Visualização normal

Antes de ontemStream principal
  • ✇Cybersecurity News
  • NightmareEclipse Releases PoCs for Avast, Kaspersky, and NVIDIA Flaws Do Son
    Discover the details of three new NightmareEclipse vulnerabilities targeting Avast, Kaspersky, and NVIDIA components, lacking official vendor confirmation. Related Posts: CVE-2026-81934: Redis RCE PoC Exploit Now Public CVE-2026-78319: SAUTER Controller RCE Flaw Disclosed CVE-2026-82329 Exploited: JFrog Artifactory Admin Takeover The post NightmareEclipse Releases PoCs for Avast, Kaspersky, and NVIDIA Flaws appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Anthropic Issues Claude Security Warnings Do Son
    Anthropic is sending security warnings and deleting payment methods as info-stealing malware compromises Claude user sessions. Protect your account now. Related Posts: ToxNetV2 Botnet Integrates AI ToxicPanda 2.0 Banking Trojan Attacks Escalate Globally NPM Typosquatting Malware Targets WSL Developers The post Anthropic Issues Claude Security Warnings appeared first on Daily CyberSecurity.
     

Anthropic Issues Claude Security Warnings

Por:Do Son
31 de Agosto de 2026, 07:23

Anthropic is sending security warnings and deleting payment methods as info-stealing malware compromises Claude user sessions. Protect your account now.

Related Posts:

The post Anthropic Issues Claude Security Warnings appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • NCSC Warns of Physical Disruptions from Cyberattacks on OT Systems Do Son
    The UK NCSC warns of rising cyberattacks on operational technology, urging organizations to secure internet-exposed industrial systems against physical disruptions. Related Posts: Google Tracks Russian Cyber Espionage Clusters OpenAI Disrupts Russian Influence Campaign Promoting Fake Think Tank NIST Asks for Help Putting People First in Cybersecurity The post NCSC Warns of Physical Disruptions from Cyberattacks on OT Systems appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Fire Ant Threat Actor Targets Trusted Infrastructure Do Son
    The Fire Ant threat actor uses trusted infrastructure compromise to breach high-value targets. Discover how this group evades detection in networks. Related Posts: ValleyRAT Backdoor Spread via Signed Chinese Adware UAT-10147 Deploys SPECTRE Cross-Platform Implant Kimsuky Spear Phishing Abuses Remote Control Tools The post Fire Ant Threat Actor Targets Trusted Infrastructure appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • TeamPCP Hackers Arrested in Joint Operation Do Son
    Discover the details of the TeamPCP hackers arrested in Australia for executing devastating open-source supply chain attacks using the Mini Shai-Hulud worm. Related Posts: FBI Seizes QScan and QTRouter Platforms Run by China State Hackers SilkParasite APT Hits Central Asian Governments With 7 RATs Operation CameraSwarm: 14,500 Dahua Cameras Compromised Across Ukraine and Russia The post TeamPCP Hackers Arrested in Joint Operation appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Mercor Data Breach Targets AI Supply Chain Do Son
    Discover the details of the massive Mercor data breach exposing 4TB of recruiting data for OpenAI, Google, Meta, and Microsoft. Related Posts: Meta Settles Child Privacy Lawsuit Rapidly Exposed Git Repositories Leak Critical Cloud Secrets Take-Two Subpoenas Microsoft and Discord Over GTA VI "Cyberleek" Leaks The post Mercor Data Breach Targets AI Supply Chain appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Jewelbug APT Group Operations Combine Espionage and Fraud Do Son
    The Jewelbug APT group runs espionage alongside cryptocurrency scams. Read our report on Jewelbug APT group operations. Related Posts: Cisco Talos Discovers JWR Phishing Framework US Agencies Warn of AI-Generated Exploits Targeting Siemens S7 PLCs PATCHCORD Malware Hits Afghan Telecom in New APT36 Campaign The post Jewelbug APT Group Operations Combine Espionage and Fraud appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Cisco Talos Discovers JWR Phishing Framework Do Son
    Cisco Talos discovered the JWR phishing framework, a new PhaaS variant. Read our JWR phishing framework analysis to learn about this real-time cyber threat. Related Posts: Jewelbug APT Group Operations Combine Espionage and Fraud US Agencies Warn of AI-Generated Exploits Targeting Siemens S7 PLCs PATCHCORD Malware Hits Afghan Telecom in New APT36 Campaign The post Cisco Talos Discovers JWR Phishing Framework appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Armored Likho Still Toolkit Deploys Covert Spying Implants Do Son
    Kaspersky uncovered the Armored Likho Still Toolkit. Read our Armored Likho Still Toolkit analysis to explore the Telegram stealer and audio spying tools. Related Posts: PATCHCORD Malware Hits Afghan Telecom in New APT36 Campaign HoneyMyte CoolClient Rootkit Deploys Kernel Driver DOJ Charges 17 Iranians in Mabna Institute Cyber Theft The post Armored Likho Still Toolkit Deploys Covert Spying Implants appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Abyssos Modular RAT: Zscaler ThreatLabz Analysis Do Son
    Zscaler ThreatLabz analysts discovered the Abyssos modular RAT. This Abyssos RAT gives attackers total remote control, stealing data and credentials. Related Posts: GEEKOM Mini PC Driver Downloads Found Bundled With Backdoor Since 2024 Aeternum Blockchain Botnet Hides C2 Commands in Polygon Smart Contracts DCRat Campaign Uses SVG HTML Smuggling to Deliver DarkCrystal RAT The post Abyssos Modular RAT: Zscaler ThreatLabz Analysis appeared first on Daily CyberSecurity.
     
  • ✇Open Source Intelligence Brasil
  • A Investigação Digital osintbrasil.blogspot.com
    RDS | Investigação Defensiva & Perícia OSINT — Rogério Souza (@RDSWEB) RDS · @RDSWEB · Investigação Digital Defensiva Prova digital que resiste ao contraditório. "Quem não controla a informação, vira alvo dela." Investigação defensiva, OSINT, CTI e SOCMINT aplicados à defesa técnica — para advogados, departamentos jurídicos e compliance corporativo. Falar no WhatsApp Ver no LinkedIn Perfil Sobre Rogério
     

A Investigação Digital




RDS | Investigação Defensiva & Perícia OSINT — Rogério Souza (@RDSWEB)
RDS · @RDSWEB · Investigação Digital Defensiva

Prova digital que resiste ao contraditório.

"Quem não controla a informação, vira alvo dela." Investigação defensiva, OSINT, CTI e SOCMINT aplicados à defesa técnica — para advogados, departamentos jurídicos e compliance corporativo.

Perfil

Sobre Rogério Souza (RDS)

Toda decisão estratégica nasce da mesma pergunta: quem sabe mais, decide primeiro. Rogério Souza atua na linha de frente da ciberinteligência, cibersegurança e contraespionagem, transformando dados dispersos em vantagem decisória para quem não pode se dar ao luxo de ser surpreendido.

