 2022, which gained substantial exposure at that time:</description></item><item><title> [OSINT/CTI] Investigating a terrorist IT infrastructure</title><link>https://riga.sh/investigations/terroristinfrastructure/</link><pubDate>Thu, 12 Oct 2023 00:00:00 +0000</pubDate><guid>https://riga.sh/investigations/terroristinfrastructure/</guid><description>With the ongoing war between Israeli forces and Hamas, I wanted to analyze different propaganda tools and how they are built.</description></item><item><title>[OSINT] Elon Musk vs OSINT</title><link>https://riga.sh/investigations/elonmusk/</link><pubDate>Tue, 01 Aug 2023 00:00:00 +0000</pubDate><guid>https://riga.sh/investigations/elonmusk/</guid><description>What the internet has to offer for a high value profile (who likes to troll a lot)</description></item><item><title>[OSINT] Oil giant Perenco: investigation</title><link>https://riga.sh/investigations/moneylaunderingkabila/</link><pubDate>Wed, 19 Jul 2023 00:00:00 +0000</pubDate><guid>https://riga.sh/investigations/moneylaunderingkabila/</guid><description>Oil giant Perenco’s suspicious deals with companies close to Congo’s ex-president&amp;quot;</description></item><item><title>[OSINT] The shady Pimeyes</title><link>https://riga.sh/investigations/theshadypimeyes/</link><pubDate>Fri, 13 Jan 2023 00:00:00 +0000</pubDate><guid>https://riga.sh/investigations/theshadypimeyes/</guid><description>Pimeyes is on a thin line</description></item><item><title>[OSINT] Anatomy of a crypto/banking scam</title><link>https://riga.sh/investigations/anatomycryptoscam/</link><pubDate>Sat, 27 Aug 2022 00:00:00 +0000</pubDate><guid>https://riga.sh/investigations/anatomycryptoscam/</guid><description>Scam me if you can</description></item></channel></rss>