SYMBOL | COMMON_NAME | aka. SYNONYMS |
Leviathan is an espionage actor targeting organizations and high-value targets in defense and government. Active since at least 2014, this actor has long-standing interest in maritime industries, naval defense contractors, and associated research institutions in the United States and Western Europe.
2024-11-12
⋅
Recorded Future
⋅
China-Nexus TAG-112 Compromises Tibetan Websites to Distribute Cobalt Strike Cobalt Strike |
2024-10-31
⋅
Hunt.io
⋅
Tricks, Treats, and Threats: Cobalt Strike & the Goblin Lurking in Plain Sight Cobalt Strike |
2024-10-24
⋅
Seqrite
⋅
Operation Cobalt Whisper: Threat Actor Targets Multiple Industries Across Hong Kong and Pakistan Cobalt Strike Operation Cobalt Whisper |
2024-10-23
⋅
Cisco Talos
⋅
Highlighting TA866/Asylum Ambuscade Activity Since 2021 WasabiSeed Cobalt Strike csharp-streamer RAT Resident Rhadamanthys WarmCookie |
2024-10-23
⋅
Cisco Talos
⋅
Threat Spotlight: WarmCookie/BadSpace Cobalt Strike csharp-streamer RAT WarmCookie |
2024-10-10
⋅
Hunt.io
⋅
Unmasking Adversary Infrastructure: How Certificates and Redirects Exposed Earth Baxia and PlugX Activity PlugX |
2024-09-19
⋅
Trend Micro
⋅
Earth Baxia Uses Spear-Phishing and GeoServer Exploit to Target APAC (IoCs) Cobalt Strike Earth Baxia |
2024-09-19
⋅
Trend Micro
⋅
Earth Baxia Uses Spear-Phishing and GeoServer Exploit to Target APAC Cobalt Strike Earth Baxia |
2024-09-10
⋅
Talos Intelligence
⋅
DragonRank, a Chinese-speaking SEO manipulator service provider IISpy PlugX DragonRank |
2024-08-29
⋅
Securonix
⋅
From Cobalt Strike to Mimikatz: A Deep Dive into the SLOW#TEMPEST Campaign Targeting Chinese Users Cobalt Strike MimiKatz |
2024-08-26
⋅
The DFIR Report
⋅
BlackSuit Ransomware BlackSuit Cobalt Strike SystemBC |
2024-08-23
⋅
TEAMT5
⋅
Sailing the Seven SEAs: Deep Dive into Polaris' Arsenal and Intelligence Insights Cobalt Strike Hodur PlugX TONESHELL |
2024-08-23
⋅
ITOCHU
⋅
Pirates of The Nang Hai: Follow the Artifacts No One Know Cobalt Strike Xiangoop |
2024-08-22
⋅
⋅
NTT
⋅
AppDomainManager Injectionを悪用したマルウェアによる攻撃について Cobalt Strike Earth Baxia |
2024-08-21
⋅
TG Soft
⋅
Chinese APT abuses MSC files with GrimResource vulnerability Cobalt Strike Earth Baxia |
2024-08-04
⋅
Twitter (@embee_research)
⋅
Decoding a Cobalt Strike Downloader Script With CyberChef Cobalt Strike |
2024-07-25
⋅
SOC Prime
⋅
UAC-0057 Attack Detection: A Surge in Adversary Activity Distributing PICASSOLOADER and Cobalt Strike Beacon Cobalt Strike PicassoLoader Ghostwriter |
2024-07-22
⋅
Censys
⋅
A Beginner’s Guide to Hunting Malicious Open Directories Cobalt Strike Lumma Stealer Vidar |
2024-07-18
⋅
Mandiant
⋅
APT41 Has Arisen From the DUST Cobalt Strike |
2024-07-16
⋅
Recorded Future
⋅
TAG-100 Uses Open-Source Tools in Suspected Global Espionage Campaign, Compromising Two Asia-Pacific Intergovernmental Bodies Cobalt Strike |
2024-07-10
⋅
Zscaler
⋅
DodgeBox: A deep dive into the updated arsenal of APT41 | Part 1 Cobalt Strike DUSTPAN DUSTTRAP |
2024-07-10
⋅
Akamai
⋅
CVE-2024-4577 Exploits in the Wild One Day After Disclosure Tsunami Ghost RAT xmrig |
2024-07-09
⋅
Spamhaus
⋅
Spamhaus Botnet Threat Update January to June 2024 Coper FluBot Hook Bashlite Mirai FAKEUPDATES AsyncRAT BianLian Cobalt Strike DCRat Havoc NjRAT QakBot Quasar RAT RedLine Stealer Remcos Rhadamanthys RisePro Sliver |
2024-07-02
⋅
Sekoia
⋅
Exposing FakeBat loader: distribution methods and adversary infrastructure BlackCat Royal Ransom EugenLoader Carbanak Cobalt Strike DICELOADER Gozi IcedID Lumma Stealer NetSupportManager RAT Pikabot RedLine Stealer SectopRAT Sliver SmokeLoader Vidar |
2024-06-21
⋅
Elastic
⋅
GrimResource - Microsoft Management Console for initial access and evasion Cobalt Strike |
2024-05-23
⋅
Checkpoint
⋅
Sharp dragon expands towards africa and the caribbean 5.t Downloader Cobalt Strike |
2024-05-23
⋅
Palo Alto Networks Unit 42
⋅
Operation Diplomatic Specter: An Active Chinese Cyberespionage Campaign Leverages Rare Tool Set to Target Governmental Entities in the Middle East, Africa and Asia Agent Racoon CHINACHOPPER Ghost RAT JuicyPotato MimiKatz Ntospy PlugX SweetSpecter TunnelSpecter CL-STA-0043 |
2024-05-23
⋅
Check Point
⋅
Chinese Espionage Campaign Expands to Target Africa and The Caribbean 5.t Downloader Cobalt Strike |
2024-05-15
⋅
Microsoft
⋅
Threat actors misusing Quick Assist in social engineering attacks leading to ransomware Black Basta Cobalt Strike QakBot |
2024-05-14
⋅
Kaspersky
⋅
QakBot attacks with Windows zero-day (CVE-2024-30051) Cobalt Strike QakBot |
2024-05-10
⋅
Rapid7 Labs
⋅
Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators Black Basta Black Basta Cobalt Strike NetSupportManager RAT |
2024-04-27
⋅
Google
⋅
Finding Malware: Detecting SOGU with Google Security Operations. PlugX |
2024-04-24
⋅
Securonix
⋅
Analysis of Ongoing FROZEN#SHADOW Attack Campaign Leveraging SSLoad Malware and RMM Software for Domain Takeover Cobalt Strike Latrodectus |
2024-04-19
⋅
⋅
Spiegel Online
⋅
VW-Konzern wurde jahrelang ausspioniert – von China? CHINACHOPPER PlugX |
2024-04-01
⋅
The DFIR Report
⋅
From OneNote to RansomNote: An Ice Cold Intrusion Cobalt Strike IcedID Nokoyawa Ransomware PhotoLoader |
2024-03-18
⋅
Trend Micro
⋅
Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks DinodasRAT PlugX Reshell ShadowPad Earth Krahang |
2024-03-01
⋅
Medium b.magnezi
⋅
Malware Analysis - Cobalt Strike Cobalt Strike |
2024-02-21
⋅
YouTube (SentinelOne)
⋅
LABSCon23 Replay | Chasing Shadows | The rise of a prolific espionage actor 9002 RAT PlugX ShadowPad Spyder Earth Lusca |
2024-02-09
⋅
Censys
⋅
A Beginners Guide to Tracking Malware Infrastructure AsyncRAT BianLian Cobalt Strike QakBot |
2024-02-08
⋅
YouTube (Embee Research)
⋅
Cobalt Strike Decoding and C2 Extraction - 3 Minute Malware Analysis Speedrun Cobalt Strike |
2024-01-26
⋅
Trendmicro
⋅
Spot the Difference: An Analysis of the New LODEINFO Campaign by Earth Kasha Anel Cobalt Strike LODEINFO NOOPDOOR |
2024-01-25
⋅
JSAC 2024
⋅
Unveiling TeleBoyi: Chinese APT Group Targeting Critical Infrastructure Worldwide PlugX |
2024-01-25
⋅
JSAC 2024
⋅
