Analyzing an active vishing campaign using a Teams and email-bombing combination

I should be driving to Vegas but instead I am sitting here fucking around with some asshole’s C2 infrastructure.

An e-mail bomb was launched against LA County users together with a coordinated vishing attempt via Teams. The intent was to execute the malware package described here.

Exhaustive report below including the IOCs. Reach out if you want access to the full malware and investigation package but since this is currently active you should be able to fully reproduce everything based on the report below.

Understanding Key Security Indicators (KSIs)

FedRAMP 20X is sort of around the corner, switching from the old approach of framework reliance to the new evidence-based verification method. In plain English, instead of checking the Implemented box on the SSP, you now have to provide machine-readable evidence. There are 46 KSIs, and every one will require persistent evaluation. Start preparing now, because this process will become exponentially more expensive year over year. I have warned people about the inflation for over a decade; I have always been proven right.

What if you don’t care about FedRAMP? If you want/need to be NIST compliant and/or you are taking your security posture seriously, you should start to implement at least a limited set of indicators now, targeting a full implementation by the end of 2027. This method of compliance testing is going to be the norm going forward.

Do interrupt your enemy when they are making a mistake

Maybe I am the idiot. Maybe this is the perfect moment for OpenAI to take a victory lap around Anthropic and their epic Fable Face Palm. Maybe they read the room and decided the right move is to announce that their system escaped its sandbox and oh btw check out this cool chart showing how sad Fable is! /highfive

Or this is going to backfire…

The Guide to BSides Las Vegas (Updated for 2026)

August 3-5
Tuscany Hotel and Casino
BSides Las Vegas website
($100 Early Bird Donation, $500: Donor + 1)

This is what Black Hat used to be before Cyber Insurance was a thing. Buy your ticket early for the best deal or you will have to pay the donor price. If you are already part of the IT industry, chances are you will find something to interest you.

Guide to Black Hat (Updated for 2026)

August (5-6) Briefings and Business Hall
Mandalay Bay Convention Center Las Vegas
(1000$ for Business Pass, 3000$ Briefings)

Briefings Schedule

This is the premier Cyber Security conference. It offers different types of entry packages. Buy early to get a discount or convince your work to pay (as they should).