Method of infection: Water-holing
OSIRIS used a Social Engineering method called “water holing” to attack German IP addresses.Β
How does water holing attack work?
- Β The victim enters the infected website.
- The website checks if the target IP is German.
- If it’s a German IP – few evasion techniques are used to bypass EDR
- And then the virus connects to its command server through the Darknet
Save Your Company from Social Engineering Attacks Like that
Register and Get your Personalized Free Exposure Report NOW,
And see where your Company is Exposed to Hackers
Recently Posted on AUMINT.io Blog
β‘ Top Free Threat Intelligence Resources Every CISO Needs β‘
Staying ahead of attackers means knowing their next move β but high-quality threat intelligence doesnβt have to come with a high price tag.
Hereβs a curated list of free threat intelligence resources every CISO should use to monitor, analyze, and respond to emerging cyber threats:
1οΈβ£ MISP (Malware Information Sharing Platform) β Community-driven platform to share and consume threat intelligence.
https://www.misp-project.org/
2οΈβ£ CIRCL CTI Feeds β Open-source indicators and threat intelligence feeds for proactive defense.
https://www.circl.lu/services/cts/
3οΈβ£ AlienVault Open Threat Exchange (OTX) β Free access to crowd-sourced threat data and IOCs.
https://otx.alienvault.com/
4οΈβ£ MITRE ATT&CK Framework β Map attacker tactics and techniques to improve detection and response.
https://attack.mitre.org/
5οΈβ£ Abuse.ch Threat Feeds β Real-time feeds on malware, ransomware, and botnet activity.
https://abuse.ch/
6οΈβ£ VirusTotal Intelligence β Free malware scanning and IOC search to enhance threat awareness.
https://www.virustotal.com/gui/intelligence
7οΈβ£ Spamhaus DBL & DROP Lists β Blocklists for domains and IPs linked to malicious activity.
https://www.spamhaus.org/
8οΈβ£ Recorded Future Free Intelligence β Limited free dashboards and alerts on emerging threats.
https://www.recordedfuture.com/free-threat-intelligence/
These resources empower CISOs to make informed decisions, enhance SOC visibility, and strengthen defensive strategies β without any licensing costs.
Want to see how your teamβs human behavior aligns with threat intelligence? π§ AUMINT.io delivers actionable insights through social engineering simulations to uncover unseen risks.
π Book a free intro call today: Schedule here
πΎ Save this post and level up your threat intelligence in 2025!
#CISO #ThreatIntelligence #OpenSourceSecurity #SOC #CyberSecurity #AUMINT