Com especialização em Segurança da Informação pela ULT Grupo América, construiu sua trajetória em parceria com a MPSafe CyberSecurity & CounterEspionage e com atuação junto ao CIASC — Centro de Informática e Automação do Estado de Santa Catarina, somando-se a diversos cases de sucesso em investigação digital, due diligence e proteção de marca para clientes corporativos e jurídicos. Opera como Analista de Open Source Intelligence (OSINT) — planejando e conduzindo operações de coleta de informação, mitigação de risco e produção de inteligência estratégica nas frentes política, militar, econômico-financeira, criminal, social e de contrapropaganda. Para o C-level, isso se traduz em cenários antecipados antes de virarem crise, leitura profunda do ambiente competitivo e decisões blindadas por inteligência verificável — não por achismo.

Sua trajetória inclui vivência em cyber comando privado, com estágio internacional e participação em operações globais de caráter cibernético, antecipando e neutralizando anormalidades, crimes cibernéticos e ataques, com identificação de agentes e grupos. Atua na instrução de fontes abertas (OSINT) e, a convite, apoia ações de polícia e agências governamentais nacionais e internacionais — um nível de confiança que poucos profissionais do mercado carregam.

Faz parte do time de instrutores do Criminal Player, a maior comunidade de direito criminal do Brasil, formando advogados e profissionais do direito em investigação digital, prova técnica e metodologia OSINT aplicada ao processo penal. É autor de curso e apresentação técnica sobre Open Source Intelligence (OSINT), utilizada como material de referência para formação de investigadores e defensores técnicos.

Sua atuação é construída em rede: parcerias recorrentes com advogados criminalistas, peritos e demais profissionais de cybersecurity, CTI, InfoSec e SOCMINT para a resolução conjunta de casos complexos — combinando profundidade técnica investigativa com defensibilidade jurídica em cada entrega.

Tem experiência consolidada em compliance e mitigação de risco, apoiando empresas e escritórios na antecipação de exposições reputacionais, regulatórias e probatórias antes que se tornem contencioso. Atendimento 100% virtual, para todo o Brasil.

Atuação

Frentes de Investigação Defensiva

Processo Penal

Investigação defensiva

Coleta e análise técnica de provas favoráveis à defesa, com metodologia documentada e rastreável, pronta para o contraditório.

Perícia

Cadeia de custódia digital

Preservação e documentação de evidências digitais com integridade probatória, do primeiro contato ao laudo final.

Inteligência

OSINT, CTI & SOCMINT

Inteligência de fontes abertas, ciclo formal de inteligência e Diamond Model aplicados a investigações e due diligence.

Formação

Treinamento jurídico e institucional

Capacitação de advogados e forças de aplicação da lei em investigação digital, via Criminal Player e programas próprios.

Corporativo

Compliance & mitigação de risco

Due diligence, identificação de exposição digital e planos de mitigação antes da judicialização ou crise reputacional.

Colaboração

Rede multidisciplinar

Atuação conjunta com advogados, peritos e especialistas em cybersecurity/infosec para casos de alta complexidade.

Impacto Organizacional

Por que investigação defensiva importa para a empresa

CEO / BoardContinuidade e risco reputacional sob controle antes de virar manchete.
JurídicoProvas tecnicamente defensáveis e aderentes à LGPD.
ComplianceDue diligence e evidência estruturada para decisões regulatórias.
CFOExposição financeira mapeada antes da escalada do litígio.
AuditoriaRastreabilidade de evidências e cadeia de custódia documentada.
RHIdentificação de risco interno com abordagem discreta e legal.
Credenciais

Formação e Trajetória

  • Especialização em Segurança da Informação — ULT Grupo América
  • Ciberinteligência, Cibersegurança e Contraespionagem — em parceria com a MPSafe CyberSecurity & CounterEspionage
  • Atuação junto ao CIASC — Centro de Informática e Automação do Estado de Santa Catarina
  • Diversos cases de sucesso em investigação digital, due diligence e proteção de marca para clientes corporativos e jurídicos
  • Instrutor de investigação digital — Criminal Player (maior comunidade de direito criminal do Brasil)
  • Autor de curso e apresentação técnica sobre OSINT (RDSWEB)
  • Estágio internacional em cyber comando privado e operações globais de inteligência proativa
  • Rede de colaboração com advogados, peritos e especialistas em CTI/InfoSec/SOCMINT
Dúvidas

Perguntas Frequentes

O que é investigação defensiva?

É a coleta, análise e documentação técnica de provas digitais e de fontes abertas a favor da defesa em processos judiciais, administrativos ou de compliance, sempre observando cadeia de custódia e legalidade probatória.

Como o OSINT é usado como prova técnica em um processo?

Dados publicamente disponíveis são coletados, correlacionados e documentados com metodologia rastreável, permitindo que o laudo seja submetido ao contraditório e resista a questionamentos técnicos da parte contrária.

O atendimento é presencial?

Não. O atendimento é 100% virtual, para advogados, escritórios e empresas em todo o Brasil, via WhatsApp e videochamada.

  • ✇Cybersecurity News
  • Kimwolf Botnet Malware Upgrades DDoS and C2 Defenses Do Son
    Palo Alto Networks analyzed Kimwolf botnet malware. Read our Kimwolf botnet malware analysis to learn how it attacks Android TV boxes. Related Posts: Project CAV3RN Framework Adds DNS and Google Relays DeadLock Ransomware Employs Decentralized Infrastructure Apple Sends Mercenary Spyware Alerts to Users in 110+ Countries The post Kimwolf Botnet Malware Upgrades DDoS and C2 Defenses appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Project CAV3RN Framework Adds DNS and Google Relays Do Son
    Kaspersky analyzed the Project CAV3RN framework. Read our Project CAV3RN framework analysis to see how attackers abuse DNS and Google Apps Script. Related Posts: Kimwolf Botnet Malware Upgrades DDoS and C2 Defenses DeadLock Ransomware Employs Decentralized Infrastructure Apple Sends Mercenary Spyware Alerts to Users in 110+ Countries The post Project CAV3RN Framework Adds DNS and Google Relays appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • DeadLock Ransomware Employs Decentralized Infrastructure Do Son
    DeadLock ransomware uses blockchain nodes and Session chat. Learn how the DeadLock ransomware encryptor targets networks worldwide. Related Posts: Kimwolf Botnet Malware Upgrades DDoS and C2 Defenses Project CAV3RN Framework Adds DNS and Google Relays Apple Sends Mercenary Spyware Alerts to Users in 110+ Countries The post DeadLock Ransomware Employs Decentralized Infrastructure appeared first on Daily CyberSecurity.
     
  • ✇Open Source Intelligence Brasil
  • Quer um diagnóstico da exposição real da sua empresa? osintbrasil.blogspot.com
    Tutorial: Implantando Governança de Identidade Não-Humana | RDS @RDSWEB RDS // intelligence & digital investigation @RDSWEB LinkedIn Facebook Tutorial / Implantação / Governança de IA A Hipótese 3 do nosso raio-x sobre o que o CEO quer da segurança da informação apontava um vácuo real: agentes de IA, bots e service accounts operando com privilégio que ninguém formalmente concedeu. Aqui está o passo a passo para fechar esse vác
     

Quer um diagnóstico da exposição real da sua empresa?