The Secret Life of RATs: connecting the dots by dissecting multiple backdoors DracuLoader GroundPeony HemiGate PlugX |
2024-01-23
⋅
CSIRT-CTI
⋅
Stately Taurus Targets Myanmar Amidst Concerns over Military Junta’s Handling of Rebel Attacks PlugX PUBLOAD TONESHELL |
2024-01-21
⋅
Mahmoud Zohdy Blog
⋅
A Look into PlugX Kernel driver PlugX |
2024-01-13
⋅
YouTube (Embee Research)
⋅
Cobalt Strike Shellcode Analysis and C2 Extraction Cobalt Strike |
2024-01-12
⋅
Spamhaus
⋅
Spamhaus Botnet Threat Update Q4 2023 FluBot Hook FAKEUPDATES AsyncRAT BianLian Cobalt Strike DCRat Havoc IcedID Lumma Stealer Meterpreter NjRAT Pikabot QakBot Quasar RAT RecordBreaker RedLine Stealer Remcos Rhadamanthys Sliver |
2024-01-09
⋅
Recorded Future
⋅
2023 Adversary Infrastructure Report AsyncRAT Cobalt Strike Emotet PlugX ShadowPad |
2024-01-04
⋅
Netresec
⋅
Hunting for Cobalt Strike in PCAP Cobalt Strike |
2023-12-20
⋅
Twitter (@embee_research)
⋅
Defeating Obfuscated Malware Scripts - Cobalt Strike Cobalt Strike |
2023-12-19
⋅
Twitter (@embee_research)
⋅
Free Ghidra Tutorials for Beginners Cobalt Strike DarkGate |
2023-12-08
⋅
Twitter (@embee_research)
⋅
Ghidra Basics - Manual Shellcode Analysis and C2 Extraction Cobalt Strike |
2023-12-06
⋅
splunk
⋅
Unmasking the Enigma: A Historical Dive into the World of PlugX Malware PlugX |
2023-12-04
⋅
The DFIR Report
⋅
SQL Brute Force leads to Bluesky Ransomware BlueSky Cobalt Strike |
2023-11-19
⋅
Twitter (@embee_research)
⋅
Combining Pivot Points to Identify Malware Infrastructure - Redline, Smokeloader and Cobalt Strike Amadey Cobalt Strike RedLine Stealer SmokeLoader |
2023-11-14
⋅
Medium joshuapenny88
⋅
HostingHunter Series: CHANG WAY TECHNOLOGIES CO. LIMITED Hook Hydra Cobalt Strike SectopRAT |
2023-11-10
⋅
NSFOCUS
⋅
The New APT Group DarkCasino and the Global Surge in WinRAR 0-Day Exploits Cobalt Strike Konni DarkCasino Opal Sleet |
2023-11-07
⋅
SOCRadar
⋅
New Gootloader Variant “GootBot” Changes the Game in Malware Tactics GootLoader Cobalt Strike UNC2565 |
2023-11-06
⋅
Twitter (@embee_research)
⋅
Unpacking Malware With Hardware Breakpoints - Cobalt Strike Cobalt Strike |
2023-11-01
⋅
nccgroup
⋅
Popping Blisters for research: An overview of past payloads and exploring recent developments Blister Cobalt Strike |
2023-10-23
⋅
Twitter (@embee_research)
⋅
Cobalt Strike .VBS Loader - Decoding with Advanced CyberChef and Emulation Cobalt Strike |
2023-10-20
⋅
Twitter (@embee_research)
⋅
Decoding a Cobalt Strike .hta Loader Using CyberChef and Emulation Cobalt Strike |
2023-10-18
⋅
Twitter (@embee_research)
⋅
Ghidra Tutorial - Using Entropy To Locate a Cobalt Strike Decryption Function Cobalt Strike |
2023-10-18
⋅
Google
⋅
Government-backed actors exploiting WinRAR vulnerability APT40 |
2023-10-12
⋅
Spamhaus
⋅
Spamhaus Botnet Threat Update Q3 2023 FluBot AsyncRAT Ave Maria Cobalt Strike DCRat Havoc IcedID ISFB Nanocore RAT NjRAT QakBot Quasar RAT RecordBreaker RedLine Stealer Remcos Rhadamanthys Sliver Stealc Tofsee Vidar |
2023-10-12
⋅
Netresec
⋅
Forensic Timeline of an IcedID Infection Cobalt Strike IcedID IcedID Downloader |
2023-10-10
⋅
Symantec
⋅
Grayling: Previously Unseen Threat Actor Targets Multiple Organizations in Taiwan Cobalt Strike Havoc MimiKatz Grayling |
2023-10-03
⋅
Malware Traffic Analysis
⋅
2023-10-03 (Tuesday) - PikaBot infection with Cobalt Strike Cobalt Strike Pikabot |
2023-09-22
⋅
Mandiant
⋅
Backchannel Diplomacy: APT29’s Rapidly Evolving Diplomatic Phishing Operations Brute Ratel C4 Cobalt Strike EnvyScout GraphDrop QUARTERRIG sRDI Unidentified 107 (APT29) |
2023-09-22
⋅
Palo Alto Networks Unit 42
⋅
Cyberespionage Attacks Against Southeast Asian Government Linked to Stately Taurus, Aka Mustang Panda Cobalt Strike MimiKatz RemCom ShadowPad TONESHELL |
2023-09-12
⋅
⋅
ANSSI
⋅
FIN12: A Cybercriminal Group with Multiple Ransomware BlackCat Cobalt Strike Conti Hive MimiKatz Nokoyawa Ransomware PLAY Royal Ransom Ryuk SystemBC |
2023-09-08
⋅
PolySwarm Tech Team
⋅
Carderbee Targets Hong Kong in Supply Chain Attack PlugX Carderbee |
2023-09-07
⋅
Sekoia
⋅
My Tea’s not cold. An overview of China’s cyber threat Melofee PingPull SoWaT Sword2033 MgBot MQsTTang PlugX TONESHELL Dalbit MirrorFace |
2023-08-30
⋅
Trend Micro
⋅
Earth Estries Targets Government, Tech for Cyberespionage Cobalt Strike HemiGate Earth Estries |
2023-08-28
⋅
The DFIR Report
⋅
HTML Smuggling Leads to Domain Wide Ransomware Cobalt Strike IcedID Nokoyawa Ransomware |
2023-08-22
⋅
Symantec
⋅
Carderbee: APT Group use Legit Software in Supply Chain Attack Targeting Orgs in Hong Kong PlugX Carderbee |
2023-08-18
⋅
TEAMT5
⋅
Unmasking CamoFei: An In-depth Analysis of an Emerging APT Group Focused on Healthcare Sectors in East Asia CatB Cobalt Strike DoorMe GIMMICK |
2023-08-18
⋅
d01a
⋅
Understanding Syscalls: Direct, Indirect, and Cobalt Strike Implementation Cobalt Strike |
2023-08-17
⋅
SentinelOne
⋅
Chinese Entanglement | DLL Hijacking in the Asian Gambling Sector Cobalt Strike HUI Loader BRONZE STARLIGHT |
2023-08-07
⋅
Recorded Future
⋅
RedHotel: A Prolific, Chinese State-Sponsored Group Operating at a Global Scale Winnti Brute Ratel C4 Cobalt Strike FunnySwitch PlugX ShadowPad Spyder Earth Lusca |
2023-07-29
⋅
Google
⋅
Threat Horizons August 2023 Threat Horizons Report SharkBot Cobalt Strike |
2023-07-11
⋅
Spamhaus
⋅
Spamhaus Botnet Threat Update Q2 2023 Hydra AsyncRAT Aurora Stealer Ave Maria BumbleBee Cobalt Strike DCRat Havoc IcedID ISFB NjRAT QakBot Quasar RAT RecordBreaker RedLine Stealer Remcos Rhadamanthys Sliver Tofsee |
2023-07-11
⋅
Mandiant
⋅
The Spies Who Loved You: Infected USB Drives to Steal Secrets PlugX |
2023-07-07
⋅
Lab52
⋅
Beyond appearances: unknown actor using APT29’s TTP against Chinese users Cobalt Strike |
2023-06-30
⋅
K7 Security
⋅
Cobalt Strike’s Deployment with Hardware Breakpoint for AMSI Bypass Cobalt Strike |
2023-06-16
⋅
Palo Alto Networks: Cortex Threat Research
⋅
Through the Cortex XDR Lens: Uncovering a New Activity Group Targeting Governments in the Middle East and Africa CHINACHOPPER Ladon Yasso CL-STA-0043 |
2023-06-16
⋅
SOC Prime
⋅
