ru
Feedback
ᴛʜᴇ ɢʜᴏꜱᴛ ɪɴ ᴛʜᴇ ᴍᴀᴄʜɪɴᴇ

ᴛʜᴇ ɢʜᴏꜱᴛ ɪɴ ᴛʜᴇ ᴍᴀᴄʜɪɴᴇ

Открыть в Telegram

A coalition focused on cyber resistance.

Больше
Израиль2 801Категория не указана
318
Подписчики
-124 часа
Нет данных7 дней
+330 день
Архив постов
A startup in Virginia just launched a social network called Twitter and it has NOTHING to do with Elon Musk. The blue bird is back, tweets and retweets are back, and it costs $20 to get through the door.

Louis Michael Gaebler, 23, of Mandurah, Western Australia, was arrested in Perth in connection with the TeamPCP investigation. Reporting from Australian media said he was one of two West Australian men charged after a joint investigation involving the Australian Federal Police, Western Australia Police, and the FBI. TeamPCP has been linked in reporting to major supply-chain attacks that allegedly spread malicious code through open-source software and affected a large number of organizations worldwide. In this case, the important point is not a single technical failure, but the accumulation of public traces that allowed investigators to connect online identities, platform activity, and real-world records. For a cybersecurity audience, the lesson is straightforward. Attribution in cases like this usually comes from correlation rather than one dramatic breakthrough. Names, usernames, account histories, public profiles, and infrastructure references can all become part of the same investigative picture when they overlap consistently over time. The case also highlights how operational security failures tend to be cumulative. A handle, avatar, social profile, or business record may seem insignificant in isolation, but repeated across services it can create a durable identity trail. That trail becomes more valuable when it is preserved for years and can later be matched against other account activity or public records. Gaebler’s arrest in Perth therefore matters not only as a law-enforcement action, but as a reminder that long-term identity reuse can become an attribution risk. In modern cyber investigations, the strongest cases often do not come from one isolated clue. They come from multiple small clues that point to the same person. #TGITM @TheGhostITM

Two people linked to TeamPCP were reportedly arrested in Australia today. TeamPCP is believed to be behind a string of major supply-chain attacks that sent shockwaves through the cybersecurity community.

- Cross-platform alias persistence: Handles and identity fragments were reportedly retained across HackerOne, GitHub, Hugging Face, TikTok, Steam, and Telegram. - Infrastructure exposure: A domain reportedly associated with malicious command-and-control activity was publicly linked from developer-facing profiles. - Weak identity separation: A possible real name, initials, aliases, and related account data were sufficiently connected to enable further OSINT pivots. - Historical timeline overlap: Steam VAC-ban dates and account interactions reportedly aligned across multiple identities. - Visual-identity reuse: The same distinctive cat avatar reportedly appeared on Steam and Telegram accounts associated with the wider TeamPCP ecosystem. - Public-record exposure: A business reportedly operated under the name OPSEC EXPRESS created an additional real-world attribution surface. Corporate records are routinely useful when they can be correlated with online identifiers, financial activity, communications, or infrastructure evidence. Analytical Takeaway This case demonstrates that operational security fails cumulatively. An individual does not need to expose a home address, leave a real IP address in a server log, or publish a direct confession to become attributable. Small artifacts—an old Steam ban, a contact comment, a reused profile image, a domain on a public developer profile, or a social-media video—can persist for years and later become critical evidence. The central mistake was treating individual accounts as isolated identities. They were not isolated. The reported evidence indicates that each platform preserved a fragment of the same operational history. Once one fragment was linked to a real-world identity, the remaining artifacts could be examined as part of a single pattern. For cyber-intelligence teams, the lesson is equally practical: prioritize pivots that establish independent corroboration. A username is a lead, not a conclusion. Confidence grows when a handle is supported by shared infrastructure, time-based correlations, platform relationships, visual markers, and verifiable public records. #TGITM @TheGhostITM