Tutorial: Implantando Governança de Identidade Não-Humana | RDS @RDSWEB
RDS // intelligence & digital investigation
Tutorial / Implantação / Governança de IA

A Hipótese 3 do nosso raio-x sobre o que o CEO quer da segurança da informação apontava um vácuo real: agentes de IA, bots e service accounts operando com privilégio que ninguém formalmente concedeu. Aqui está o passo a passo para fechar esse vácuo antes que ele vire incidente — ou processo.

Nível: Implantação prática Público: CISO, TI, Compliance, Jurídico Pré-requisito: Inventário de sistemas e diretório de identidade existente

Por que "identidade não-humana" virou perímetro

Todo controle de acesso corporativo foi desenhado em torno de uma premissa: existe uma pessoa do outro lado do login. Essa premissa quebrou. Hoje um agente de IA pode abrir chamado, consultar banco de dados, aprovar fluxo, gerar relatório e se comunicar com outro sistema — sem que ninguém tenha preenchido formulário de acesso, assinado termo de responsabilidade ou passado por processo de desligamento quando o projeto acabou.

Isso não é uma falha de ferramenta. É a ausência de um processo formal de ciclo de vida para um tipo de identidade que a maioria das políticas de segurança brasileiras simplesmente não prevê ainda. O objetivo deste tutorial é fechar esse vácuo com um processo replicável, não com mais uma licença de software.

Atenção: antes de qualquer ferramenta, o problema aqui é de processo e responsabilidade. Comprar uma plataforma de gestão de identidade não resolve nada se ninguém for dono do ciclo de vida do agente.

O passo a passo

Passo 1 — Descoberta (encontre o que você não sabe que existe)

Faça o inventário de identidades não-humanas em produção

Antes de governar, é preciso enxergar. Levante, sistema por sistema, toda credencial que não pertence a uma pessoa física: chaves de API, service accounts, tokens OAuth de integração, webhooks, copilotos plugados em ferramentas de produtividade, agentes autônomos e bots de automação (RPA). Cruze três fontes: o diretório de identidade (Active Directory / Azure AD / Okta), os logs de acesso das plataformas SaaS críticas, e o cofre de segredos (secrets manager), se existir.

Em paralelo, rode uma varredura de Shadow AI: pergunte a cada gestor de área, por escrito, "quais ferramentas de IA sua equipe usa hoje que não passaram pela aprovação de TI?". A resposta honesta costuma revelar mais do que qualquer scanner técnico.

Por que isso importa: pesquisas com CISOs de grandes empresas mostram que a maior parte das identidades de IA hoje em produção nunca passou por aprovação formal — elas simplesmente apareceram junto com a adoção orgânica de ferramentas.
Passo 2 — Classificação (nem toda identidade carrega o mesmo risco)

Classifique cada identidade não-humana por criticidade de acesso

Construa uma matriz simples com três eixos: o que o agente acessa (dado pessoal, dado financeiro, propriedade intelectual, sistema operacional crítico), o que ele pode fazer (só ler, ou também escrever/executar/aprovar) e quem é o dono humano responsável por aquele agente dentro da organização. Todo agente sem dono humano identificado entra automaticamente na categoria de risco mais alta até ser regularizado.

Nível 1 — Leitura de dado público / interno não sensível
Nível 2 — Leitura de dado sensível ou pessoal (LGPD)
Nível 3 — Escrita/execução em sistema operacional
Nível 4 — Aprovação financeira, jurídica ou decisória
Nível 5 — Acesso irrestrito / privilégio administrativo
Por que isso importa: sem classificação, toda a governança vira burocracia genérica aplicada igualmente a um bot de FAQ e a um agente com acesso a folha de pagamento — o que garante que ninguém leve a política a sério.
Passo 3 — Menor privilégio (corte o que sobra)

Aplique privilégio mínimo e segregação de função também para agentes

Nenhum agente de IA deveria ter, por padrão, mais acesso do que a tarefa específica exige. Revogue permissões herdadas "por conveniência" no momento da criação e substitua credenciais compartilhadas por credenciais únicas e escopadas por agente — nunca uma chave de API genérica reutilizada em cinco automações diferentes. Sempre que possível, separe o agente que dado do agente que age sobre esse dado.

Por que isso importa: a maior parte dos incidentes envolvendo automação não vem de invasão externa — vem de um agente que tinha permissão de sobra sendo usado (por erro ou por ataque) fora do escopo para o qual foi criado.
Passo 4 — Ciclo de vida formal (nasce, muda, morre)

Trate cada agente como um funcionário com admissão, mudança de cargo e desligamento

Formalize três momentos obrigatórios: provisionamento (todo novo agente exige solicitação registrada, dono humano nomeado e justificativa de acesso), revisão periódica (a cada 90 dias, o dono confirma por escrito que o agente ainda é necessário e que o escopo de acesso continua correto) e desligamento formal (quando o projeto termina, o time muda ou a ferramenta é substituída, a credencial é revogada no mesmo dia — não "quando alguém lembrar").

Por que isso importa: a maioria das credenciais comprometidas em incidentes reais não são credenciais ativas sendo mal usadas — são credenciais de projetos encerrados que ninguém desligou.
Passo 5 — Monitoramento contínuo (comportamento, não só acesso)

Monitore o comportamento do agente, não apenas se ele tem permissão

Ter acesso autorizado não significa comportamento normal. Estabeleça uma linha de base de comportamento esperado para cada identidade não-humana (volume de chamadas, horário de execução, escopo de dado tocado) e alerte sobre desvios: um agente que normalmente consulta 200 registros por dia e de repente consulta 40 mil merece investigação, mesmo estando dentro da permissão técnica que possui.

Por que isso importa: em ataques que sequestram credenciais legítimas, o comportamento anômalo costuma aparecer semanas antes de qualquer alerta tradicional de segurança disparar.
Passo 6 — Auditoria e evidência (documente para o Jurídico e o Conselho)

Produza evidência formal de que o processo existe e está sendo seguido

Mantenha registro auditável de cada decisão: quem aprovou o acesso, quando foi revisado pela última vez, e quando foi revogado. Esse não é um exercício burocrático — é exatamente o tipo de evidência de diligência prévia que protege administradores de responsabilização pessoal em caso de incidente, sob a LGPD e sob o Marco Civil da Internet.

Por que isso importa: em qualquer investigação pós-incidente, a pergunta decisiva não é "o ataque foi sofisticado?" — é "a organização conseguia demonstrar controle sobre quem/o que tinha acesso ao dado comprometido?".

Matriz de responsabilidade sugerida

EtapaResponsável sugeridoFrequência
Descoberta e inventárioTI / Segurança da InformaçãoContínua, com varredura formal trimestral
Classificação de riscoSegurança da Informação + área de negócio dona do agenteNo provisionamento e a cada mudança de escopo
Aprovação de acessoGestor da área + Segurança da InformaçãoNo provisionamento
Revisão de privilégioDono humano do agenteA cada 90 dias
DesligamentoTI, mediante confirmação do donoImediato ao fim do uso
Auditoria e evidênciaCompliance / Auditoria internaSemestral

O que isso significa sob a lei brasileira

Base legal para justificar o investimento internamente
  • LGPD — um agente de IA com acesso não governado a dado pessoal é, na prática, um ponto de tratamento de dado sem controlador claro, o que agrava a responsabilização em caso de incidente.
  • Marco Civil da Internet — a guarda de registros de acesso e uso precisa contemplar também identidades não-humanas, sob pena de lacuna probatória em investigação futura.
  • Resolução BCB nº 493/2025 — para empresas do setor financeiro, gestão de risco cibernético de terceiros e de automações já é exigência regulatória explícita, não boa prática opcional.