PicassoLoader and Cobalt Strike Beacon Detection: UAC-0057 aka GhostWriter Hacking Group Attacks the Ukrainian Leading Military Educational Institution Cobalt Strike PicassoLoader Ghostwriter |
2023-06-15
⋅
eSentire
⋅
eSentire Threat Intelligence Malware Analysis: Resident Campaign Cobalt Strike Resident Rhadamanthys WarmCookie |
2023-06-10
⋅
The DFIR Report
⋅
IcedID Brings ScreenConnect and CSharp Streamer to ALPHV Ransomware Deployment BlackCat Cobalt Strike IcedID |
2023-06-08
⋅
Twitter (@embee_research)
⋅
Practical Queries for Identifying Malware Infrastructure: An informal page for storing Censys/Shodan queries Amadey AsyncRAT Cobalt Strike QakBot Quasar RAT Sliver solarmarker |
2023-06-08
⋅
VMRay
⋅
Busy Bees - The Transformation of BumbleBee BumbleBee Cobalt Strike Conti Meterpreter Sliver |
2023-05-15
⋅
Symantec
⋅
Lancefly: Group Uses Custom Backdoor to Target Orgs in Government, Aviation, Other Sectors Merdoor PlugX ShadowPad ZXShell Lancefly |
2023-05-11
⋅
cocomelonc
⋅
Malware development trick - part 28: Dump lsass.exe. Simple C++ example. Cobalt Strike APT3 Keylogger |
2023-05-03
⋅
Lab52
⋅
New Mustang Panda’s campaing against Australia PlugX |
2023-04-24
⋅
Cofense
⋅
Open-Source Gh0st RAT Still Haunting Inboxes 15 Years After Release Ghost RAT |
2023-04-20
⋅
Github (dodo-sec)
⋅
An analysis of syscall usage in Cobalt Strike Beacons Cobalt Strike |
2023-04-20
⋅
Secureworks
⋅
Bumblebee Malware Distributed Via Trojanized Installer Downloads BumbleBee Cobalt Strike |
2023-04-18
⋅
Mandiant
⋅
M-Trends 2023 QUIETEXIT AppleJeus Black Basta BlackCat CaddyWiper Cobalt Strike Dharma HermeticWiper Hive INDUSTROYER2 Ladon LockBit Meterpreter PartyTicket PlugX QakBot REvil Royal Ransom SystemBC WhisperGate |
2023-04-13
⋅
Intel 471
⋅
From GhostNet to PseudoManuscrypt - The evolution of Gh0st RAT BBSRAT Gh0stTimes Ghost RAT PseudoManuscrypt |
2023-04-12
⋅
Spamhaus
⋅
Spamhaus Botnet Threat Update Q1 2023 FluBot Amadey AsyncRAT Aurora Ave Maria BumbleBee Cobalt Strike DCRat Emotet IcedID ISFB NjRAT QakBot RecordBreaker RedLine Stealer Remcos Rhadamanthys Sliver Tofsee Vidar |
2023-04-03
⋅
The DFIR Report
⋅
Malicious ISO File Leads to Domain Wide Ransomware Cobalt Strike IcedID Mount Locker |
2023-03-30
⋅
United States District Court (Eastern District of New York)
⋅
Cracked Cobalt Strike (1:23-cv-02447) Black Basta BlackCat LockBit RagnarLocker LockBit Black Basta BlackCat Cobalt Strike Cuba Emotet LockBit Mount Locker PLAY QakBot RagnarLocker Royal Ransom Zloader |
2023-03-30
⋅
Recorded Future
⋅
With KEYPLUG, China’s RedGolf Spies On, Steals From Wide Field of Targets KEYPLUG Cobalt Strike PlugX RedGolf |
2023-03-30
⋅
eSentire
⋅
eSentire Threat Intelligence Malware Analysis: BatLoader BATLOADER Cobalt Strike ISFB SystemBC Vidar |
2023-03-28
⋅
ExaTrack
⋅
Mélofée: a new alien malware in the Panda's toolset targeting Linux hosts HelloBot Melofee Winnti Cobalt Strike SparkRAT STOWAWAY |
2023-03-10
⋅
Medium walmartglobaltech
⋅
From Royal With Love Cobalt Strike Conti PLAY Royal Ransom Somnia |
2023-03-09
⋅
ASEC
⋅
PlugX Malware Being Distributed via Vulnerability Exploitation PlugX |
2023-03-09
⋅
Sophos
⋅
A border-hopping PlugX USB worm takes its act on the road PlugX |
2023-03-01
⋅
Zscaler
⋅
OneNote: A Growing Threat for Malware Distribution AsyncRAT Cobalt Strike IcedID QakBot RedLine Stealer |
2023-02-24
⋅
Trend Micro
⋅
Investigating the PlugX Trojan Disguised as a Legitimate Windows Debugger Tool PlugX |
2023-02-23
⋅
Bitdefender
⋅
Technical Advisory: Various Threat Actors Targeting ManageEngine Exploit CVE-2022-47966 Cobalt Strike DarkComet QuiteRAT RATel |
2023-02-22
⋅
Symantec
⋅
Hydrochasma: Previously Unknown Group Targets Medical and Shipping Organizations in Asia Cobalt Strike |
2023-02-14
⋅
Cybereason
⋅
GootLoader - SEO Poisoning and Large Payloads Leading to Compromise GootLoader Cobalt Strike SystemBC |
2023-02-13
⋅
AhnLab
⋅
Dalbit (m00nlight): Chinese Hacker Group’s APT Attack Campaign Godzilla Webshell ASPXSpy BlueShell CHINACHOPPER Cobalt Strike Ladon MimiKatz Dalbit |
2023-02-13
⋅
Kroll
⋅
Royal Ransomware Deep Dive Cobalt Strike Royal Ransom |
2023-02-08
⋅
Trend Micro
⋅
Earth Zhulong: Familiar Patterns Target Southeast Asian Firms Cobalt Strike MACAMAX 1937CN |
2023-02-03
⋅
Mandiant
⋅
Float Like a Butterfly Sting Like a Bee BazarBackdoor BumbleBee Cobalt Strike |
2023-02-02
⋅
Kroll
⋅
Hive Ransomware Technical Analysis and Initial Access Discovery BATLOADER Cobalt Strike Hive |
2023-02-02
⋅
EclecticIQ
⋅
Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware PlugX |
2023-01-30
⋅
Checkpoint
⋅
Following the Scent of TrickGate: 6-Year-Old Packer Used to Deploy the Most Wanted Malware Agent Tesla Azorult Buer Cerber Cobalt Strike Emotet Formbook HawkEye Keylogger Loki Password Stealer (PWS) Maze NetWire RC Remcos REvil TrickBot |
2023-01-26
⋅
TEAMT5
⋅
Brief History of MustangPanda and its PlugX Evolution PlugX MUSTANG PANDA |
2023-01-26
⋅
Palo Alto Networks Unit 42
⋅
Chinese PlugX Malware Hidden in Your USB Devices? PlugX |
2023-01-24
⋅
Fortinet
⋅
The Year of the Wiper Azov Wiper Bruh Wiper CaddyWiper Cobalt Strike Vidar |
2023-01-23
⋅
Kroll
⋅
Black Basta – Technical Analysis Black Basta Cobalt Strike MimiKatz QakBot SystemBC |
2023-01-16
⋅
Intrinsec
⋅
ProxyNotShell – OWASSRF – Merry Xchange Cobalt Strike SystemBC |
2023-01-09
⋅
kienmanowar Blog
⋅
[QuickNote] Another nice PlugX sample PlugX |
2023-01-05
⋅
Symantec
⋅
Bluebottle: Campaign Hits Banks in French-speaking Countries in Africa CloudEyE Cobalt Strike MimiKatz NetWire RC POORTRY Quasar RAT BlueBottle |
2022-12-27
⋅
kienmanowar Blog
⋅
Diving into a PlugX sample of Mustang Panda group PlugX |
2022-12-24
⋅
Medium (@DCSO_CyTec)
⋅
APT41 — The spy who failed to encrypt me CHINACHOPPER |
2022-12-15
⋅
Mandiant
⋅
Trojanized Windows 10 Operating System Installers Targeted Ukrainian Government Cobalt Strike STOWAWAY |
2022-12-08
⋅
Cisco Talos
⋅
Breaking the silence - Recent Truebot activity Clop Cobalt Strike FlawedGrace Raspberry Robin Silence Teleport |
2022-12-06
⋅
EuRepoC
⋅
Conti/Wizard Spider BazarBackdoor Cobalt Strike Conti Emotet IcedID Ryuk TrickBot WIZARD SPIDER |
2022-12-06
⋅
Blackberry
⋅
Mustang Panda Uses the Russian-Ukrainian War to Attack Europe and Asia Pacific Targets PlugX |
