<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CTI on Riga</title><link>https://riga.sh/tags/cti/</link><description>Recent content in CTI on Riga</description><generator>Hugo 0.125.0</generator><language>en-us</language><lastBuildDate>Fri, 12 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://riga.sh/tags/cti/index.xml" rel="self" type="application/rss+xml"/><item><title>🥷 Threat Intel toolbox</title><link>https://riga.sh/toolbox/-threat-intel/</link><pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate><guid>https://riga.sh/toolbox/-threat-intel/</guid><description>I endorse nothing you&amp;rsquo;ll do with these tools, use them at your own risks.
Combining multiple sources while investigating is highly recommended. Remember, these tools are only there to help your investigation, the conclusion is up to you. This list is updated often, check the date above for the latest update.
Domain and IP Threat Intel Search by IP, domain, or network owner for real-time threat data
https://talosintelligence.com/ Website reputation checker</description></item><item><title> [OSINT/CTI] The Great Canadian Scammers</title><link>https://riga.sh/investigations/the-great-canadian-scammers/</link><pubDate>Mon, 28 Oct 2024 00:00:00 +0000</pubDate><guid>https://riga.sh/investigations/the-great-canadian-scammers/</guid><description>This article is made for educational purpose only, to show what&amp;rsquo;s going on behind the scenes of malicious actors and their digital platforms. Everything comes from open and legal sources.
I received an SMS asking me to log in to: auth-rbcroyalbank-online[.]com. Well, thanks to this scam, I was able to map a wide phishing network targeting Canadian institutions.
Key points:
⏺️ Mostly Russian and Chinese registrars/hosting providers (JSC Selectel, Nicenic&amp;hellip;) are involved.</description></item><item><title>[CTI] NoName057(16) mapping</title><link>https://riga.sh/investigations/noname05716/</link><pubDate>Sun, 21 Jul 2024 00:00:00 +0000</pubDate><guid>https://riga.sh/investigations/noname05716/</guid><description>NoName057(16) is a pro russian hacking group targeting multiple strategic organizations (by DOS/DDOS) associated with countries supporting Ukraine in the ongoing war. They also rely on Botnets (infected machines) to carry large scale attacks. They are very talkative on different platforms, sharing their assets and targets, so I&amp;rsquo;ll try to summarize all of this here.
NoName057(16) operates on two principal Telegram channels:
🇷🇺 https://t.me/noname0571
🇬🇧 https://t.me/noname05716eng
They mainly share news about their attacks: What makes NoName057(16) interesting, is their community implication where anyone can download their DOS/DDOS tools, ask questions and support their actions broadly.</description></item><item><title>[CTI] Phish me if you can</title><link>https://riga.sh/investigations/government-phishing/</link><pubDate>Wed, 20 Dec 2023 00:00:00 +0000</pubDate><guid>https://riga.sh/investigations/government-phishing/</guid><description>Recently, I received quite an unusual phishing email.
At first, it looks like a typical delivery phishing, but it came from&amp;hellip; a government address!
It came from the doctor appointment service from the Serbian Ministry of Health:
This domain has no DMARC policy in place, meaning it could be more easily beings used to spread malicious emails.
The email is simply an image rendered by HTML, and linked 2 fraudulent files:</description></item><item><title> [OSINT/CTI] Investigating a terrorist IT infrastructure</title><link>https://riga.sh/investigations/terroristinfrastructure/</link><pubDate>Thu, 12 Oct 2023 00:00:00 +0000</pubDate><guid>https://riga.sh/investigations/terroristinfrastructure/</guid><description>With the ongoing war between Israeli forces and Hamas, I wanted to analyze different propaganda tools and how they are built.</description></item></channel></rss>