Checklist rápido de implantação

  • Inventário completo de identidades não-humanas concluído e validado com gestores de área
  • Matriz de classificação de risco aplicada a cada agente identificado
  • Todo agente sem dono humano nomeado foi regularizado ou desativado
  • Processo formal de provisionamento e desligamento documentado e comunicado
  • Linha de base de comportamento estabelecida para agentes de risco alto
  • Evidência de revisão periódica armazenada para consulta de auditoria e Jurídico

Quer um diagnóstico da exposição real da sua empresa?

RDS conduz levantamento de identidades não-humanas, due diligence digital e produção de evidência técnico-jurídica para blindagem de Conselho, Compliance e Jurídico — atendimento 100% virtual, sem deslocamento.

Uma produção de RDS @RDSWEB — inteligência cibernética, OSINT e investigação digital defensiva. Acompanhe também no Facebook OSINT Brasil.

Fale com RDS 47 98861-8255
Gostou? Te ajudou? Pague-me um café via PIX 47 98861-8255
  • ✇Security Boulevard
  • The Dark Web Explained with John Hammond Tom Eston
    The dark web is often misunderstood, but it plays an important role in both privacy technology and cybercrime activity. In this episode, Tom Eston speaks with cybersecurity researcher and educator John Hammond about what the dark web actually is and how it has evolved in recent years. The discussion covers underground marketplaces, ransomware leak sites, […] The post The Dark Web Explained with John Hammond appeared first on Shared Security Podcast. The post The Dark Web Explained with John Hamm
     

The Dark Web Explained with John Hammond

13 de Abril de 2026, 01:00

The dark web is often misunderstood, but it plays an important role in both privacy technology and cybercrime activity. In this episode, Tom Eston speaks with cybersecurity researcher and educator John Hammond about what the dark web actually is and how it has evolved in recent years. The discussion covers underground marketplaces, ransomware leak sites, […]

The post The Dark Web Explained with John Hammond appeared first on Shared Security Podcast.

The post The Dark Web Explained with John Hammond appeared first on Security Boulevard.

💾

  • ✇Security Boulevard
  • TikTok’s New U.S. Deal and Privacy Policy: What Users Don’t Understand Tom Eston
    TikTok has shifted to a majority-American entity, TikTok USDS Joint Venture, LLC, to comply with U.S. national security requirements and avoid a ban. This week we discuss why a recent privacy policy update went viral—especially language about sensitive data like immigration status and precise location—and argue much of it reflects longstanding practices and required California […] The post TikTok’s New U.S. Deal and Privacy Policy: What Users Don’t Understand appeared first on Shared Security Po
     
  • ✇Krebs on Security
  • Drones to Diplomas: How Russia’s Largest Private University is Linked to a $25M Essay Mill BrianKrebs
    A sprawling academic cheating network turbocharged by Google Ads that has generated nearly $25 million in revenue has curious ties to a Kremlin-connected oligarch whose Russian university builds drones for Russia’s war against Ukraine. The Nerdify homepage. The link between essay mills and Russian attack drones might seem improbable, but understanding it begins with a simple question: How does a human-intensive academic cheating service stay relevant in an era when students can simply ask AI to
     

Drones to Diplomas: How Russia’s Largest Private University is Linked to a $25M Essay Mill

6 de Dezembro de 2025, 11:45

A sprawling academic cheating network turbocharged by Google Ads that has generated nearly $25 million in revenue has curious ties to a Kremlin-connected oligarch whose Russian university builds drones for Russia’s war against Ukraine.

The Nerdify homepage.

The link between essay mills and Russian attack drones might seem improbable, but understanding it begins with a simple question: How does a human-intensive academic cheating service stay relevant in an era when students can simply ask AI to write their term papers? The answer – recasting the business as an AI company – is just the latest chapter in a story of many rebrands that link the operation to Russia’s largest private university.

Search in Google for any terms related to academic cheating services — e.g., “help with exam online” or “term paper online” — and you’re likely to encounter websites with the words “nerd” or “geek” in them, such as thenerdify[.]com and geekly-hub[.]com. With a simple request sent via text message, you can hire their tutors to help with any assignment.

These nerdy and geeky-branded websites frequently cite their “honor code,” which emphasizes they do not condone academic cheating, will not write your term papers for you, and will only offer support and advice for customers. But according to This Isn’t Fine, a Substack blog about contract cheating and essay mills, the Nerdify brand of websites will happily ignore that mantra.

“We tested the quick SMS for a price quote,” wrote This Isn’t Fine author Joseph Thibault. “The honor code references and platitudes apparently stop at the website. Within three minutes, we confirmed that a full three-page, plagiarism- and AI-free MLA formatted Argumentative essay could be ours for the low price of $141.”

A screenshot from Joseph Thibault’s Substack post shows him purchasing a 3-page paper with the Nerdify service.

Google prohibits ads that “enable dishonest behavior.” Yet, a sprawling global essay and homework cheating network run under the Nerdy brands has quietly bought its way to the top of Google searches – booking revenues of almost $25 million through a maze of companies in Cyprus, Malta and Hong Kong, while pitching “tutoring” that delivers finished work that students can turn in.

When one Nerdy-related Google Ads account got shut down, the group behind the company would form a new entity with a front-person (typically a young Ukrainian woman), start a new ads account along with a new website and domain name (usually with “nerdy” in the brand), and resume running Google ads for the same set of keywords.

UK companies belonging to the group that have been shut down by Google Ads since Jan 2025 include:

Proglobal Solutions LTD (advertised nerdifyit[.]com);
AW Tech Limited (advertised thenerdify[.]com);
Geekly Solutions Ltd (advertised geekly-hub[.]com).

Currently active Google Ads accounts for the Nerdify brands include:

-OK Marketing LTD (advertising geekly-hub[.]net⁩), formed in the name of Olha Karpenko, a young Ukrainian woman;
Two Sigma Solutions LTD (advertising litero[.]ai), formed in the name of Olekszij (Alexey) Pokatilo.

Google’s Ads Transparency page for current Nerdify advertiser OK Marketing LTD.

Mr. Pokatilo has been in the essay-writing business since at least 2009, operating a paper-mill enterprise called Livingston Research alongside Alexander Korsukov, who is listed as an owner. According to a lengthy account from a former employee, Livingston Research mainly farmed its writing tasks out to low-cost workers from Kenya, Philippines, Pakistan, Russia and Ukraine.

Pokatilo moved from Ukraine to the United Kingdom in Sept. 2015 and co-founded a company called Awesome Technologies, which pitched itself as a way for people to outsource tasks by sending a text message to the service’s assistants.

The other co-founder of Awesome Technologies is 36-year-old Filip Perkon, a Swedish man living in London who touts himself as a serial entrepreneur and investor. Years before starting Awesome together, Perkon and Pokatilo co-founded a student group called Russian Business Week while the two were classmates at the London School of Economics. According to the Bulgarian investigative journalist Christo Grozev, Perkon’s birth certificate was issued by the Soviet Embassy in Sweden.