2022-12-02
⋅
Palo Alto Networks Unit 42
⋅
Blowing Cobalt Strike Out of the Water With Memory Analysis Cobalt Strike |
2022-12-02
⋅
Avast Decoded
⋅
Hitching a ride with Mustang Panda PlugX |
2022-11-30
⋅
⋅
FFRI Security
⋅
Evolution of the PlugX loader PlugX Poison Ivy |
2022-11-15
⋅
SOC Prime
⋅
Somnia Malware Detection: UAC-0118 aka FRwL Launches Cyber Attacks Against Organizations in Ukraine Using Enhanced Malware Strains Cobalt Strike Vidar UAC-0118 |
2022-11-09
⋅
Trend Micro
⋅
Hack the Real Box: APT41’s New Subgroup Earth Longzhi Cobalt Strike MimiKatz Earth Longzhi |
2022-11-03
⋅
paloalto Netoworks: Unit42
⋅
Cobalt Strike Analysis and Tutorial: Identifying Beacon Team Servers in the Wild Cobalt Strike |
2022-11-03
⋅
Group-IB
⋅
Financially motivated, dangerously activated: OPERA1ER APT in Africa Cobalt Strike Common Raven |
2022-11-03
⋅
Github (chronicle)
⋅
GCTI Open Source Detection Signatures Cobalt Strike Sliver |
2022-10-31
⋅
Cynet
⋅
Orion Threat Alert: Qakbot TTPs Arsenal and the Black Basta Ransomware Black Basta Cobalt Strike QakBot |
2022-10-13
⋅
Spamhaus
⋅
Spamhaus Botnet Threat Update Q3 2022 FluBot Arkei Stealer AsyncRAT Ave Maria BumbleBee Cobalt Strike DCRat Dridex Emotet Loki Password Stealer (PWS) Nanocore RAT NetWire RC NjRAT QakBot RecordBreaker RedLine Stealer Remcos Socelars Tofsee Vjw0rm |
2022-10-13
⋅
Microsoft
⋅
Hunting for Cobalt Strike: Mining and plotting for fun and profit Cobalt Strike |
2022-10-12
⋅
Trend Micro
⋅
Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike Black Basta Brute Ratel C4 Cobalt Strike QakBot |
2022-10-06
⋅
Blackberry
⋅
Mustang Panda Abuses Legitimate Apps to Target Myanmar Based Victims PlugX |
2022-10-03
⋅
Check Point
⋅
Bumblebee: increasing its capacity and evolving its TTPs BumbleBee Cobalt Strike Meterpreter Sliver Vidar |
2022-10-03
⋅
Trend Micro
⋅
Water Labbu Abuses Malicious DApps to Steal Cryptocurrency Cobalt Strike Water Labbu |
2022-09-29
⋅
Symantec
⋅
Witchetty: Group Uses Updated Toolset in Attacks on Governments in Middle East CHINACHOPPER Lookback MimiKatz PlugX Unidentified 096 (Keylogger) x4 Witchetty |
2022-09-26
⋅
Palo Alto Networks Unit 42
⋅
Hunting for Unsigned DLLs to Find APTs PlugX Raspberry Robin Roshtyak |
2022-09-26
⋅
The DFIR Report
⋅
BumbleBee: Round Two BumbleBee Cobalt Strike Meterpreter |
2022-09-25
⋅
YouTube (Arda Büyükkaya)
⋅
Cobalt Strike Shellcode Loader With Rust (YouTube) Cobalt Strike |
2022-09-15
⋅
Symantec
⋅
Webworm: Espionage Attackers Testing and Using Older Modified RATs 9002 RAT Ghost RAT Trochilus RAT |
2022-09-14
⋅
Security Joes
⋅
Dissecting PlugX to Extract Its Crown Jewels PlugX |
2022-09-13
⋅
Symantec
⋅
New Wave of Espionage Activity Targets Asian Governments MimiKatz PlugX Quasar RAT ShadowPad Trochilus RAT |
2022-09-13
⋅
AdvIntel
⋅
AdvIntel's State of Emotet aka "SpmTools" Displays Over Million Compromised Machines Through 2022 Conti Cobalt Strike Emotet Ryuk TrickBot |
2022-09-12
⋅
The DFIR Report
⋅
Dead or Alive? An Emotet Story Cobalt Strike Emotet |
2022-09-09
⋅
Github (m4now4r)
⋅
“Mustang Panda” – Enemy at the gate PlugX |
2022-09-08
⋅
Secureworks
⋅
BRONZE PRESIDENT Targets Government Officials PlugX |
2022-09-08
⋅
Cybereason
⋅
Threat Analysis Report: PlugX RAT Loader Evolution PlugX |
2022-09-07
⋅
Google
⋅
Initial access broker repurposing techniques in targeted attacks against Ukraine AnchorMail Cobalt Strike IcedID |
2022-09-07
⋅
cyble
⋅
Bumblebee Returns With New Infection Technique BumbleBee Cobalt Strike |
2022-09-06
⋅
⋅
INCIBE-CERT
⋅
Estudio del análisis de Nobelium BEATDROP BOOMBOX Cobalt Strike EnvyScout Unidentified 099 (APT29 Dropbox Loader) VaporRage |
2022-09-06
⋅
CISA
⋅
Alert (AA22-249A) #StopRansomware: Vice Society Cobalt Strike Empire Downloader FiveHands HelloKitty SystemBC Zeppelin |
2022-09-06
⋅
Didier Stevens
⋅
An Obfuscated Beacon – Extra XOR Layer Cobalt Strike |
2022-09-06
⋅
cocomelonc
⋅
Malware development tricks: parent PID spoofing. Simple C++ example. Cobalt Strike Konni |
2022-09-01
⋅
Medium michaelkoczwara
⋅
Hunting C2/Adversaries Infrastructure with Shodan and Censys Brute Ratel C4 Cobalt Strike Deimos GRUNT IcedID Merlin Meterpreter Nighthawk PoshC2 Sliver |
2022-09-01
⋅
Trend Micro
⋅
Ransomware Spotlight Black Basta Black Basta Cobalt Strike MimiKatz QakBot |
2022-08-30
⋅
Proofpoint
⋅
Rising Tide: Chasing the Currents of Espionage in the South China Sea scanbox Meterpreter APT40 |
2022-08-30
⋅
eSentire
⋅
Hacker Infrastructure Used in Cisco Breach Discovered Attacking a Top Workforce Management Corporation & an Affiliate of Russia’s Evil Corp Gang Suspected, Reports eSentire Cobalt Strike FiveHands UNC2447 |
2022-08-25
⋅
SentinelOne
⋅
BlueSky Ransomware | AD Lateral Movement, Evasion and Fast Encryption Put Threat on the Radar BlueSky Cobalt Strike JuicyPotato |
2022-08-22
⋅
Microsoft
⋅
Extortion Economics - Ransomware’s new business model BlackCat Conti Hive REvil AgendaCrypt Black Basta BlackCat Brute Ratel C4 Cobalt Strike Conti Hive Mount Locker Nokoyawa Ransomware REvil Ryuk |
2022-08-19
⋅
nccgroup
⋅
Back in Black: Unlocking a LockBit 3.0 Ransomware Attack FAKEUPDATES Cobalt Strike LockBit |
2022-08-18
⋅
⋅
NSFOCUS
⋅
New APT group MURENSHARK investigative report: Torpedoes hit Turkish Navy Cobalt Strike |
2022-08-18
⋅
Group-IB
⋅
APT41 World Tour 2021 on a tight schedule Cobalt Strike |
2022-08-18
⋅
Sophos
⋅
Cookie stealing: the new perimeter bypass Cobalt Strike Meterpreter MimiKatz Phoenix Keylogger Quasar RAT |
2022-08-18
⋅
Trustwave
⋅
Overview of the Cyber Weapons Used in the Ukraine - Russia War AcidRain CaddyWiper Cobalt Strike CredoMap DCRat DoubleZero GraphSteel GrimPlant HermeticWiper INDUSTROYER2 InvisiMole IsaacWiper PartyTicket |
2022-08-18
⋅
Trustwave
⋅
Overview of the Cyber Weapons Used in the Ukraine - Russia War AcidRain CaddyWiper Cobalt Strike CredoMap DCRat DoubleZero GraphSteel GrimPlant HermeticWiper INDUSTROYER2 InvisiMole IsaacWiper PartyTicket |
2022-08-17
⋅
Cybereason
⋅
Bumblebee Loader – The High Road to Enterprise Domain Control BumbleBee Cobalt Strike |
2022-08-17
⋅
Secureworks
⋅
