Threat Intelligence

contagious interview fleet

An Undocumented OtterCookie-Lineage Build and Its Invisible C2 Fleet

How one stage-3 payload led to nine OtterCookie-related hosts, three server fingerprints, and a Contagious Interview infrastructure fleet sitting at zero detections. Author: Yury Sergeev, RST Cloud Published: 15 August 2026 Summary A client shared a single stage-3 payload from a DPRK-nexus Contagious Interview delivery chain. Deobfuscating it yielded more than a capability list: it exposed the […]

An Undocumented OtterCookie-Lineage Build and Its Invisible C2 Fleet Read More »

threat intel scoring

Beyond Decay Curves: Rethinking IOC Scoring

This methodology now lives at /how-we-score/ as a short, evergreen reference — this post remains the full technical deep-dive. Most security teams assume IOC scoring is a solved problem. Indicators arrive from threat feeds, confidence values are assigned, decay functions reduce scores over time, and detections are prioritized accordingly. On paper, the process appears objective

Beyond Decay Curves: Rethinking IOC Scoring Read More »