Alexey Pokatilo (left) and Filip Perkon at a Facebook event for startups in San Francisco in mid-2015.

Around the time Perkon and Pokatilo launched Awesome Technologies, Perkon was building a social media propaganda tool called the Russian Diplomatic Online Club, which Perkon said would “turbo-charge” Russian messaging online. The club’s newsletter urged subscribers to install in their Twitter accounts a third-party app called Tweetsquad that would retweet Kremlin messaging on the social media platform.

Perkon was praised by the Russian Embassy in London for his efforts: During the contentious Brexit vote that ultimately led to the United Kingdom leaving the European Union, the Russian embassy in London used this spam tweeting tool to auto-retweet the Russian ambassador’s posts from supporters’ accounts.

Neither Mr. Perkon nor Mr. Pokatilo replied to requests for comment.

A review of corporations tied to Mr. Perkon as indexed by the business research service North Data finds he holds or held director positions in several U.K. subsidiaries of Synergy University, Russia’s largest private education provider. Synergy has more than 35,000 students, and sells T-shirts with patriotic slogans such as “Crimea is Ours,” and “The Russian Empire — Reloaded.”

The president of Synergy University is Vadim Lobov, a Kremlin insider whose headquarters on the outskirts of Moscow reportedly features a wall-sized portrait of Russian President Vladimir Putin in the pop-art style of Andy Warhol. For a number of years, Lobov and Perkon co-produced a cross-cultural event in the U.K. called Russian Film Week.

Synergy President Vadim Lobov and Filip Perkon, speaking at a press conference for Russian Film Week, a cross-cultural event in the U.K. co-produced by both men.

Mr. Lobov was one of 11 individuals reportedly hand-picked by the convicted Russian spy Marina Butina to attend the 2017 National Prayer Breakfast held in Washington D.C. just two weeks after President Trump’s first inauguration.

While Synergy University promotes itself as Russia’s largest private educational institution, hundreds of international students tell a different story. Online reviews from students paint a picture of unkept promises: Prospective students from Nigeria, Kenya, Ghana, and other nations paying thousands in advance fees for promised study visas to Russia, only to have their applications denied with no refunds offered.

“My experience with Synergy University has been nothing short of heartbreaking,” reads one such account. “When I first discovered the school, their representative was extremely responsive and eager to assist. He communicated frequently and made me believe I was in safe hands. However, after paying my hard-earned tuition fees, my visa was denied. It’s been over 9 months since that denial, and despite their promises, I have received no refund whatsoever. My messages are now ignored, and the same representative who once replied instantly no longer responds at all. Synergy University, how can an institution in Europe feel comfortable exploiting the hopes of Africans who trust you with their life savings? This is not just unethical — it’s predatory.”

This pattern repeats across reviews by multilingual students from Pakistan, Nepal, India, and various African nations — all describing the same scheme: Attractive online marketing, promises of easy visa approval, upfront payment requirements, and then silence after visa denials.

Reddit discussions in r/Moscow and r/AskARussian are filled with warnings. “It’s a scam, a diploma mill,” writes one user. “They literally sell exams. There was an investigation on Rossiya-1 television showing students paying to pass tests.”

The Nerdify website’s “About Us” page says the company was co-founded by Pokatilo and an American named Brian Mellor. The latter identity seems to have been fabricated, or at least there is no evidence that a person with this name ever worked at Nerdify.

Rather, it appears that the SMS assistance company co-founded by Messrs. Pokatilo and Perkon (Awesome Technologies) fizzled out shortly after its creation, and that Nerdify soon adopted the process of accepting assignment requests via text message and routing them to freelance writers.

A closer look at an early “About Us” page for Nerdify in The Wayback Machine suggests that Mr. Perkon was the real co-founder of the company: The photo at the top of the page shows four people wearing Nerdify T-shirts seated around a table on a rooftop deck in San Francisco, and the man facing the camera is Perkon.

Filip Perkon, top right, is pictured wearing a Nerdify T-shirt in an archived copy of the company’s About Us page. Image: archive.org.

Where are they now? Pokatilo is currently running a startup called Litero.Ai, which appears to be an AI-based essay writing service. In July 2025, Mr. Pokatilo received pre-seed funding of $800,000 for Litero from an investment program backed by the venture capital firms AltaIR Capital, Yellow Rocks, Smart Partnership Capital, and I2BF Global Ventures.

Meanwhile, Filip Perkon is busy setting up toy rubber duck stores in Miami and in at least three locations in the United Kingdom. These “Duck World” shops market themselves as “the world’s largest duck store.”

This past week, Mr. Lobov was in India with Putin’s entourage on a charm tour with India’s Prime Minister Narendra Modi. Although Synergy is billed as an educational institution, a review of the company’s sprawling corporate footprint (via DNS) shows it also is assisting the Russian government in its war against Ukraine.

Synergy University President Vadim Lobov (right) pictured this week in India next to Natalia Popova, a Russian TV presenter known for her close ties to Putin’s family, particularly Putin’s daughter, who works with Popova at the education and culture-focused Innopraktika Foundation.

The website bpla.synergy[.]bot, for instance, says the company is involved in developing combat drones to aid Russian forces and to evade international sanctions on the supply and re-export of high-tech products.

A screenshot from the website of synergy,bot shows the company is actively engaged in building armed drones for the war in Ukraine.

KrebsOnSecurity would like to thank the anonymous researcher NatInfoSec for their assistance in this investigation.

Update, Dec. 8, 10:06 a.m. ET: Mr. Pokatilo responded to requests for comment after the publication of this story. Pokatilo said he has no relation to Synergy nor to Mr. Lobov, and that his work with Mr. Perkon ended with the dissolution of Awesome Technologies.

“I have had no involvement in any of his projects and business activities mentioned in the article and he has no involvement in Litero.ai,” Pokatilo said of Perkon.

Mr. Pokatilo said his new company Litero “does not provide contract cheating services and is built specifically to improve transparency and academic integrity in the age of universal use of AI by students.”

“I am Ukrainian,” he said in an email. “My close friends, colleagues, and some family members continue to live in Ukraine under the ongoing invasion. Any suggestion that I or my company may be connected in any way to Russia’s war efforts is deeply offensive on a personal level and harmful to the reputation of Litero.ai, a company where many team members are Ukrainian.”

Update, Dec. 11, 12:07 p.m. ET: Mr. Perkon responded to requests for comment after the publication of this story. Perkon said the photo of him in a Nerdify T-shirt (see screenshot above) was taken after a startup event in San Francisco, where he volunteered to act as a photo model to help friends with their project.

“I have no business or other relations to Nerdify or any other ventures in that space,” Mr. Perkon said in an email response. “As for Vadim Lobov, I worked for Venture Capital arm at Synergy until 2013 as well as his business school project in the UK, that didn’t get off the ground, so the company related to this was made dormant. Then Synergy kindly provided sponsorship for my Russian Film Week event that I created and ran until 2022 in the U.K., an event that became the biggest independent Russian film festival outside of Russia. Since the start of the Ukraine war in 2022 I closed the festival down.”

