All Newsletters

Valid Points · October 2025

Continuous YARA Detection and Joint Research with Elastic Security Labs

We're excited to announce continuous YARA detection, share our latest joint research with Elastic Security Labs, and more in our monthly newsletter.

Welcome back to Validin's monthly newsletter and thank you for inviting us into your inbox. This past month we announced YARA continuous detection, collaborated with Elastic Security Labs, and explored an invoice fraud email (and more). As always, we appreciate any feedback! - The Validin Team

2

PRODUCT UPDATES

YARA detection now runs across live host responses

We’re excited to announce that Validin’s YARA engine now runs continuously on live data, as it arrives. With continuous execution, rule versioning, and contextual visibility, YARA in Validin now operates as a live detection layer across our vast virtual host response dataset.

Recent updates enable security teams to track infrastructure in near-real time as adversaries adjust their attack vectors to avoid detection.

Key Outcomes:

  • Expedited Discovery: Detect new or recycled infrastructure in hours, not days
  • Improved Efficiency: Refine detection logic with an enhanced YARA editor with immediate feedback
  • Minimize Risk: Contain threats before they propagate

👉 Read the full update blog

3

FEATURED RESEARCH

Exploring Invoice Fraud Email Attempts

Someone on the Validin team received an email that was so convincing that they had to ask if it was real. In this article, we show you how we dove into the breadcrumbs left by this email to identify dozens of domains likely related to this surprisingly sophisticated and intricate campaign. We blocked the list of related domain names we uncovered and encourage you to do the same with the list of indicators at the end of this blog post. 👉 Read the article

IN CASE YOU MISSED IT

tollbooth

ELASTIC SECURITY LABS COLLABORATION

TOLLBOOTH: What's yours, IIS mine

In September 2025, Texas A&M Cybersecurity Center, a managed detection and response provider in collaboration with Elastic Security Labs, discovered post-exploitation activity by a Chinese-speaking threat actor who installed a malicious IIS module, which they are calling TOLLBOOTH.

Through collaboration with Validin, leveraging our global scanning infrastructure, Elastic Security Labs determined that organizations worldwide have been impacted by this campaign.

The full report from Elastic Security Labs details the events and tooling used in this activity cluster, known as REF3927. → Read the full report here

Additionally, HarfangLab also has an excellent writeup on this threat, which they dubbed RudePanda, with additional indicators and detection methodologies. → Read the report here

Screenshot 2025-10-24 at 6.12.32 PM

SENTINELLABS RESEARCH

Additional Infrastructure Uncovered Using Validin

SentinelLABS uncovered a coordinated spearphishing campaign targeting individual members of NGOs involved in war relief efforts and Ukrainian regional government administration. An additional infrastructure pivot leveraging Validin revealed a link to a wider campaign making use of adult-oriented social and entertainment lures, with potential links to Russia/Belarus source development. → Read the full report

73ebe120-5819-479e-8529-a160331307c2_795x594

FEATURING VALIDIN

Mapping the Latest Lumma Infrastructure

Learn how Vasilis Orlof recently mapped Lumma infrastructure in his latest Substack article, featuring Validin. → Read on SubStack
(We ❤️ when researchers feature the platform in their write ups!)

BY THE NUMBERS

October's Top Viewed Threat Actor Profiles

If you're logged into Validin, view the full profiles:

  1. ClickFix
  2. Lazarus Group
  3. Fake Software Downloads
  4. Poseidon Group
  5. Lumma Stealer

Get in touch

Contact us

Validin is the first tab I open every morning.
Senior Analyst, Financial Services IT Company