Case Study: How Reused Digital Identity Exposed an Alleged TeamPCP Member By Yara Tabet (The Ghost In The Machine) Executive Assessment The reported arrest of Ruben Thomson in Western Australia illustrates a common failure in hacking OPSEC: identity reuse across platforms with radically different levels of visibility. The reported attribution was not built around a zero-day, a covert implant, or a single leaked identifier. It emerged from publicly accessible traces that, when correlated, connected a long-standing online persona to an alleged TeamPCP member. The core failure was poor compartmentalization. Handles, infrastructure references, historical account activity, profile imagery, and social-media content allegedly overlapped for years. Any one artifact would have been weak evidence. Together, they created an attribution chain that was difficult to dismiss. Scope and Attribution Caveat This assessment is based on publicly reported material and open-source observations. It does not independently establish guilt or validate all claims of group membership. The reference to Thomson’s reported arrest and alleged connection to TeamPCP should be read as an attribution assessment pending the outcome of judicial proceedings. Initial Identity Pivot The investigation reportedly began with the handle DeadCatx3, which was associated with a HackerOne profile connected to the name Ruben Thomson. The account was significant because it created an initial bridge between a real-world identity and an established online alias. Researchers then identified what appeared to be an associated Hugging Face account using initials consistent with the same name. That profile reportedly referenced masscan[.]cloud. The domain had been identified publicly as command-and-control infrastructure associated with the Mini Shai-Hulud npm worm activity. The same domain was also reportedly present on the DeadCatx3 GitHub profile. This overlap mattered because it was not merely a reused username. It connected a named identity, developer-platform profiles, and infrastructure allegedly tied to a malware campaign. The evidentiary value came from convergence: distinct services independently pointing toward the same operational ecosystem. Social-Media and Steam Correlation Once Ruben Thomson became a working lead, investigators and researchers reportedly pivoted through account-linked data and open-source records. This led to a TikTok account using the name yolosolo17. The account reportedly contained a single video, published in March 2017, showing a Steam profile named YolocrownZ. The footage showed that the account had received a VAC ban $$175$$ days earlier. This places the likely ban date at approximately September 13, 2016. Further Steam research reportedly identified an account called Ellis that had also received a VAC ban on September 13, 2016. Public Steam-profile interactions and comments reportedly established a relationship between the Ellis and YolocrownZ identities. This is a valuable example of timestamp-based correlation. A shared ban date does not identify a person on its own, but it becomes meaningful when aligned with connected accounts, relationships, alias reuse, and the wider attribution record. The Avatar Link The strongest and most memorable pivot was visual rather than technical. A distinctive cat avatar appeared on a Steam profile associated with the identity chain. The same image was reportedly reused by the PCPsh Telegram account linked publicly to TeamPCP. Reverse-image searches reportedly produced few or no unrelated uses of the image. This gave the avatar limited but useful attribution value. Profile pictures are generally weak indicators because they can be copied, but their value rises when they appear consistently across accounts that also share timelines, contacts, aliases, and operational context. The cat image did not prove identity. It corroborated an identity chain that was already supported by multiple independent sources. OPSEC Failures Identified

Proton is currently experiencing a major outage affecting Proton's services due to a cooling failure in their Frankfurt datacenter.

The Uwais al-Qarani Hacker Group claims responsibility for a cyberattack on Israel's power grid, targeting critical infrastructure and sending a message of resistance. #TGITM @TheGhostITM