“I have had no business with Vadim Lobov since 2021 (the last film festival) and I don’t keep track of his endeavours,” Perkon continued. “As for Alexey Pokatilo, we are university friends. Our business relationship has ended after the concierge service Awesome Technologies didn’t work out, many years ago.”

  • ✇Posts By SpecterOps Team Members - Medium
  • The SQL Server Crypto Detour Adam Chester
    As part of my role as Service Architect here at SpecterOps, one of the things I’m tasked with is exploring all kinds of technologies to help those on assessments with advancing their engagement.Not long after starting this new role, I was approached with an interesting problem. A SQL Server database backup for a ManageEngine’s ADSelfService Plus product had been recovered and, while the team had walked through the database recovery, SQL Server database encryption was in use. With a ticking clock
     

The SQL Server Crypto Detour

As part of my role as Service Architect here at SpecterOps, one of the things I’m tasked with is exploring all kinds of technologies to help those on assessments with advancing their engagement.

Not long after starting this new role, I was approached with an interesting problem. A SQL Server database backup for a ManageEngine’s ADSelfService Plus product had been recovered and, while the team had walked through the database recovery, SQL Server database encryption was in use. With a ticking clock, the request was clear… can we do anything to recover sensitive information from the database with only a .bak file available?

One of the things that I love about this job is getting to dig into various technologies and seeing the resulting research being used in real-time. After some research, we had decryption keys, a method of decrypting sensitive data, and DA credentials extracted and ready to go!

This post will explore how this was done, look at how SQL Server encryption works, introduce some new methods of brute-forcing database encryption keys, and show a mistake in ManageEngine’s ADSelfService product which allows compromised database backups to reveal privileged credentials.

Manage Engine Protected Data

Let’s start with Manage Engine’s ADSelfService product. Documentation shows that Domain Admin credentials are likely present:

If we setup this tool in a lab environment, we find encrypted fields such as the below USER_NAME column:

Further, if we review the configuration of the database, we see that this is SQL Server’s builtin encryption functionality that is being used to protect these fields. So the mission is clear: we need to understand SQL Server Encryption before we can hope to retrieve this data in cleartext.

SQL Server Encryption Overview

The root of the cryptography chain in SQL Server is the Service Master Key (SMK). This key is associated and stored in the master database for the server.

At a database layer, the Database Master Key (DMK) is the start of the encryption chain for each database. This diagram from Microsoft gives a brilliant visualisation of this in action:

https://learn.microsoft.com/en-us/sql/relational-databases/security/encryption/encryption-hierarchy?view=sql-server-ver16

For us to explore this encryption functionality, let’s run a few TSQL commands on a lab instance of SQL Server 2019.

First up, we create a new database and master key:

USE CryptoDB;
CREATE MASTER KEY ENCRYPTION BY PASSWORD='Password123'

We can then view our created master key with:

SELECT * FROM sys.symmetric_keys

Now this doesn’t show the actual content of the master key. Instead, to see this, we can use the query to list encryption keys in a database:

SELECT * FROM sys.key_encryptions

The crypt_property field shows our newly created master key in some form. We can also see that the crypt_type and crypt_type_description fields give a good indication as to each key’s type.

After searching Microsoft’s documentation for how these keys are actually stored, or ways that we can extract them, I found a few snippets of information:

Unfortunately none of this is useful for our purpose, so into the disassembler and debugger I needed to go.

Strap In Peeps.. We’re Going Low Level!

For this exercise, it usually makes sense to try and find a good lead as to the APIs that Microsoft SQL Server may use to handle encryption/decryption. My lab ran SQL Server 2017 on Microsoft Windows Server 2019 and installing WinDBG Preview was too much of a pain without access to the Windows Store, so I spun up API Monitor and hooked the Crypto APIs to see if anything indicated their use during cryptographic operations on SQL Server. We execute the TSQL to open the master key and:

As far as indicators go, this was a good one. We see that BCryptHashData was used along with a password provided during the opening of the database master key.

The important part for us is the call stack, which showed sqllang.dll and sqlmin.dll were prime candidates for reversing:

Symbols were available for both of these dynamic-link libraries (DLLs) are grabbed using symchk.exe:

Service Master Key Encryption

Let’s look at how the Service Master Key is generated and stored on SQL Server. This is the root of the encryption chain as shown in Microsoft’s diagram, so if we can find a vulnerability here, or some method of cracking this key, everything else will fall!

We know that a Database Master Key is encrypted using the Service Master Key. We also know from Microsoft’s documentation that this is likely protected using the data protection APIs (DPAPIs), which means that if we add a breakpoint on CryptUnprotectData / CryptProtectData and create a new DMK, we are in with a shot of seeing where in SQL Server is responsible for using the SMK.

To create the new key we use:

CREATE MASTER KEY ENCRYPTION BY PASSWORD='Password123'

And we hit a breakpoint with a valuable stack trace:

Here we see two method calls which tell us a story:

CSECDBMasterKey::Decrypt

CSECServiceMasterKey::Initialize

This makes sense, because we know that the SMK is used to decrypt the DMK and the DPAPI should protect the SMK.

We can pull out the arguments to CryptoUnprotectData and find the following value being decrypted:

And if we use the following TSQL query:

SELECT * FROM master.sys.key_encryptions

We find that the encrypted SMK matches the encrypted key stored in the master database:

Another caveat is a value passed to CryptUnprotectData as the optional entropy value. After a bit of digging, we find that this value is taken from the registry key:

HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL14.MSSQLSERVER\Security

So what does this mean? Well, if you have execution rights on a machine running SQL Server, we can use the following C# to recover the SMK:

using System;
using System.Security.Cryptography;
using Microsoft.Win32;

namespace ConsoleApp1
{
internal class Program
{
static void Main(string[] args)
{
// Read registry key
var rk = Registry.LocalMachine.OpenSubKey(@"SOFTWARE\\Microsoft\\Microsoft SQL Server\\MSSQL14.MSSQLSERVER\\Security");
byte[] entropy = (byte[])rk.GetValue("Entropy", new byte[] { 0x41 });
// SQL Encrypted SMK (minus the first 8 bytes)
byte[] encryptedData = new byte[]
{
0x01, 0x00, 0x00, 0x00, 0xD0, 0x8C, 0x9D, 0xDF, 0x01, 0x15, 0xD1, 0x11, 0x8C, 0x7A, 0x00, 0xC0, 0x4F, 0xC2, 0x97, 0xEB, 0x01, 0x00, 0x00, 0x00, 0xAC, 0x5E, 0xB2, 0x87, 0xF5, ... 0x8E, 0x50, 0x44, 0xFA, 0xDC, 0xBE, 0x47, 0x88, 0x16, 0x57, 0xBF, 0xCB, 0xB3, 0x56, 0x7B, 0x43, 0x86, 0x68, 0x31, 0x7E, 0x30, 0xE3, 0xE4, 0x3A, 0x14, 0xB4
};
try
{
// Decrypt key
byte[] data = ProtectedData.Unprotect(encryptedData, (byte[])entropy, DataProtectionScope.LocalMachine);
Console.WriteLine("Key Recovered");
} catch (Exception ex)
{
Console.WriteLine(ex.Message);
}
}
}
}

Unfortunately with only the database backup that we hold for ADSelfService, this isn’t an option, so we move onto the next crypto layer, the Database Master Key.

