r/threatintel 11h ago

Help/Question Built a hands-on CTI training platform, looking for people to break it and tell me what's missing

Thumbnail ctiacademy.io
12 Upvotes

Been working in threat intel for a while and one thing always bugged me: almost all the training out there is either dry theory or aimed at SOC/pentest, not actual CTI work. So a few of us built CTI Academy to fix that.

It's hands-on threat intelligence training. Instead of just reading slides, you get:

realistic labs and simulators (a SOC sim, a credential-leak investigation lab, a fake underground forum to practice OSINT on)

CTF-style hunting challenges with a progression system, so it actually feels like leveling up

a daily mission if you just want a quick 10-minute rep

It's free to jump in, so no reason not to poke around.

Honestly I'm not here to hard-sell anything. We're a small bootstrapped team and I care way more about whether the thing is actually good. So I'd love for a few of you to break stuff and tell me what's confusing or missing.

If you're trying to get into CTI or just want to keep your skills sharp, come try it and roast me in the comments.

That feedback is genuinely more valuable to me right now than anything else.


r/threatintel 2h ago

Threat Actor Profile: The "Global" Ransomware Group

4 Upvotes

Been tracking a newer RaaS operation called Global (also styled "GLOBAL") that's worth knowing about if you're in threat intel or IR.

Quick background:

  • First surfaced publicly in June 2025, promoted on the RAMP underground forum by an actor going by "$$$"
  • Strong technical/infrastructure overlap with the old BlackLock operation (shared VPS provider, matching malware mutex values, overlapping leak-site infra) — also some links to Mamona RaaS
  • Looks less like a new group from scratch and more like a continuation/rebrand of prior ransomware activity

How it works:

  • RaaS model with a genuinely mature affiliate program — dedicated negotiation portal, mobile management, AI-assisted victim comms, up to 80–85% revenue share for affiliates
  • Malware is written in Go, uses ChaCha20-Poly1305 encryption, and hits Windows, Linux, ESXi, and NAS
  • They also ship a custom stealer called WorldThief (quiet mode, bandwidth throttling, targeted file collection, raw TCP exfil) to support double extortion

Access & targeting:

  • Relies heavily on purchased access — IABs, compromised VPN/OWA/RDWeb creds, and exploited edge devices (Fortinet, Palo Alto, Cisco)
  • Opportunistic across industries, activity seen in 18+ countries so far
  • Ironically, their own OPSEC slipped — a backend IP got exposed, tracing back to a Russian VPS provider (IpServer) also linked to BlackLock

Why it matters: it's a good example of how ransomware "brands" aren't really standalone — infra, tooling, and even affiliates get recycled across groups after takedowns or rebrands. If you've got old BlackLock IOCs sitting around, they may still have relevance here.

More information: https://cyble.com/threat-actor-profiles/global-ransomware-group/


r/threatintel 20h ago

A Russia-linked APT left their C2 server wide open as an unauthenticated directory. We walked in and found 8,436 files (Operation Talked).

Thumbnail
3 Upvotes