DarkTortilla Malware Analysis Agent Tesla AsyncRAT Cobalt Strike DarkTortilla Nanocore RAT RedLine Stealer |
2022-08-12
⋅
SANS ISC
⋅
Monster Libra (TA551/Shathak) pushes IcedID (Bokbot) with Dark VNC and Cobalt Strike Cobalt Strike DarkVNC IcedID |
2022-08-11
⋅
Malcat
⋅
LNK forensic and config extraction of a cobalt strike beacon Cobalt Strike |
2022-08-11
⋅
SecurityScorecard
⋅
The Increase in Ransomware Attacks on Local Governments BlackCat BlackCat Cobalt Strike LockBit |
2022-08-10
⋅
⋅
Weixin
⋅
Operation(верность) mercenary: a torrent of steel trapped in the plains of Eastern Europe BumbleBee Cobalt Strike |
2022-08-08
⋅
The DFIR Report
⋅
BumbleBee Roasts Its Way to Domain Admin BumbleBee Cobalt Strike |
2022-08-04
⋅
YouTube (Arda Büyükkaya)
⋅
LockBit Ransomware Sideloads Cobalt Strike Through Microsoft Security Tool Cobalt Strike LockBit |
2022-08-04
⋅
Mandiant
⋅
Advanced Persistent Threats (APTs) APT1 APT10 APT12 APT14 APT15 APT16 APT17 APT18 APT19 APT2 APT20 APT21 APT22 APT23 APT24 APT27 APT3 APT30 APT31 APT4 APT40 APT5 APT9 Naikon |
2022-08-03
⋅
Palo Alto Networks Unit 42
⋅
Flight of the Bumblebee: Email Lures and File Sharing Services Lead to Malware BazarBackdoor BumbleBee Cobalt Strike Conti |
2022-08-02
⋅
Cisco Talos
⋅
Manjusaka: A Chinese sibling of Sliver and Cobalt Strike Manjusaka Cobalt Strike Manjusaka |
2022-07-30
⋅
Malware AV evasion - part 8. Encode payload via Z85 Agent Tesla Carbanak Carberp Cardinal RAT Cobalt Strike donut_injector |
2022-07-28
⋅
SentinelOne
⋅
Living Off Windows Defender | LockBit Ransomware Sideloads Cobalt Strike Through Microsoft Security Tool Cobalt Strike LockBit |
2022-07-27
⋅
ReversingLabs
⋅
Threat analysis: Follina exploit fuels 'live-off-the-land' attacks Cobalt Strike MimiKatz |
2022-07-27
⋅
cyble
⋅
Targeted Attacks Being Carried Out Via DLL SideLoading Cobalt Strike QakBot |
2022-07-27
⋅
Trend Micro
⋅
Gootkit Loader’s Updated Tactics and Fileless Delivery of Cobalt Strike Cobalt Strike GootKit Kronos REvil SunCrypt |
2022-07-26
⋅
Microsoft
⋅
Malicious IIS extensions quietly open persistent backdoors into servers CHINACHOPPER MimiKatz |
2022-07-22
⋅
Binary Ninja
⋅
Reverse Engineering a Cobalt Strike Dropper With Binary Ninja Cobalt Strike |
2022-07-20
⋅
NVISO Labs
⋅
Analysis of a trojanized jQuery script: GootLoader unleashed GootLoader Cobalt Strike |
2022-07-20
⋅
U.S. Cyber Command
⋅
Cyber National Mission Force discloses IOCs from Ukrainian networks Cobalt Strike GraphSteel GrimPlant MicroBackdoor |
2022-07-20
⋅
Advanced Intelligence
⋅
Anatomy of Attack: Truth Behind the Costa Rica Government Ransomware 5-Day Intrusion Cobalt Strike |
2022-07-20
⋅
Mandiant
⋅
Evacuation and Humanitarian Documents used to Spear Phish Ukrainian Entities Cobalt Strike GraphSteel GrimPlant MicroBackdoor |
2022-07-19
⋅
Palo Alto Networks Unit 42
⋅
Russian APT29 Hackers Use Online Storage Services, DropBox and Google Drive Cobalt Strike EnvyScout Gdrive |
2022-07-18
⋅
Palo Alto Networks Unit 42
⋅
Obscure Serpens Cobalt Strike Empire Downloader Meterpreter MimiKatz DarkHydrus |
2022-07-18
⋅
YouTube (Security Joes)
⋅
PlugX DLL Side-Loading Technique PlugX |
2022-07-18
⋅
Palo Alto Networks Unit 42
⋅
Shallow Taurus FormerFirstRAT IsSpace NewCT PlugX Poison Ivy Tidepool DragonOK |
2022-07-18
⋅
Censys
⋅
Russian Ransomware C2 Network Discovered in Censys Data Cobalt Strike DeimosC2 MimiKatz PoshC2 |
2022-07-18
⋅
Palo Alto Networks Unit 42
⋅
Iron Taurus CHINACHOPPER Ghost RAT Wonknu ZXShell APT27 |
2022-07-13
⋅
Malwarebytes Labs
⋅
Cobalt Strikes again: UAC-0056 continues to target Ukraine in its latest campaign Cobalt Strike |
2022-07-13
⋅
Palo Alto Networks Unit 42
⋅
Cobalt Strike Analysis and Tutorial: CS Metadata Encryption and Decryption Cobalt Strike |
2022-07-11
⋅
⋅
Cert-UA
⋅
UAC-0056 attack on Ukrainian state organizations using Cobalt Strike Beacon (CERT-UA#4941) Cobalt Strike |
2022-07-07
⋅
SANS ISC
⋅
Emotet infection with Cobalt Strike Cobalt Strike Emotet |
2022-07-07
⋅
IBM
⋅
Unprecedented Shift: The Trickbot Group is Systematically Attacking Ukraine AnchorMail BumbleBee Cobalt Strike IcedID Meterpreter |
2022-07-06
⋅
⋅
Cert-UA
⋅
UAC-0056 cyberattack on Ukrainian state organizations using Cobalt Strike Beacon (CERT-UA#4914) Cobalt Strike |
2022-06-30
⋅
Trend Micro
⋅
Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit Black Basta Cobalt Strike QakBot |
2022-06-28
⋅
Lumen
⋅
ZuoRAT Hijacks SOHO Routers To Silently Stalk Networks ZuoRAT Cobalt Strike |
2022-06-27
⋅
Kaspersky ICS CERT
⋅
Attacks on industrial control systems using ShadowPad Cobalt Strike PlugX ShadowPad |
2022-06-26
⋅
Overview of Russian GRU and SVR Cyberespionage Campaigns 1H 2022 Cobalt Strike CredoMap EnvyScout |
2022-06-23
⋅
cyble
⋅
Matanbuchus Loader Resurfaces Cobalt Strike Matanbuchus |
2022-06-23
⋅
Secureworks
⋅
BRONZE STARLIGHT Ransomware Operations Use HUI Loader ATOMSILO Cobalt Strike HUI Loader LockFile NightSky Pandora PlugX Quasar RAT Rook SodaMaster BRONZE STARLIGHT |
2022-06-21
⋅
Cisco Talos
⋅
Avos ransomware group expands with new attack arsenal AvosLocker Cobalt Strike DarkComet MimiKatz |
2022-06-20
⋅
⋅
Cert-UA
⋅
UAC-0098 group cyberattack on critical infrastructure of Ukraine (CERT-UA#4842) Cobalt Strike |
2022-06-17
⋅
SANS ISC
⋅
Malspam pushes Matanbuchus malware, leads to Cobalt Strike Cobalt Strike Matanbuchus |
2022-06-15
⋅
Security Joes
⋅
Backdoor via XFF: Mysterious Threat Actor Under Radar CHINACHOPPER |
2022-06-11
⋅
Twitter (@MsftSecIntel)
⋅
Tweet on DEV-0401, DEV-0234 exploiting Confluence RCE CVE-2022-26134 Kinsing Mirai Cobalt Strike Lilac Typhoon |
2022-06-07
⋅
AdvIntel
⋅
BlackCat — In a Shifting Threat Landscape, It Helps to Land on Your Feet: Tech Dive BlackCat BlackCat Cobalt Strike |
2022-06-07
⋅
cyble
⋅
Bumblebee Loader on The Rise BumbleBee Cobalt Strike |
2022-06-06
⋅
Trellix
⋅
Growling Bears Make Thunderous Noise Cobalt Strike HermeticWiper WhisperGate NB65 |
2022-06-04
⋅
kienmanowar Blog
⋅
[QuickNote] CobaltStrike SMB Beacon Analysis Cobalt Strike |
2022-06-03
⋅
AttackIQ
⋅
Attack Graph Response to US CERT AA22-152A: Karakurt Data Extortion Group Cobalt Strike MimiKatz |
2022-06-03
⋅
Avast Decoded
⋅