Database Master Key Encryption

With DPAPI being used to protect the SMK, next up we tackle the DMK to see what we can unearth here.

We know from our TSQL that when we initialized the DMK, we used a password:

CREATE MASTER KEY ENCRYPTION BY PASSWORD='Password123'

This password is surely a weak link in the chain, but there are a few questions that come up:

  1. How is this password stored in the database?
  2. Is all of the keying material for this password stored in a database backup?
  3. Can we bruteforce this key?

First up, we need to understand how this key is actually stored in the database. We attach a debugger to SQLServr.exeand use a password to attempt to open the DMK:

OPEN MASTER KEY DECRYPTION BY PASSWORD='ABCDE'

We add breakpoints to the previously observed BCrypt suite of APIs and we find that, after being executed, we land on a method called BCryptHashData:

The call stack shows where this is invoked:

What’s interesting is the use of the word Obfus in the method CMEDProxyObfusKey::SearchEncryptionByUserData . Obfuscation usually means something fishy is going on, so we dig into this method a bit more and we find reference to a key thumbprint:

Add a breakpoint to ComparePartialThumbPrint and attempt to open the master key again with an invalid password using:

OPEN MASTER KEY DECRYPTION BY PASSWORD='password123'

This time we find that our password is passed to this method as an argument, along with the unicode byte length:

But what is this being compared to? Dumping the third argument to this method call shows the following memory content:

This is not something that we’ve seen so far, but a bit of digging in SQL reveals the following table (requires DAC / diagnostic connection on a live database):

SELECT * FROM sys.sysobjkeycrypts

This looks similar to the previous sys.key_encryptions table; however, the thumbprint value is populated this time. What is going on here?

At this point, we know that the thumbprint is being used alongside our plaintext password. Let’s look in ComparePartialThumbPrint to see what the comparison is doing.

First the provided password is hashed:

Then the hash is salted:

And then the result is compared to the thumbprint:

If this is the case, this gives us a brilliant opportunity to create a brute-force method for our target database. After all:

  1. All of the keying material is stored in the database (and therefore the database backup)
  2. Nothing relates to the SMK and, therefore, DPAPI

But what are the algorithms used to hash the password? Well, in the type field of sys.key_encryptions we have a number of values:

  • ESKP - Observed in databases starting at SQL Server 2008
  • ESP2 - Observed in databases starting at SQL Server 2012

Starting with ESP2, if we add a breakpoint to BCryptHashData, we find that this is SHA-512 salted with 8 bytes. The resulting hash is then truncated to 24 bytes and then compared to the thumbprint.

Unfortunately for us, there is an additional step that SQL Server takes when storing the SHA-512 hash of the DMK: the hash truncates to 24 bytes.

This step alone appears to put it out of the reach of stock Hashcat rules; however, if we turn to John The Ripper, we have the option of Dynamic Rules.

A warning in advance: this is going to be slow, but we can add the following dynamic rule which will crack ESP2 keys:

[List.Generic:dynamic_2020]
Expression=sha512(utf16le($p).$s) (hash truncated to length 24)
Flag=MGF_SALTED
Flag=MGF_FLAT_BUFFERS
Flag=MGF_INPUT_24_BYTE
SaltLen=8
Func=DynamicFunc__clean_input_kwik
Func=DynamicFunc__setmode_unicode
Func=DynamicFunc__append_keys
Func=DynamicFunc__setmode_normal
Func=DynamicFunc__append_salt
Func=DynamicFunc__SHA512_crypt_input1_to_output1_FINAL
Test=$dynamic_2020$E45AF6FA6601E13A8F2B620FF8A859AE4B459B848D06F5C7$HEX$28E3C09896ED6177:Wibble123

This dynamic format can then be used with:

./run/john --format=dynamic_2020 /tmp/hashes --wordlist=/tmp/wordlist --encoding=raw

A quick demo to show how this works:

The second type is ESKP, which is using MD5 salted with four bytes. The result is then compared to the thumbprint.

Looking at Hashcat, we find a format which suits our cracking format:

md5(utf16le($pass).$salt)

This means we can crack using:

hashcat -m 30 --hex-salt /tmp/hashes /tmp/uberwordlist.txt

A quick demo to show how this works:

Brute-Forcing the ManageEngine Hashed Database Master Key

So now we have a technique to hopefully recover database encryption keys. We cross our fingers and look in our target database backup and we find ESKP. This means that we have a DMK protected using MD5 and, thankfully, a GPU cracking rig just waiting for us to feed it hashes!

Adding our hash to a file, we fire up our cracking job and…nothing.

The key hasn’t been rotated in a long time. Experience tells us that something is wrong here, so I did what I should have done in the first place. I spun up a local instance of ManageEngine to take a look at what was happening.

After reviewing, I found a file named product-config.xml, which looks like this:

The masterkey.password property has a value of 23987hxJ#KL95234nl0zBe, and if we throw this into our new method of cracking database encryption keys, we find that it cracks.

More concerningly, I then try this against the provided .bak file from the client environment and it cracks!

So what is this key: just a hardcoded value? A quick throw of this password into Google and…

The key is the example key used in Microsoft’s documentation for setting up a DMK!

TADA, dopamine hit! Using the database backup, we can now unseal the certificate and symmetric keys ManageEngine uses for decryption and pull out those sensitive credentials:

use DATABASE_NAME_HERE -- Update to contain the restored database name
OPEN MASTER KEY DECRYPTION BY PASSWORD = '23987hxJ#KL95234nl0zBe'
OPEN SYMMETRIC KEY ZOHO_SYMM_KEY DECRYPTION BY CERTIFICATE ZOHO_CERT;

And we can use this to decrypt any sensitive data contained within:

SELECT CONVERT(NVARCHAR(MAX), DecryptByKey((SELECT [Password] FROM ADSMDomainConfiguration))) as Password, CONVERT(NVARCHAR(MAX), DecryptByKey((SELECT [USER_NAME] FROM ADSMDomainConfiguration))) as UserName

Here’s what we’ve learned during this exercise:

  1. ManageEngine ADSelfService backups created use an example key Microsoft provides
  2. If you find a database backup that uses a DMK with the ESKP type, you can brute-force the decryption password with the speed of MD5
  3. Always lab your target product before spending so much time in a disassembler

This blog post was presented at SOCON 2025. Stay tuned for the video!


The SQL Server Crypto Detour was originally published in Posts By SpecterOps Team Members on Medium, where people are continuing the conversation by highlighting and responding to this story.

  • ✇Posts By SpecterOps Team Members - Medium
  • Life at SpecterOps Part II: From Dream to Reality Duane Michael
    TL;DRWe are hiring consultants at various levels. The job posting can be found under the Consultant opening here: https://specterops.io/careers/#careersIntroductionHey, it’s me again! The last time we spoke back in August 2024, I told you all about life and some of the intangible benefits of working as a consultant at SpecterOps. In that blog post, I also promised a follow-up that outlines the interview process. So, here we are…My goal for this blog is to provide a high level overview of our rec
     

Life at SpecterOps Part II: From Dream to Reality

TL;DR

We are hiring consultants at various levels. The job posting can be found under the Consultant opening here: https://specterops.io/careers/#careers

Introduction

Hey, it’s me again! The last time we spoke back in August 2024, I told you all about life and some of the intangible benefits of working as a consultant at SpecterOps. In that blog post, I also promised a follow-up that outlines the interview process. So, here we are…

My goal for this blog is to provide a high level overview of our recruiting process for consultants. I’ll explain what each step entails but I will not provide specific technical details or hints for any challenges. I want to demystify our recruiting process and make it less intimidating and hopefully encourage those of you who have considered taking that next step but haven’t yet.

