Valid Points · October 2025
Continuous YARA Detection and Joint Research with Elastic Security Labs
We're excited to announce continuous YARA detection, share our latest joint research with Elastic Security Labs, and more in our monthly newsletter.
Welcome back to Validin's monthly newsletter and thank you for inviting us into your inbox. This past month we announced YARA continuous detection, collaborated with Elastic Security Labs, and explored an invoice fraud email (and more). As always, we appreciate any feedback! - The Validin Team
PRODUCT UPDATES
YARA detection now runs across live host responses
We’re excited to announce that Validin’s YARA engine now runs continuously on live data, as it arrives. With continuous execution, rule versioning, and contextual visibility, YARA in Validin now operates as a live detection layer across our vast virtual host response dataset.
Recent updates enable security teams to track infrastructure in near-real time as adversaries adjust their attack vectors to avoid detection.
Key Outcomes:
- Expedited Discovery: Detect new or recycled infrastructure in hours, not days
- Improved Efficiency: Refine detection logic with an enhanced YARA editor with immediate feedback
- Minimize Risk: Contain threats before they propagate
FEATURED RESEARCH
Exploring Invoice Fraud Email Attempts
Someone on the Validin team received an email that was so convincing that they had to ask if it was real. In this article, we show you how we dove into the breadcrumbs left by this email to identify dozens of domains likely related to this surprisingly sophisticated and intricate campaign. We blocked the list of related domain names we uncovered and encourage you to do the same with the list of indicators at the end of this blog post. 👉 Read the article
IN CASE YOU MISSED IT
ELASTIC SECURITY LABS COLLABORATION
TOLLBOOTH: What's yours, IIS mine
In September 2025, Texas A&M Cybersecurity Center, a managed detection and response provider in collaboration with Elastic Security Labs, discovered post-exploitation activity by a Chinese-speaking threat actor who installed a malicious IIS module, which they are calling TOLLBOOTH.
Through collaboration with Validin, leveraging our global scanning infrastructure, Elastic Security Labs determined that organizations worldwide have been impacted by this campaign.
The full report from Elastic Security Labs details the events and tooling used in this activity cluster, known as REF3927. → Read the full report here
Additionally, HarfangLab also has an excellent writeup on this threat, which they dubbed RudePanda, with additional indicators and detection methodologies. → Read the report here
SENTINELLABS RESEARCH
Additional Infrastructure Uncovered Using Validin
SentinelLABS uncovered a coordinated spearphishing campaign targeting individual members of NGOs involved in war relief efforts and Ukrainian regional government administration. An additional infrastructure pivot leveraging Validin revealed a link to a wider campaign making use of adult-oriented social and entertainment lures, with potential links to Russia/Belarus source development. → Read the full report
FEATURING VALIDIN
Mapping the Latest Lumma Infrastructure
Learn how Vasilis Orlof recently mapped Lumma infrastructure in his latest Substack article, featuring Validin. → Read on SubStack
(We ❤️ when researchers feature the platform in their write ups!)
BY THE NUMBERS
October's Top Viewed Threat Actor Profiles
If you're logged into Validin, view the full profiles:
Get in touch
Contact us
Validin is the first tab I open every morning.