Outbreak of Follina in Australia AsyncRAT APT40 |
2022-06-02
⋅
Mandiant
⋅
TRENDING EVIL Q2 2022 CloudEyE Cobalt Strike CryptBot Emotet IsaacWiper QakBot |
2022-06-02
⋅
Mandiant
⋅
To HADES and Back: UNC2165 Shifts to LOCKBIT to Evade Sanctions FAKEUPDATES Blister Cobalt Strike DoppelPaymer Dridex FriedEx Hades LockBit Macaw MimiKatz Phoenix Locker WastedLocker |
2022-06-01
⋅
Elastic
⋅
CUBA Ransomware Campaign Analysis Cobalt Strike Cuba Meterpreter MimiKatz SystemBC |
2022-05-25
⋅
Medium walmartglobaltech
⋅
SocGholish Campaigns and Initial Access Kit FAKEUPDATES Blister Cobalt Strike NetSupportManager RAT |
2022-05-24
⋅
BitSight
⋅
Emotet Botnet Rises Again Cobalt Strike Emotet QakBot SystemBC |
2022-05-24
⋅
The Hacker News
⋅
Malware Analysis: Trickbot Cobalt Strike Conti Ryuk TrickBot |
2022-05-23
⋅
Trend Micro
⋅
Operation Earth Berberoka reptile oRAT Ghost RAT PlugX pupy Earth Berberoka |
2022-05-22
⋅
R136a1
⋅
Introduction of a PE file extractor for various situations Cobalt Strike Matanbuchus |
2022-05-20
⋅
sonatype
⋅
New 'pymafka' malicious package drops Cobalt Strike on macOS, Windows, Linux Cobalt Strike |
2022-05-20
⋅
VinCSS
⋅
[RE027] China-based APT Mustang Panda might have still continued their attack activities against organizations in Vietnam PlugX |
2022-05-20
⋅
Cybleinc
⋅
Malware Campaign Targets InfoSec Community: Threat Actor Uses Fake Proof Of Concept To Deliver Cobalt-Strike Beacon Cobalt Strike |
2022-05-20
⋅
AhnLab
⋅
Why Remediation Alone Is Not Enough When Infected by Malware Cobalt Strike DarkSide |
2022-05-19
⋅
InfoSec Handlers Diary Blog
⋅
Bumblebee Malware from TransferXL URLs BumbleBee Cobalt Strike |
2022-05-19
⋅
InfoSec Handlers Diary Blog
⋅
Bumblebee Malware from TransferXL URLs BumbleBee Cobalt Strike |
2022-05-18
⋅
PRODAFT Threat Intelligence
⋅
Wizard Spider In-Depth Analysis Cobalt Strike Conti WIZARD SPIDER |
2022-05-17
⋅
Trend Micro
⋅
Ransomware Spotlight: RansomEXX LaZagne Cobalt Strike IcedID MimiKatz PyXie RansomEXX TrickBot |
2022-05-17
⋅
Positive Technologies
⋅
Space Pirates: analyzing the tools and connections of a new hacker group FormerFirstRAT PlugX Poison Ivy Rovnix ShadowPad Zupdax |
2022-05-16
⋅
JPCERT/CC
⋅
Analysis of HUI Loader HUI Loader PlugX Poison Ivy Quasar RAT |
2022-05-12
⋅
Intel 471
⋅
What malware to look for if you want to prevent a ransomware attack Conti BumbleBee Cobalt Strike IcedID Sliver |
2022-05-12
⋅
Red Canary
⋅
The Goot cause: Detecting Gootloader and its follow-on activity GootLoader Cobalt Strike |
2022-05-12
⋅
Red Canary
⋅
Gootloader and Cobalt Strike malware analysis GootLoader Cobalt Strike |
2022-05-12
⋅
TEAMT5
⋅
The Next Gen PlugX/ShadowPad? A Dive into the Emerging China-Nexus Modular Trojan, Pangolin8RAT (slides) KEYPLUG Cobalt Strike CROSSWALK FunnySwitch PlugX ShadowPad Winnti SLIME29 TianWu |
2022-05-11
⋅
InfoSec Handlers Diary Blog
⋅
TA578 using thread-hijacked emails to push ISO files for Bumblebee malware BumbleBee Cobalt Strike IcedID PhotoLoader |
2022-05-11
⋅
⋅
NTT
⋅
Operation RestyLink: Targeted attack campaign targeting Japanese companies Cobalt Strike |
2022-05-10
⋅
Marco Ramilli's Blog
⋅
A Malware Analysis in RU-AU conflict Cobalt Strike |
2022-05-09
⋅
Microsoft
⋅
Ransomware-as-a-service: Understanding the cybercrime gig economy and how to protect yourself AnchorDNS BlackCat BlackMatter Conti DarkSide HelloKitty Hive LockBit REvil FAKEUPDATES Griffon ATOMSILO BazarBackdoor BlackCat BlackMatter Blister Cobalt Strike Conti DarkSide Emotet FiveHands Gozi HelloKitty Hive IcedID ISFB JSSLoader LockBit LockFile Maze NightSky Pandora Phobos Phoenix Locker PhotoLoader QakBot REvil Rook Ryuk SystemBC TrickBot WastedLocker BRONZE STARLIGHT |
2022-05-09
⋅
cocomelonc
⋅
Malware development: persistence - part 4. Windows services. Simple C++ example. Anchor AppleJeus Attor BBSRAT BlackEnergy Carbanak Cobalt Strike DuQu |
2022-05-09
⋅
⋅
Qianxin Threat Intelligence Center
⋅
Operation EviLoong: An electronic party of "borderless" hackers ZXShell |
2022-05-09
⋅
TEAMT5
⋅
Hiding in Plain Sight: Obscuring C2s by Abusing CDN Services Cobalt Strike |
2022-05-09
⋅
The DFIR Report
⋅
SEO Poisoning – A Gootloader Story GootLoader LaZagne Cobalt Strike GootKit |
2022-05-08
⋅
IronNet
⋅
Tracking Cobalt Strike Servers Used in Cyberattacks on Ukraine Cobalt Strike |
2022-05-06
⋅
Twitter (@MsftSecIntel)
⋅
Twitter Thread on initial infeciton of SocGholish/ FAKEUPDATES campaigns lead to BLISTER Loader, CobaltStrike, Lockbit and followed by Hands On Keyboard activity FAKEUPDATES Blister Cobalt Strike LockBit |
2022-05-06
⋅
Palo Alto Networks Unit 42
⋅
Cobalt Strike Analysis and Tutorial: CS Metadata Encoding and Decoding Cobalt Strike |
2022-05-06
⋅
The Hacker News
⋅
This New Fileless Malware Hides Shellcode in Windows Event Logs Cobalt Strike |
2022-05-05
⋅
Cisco Talos
⋅
Mustang Panda deploys a new wave of malware targeting Europe Cobalt Strike Meterpreter PlugX PUBLOAD |
2022-05-04
⋅
Kaspersky
⋅
A new secret stash for “fileless” malware Cobalt Strike |
2022-05-04
⋅
Twitter (@felixw3000)
⋅
Twitter Thread with info on infection chain with IcedId, Cobalt Strike, and Hidden VNC. Cobalt Strike IcedID PhotoLoader |
2022-05-03
⋅
Recorded Future
⋅
SOLARDEFLECTION C2 Infrastructure Used by NOBELIUM in Company Brand Misuse Cobalt Strike EnvyScout |
2022-05-03
⋅
Cluster25
⋅
The Strange Link Between A Destructive Malware And A Ransomware-Gang Linked Custom Loader: IsaacWiper Vs Vatet Cobalt Strike IsaacWiper PyXie |
2022-05-03
⋅
Recorded Future
⋅
SOLARDEFLECTION C2 Infrastructure Used by NOBELIUM in Company Brand Misuse Cobalt Strike |
2022-05-02
⋅
Sentinel LABS
⋅
Moshen Dragon’s Triad-and-Error Approach | Abusing Security Software to Sideload PlugX and ShadowPad PlugX ShadowPad Moshen Dragon |
2022-05-02
⋅
Cisco Talos
⋅
Conti and Hive ransomware operations: Leveraging victim chats for insights Cobalt Strike Conti Hive |
2022-05-02
⋅
⋅
Macnica
⋅
Attack Campaigns that Exploit Shortcuts and ISO Files Cobalt Strike |
2022-04-28
⋅
PWC
⋅
Cyber Threats 2021: A Year in Retrospect (Annex) Cobalt Strike Conti PlugX RokRAT Inception Framework Red Menshen |
2022-04-28
⋅
DARKReading
⋅