THE FOREIGN HAND: ISRAEL’S ROLE IN U.S. SURVEILLANCE INFRASTRUCTURE Unit 8200 and Its American Footprint Unit 8200 is Israel’s elite signals-intelligence and cyber unit, often compared to the U.S. National Security Agency. Its role includes intercepting communications, conducting cyber operations, and gathering intelligence. Over decades, it has developed a reputation as one of the world’s most capable cyber-intelligence organizations. For people across the Arab world, especially Palestinians and Lebanese, this is not an abstract subject. Israel’s surveillance capabilities have been used in the region for military occupation, targeting, intelligence collection, and monitoring civilians. That history should matter when technologies and companies shaped by this ecosystem enter public institutions abroad. Unit 8200 is also known as a powerful pipeline into the technology industry. Many former members have gone on to found or work for prominent cybersecurity, software, and data companies. Israel’s technology sector has benefited heavily from skills, networks, and experience developed through military intelligence service. Some of those companies have expanded into the United States, where they may work with corporations, police departments, public agencies, and security institutions. Their products can involve sensitive information: license-plate records, location data, video feeds, emergency communications, biometric data, and other forms of digital surveillance. That raises legitimate questions—not about the ethnicity or nationality of individual engineers, but about accountability. Who owns the data? Where is it stored? Who can access it? What safeguards prevent misuse? And what public oversight exists when surveillance tools move between military, private-sector, and government environments? The case of NSO Group offers an important warning. Founded by former members of Israel’s military-intelligence ecosystem, NSO developed Pegasus spyware, a tool that has been linked to the targeting of journalists, activists, political opponents, and human-rights defenders in numerous countries. The company said its technology was intended to fight crime and terrorism, yet repeated investigations showed how easily powerful surveillance technology can be abused when oversight fails. The issue is larger than any one company. It is the wider military-to-tech pipeline: intelligence experience becomes commercial technology, commercial technology enters foreign markets, and public institutions adopt it in the name of safety. Once these systems are embedded, they can quietly expand beyond their original purpose. In the United States, automated license-plate readers, facial-recognition systems, border-surveillance platforms, and large-scale data-sharing networks have become increasingly common. These tools affect ordinary people every day, often with limited public debate and weak safeguards against misuse. From a Lebanese perspective, there is every reason to view this trend critically. Lebanon and the wider region have lived with the consequences of Israeli military power, intelligence operations, aerial surveillance, and cyber capabilities. When systems shaped by that security model are exported abroad, the public deserves to ask whether they bring the same assumptions: that mass monitoring is normal, that privacy is expendable, and that security institutions should operate without meaningful scrutiny. This is not an argument against cooperation between countries or against technology itself. It is an argument for transparency, democratic oversight, data sovereignty, and human rights. No foreign government, military-linked network, or private contractor should gain privileged access to the personal data of another population without clear safeguards and public accountability. @TheGhostITM

نشر وثائق عن تعاون شركة Novamill مع الصناعات العسكرية التابعة للاحتلال الإسرائيلي نشرت جبهة الإسناد السيبراني أجزاءً من وثائق داخلية لشركة Novamill Systems، بتبيّن تفاصيل تعاون الشركة في مجال القطع الصناعية والتكنولوجيا مع الصناعات العسكرية والفضائية التابعة للاحتلال الإسرائيلي. بتشمل الوثائق عقودًا، واتفاقيات تعاون، وتقارير فنية مرتبطة بشركات، منها Elbit Systems وRafael والصناعات الجوية الإسرائيلية (IAI). ومن بين الوثائق المنشورة مخططات هندسية، ومعلومات عن القطع، وتفاصيل عن أوجه التعاون التقني كمان. Documents Released on Novamill’s Cooperation with Israeli Military Industries The Cyber Isnaad Front has released portions of internal documents from Novamill Systems. The documents reportedly show details of the company’s cooperation in industrial components and technology with Israeli military and aerospace industries. The documents include contracts, cooperation agreements, and technical reports related to companies including Elbit Systems, Rafael, and Israel Aerospace Industries (IAI). The released materials also include engineering designs, information on components, and details of technical cooperation. #TGITM @TheGhostITM

نشر وثائق عن تعاون شركة Novamill مع الصناعات العسكرية التابعة للاحتلال الإسرائيلي نشرت جبهة الدعم السيبراني أجزاءً من وثائق داخلية لشركة Novamill Systems، بتبيّن تفاصيل تعاون الشركة في مجال القطع الصناعية والتكنولوجيا مع الصناعات العسكرية والفضائية التابعة للاحتلال الإسرائيلي. بتشمل الوثائق عقودًا، واتفاقيات تعاون، وتقارير فنية مرتبطة بشركات، منها Elbit Systems وRafael والصناعات الجوية الإسرائيلية (IAI). ومن بين الوثائق المنشورة مخططات هندسية، ومعلومات عن القطع، وتفاصيل عن أوجه التعاون التقني كمان. (Documents Released on Novamill’s Cooperation with Israeli Military Industries The Cyber Support Front has released portions of internal documents from Novamill Systems. The documents reportedly show details of the company’s cooperation in industrial components and technology with Israeli military and aerospace industries. The documents include contracts, cooperation agreements, and technical reports related to companies including Elbit Systems, Rafael, and Israel Aerospace Industries (IAI). The released materials also include engineering designs, information on components, and details of technical cooperation.) #TGITM @TheGhostITM

Cyberattack on Boston Scientific, a Medical Device Company Boston Scientific, a medical device company, has been targeted by a cyberattack that has disrupted its network and some operational systems globally. #TGITM

A large-scale DDoS attack has targeted the shared infrastructure of Norway's digital government services since Monday, causing disruptions to some public services.

