How much of a campaign can be assembled from pre-built components before reliable attribution starts to break down? We've decided to call this one PAPERMILL. The designation refers to an emerging, Silver Fox-like activity cluster identified during our investigation of a tax-themed phishing campaign. Beneath a layered chain of trusted software abuse, sideloaded DLLs, and multiple loader stages sat a familiar objective: delivering VenomRAT to establish remote access to the victim system. While the activity exhibits characteristics associated with broader China-nexus operations, the evidence does not currently support confident attribution to a specific threat actor. For now, PAPERMILL provides a working designation for a cluster that appears defined less by bespoke malware and more by the industrialised assembly of existing components. Read the full research: PAPERMILL: https://lnkd.in/eni74trK
JUMPSEC
Computer and Network Security
Acton, London 3,864 followers
Futureproof your cyber defences, realise genuine improvement with JUMPSEC managed services and consultancy solutions.
About us
Adaptive Cyber Security JUMPSEC operates on a core principle: real attack insight drives stronger defence. As a specialist cyber‑security organisation, we deliver deep technical expertise, advanced capabilities, and tailored solutions that strengthen resilience and support secure organisational transformation.
- Website
-
http://www.jumpsec.com
External link for JUMPSEC
- Industry
- Computer and Network Security
- Company size
- 51-200 employees
- Headquarters
- Acton, London
- Type
- Privately Held
- Founded
- 2012
- Specialties
- Cyber Incident Response, Security Architecture Consultancy, Application and Mobile penetration testing, Social Engineering, Security Assessments, Managed Vulnerability Scanning, Security Operations Centre, SOC-as-a-service, Threat Intelligence, Security awareness workshops & training, Threat Modelling, Cyber Incident Response capability review, Incident detection and capability review, Cyber Security Consultancy, ransomware, Cyber Security, Penetration Testing, managed services, Red Teaming, and MXDR
Locations
-
Primary
Get directions
33 - 34 Westpoint
Warple Way
Acton, London W3 0RG, GB
Employees at JUMPSEC
Updates
-
Today marks another important milestone for JUMPSEC. We are pleased to confirm that JUMPSEC has successfully secured a place on G-Cloud 15 under Lot 3 - Cloud Support. Over the last few years, JUMPSEC's capability has expanded significantly beyond traditional testing services, and in G-Cloud 15, we've included this wider capability, grounded in the reality that resilience is built through informed decisions, continuous improvement, and a clear understanding of risk. Today, our clients engage us across five core areas: ● Offensive: understand how an attacker could compromise your organisation. ● Defensive: strengthen resilience before incidents occur. ● MXDR: improve the speed and effectiveness of threat detection and response. ● Continuous Reconnaissance: understand what a motivated attacker can see, learn and exploit today. ● AI Assurance: adopt AI securely, responsibly and with confidence. Our team includes specialists who help organisations understand not only where risk exists, but what to do about it next. Whether you're a central government department, local authority, NHS organisation, university, emergency service, housing association or wider public sector body, G-Cloud 15 now provides a straightforward route to access JUMPSEC's expertise. We're looking forward to supporting organisations that want to move beyond compliance exercises and make genuine improvements to their cyber resilience. If you'd like to discuss an upcoming requirement or simply sense-check your current strategy, we'd be delighted to talk. #GCloud15 #CyberSecurity #CyberResilience #PublicSector #Microsoft #ManagedDetectionAndResponse #ThreatLedSecurity #SocialValue #GCloud15
-
-
Trust is becoming an ever greater part of an organisation's attack surface. Our Threat Researcher Jack L. recently analysed the source code behind an active BlueNoroff phishing operation impersonating Zoom and Microsoft Teams. What he uncovered wasn't just another #phishing kit; the reverse engineering revealed a particularly effective victim acquisition platform. Compromised Telegram accounts, fake meetings, AI-generated participants, wallet profiling and malware delivery. The attack spreads through genuine business relationships. Read the blog post: https://lnkd.in/gFfhJ2Dk The research has already been picked up by The Hacker News: Read the coverage here: https://lnkd.in/gFbN3eZi When a real account belonging to someone you know becomes the attack vector, traditional anti-phishing advice breaks down. BlueNoroff's model works because the sender isn't a stranger. #teams #zoom #BlueNoroff #clickfix
-
-
Many security controls implicitly rely on visual and vocal trust, from supplier payment approvals to HR requests and password resets. But what happens when seeing and hearing someone is no longer reliable evidence of identity? In our latest research, "Project Havoc," JUMPSEC's team built live, interactive video/audio clones using nothing but free open-source tools, then used them on internal video calls to see how convincing our synthetic identities were. Interestingly, our real-time face re-enactment and voice conversion was good enough to make colleagues believe they were talking to a genuine exec and act on it – under certain conditions. It's effective but not flawless, and instances where it doesn't work are arguably just as interesting. We break down: ▶️ Exactly how the framework works (and how accessible it is) ▶️ How real-world precedent informs the three attack paths we assess as most viable right now (Finance, IT/SecOps, and HR) ▶️ Why it works in