Process Overview

Step 1: Application Review

This step may seem obvious. The first thing we do after receiving your application is review your resume and the questions you answered on the submission form. Our recruiters are excellent and will determine if an application meets the requisite criteria to advance (depending on the position and level). Everyone has a unique story, background, and experience; therefore, we give the application a holistic review. Thoughtful responses to the application questions will receive extra attention compared to applications that ignore them.

The requisite criteria for each level is outlined in the respective job postings. On a broader level, we’re looking for prior technical (offensive or defensive, depending on the role) security and consulting experience. Do you have security experience but no consulting experience? That’s OK, but it may affect the level at which we interview you (e.g., Associate, Consultant, or Senior). Sometimes we target specific levels, such as Consultant or Senior Consultant. During such periods, we may reject Associate-level applications or hold onto them until we hire Associates again in the future.

We like to see community involvement and sharing. We’re looking for candidates that share our commitment to transparency. Do you publish blogs, research, and/or tools? What has your learning and development journey been like through your career? That does not mean you have to write the next Rubeus or BloodHound. Any level of contribution goes a long way. Contributions can be blog posts, walkthroughs, notes from a course, PoC or helper scripts from a training, experimental tools, or contributions to other people’s repos. Make sure to include links to your contributions and accomplishments on your resume!

Note: Be prepared to discuss your resume content and community contributions.

Step 2: Scripting Challenge

We liked your resume and application and want to get to know you better.

The next step is a scripting challenge, where you will enter a challenge on a coding platform and solve a solution in a language of your choice. The environment is recorded but we do not set a strict time limit (e.g., one hour). We encourage you to take your time, pay attention to detail, and consult appropriate references. It is pass/fail and the solution must be exactly correct.

The challenge should be doable for anyone with fundamental scripting skills. If you’ve written automation, PoC scripts, or open-source contributions, you should be able to pass this challenge. If you are a clear senior-level candidate and have extensive open-source software contributions, we may waive the scripting challenge.

Basic scripting/programming ability is a requirement to be a successful red team operator. Therefore, this challenge identifies those that meet that minimum requirement.

Step 3: Preliminary Interview

Great! You passed the scripting challenge and made it through to the next phase. Now our recruiters will get to know you better on a video conference where they will talk about your background, experience, career aspirations, salary expectations, etc. This is also an opportunity for you to ask the recruiters questions about the position and company. This step is fairly straightforward and where the real interview process begins.

All of our interviews will be conducted virtually via video conference and we expect you to be on camera.

Step 4: Technical Challenge

After the preliminary interview, you’ll receive the prompt for a technical challenge that varies based on the role. The primary goal of the challenge is to gauge your technical depth, writing ability, and creativity. Rather than taking a pass/fail approach to assessing your response, we gauge where your submission is on a capability spectrum. We’re looking to see how deep you can go and how well you convey technical information in a clear and concise manner.

Disclaimer: Of course, there is a minimum bar. Not all submissions will advance past this round, especially when we’re seeking only more senior candidates.

The technical challenge will inform us on where your technical capabilities are in preparation for the technical interview. If your submission reads like Senior-level work, then your technical interview will be anchored at that level. There is no hard timeline on the technical challenge but you should submit it within approximately one week.

Step 5: Technical Interview

If we like your technical challenge submission, we’ll advance to the technical interview. This interview is 60 minutes and will be conducted by three senior members of our consulting staff. Similar to the previous round, we’re not looking to stump you. We will ask you about experiences and seed some topics with questions and see how deep you can go.

It is absolutely okay to say you don’t know something. It is also encouraged to talk through your thought process so the interviewers get a glimpse of how you think. Please don’t try to cover up a knowledge gap. It will be obvious. No one knows everything, and we understand that. It’s OK. Be humble and keep it real!

We’ll leave some time at the end of the interview for you to ask us questions. After all, a job interview is as much about you interviewing us as it is the converse.

Step 6: Peer Interview

Congratulations! You’ve survived the technical portions of the process. Now, you’ll meet with three of your potential Specter peers. At this stage, we want to get to know you as a person. Do you match our core values? Will you get along with the team? Will the team enjoy traveling with you for several weeks at a time? There’s no script here and not much to prepare for. Bring your genuine self, have a conversation, and have fun!

Step 7: Management Interview

At this point, you’ve almost made it. You would not have made it this far if you weren’t a good fit. Now, management will meet with you for 60 minutes to discuss your experience, professional development, career growth, etc. This is not a technical interview. If we ask how you did something or how you handled a situation, we’re not looking for technical depth. As always, we’re gauging your alignment with our core values and at what level you should be hired.

As with every previous step, bring your genuine self. Dishonesty and resume discrepancies are commonly identified at this stage.

Why So Many Steps?

The interview process may seem like a lot, and it is, but we pride ourselves on building the right teams with the right people. As much as we want to welcome you into our ranks, we also want to focus on candidates that want to be here. Those candidates will understand the seven steps and work through them to earn their spot on the team.

We’re not looking to stump you or fail you out of the process. We take a holistic view of you as a person, red team operator, and consultant. Inherently, this requires more steps.

You’re interviewing us too. Choosing a company to work with is not a decision to be taken lightly. You spend eight hours per day, five days per week with your colleagues. Through our process, you’ll directly interface with at least 10 Specters, which should help you gain a solid understanding of who we are and what we’re all about.

We strive to complete the entire process in less than four weeks and we’ve completed it in as little as two weeks. However, we understand life happens and we are flexible with scheduling.

Still Unsure?

Don’t think you’re “ready” to join the SpecterOps team? To be honest, a lot of us felt the same way before applying. We all suffer from imposter syndrome and we empathize with you. We will keep this in mind throughout the interviews and will do our best to alleviate those concerns. As you progress through the process, just remember: you’ve made it that far for a reason. To quote an excellent talk from Billy Boatright (and Babe Ruth) at the Social Engineering Village several years ago, “If you’re good enough to have a bat in your hands, you’re good enough to swing it.” So, swing for the fences!

We will help you reach your technical goals. What’s most important to us is aptitude, attitude, and alignment with our core values. Don’t wait for the “right time.” We want to talk to you now!

Next Steps

We will grow steadily throughout 2025 and we’d love to have you apply!

We are hiring consultants at various levels. The job posting (including salary bands) can be found under the Consultant openings here: https://specterops.io/careers/#careers

Please feel free to reach out to me on Bluesky, X, LinkedIn, or BloodHound Slack if you have any questions about SpecterOps or the role, or directly to careers@specterops.io.


Life at SpecterOps Part II: From Dream to Reality was originally published in Posts By SpecterOps Team Members on Medium, where people are continuing the conversation by highlighting and responding to this story.

❌
❌