Untitled Blog Post
- Patrick Duggan
- Dec 2, 2025
- 3 min read
Updated: Aug 11
--- title: "The Minnesota Threat Intelligence Gap (And Why We're Filling It)" subtitle: "5 Days, 51 Pulses, 5,186 IOCs - A Startup's Journey Into Cyber Defense" date: 2025-12-03 author: Patrick Duggan tags: [threat-intelligence, startup, seed-funding, otx, pattern-38, ransomware] ---
The Gap Nobody's Filling
Here's a dirty secret about threat intelligence: the big players are drowning in legacy malware signatures while fresh threats slip through GitHub every hour.
AlienVault has 566,000 indicators. Impressive. But scroll through - you'll find Berbew (a 2018 banking trojan), Skype worms from 2015, and 24,000+ generic "trojan" entries that help exactly nobody.
• `Thrbvbb` - Crypto wallet drainers
• `Aestrpljabt` - Fake balance tools
• `HangTheDrt` - Electrum phishing kits
By 6 PM Central, we'd published IOCs. By tomorrow, they'll probably be suspended. That's the gap.
What We Actually Do
DugganUSA LLC is a Minnesota-based threat intelligence operation. Two guys, a Claude Code subscription, and an unhealthy obsession with GitHub malware.
Our Niche: Pattern 38 Supply Chain Attacks
• Fake software cracks ("Adobe-Premiere-2025-Crack")
• Open source project issue comments with malicious ZIPs
• Bot farms (800+ repos, mechanical timing)
• Follower networks that amplify malware reach
We call it Pattern 38. We've documented 40+ variations.
The Numbers (5 Days In)
| Metric | Count | |--------|-------| | OTX Pulses | 51 | | Indicators Published | 5,186 | | Subscribers | 14 | | GitHub Accounts Reported | 47 | | Accounts Subsequently Suspended | 12 | | Ransomware Families Covered | 11 | | Time to IOC Publication | <4 hours |
Our Unique Methodology
1. Pattern 42 "Reblessing" - We follow threat actor social graphs. One RAT author leads to their followers, who lead to their tools, which lead to C2 infrastructure.
2. Same-Day Detection - Account created at 5 PM? We've got a pulse by 9 PM.
3. CISA-Sourced Ransomware Intel - LockBit, BlackCat, Rhysida, Cl0p - all with official advisory references.
4. Judge Dredd Disclosure - We post warnings directly on malicious repos. "I AM THE LAW."
Why This Matters
Every crypto drainer we catch saves someone's retirement. Every RAT builder we report prevents a hospital from getting pwned. Every C2 IP we publish helps a SOC analyst sleep better.
• 4 malware droppers suspended (FireSuper, rampubg14-cmyk, anuxagfr, winchmrsmilegodsgf)
• 1 C2 IP blocked (149.102.156.62 - Contabo/Rhadamanthys)
• 16 GitHub repos warned with evidence
The Business Model
Free threat intel builds reputation. Reputation builds subscribers. Subscribers become customers.
• Real-time GitHub malware alerts (API)
• Custom threat hunting for your supply chain
• Incident response with Pattern 38 expertise
• STIX feed integration for enterprise SIEMs
We're Looking for Seed Funding
Here's the honest pitch:
• Proven methodology (51 pulses in 5 days)
Microsoft pulls this feed daily. AT&T pulls this feed daily. Starlink pulls this feed daily. Get the DugganUSA STIX feed — $9/mo →
• Growing OTX subscriber base (14 and climbing)
• Automated detection pipeline (GitHub Actions, daily scans)
• Domain expertise (Pattern 38-42 taxonomy)
• Zero overhead (Minnesota garage operation)
• $150K seed to go full-time
• ThreatFox API access ($$$)
• VirusTotal Enterprise ($$$)
• One more analyst
• Equity in the only company doing systematic GitHub supply chain threat intel
• First-mover advantage in an underserved market
• Two founders who ship faster than your last three acquisitions
Contact
Patrick Duggan DugganUSA LLC [email protected] Minnesota, USA
• OTX: [pduggusa](https://otx.alienvault.com/user/pduggusa)
• STIX Feed: analytics.dugganusa.com/api/v1/stix-feed
• Blog: www.dugganusa.com
*"Feed subscribers get IOCs first. Bad actors get public shaming second. Investors get returns third."*
*- The DugganUSA Way*
Get Free IOCs
Subscribe to our threat intelligence feeds for free, machine-readable IOCs:
AlienVault OTX: https://otx.alienvault.com/user/pduggusa
STIX 2.1 Feed: https://analytics.dugganusa.com/api/v1/stix-feed
Questions? [email protected]
The cheapest, fastest, most accurate threat feed on the internet.
275+ enterprises pulling daily. 1M+ IOCs. 17.4M indexed documents. We beat Zscaler by 43 days on NrodeCodeRAT. Starter tier $9/mo — less than any competitor’s sales demo.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=untitled-blog-post




Comments