Chinese APT Bronze President Mounts Spy Campaign on Russian Military PlugX MUSTANG PANDA |
2022-04-28
⋅
Mandiant
⋅
Trello From the Other Side: Tracking APT29 Phishing Campaigns Cobalt Strike |
2022-04-27
⋅
Trendmicro
⋅
IOCs for Earth Berberoka - Windows AsyncRAT Cobalt Strike PlugX Quasar RAT Earth Berberoka |
2022-04-27
⋅
⋅
ANSSI
⋅
LE GROUPE CYBERCRIMINEL FIN7 Bateleur BELLHOP Griffon SQLRat POWERSOURCE Andromeda BABYMETAL BlackCat BlackMatter BOOSTWRITE Carbanak Cobalt Strike DNSMessenger Dridex DRIFTPIN Gameover P2P MimiKatz Murofet Qadars Ranbyus SocksBot |
2022-04-27
⋅
Trend Micro
⋅
New APT Group Earth Berberoka Targets Gambling Websites With Old and New Malware HelloBot AsyncRAT Ghost RAT HelloBot PlugX Quasar RAT Earth Berberoka |
2022-04-27
⋅
Mandiant
⋅
Assembling the Russian Nesting Doll: UNC2452 Merged into APT29 Cobalt Strike Raindrop SUNBURST TEARDROP |
2022-04-27
⋅
Trendmicro
⋅
Operation Gambling Puppet reptile oRAT AsyncRAT Cobalt Strike DCRat Ghost RAT PlugX Quasar RAT Trochilus RAT Earth Berberoka |
2022-04-27
⋅
Sentinel LABS
⋅
LockBit Ransomware Side-loads Cobalt Strike Beacon with Legitimate VMware Utility Cobalt Strike LockBit |
2022-04-27
⋅
Sentinel LABS
⋅
LockBit Ransomware Side-loads Cobalt Strike Beacon with Legitimate VMware Utility Cobalt Strike LockBit BRONZE STARLIGHT |
2022-04-26
⋅
Trend Micro
⋅
How Cybercriminals Abuse Cloud Tunneling Services AsyncRAT Cobalt Strike DarkComet Meterpreter Nanocore RAT |
2022-04-26
⋅
Intel 471
⋅
Conti and Emotet: A constantly destructive duo Cobalt Strike Conti Emotet IcedID QakBot TrickBot |
2022-04-25
⋅
The DFIR Report
⋅
Quantum Ransomware Cobalt Strike IcedID |
2022-04-25
⋅
Morphisec
⋅
New Core Impact Backdoor Delivered Via VMware Vulnerability Cobalt Strike JSSLoader |
2022-04-21
⋅
ZeroSec
⋅
Understanding Cobalt Strike Profiles - Updated For Cobalt Strike 4.6 Cobalt Strike |
2022-04-19
⋅
Blake's R&D
⋅
Extracting Cobalt Strike from Windows Error Reporting Cobalt Strike |
2022-04-19
⋅
Varonis
⋅
Hive Ransomware Analysis Cobalt Strike Hive MimiKatz |
2022-04-18
⋅
AdvIntel
⋅
Enter KaraKurt: Data Extortion Arm of Prolific Ransomware Group AvosLocker BazarBackdoor BlackByte BlackCat Cobalt Strike HelloKitty Hive Karakurt |
2022-04-18
⋅
SentinelOne
⋅
From the Front Lines | Peering into A PYSA Ransomware Attack Chisel Chisel Cobalt Strike Mespinoza |
2022-04-18
⋅
vanmieghem
⋅
A blueprint for evading industry leading endpoint protection in 2022 Cobalt Strike |
2022-04-15
⋅
Center for Internet Security
⋅
Top 10 Malware March 2022 Mirai Shlayer Agent Tesla Ghost RAT Nanocore RAT SectopRAT solarmarker Zeus |
2022-04-14
⋅
NSHC RedAlert Labs
⋅
Hacking activity of SectorB Group in 2021 Chinese government supported hacking group SectorB PlugX |
2022-04-14
⋅
Cynet
⋅
Orion Threat Alert: Flight of the BumbleBee BumbleBee Cobalt Strike |
2022-04-13
⋅
ESET Research
⋅
ESET takes part in global operation to disrupt Zloader botnets Cobalt Strike Zloader |
2022-04-13
⋅
Microsoft
⋅
Dismantling ZLoader: How malicious ads led to disabled security tools and ransomware BlackMatter Cobalt Strike DarkSide Ryuk Zloader |
2022-04-12
⋅
Max Kersten's Blog
⋅
Ghidra script to handle stack strings CaddyWiper PlugX |
2022-04-08
⋅
Infinitum Labs
⋅
Threat Spotlight: Conti Ransomware Group Behind the Karakurt Hacking Team Cobalt Strike MimiKatz |
2022-04-07
⋅
splunk
⋅
You Bet Your Lsass: Hunting LSASS Access Cobalt Strike MimiKatz |
2022-04-07
⋅
InQuest
⋅
Ukraine CyberWar Overview CyclopsBlink Cobalt Strike GraphSteel GrimPlant HermeticWiper HermeticWizard MicroBackdoor PartyTicket Saint Bot Scieron WhisperGate |
2022-04-06
⋅
Github (infinitumlabs)
⋅
Karakurt Hacking Team Indicators of Compromise (IOC) Cobalt Strike |
2022-04-04
⋅
Mandiant
⋅
FIN7 Power Hour: Adversary Archaeology and the Evolution of FIN7 Griffon BABYMETAL Carbanak Cobalt Strike JSSLoader Termite |
2022-04-01
⋅
The Hacker News
⋅
Chinese Hackers Target VMware Horizon Servers with Log4Shell to Deploy Rootkit Fire Chili Ghost RAT |
2022-03-31
⋅
nccgroup
⋅
Conti-nuation: methods and techniques observed in operations post the leaks Cobalt Strike Conti QakBot |
2022-03-31
⋅
SC Media
⋅
Novel obfuscation leveraged by Hive ransomware Cobalt Strike Hive |
2022-03-30
⋅
Bleeping Computer
⋅
Phishing campaign targets Russian govt dissidents with Cobalt Strike Unidentified PS 002 (RAT) Cobalt Strike |
2022-03-30
⋅
Prevailion
⋅
Wizard Spider continues to confound BazarBackdoor Cobalt Strike Emotet |
2022-03-30
⋅
Fortinet
⋅
New Milestones for Deep Panda: Log4Shell and Digitally Signed Fire Chili Rootkits Fire Chili Ghost RAT |
2022-03-29
⋅
Malwarebytes Labs
⋅
New spear phishing campaign targets Russian dissidents Unidentified PS 002 (RAT) Cobalt Strike |
2022-03-29
⋅
SentinelOne
⋅
From the Front Lines | Hive Ransomware Deploys Novel IPfuscation Technique To Avoid Detection Cobalt Strike Hive |
2022-03-28
⋅
Trellix
⋅
PlugX: A Talisman to Behold PlugX |
2022-03-28
⋅
Medium walmartglobaltech
⋅
CobaltStrike UUID stager Cobalt Strike |
2022-03-25
⋅
nccgroup
⋅
Mining data from Cobalt Strike beacons Cobalt Strike |
2022-03-25
⋅
⋅
ESET Research
⋅
Mustang Panda's Hodur: Old stuff, new variant of Korplug PlugX |
2022-03-25
⋅
GOV.UA
⋅
Who is behind the Cyberattacks on Ukraine's Critical Information Infrastructure: Statistics for March 15-22 Xloader Agent Tesla CaddyWiper Cobalt Strike DoubleZero GraphSteel GrimPlant HeaderTip HermeticWiper IsaacWiper MicroBackdoor Pandora RAT |
2022-03-24
⋅
Threat Post
⋅
Chinese APT Combines Fresh Hodur RAT with Complex Anti-Detection PlugX |
2022-03-23
⋅
BleepingComputer
⋅
New Mustang Panda hacking campaign targets diplomats, ISPs PlugX |
2022-03-23
⋅
ESET Research
⋅
Mustang Panda’s Hodur: Old tricks, new Korplug variant Hodur PlugX |
2022-03-22
⋅
Red Canary
⋅
2022 Threat Detection Report FAKEUPDATES Silver Sparrow BazarBackdoor Cobalt Strike GootKit Yellow Cockatoo RAT |
2022-03-22
⋅
NVISO Labs
⋅
Cobalt Strike: Overview – Part 7 Cobalt Strike |
2022-03-21
⋅
Threat Post
⋅
Conti Ransomware V. 3, Including Decryptor, Leaked Cobalt Strike Conti TrickBot |
2022-03-21
⋅
eSentire
⋅
