Sekoia.io blog
sekoia · B · active
French CTI vendor; strong European threat coverage. RSS at https://blog.sekoia.io/feed/ also works. 2026-05-08 audit: 5 dated 2026 articles (EvilTokens, APT28/.NET, Silver Fox). | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → rss: feed https://blog.sekoia.io/feed/ 5 (or webfetch the feed) then webfetch per-article URL for body. Homepage webfetch also works.. AVOID: Nothing blocks it. Feed and HTML both clean.. | 2026-07-05 admiralty audit: B — French/EU CTI vendor lab, original research; live. NOTE: blog.sekoia.io now 301-redirects to www.sekoia.com/blog and the RSS feed failed XML parsing — operator may want to update url/rss_url to www.sekoia.com/blog. Status stays active.
Cited in 9 entries
Citation cadence
Citation days per ISO week (6 weeks of coverage span, total 7).
- Research: ClickFix matured into a productised malware-as-a-service supply chain2026-06-22
- Sekoia: ErrTraffic — a ClickFix Malware-as-a-Service framework resolving C2 through the Polygon blockchain2026-06-17
- Sekoia: APT28 (GRU Unit 26165) tradecraft shifts to LLM-generated payloads and cloud-native C22026-06-14
- APT28 (GRU Unit 26165) — Sekoia documents a shift to LLM-generated payloads and cloud-native C22026-06-14
- Gamaredon weaponises WinRAR CVE-2025-8088 and adds the GammaSteel stealer2026-06-03
- Sekoia consolidates Gamaredon tooling under GammaPhish / GammaWorm, details an NTFS-ADS USB+network worm2026-06-02
- Gamaredon: GammaPhish → GammaWorm (NTFS ADS + USB) → GammaSteel (S3 exfil) — the week's most complete intrusion kill-chain disclosure2026-06-01
- Gamaredon — GammaPhish / GammaWorm / GammaSteel: Russian FSB campaign with USB worm and S3 exfiltration (Sekoia TDR part one)2026-06-01
- Tycoon2FA after the March 2026 takedown — OAuth Device Authorization Grant abuse on Microsoft 3652026-05-18