From the refugee camps of Jordan rise voices no border can silence. Amani al-Jundi carries not only the dreams of her people, but the unbroken belief that Palestine will one day be free.

Repost from 𓂆 Palestine
Governments Are Blind, and We Are the Eyes By Amani al-Jundi In every age, there comes a moment when ordinary people must become the voice of the unheard. For the vulnerable, the oppressed, and those who have been pushed aside, activism is not a hobby or a slogan. It is a duty. When the world turns away, someone must stand and say what is happening, name the injustice, and refuse to let silence protect wrongdoing. Activism matters because power does not always correct itself. Many governments, institutions, and leaders respond only when pressure grows too loud to ignore. That is why activists are often the eyes of society. They see what others prefer not to see. They document suffering, expose corruption, challenge abuse, and remind the world that human beings are being hurt behind closed doors, in forgotten communities, and in places where the powerful expect no one to look. Yes, activism is hard. Often it feels like losing battle after battle. Change can be slow, exhausting, and painful. People get discouraged. Movements are mocked. Voices are ignored. Sometimes the truth is buried under politics, fear, or indifference. But losing battles does not mean losing the war. History is full of people who were dismissed in their time but were later recognized as the force that changed everything. Progress rarely arrives all at once. It is built through endurance, courage, and refusal to surrender. What keeps activists going is belief. Deep inside, they believe justice is stronger than fear, and truth is stronger than propaganda. They believe that if they do not give up, victory is still possible. A movement may stumble, but as long as it continues, it remains alive. Every protest, every article, every testimony, every act of solidarity is a step forward. Even when the result is not immediate, the struggle shapes the future. Activism also matters because it reminds society of its moral responsibility. It says that suffering should not be normalized. It says that power must be accountable. It says that human dignity is not negotiable. This is why activists speak even when their voices shake. They are not speaking out of hatred. They are speaking out of love for justice, for peace, and for a world where people are treated as human beings, not as numbers. So do not ignore the call. If you see injustice, do not look away. If you know the truth, do not stay silent. Stand with the vulnerable. Speak for the voiceless. Be part of the generation that refuses to accept cruelty as normal. We may lose many battles, but if we keep going, we can still win the war for justice, dignity, and freedom. Join the movement. Become an activist today.

Repost from 𓂆 Palestine
By Amani al-Jundi The fight over Warner Bros. Discovery has become a much larger story about media power, political influence, and the concentration of corporate control in the hands of one family. At the center of the takeover battle is David Ellison’s Paramount Skydance, backed by Oracle co-founder Larry Ellison, whose wealth and influence have made the bid one of the most closely watched media deals in years. Larry Ellison gave about $45 million to a Trump-supporting political nonprofit in 2024, money that helped bolster Trump’s election effort without going directly through the campaign. Ellison has also backed Friends of the IDF with large donations, including about $26 million. What gives this story added political weight is Oracle’s long-running relationship with Israel. Critics say the company’s software and infrastructure services have been used by Israeli state institutions at a time when Palestinians are facing mass displacement, bombardment, and a catastrophic humanitarian crisis in Gaza. Oracle executive Safra Catz has also drawn attention for describing the company’s work as providing Israel with powerful technology, language that critics say shows how deeply corporate systems are tied to state violence. That is why the public comments of actor Mark Ruffalo have mattered so much. Ruffalo has argued that criticism of Oracle’s role is not antisemitic, but a legitimate response to the way advanced technology can support oppression. He has warned that the Ellison family’s growing control over media and technology raises serious concerns about who gets to shape public narratives, especially when those narratives involve Palestine and Gaza. The Warner Bros. takeover fight is not taking place in a vacuum. It is happening in a media landscape already dominated by billionaire ownership, where decisions about news, entertainment, and political coverage can be influenced by the interests of a very small number of powerful families. If one family can help steer both a major technology company and a major entertainment empire, the question is not only whether the deal is legal. It is whether such concentration of power is healthy for democracy. For Palestinians, these concerns are not abstract. They are tied to everyday realities of occupation, displacement, surveillance, and war. Technology companies that support Israeli institutions are not neutral actors in that context. They are part of the systems that can deepen inequality and make oppression more efficient. That is why critics see the Ellison-Oracle network not just as a business story, but as part of a broader political structure that helps sustain Palestinian suffering while controlling the media conversation around it. Ruffalo’s intervention brought those issues into mainstream attention. By linking media consolidation, Oracle’s Israel ties, and the devastation in Gaza, he highlighted a pattern many activists have been pointing to for years: power in the boardroom often connects directly to power on the ground. The Warner Bros. deal has therefore become more than a corporate acquisition. It is a test of whether the public can still scrutinize the interests behind the institutions that shape culture, politics, and public opinion.

