logo

So Your CFO's Phone Has Been Pwned: A DFIR Journey

ID: 0389fb2f-d60e-5a5d-bdc4-391b7c3848c4

STIX ID: report--0389fb2f-d60e-5a5d-bdc4-391b7c3848c4

Feed Name: Censys Blog

Threat Score
78/100

Date Published: 2026-08-31

Date Updated: 2026-09-01

...
...

This article uses two hypothetical SOC incidents—an Android banking trojan (ERMAC/HookBot) and an iPhone compromise involving a DarkSword iOS exploit chain and credential-phishing—to demonstrate mobile incident response: preserve devices, gather APKs/network telemetry, pivot on IOCs to historical infrastructure using Censys, and expand scope across the enterprise while converting findings into durable detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.