SentinelLabs Logo RGB WhitePurp
ABOUT
CVE DATABASE
CONTACT
VISIT SENTINELONE.COM

Tom Hegel

An accomplished cybersecurity researcher and a leader in the threat intelligence space, with a background of tracking some of the most interesting and unique threat actors globally. Tom's dedication lies in driving cutting-edge cyber threat intelligence and research, collaborating with top-tier analysts and organizations worldwide. As a Distinguished Threat Researcher and Research Lead at SentinelLABS, Tom spearheads investigations into the most sophisticated nation-state and criminal threat actors, uncovering operations from adversaries across Russia, China, Iran, North Korea, India, and beyond. His work has led to the discovery of new mercenary groups, emerging geopolitical cyber campaigns, and critical insights into global conflicts.
Ghostwriter Ftr
labs
Adversary

Ghostwriter | New Campaign Targets Ukrainian Government and Belarusian Opposition

Tom Hegel / February 25, 2025

Latest Ghostwriter campaign brings Belarusian opposition into its sights for the first time as it continues weaponizing XLS docs to drop malware.

Read More
Decoding The Past Securing The Future Enhancing Cyber Defense With Historical Threat Intelligence 13
labs
Security Research

Decoding the Past, Securing the Future | Enhancing Cyber Defense with Historical Threat Intelligence 

Tom Hegel / November 28, 2023

Explore how revisiting past cyber incidents can empower defenders and help to anticipate future threats more effectively.

Read More
Elephant Hunting Inside An Indian Hack For Hire Group 9
labs
Advanced Persistent Threat

Elephant Hunting | Inside an Indian Hack-For-Hire Group

Tom Hegel / November 16, 2023

Exploring the technical intricacies of Appin, a hack-for-hire group, revealing confirmed attribution and global threat activity, both old and new.

Read More
sentinelone

So, State-Sponsored Attackers Are Targeting Your Mobile Device. Now What?

From the Front Lines | 6 minute read
Read More >
The Israel Hamas War Cyber Domain State Sponsored Activity Of Interest 6
labs
Advanced Persistent Threat

The Israel-Hamas War | Cyber Domain State-Sponsored Activity of Interest

Tom Hegel / October 24, 2023

Cyber warfare occurring amidst the Israel-Hamas war underscores the importance of keeping tabs on rising APTs and opportunistic hacktivists.

Read More
Cyber Soft Power Chinas Continental Takeover 14
labs
Adversary

Cyber Soft Power | China’s Continental Takeover

Tom Hegel / September 21, 2023

China-aligned threat actors are increasingly involved in strategic intrusions in Africa, aiming to extend the PRC's influence across the continent.

Read More
Comrades In Arms North Korea Compromises Sanctioned Russian Missile Engineering Company 1
labs
Adversary

Comrades in Arms? | North Korea Compromises Sanctioned Russian Missile Engineering Company

Tom Hegel / August 7, 2023

North Korean threat actors attempt to further missile program by compromising sanctioned Russian defense company with OpenCarrot backdoor.

Read More
sentinelone

Illicit Brand Impersonation | A Threat Hunting Approach

From the Front Lines | 8 minute read
Read More >
JumpCloud Intrusion Attacker Infrastructure Links Compromise To North Korean APT Activity 5
labs
Advanced Persistent Threat

JumpCloud Intrusion | Attacker Infrastructure Links Compromise to North Korean APT Activity

Tom Hegel / July 20, 2023

North Korean state sponsored APT is behind a new supply chain attack on zero-trust directory platform JumpCloud.

Read More
Kimsuky Evolves Reconnaissance Capabilities In New Global Campaign 9
labs
Advanced Persistent Threat

Kimsuky Evolves Reconnaissance Capabilities in New Global Campaign

Tom Hegel / May 4, 2023

DPRK-linked threat actor deploys previously unseen reconnaissance tool 'ReconShark' in wave of ongoing attacks.

Read More
Previous
1 2 3
Next

SentinelLabs

In the era of interconnectivity, when markets, geographies, and jurisdictions merge in the melting pot of the digital domain, the perils of the threat ecosystem become unparalleled. Crimeware families achieve an unparalleled level of technical sophistication, APT groups are competing in fully-fledged cyber warfare, while once decentralized and scattered threat actors are forming adamant alliances of operating as elite corporate espionage teams.

Recent Posts

  • FreeDrain Unmasked | Uncovering an Industrial-Scale Crypto Theft Network
    FreeDrain Unmasked | Uncovering an Industrial-Scale Crypto Theft Network
    May 8, 2025
  • Top Tier Target | What It Takes to Defend a Cybersecurity Company from Today’s Adversaries
    Top Tier Target | What It Takes to Defend a Cybersecurity Company from Today’s Adversaries
    April 28, 2025
  • AkiraBot | AI-Powered Bot Bypasses CAPTCHAs, Spams Websites At Scale
    AkiraBot | AI-Powered Bot Bypasses CAPTCHAs, Spams Websites At Scale
    April 9, 2025

Sign Up

Get notified when we post new content.

Thanks! Keep an eye out for new content!

  • Twitter
  • LinkedIn
©2025 SentinelOne, All Rights Reserved.