Who I Am—and Why I Write I was raised in the shadow of a classroom, inspired by a man who believed that knowledge could change lives: my father, a Palestinian professor of computer science from Lebanon who was appointed in 1980s. He taught programming, algorithms, operating systems, and the theory of computation. His office contained a terminal connected to the university’s mainframe—a small window into a rapidly changing world. I grew up witnessing his dedication, curiosity, and discipline, and his legacy shaped my own path. I studied computer science and cyber forensics. Today, at a young age, I am a professor of cybersecurity with experience in offensive security, threat intelligence, and AI policy. Technology is my profession, but truth is my responsibility. Why Journalism Belongs Here Some people may wonder why a cyber-resistance channel publishes investigative journalism and political articles. The answer is simple: journalism is part of who I am. I studied journalism because I believe information is a form of protection. Investigative writing exposes what powerful people try to hide, gives communities a voice, and preserves evidence when facts are threatened by silence, fear, or propaganda. Cyber resistance challenges oppression. Journalism protects the truth. Activism Is Part of Our Resistance I am an activist, and journalism is one of the ways I express my activism. For me, resistance is not limited to one form. It can take the form of research, documentation, education, digital security, storytelling, or standing beside people whose voices are being ignored. Every verified fact matters. Every honest article matters. Every person who refuses to look away matters. This channel may be associated with cyber operations and the broader field of cybersecurity, but its purpose is broader: to understand threats, challenge injustice, protect people, and defend the truth. About Our Team The main administrator is currently unavailable for security and personal-safety reasons. Her private life has been deeply affected by the recent Israeli-Lebanese conflict, and we ask viewers to respect her privacy. Until she can safely return, this space will continue sharing knowledge, analysis, investigations, and perspectives that matter. We will not allow fear to erase our voice. Our Message I am not only a cybersecurity professional. I am also a daughter, a researcher, a journalist, and an activist. My father taught me how computers work. Journalism taught me how power works. Digital security taught me how vulnerable people and systems can be; activism taught me to use that knowledge to defend truth, justice, and those most at risk. So, if you wonder why this channel speaks about politics—not only hacking and digital security—here is the answer: journalism is part of who we are, and activism is part of our resistance. Security is not limited to networks and devices; it is also about protecting people, defending the truth, pursuing justice, preserving memory, and ensuring that every voice has the right to be heard. Journalism is part of us. Activism is part of our resistance. Truth is the connection between them. — Yara Tabet (The Ghost In The Machine) With Palestinian roots, Lebanese pride, and the love of Jesus: Long live the Palestinian and Lebanese resistance.

Yemeni Cyberattack on the Zionist Regime's Power Grid The hacking group "Uways al-Qarani" (أويس القرني) claimed in a statement that it carried out a cyber operation against the Zionist regime's electricity infrastructure. The group stated that in this operation, the power grid's industrial control systems were targeted, and a large solar power plant near Tel Aviv, comprising more than 5,000 solar panels, was taken offline. Hebrew-language media covered the news with concern, and in referencing this attack, warned about the vulnerability of the Zionist regime's critical infrastructure to cyberattacks. This attack shows that Yemen has extended its confrontation with the Zionist regime into cyberspace, targeting the regime's critical infrastructure. #CyberAttack #Yemen #ZionistRegime #Hacking #CyberWarfare #TGITM @TheGhostITM