{"id":9649,"date":"2026-01-05T10:03:55","date_gmt":"2026-01-05T10:03:55","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/05\/hackers-trapped-in-resecuritys-honeypot-during-targeted-attack-on-employee-network\/"},"modified":"2026-01-05T10:03:55","modified_gmt":"2026-01-05T10:03:55","slug":"hackers-trapped-in-resecuritys-honeypot-during-targeted-attack-on-employee-network","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/05\/hackers-trapped-in-resecuritys-honeypot-during-targeted-attack-on-employee-network\/","title":{"rendered":"Hackers Trapped in Resecurity\u2019s Honeypot During Targeted Attack on Employee Network"},"content":{"rendered":"<p>    Hackers Trapped in Resecurity\u2019s Honeypot During Targeted Attack on Employee Network<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Resecurity deploys synthetic data <a href=\"https:\/\/cybersecuritynews.com\/what-is-a-honeypot\/\" target=\"_blank\" rel=\"noreferrer noopener\">honeypots<\/a> to outsmart threat actors, turning reconnaissance into actionable intelligence. A recent operation not only trapped an Egyptian-linked hacker but also duped the ShinyHunters group into false breach claims.\u200b<\/p>\n<p>Resecurity has refined deception technologies for counterintelligence, mimicking enterprise environments to lure threat actors into controlled traps.<\/p>\n<p>These build on traditional honeypots, misconfigured services, or dummy resources that passively log intruders, now powered by AI-generated synthetic data that resemble real-world patterns without exposing proprietary information. Previously breached data from dark web sources enhances realism, fooling even advanced actors who validate targets.\u200b<\/p>\n<p>On November 21, 2025, Resecurity\u2019s DFIR team spotted a threat actor scanning public-facing services after targeting a low-privilege employee. Indicators included IPs like 156.193.212.244 and 102.41.112.148 (Egypt), plus VPNs 45.129.56.148 (Mullvad) and 185.253.118.70.<\/p>\n<p>Responders deployed a honeytrap in an emulated app with synthetic datasets: 28,000 consumer records (usernames, emails, fake PII from combo lists) and 190,000 Stripe-like payment transactions generated via tools like SDV, MOSTLY AI, and Faker. A bait account, \u201cMark Kelly,\u201d was planted on Russian Marketplace to draw attackers.\u200b<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjYZy27QG3LNINZGBGkKh9Y7B3MWBOZdR3DXHPjJeXMaHei1Ru-YSGv-t0puGS1MQxmclvCgV0Tld9YeQR9gvp1rZD62TNZv1odLDP-ljD54T3DBrI2mB7qw-M-RvEjswhIlUNtslkbgsDHm-4e_M0DTMujNkJikAmIRuz_LSqDHYJ-Tj8_XPvebN3ixPeA\/s16000\/Hon1.webp?ssl=1\" alt=\"Hackers Trapped Honeypot\"><figcaption class=\"wp-element-caption\">records from Honeypot<\/figcaption><\/figure>\n<\/div>\n<p>The actor logged into the honeytrap, prompting over 188,000 requests from December 12-24 to scrape data via custom automation and residential proxies.<\/p>\n<p>This yielded \u201cabuse data\u201d on tactics, infrastructure, and <a href=\"https:\/\/cybersecuritynews.com\/best-brand-protection-solutions\/\" target=\"_blank\" rel=\"noreferrer noopener\">OPSEC<\/a> slips, real IPs leaked during proxy failures. Resecurity blocked proxies, forcing the reuse of known hosts, and shared findings with law enforcement, culminating in a foreign subpoena.<\/p>\n<p>Isolated decoys like Office 365, VPNs, and a decommissioned Mattermost instance with 2023 fake chatter (six groups, AI-generated via OpenAI) proved ideal for high-value mimicry without risk.\u200b<\/p>\n<h2 class=\"wp-block-heading\" id=\"shinyhunters-snared-in-update\"><strong>ShinyHunters Caught in Update<\/strong><\/h2>\n<p>A January 3, 2026, update revealed ShinyHunters previously profiled by Resecurity fell into the same trap, boasting Telegram \u201cfull access\u201d to \u201c[honeytrap].b.idp.resecurity.com\u201d and fake systems.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjVOEaS24LCgh7IqC9V8PqKaTrUKMiV0jPpjQfVqGJiDcq7y4zZtyze6kEwEeaMLp5bhsQJhAC2T0WaNeMsX1Fl-GKdYVvzHCBcAiHV-p_CRVSxt-FJWRGCIlwZ9kEM_YMIBbAReZIxJz8n6GV5bVEqRCuMgbptSbdRGaZKXopCh8rfB7pTjs4lwm-7SNeW\/w640-h478\/Hon2.webp?ssl=1\" alt=\"Hackers Trapped Honeypot\"><figcaption class=\"wp-element-caption\">Telegram group update<\/figcaption><\/figure>\n<\/div>\n<p>Screenshots showed dummy Mattermost for \u201cMark Kelly,\u201d non-existent domains like \u201cresecure.com,\u201d bcrypt-hashed API tokens from duplicate tester accounts, and useless old logs.<\/p>\n<p>The group acknowledged disruptions caused by Resecurity\u2019s tactics; social engineering identified links to jwh*****y433@gmail.com, a US phone number, and a Yahoo account registered during the activity.\u200b<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhpYy64W_zVrYwK89KmQca6n4bi_JgqgHuWoh9tvYbz3yzmOyP37vtUeTt5CCFhnF0clFd4IoZkH3xf3zhTw5nG3i1HCOwoURLvmtkqwbdRvHhYPGXPi8fBR4daKF761ClWB10Wz-8NSuV3de-aniEQ9G3EMkgONjTu14VAUcCjslgQvw8d_kaHq-mI9o2g\/s16000\/Hon3.webp?ssl=1\" alt=\"\"><\/figure>\n<p>This validates cyber deception\u2019s power for threat hunting and investigations, generating IOCs\/IOAs from controlled engagements. Compliance with privacy laws remains key. <\/p>\n<p>Resecurity\u2019s logs and prior ShinyHunters expos\u00e9s suggest retaliation backfired into self-incrimination. Enterprises can replicate via monitored decoys in non-production environments, enhancing proactive defense against financially motivated threat actors.\u200b<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hackers-trapped-honeypot\/\">Hackers Trapped in Resecurity\u2019s Honeypot During Targeted Attack on Employee Network<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hackers-trapped-honeypot\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Trapped in Resecurity\u2019s Honeypot During Targeted Attack on Employee Network Resecurity deploys synthetic data honeypots to outsmart threat actors, turning reconnaissance into actionable intelligence. A recent operation not only trapped an Egyptian-linked hacker but also duped the ShinyHunters group into false breach claims.\u200b Resecurity has refined deception technologies for counterintelligence, mimicking enterprise environments to [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-9649","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9649"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9649"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9649\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9649"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9649"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9649"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}