some scenarios and falls flat in others ▶️ How sophisticated the tooling currently is (via a demo video) ▶️ Why "seeing is believing" no longer holds up as a security control, and what needs to replace it. As many organisations have hardened phishing defences and MFA, attackers have pushed harder into the human layer. IT helpdesk vishing, MFA fatigue, and voice-based pretexting are exactly where attackers are finding repeated success. Synthetic media is a natural next step in that arms race and it's already proving effective, as we have used it ourselves to strengthen recent vishing simulations. If someone appeared on a Teams call looking and sounding exactly like your CEO, which of your controls would still verify who they are? If the answer is "not many", this research is worth 10 minutes of your time. Read the full research here: https://lnkd.in/eT4TzYaj #CyberSecurity #SocialEngineering #Vishing #DeepfakeFraud #IdentityVerification #RedTeaming #AdversarySimulation
-
We’re proud to share that JUMPSEC is a founding signatory of the CREST AI Charter — reinforcing our commitment to using AI responsibly across cybersecurity. As AI adoption accelerates, trust, transparency, and human oversight matter more than ever. By backing CREST’s nine AI principles, we’re ensuring that innovation never comes at the expense of accountability. For our clients, this means clarity on where AI is used, confidence in how it’s governed, and assurance that expert judgement remains at the core of every service. ➡️ Read more: https://lnkd.in/ezXVYh-m #CyberSecurity #AI #ResponsibleAI #CREST #Trust #Innovation
-
-
Yesterday, we hosted our annual JUMPSEC Industry Briefing, and one thing is clear: the threat landscape is shifting faster than most organisations are structured to respond. Across the sessions, a few key themes emerged: - The attack surface has moved upstream. Modern attackers aren’t breaking into your product; they’re compromising the systems that build it. CI/CD pipelines, dependencies, and software supply chains are now prime targets, with attackers exploiting implicit trust at scale. - AI is accelerating both sides — but especially the attacker. Agentic AI is already operating inside pipelines, acting with speed, autonomy, and often excessive privilege. The challenge isn’t just capability; it’s control. These agents behave like developers, but without intuition or skepticism. - Threat actor behaviour is evolving (and blurring). From geopolitical spill over impacting private organizations to the convergence of financially motivated and state-backed tactics — attribution is getting harder and less useful as a defensive anchor. - Identity is now the primary battleground. Whether it’s credential abuse, synthetic identities, or AI-driven impersonation, attackers are increasingly logging in rather than breaking in. That shift underpins many of the most impactful incidents we’re seeing today. And perhaps the most provocative takeaway: "Security Operations is DEAD" — not the people, but the model. Alert queues and SLAs don’t measure whether you’ve stopped an attack; only that you’ve processed activity. Modern defence needs to move toward understanding behaviour, not just handling alerts. A huge thank you to our speakers and clients who joined us for such an open and thought-provoking discussion. The takeaway? Cybersecurity isn’t failing — but the way we organise around it needs to evolve quickly. If you'd like to continue the conversation or dive deeper into any of these topics, feel free to reach out. #CyberSecurity #ThreatIntelligence #AI #SupplyChainSecurity #SecOps #IdentitySecurity
-
-
-
-
-
+1
-
-
We are delighted to be hosting our annual JUMPSEC industry briefing today with a full house here in London at the Globe theatre. Looking forward to an afternoon of talks and networking. #CyberSecurity #InfoSec #JUMPSEC
-
-
What can malware really do once it’s inside your environment? In our latest threat intelligence write-up, we break down how the BlackToad campaign uses an AutoIt-based payload to manipulate network activity in subtle but impactful ways. Rather than relying on obvious or noisy techniques, this approach demonstrates how attackers can quietly control communications and evade detection using relatively simple tooling—something defenders shouldn’t underestimate. This post walks through: ➡️ How the payload works in practice ➡️ The techniques used to interfere with network behaviour ➡️ Why these methods are effective against traditional detection ➡️ What defenders should be looking out for If you're interested in how real-world threats actually operate under the hood—and what that means for detection and response—this one’s worth a read. 👉 https://lnkd.in/gsiYsW6p #ThreatIntelligence #CyberSecurity #DetectionEngineering #MalwareAnalysis #BlueTeam
-
-
It’s well established that attackers make use of legitimate system tooling to blend into normal activity. But the more important shift is how these tools are now being used to structure entire intrusion chains designed for stealth, persistence, and post-compromise control. In our new research piece, ‘BlackToad: Network Manipulation via AutoIt Payloads’, we examine how threat actors are abusing legitimate Windows scripting environments, in this case AutoIt, as part of a multi-stage payload designed for stealth and network manipulation. Key takeaways: 🔹 AutoIt remains attractive to attackers due to its legitimacy and low detection footprint 🔹 Execution chains are increasingly focused on post-compromise network manipulation, not just initial access 🔹 Obfuscation and layered scripting significantly reduce the effectiveness of static detection methods 🔹 Behavioural detection and investigative analysis remain critical for uncovering this type of activity Full write-up here: https://lnkd.in/gsiYsW6p