Latest Insights

Silent Logins: How Russian-Linked Threat Actors Weaponise AnyDesk Against APAC Organisations
A Login Nobody Initiated Once upon a time in a incident response engagement, we discovered an unusual root cause for an otherwise run-of-the-mill ransomware attack. In the middle of the night, a non-production server belonging to an APAC-based Financial Institution accepted an inbound AnyDesk connection. Access (mysteriously) granted, the incomer proceeded with internal reconnaissance to…
We Followed the Wallet: Tracking GlassWorm Through Nine C2 Rotations
TL;DR Introduction On April 24, 2026, a Solana wallet executed a transaction that cost less than a fraction of a cent. To anyone watching the blockchain as a whole, it was noise in millions of daily memos moving through the network. For our team, this was a signal we had been waiting for. The wallet…
Beyond Risky Sign-Ins: Behavioural Analysis for AiTM Attack Detection
Social engineering attacks are at an all-time high, amplified by the accessibility of phishing toolkits and open-source Artificial Intelligence (AI) offerings. This is reflected in the fact that 98% of cyberattacks leverage social engineering techniques to exploit the human element to achieve their end objectives.[1] What began as Business Email Compromise (BEC), campaigns that facilitated…