Conti Affiliate Exposed: New Domain Names, IP Addresses and Email Addresses Uncovered HelloKitty BazarBackdoor Cobalt Strike Conti FiveHands HelloKitty IcedID |
2022-03-17
⋅
Google
⋅
Exposing initial access broker with ties to Conti BazarBackdoor BumbleBee Cobalt Strike Conti |
2022-03-16
⋅
paloalto Netoworks: Unit42
⋅
Cobalt Strike Analysis and Tutorial: How Malleable C2 Profiles Make Cobalt Strike Difficult to Detect Cobalt Strike |
2022-03-16
⋅
AhnLab
⋅
Gh0stCringe RAT Being Distributed to Vulnerable Database Servers Ghost RAT Kingminer |
2022-03-16
⋅
SANS ISC
⋅
Qakbot infection with Cobalt Strike and VNC activity Cobalt Strike QakBot |
2022-03-16
⋅
InfoSec Handlers Diary Blog
⋅
Qakbot infection with Cobalt Strike and VNC activity Cobalt Strike QakBot |
2022-03-15
⋅
Prevailion
⋅
What Wicked Webs We Un-weave Cobalt Strike Conti |
2022-03-15
⋅
SentinelOne
⋅
Threat Actor UAC-0056 Targeting Ukraine with Fake Translation Software Cobalt Strike GraphSteel GrimPlant SaintBear |
2022-03-14
⋅
Bleeping Computer
⋅
Fake antivirus updates used to deploy Cobalt Strike in Ukraine Cobalt Strike |
2022-03-12
⋅
Arash's Blog
⋅
Analyzing Malware with Hooks, Stomps, and Return-addresses Cobalt Strike |
2022-03-11
⋅
⋅
Cyberattack on Ukrainian state authorities using the Cobalt Strike Beacon (CERT-UA#4145) Cobalt Strike |
2022-03-09
⋅
Bleeping Computer
⋅
CISA updates Conti ransomware alert with nearly 100 domain names BazarBackdoor Cobalt Strike Conti TrickBot |
2022-03-09
⋅
BreachQuest
⋅
The Conti Leaks | Insight into a Ransomware Unicorn Cobalt Strike MimiKatz TrickBot |
2022-03-08
⋅
Mandiant
⋅
Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments KEYPLUG Cobalt Strike LOWKEY |
2022-03-07
⋅
Proofpoint
⋅
The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates PlugX MUSTANG PANDA |
2022-03-07
⋅
The DFIR Report
⋅
2021 Year In Review Cobalt Strike |
2022-03-04
⋅
Telsy
⋅
Legitimate Sites Used As Cobalt Strike C2s Against Indian Government Cobalt Strike |
2022-03-03
⋅
Trend Micro
⋅
Cyberattacks are Prominent in the Russia-Ukraine Conflict BazarBackdoor Cobalt Strike Conti Emotet WhisperGate |
2022-03-01
⋅
VirusTotal
⋅
VirusTotal's 2021 Malware Trends Report Anubis AsyncRAT BlackMatter Cobalt Strike DanaBot Dridex Khonsari MimiKatz Mirai Nanocore RAT Orcus RAT |
2022-02-24
⋅
Cynet
⋅
New Wave of Emotet – When Project X Turns Into Y Cobalt Strike Emotet |
2022-02-24
⋅
Fortinet
⋅
Nobelium Returns to the Political World Stage Cobalt Strike |
2022-02-23
⋅
cyber.wtf blog
⋅
What the Pack(er)? Cobalt Strike Emotet |
2022-02-23
⋅
AdvIntel
⋅
24 Hours From Log4Shell to Local Admin: Deep-Dive Into Conti Gang Attack on Fortune 500 (DFIR) Cobalt Strike Conti |
2022-02-23
⋅
SophosLabs Uncut
⋅
Dridex bots deliver Entropy ransomware in recent attacks Cobalt Strike Dridex Entropy |
2022-02-22
⋅
eSentire
⋅
IcedID to Cobalt Strike In Under 20 Minutes Cobalt Strike IcedID PhotoLoader |
2022-02-22
⋅
Bleeping Computer
⋅
Vulnerable Microsoft SQL Servers targeted with Cobalt Strike Cobalt Strike Kingminer Lemon Duck |
2022-02-21
⋅
Cobalt Strike Being Distributed to Vulnerable MS-SQL Servers Cobalt Strike Lemon Duck |
2022-02-21
⋅
Qbot and Zerologon Lead To Full Domain Compromise Cobalt Strike QakBot |
2022-02-20
⋅
Medium SOCFortress
⋅
Detecting Cobalt Strike Beacons Cobalt Strike |
2022-02-18
⋅
Huntress Labs
⋅
Hackers No Hashing: Randomizing API Hashes to Evade Cobalt Strike Shellcode Detection Cobalt Strike |
2022-02-17
⋅
SinaCyber
⋅
Testimony before the U.S.-China Economic and Security Review Commission Hearing on “China’s Cyber Capabilities: Warfare, Espionage, and Implications for the United States” PlugX APT26 APT41 |
2022-02-16
⋅
Security Onion
⋅
Quick Malware Analysis: Emotet Epoch 5 and Cobalt Strike pcap from 2022-02-08 Cobalt Strike Emotet |
2022-02-15
⋅
eSentire
⋅
Increase in Emotet Activity and Cobalt Strike Deployment Cobalt Strike Emotet |
2022-02-11
⋅
Cisco Talos
⋅
Threat Roundup for February 4 to February 11 DarkComet Ghost RAT Loki Password Stealer (PWS) Tinba Tofsee Zeus |
2022-02-10
⋅
Cybereason
⋅
Threat Analysis Report: All Paths Lead to Cobalt Strike - IcedID, Emotet and QBot Cobalt Strike Emotet IcedID QakBot |
2022-02-09
⋅
vmware
⋅
Exposing Malware in Linux-Based Multi-Cloud Environments ACBackdoor BlackMatter DarkSide Erebus HelloKitty Kinsing PLEAD QNAPCrypt RansomEXX REvil Sysrv-hello TeamTNT Vermilion Strike Cobalt Strike |
2022-01-31
⋅
CyberArk
⋅
Analyzing Malware with Hooks, Stomps and Return-addresses Cobalt Strike |
2022-01-28
⋅
Morphisec
⋅
Log4j Exploit Hits Again: Vulnerable Unifi Network Application (Ubiquiti) at Risk Cobalt Strike |
2022-01-27
⋅
JSAC 2021
⋅
What We Can Do against the Chaotic A41APT Campaign CHINACHOPPER Cobalt Strike HUI Loader SodaMaster |
2022-01-26
⋅
Blackberry
⋅
Log4U, Shell4Me Cobalt Strike |
2022-01-25
⋅
Cynet
⋅
Threats Looming Over the Horizon Cobalt Strike Meterpreter NightSky |
2022-01-24
⋅
The DFIR Report
⋅
Cobalt Strike, a Defender’s Guide – Part 2 Cobalt Strike |
2022-01-20
⋅
Morphisec
⋅
Log4j Exploit Hits Again: Vulnerable VMWare Horizon Servers at Risk Cobalt Strike |
2022-01-19
⋅
Elastic
⋅
Extracting Cobalt Strike Beacon Configurations Cobalt Strike |
2022-01-19
⋅
Blackberry
⋅
Kraken the Code on Prometheus Prometheus Backdoor BlackMatter Cerber Cobalt Strike DCRat Ficker Stealer QakBot REvil Ryuk |
2022-01-19
⋅
Elastic
⋅
Collecting Cobalt Strike Beacons with the Elastic Stack Cobalt Strike |
2022-01-19
⋅
Sophos
⋅
Zloader Installs Remote Access Backdoors and Delivers Cobalt Strike Cobalt Strike Zloader |
2022-01-18
⋅
Recorded Future
⋅
2021 Adversary Infrastructure Report BazarBackdoor Cobalt Strike Dridex IcedID QakBot TrickBot |
2022-01-17
⋅
Trend Micro
⋅
Delving Deep: An Analysis of Earth Lusca’s Operations BIOPASS Cobalt Strike FunnySwitch JuicyPotato ShadowPad Winnti Earth Lusca |
2022-01-16
⋅
forensicitguy
⋅
Analyzing a CACTUSTORCH HTA Leading to Cobalt Strike CACTUSTORCH Cobalt Strike |
2022-01-15
⋅
Huntress Labs
⋅
Threat Advisory: VMware Horizon Servers Actively Being Hit With Cobalt Strike (by DEV-0401) Cobalt Strike |
2022-01-11
⋅
Medium walmartglobaltech
⋅
Signed DLL campaigns as a service BATLOADER Cobalt Strike ISFB Zloader |
2022-01-11
⋅
Twitter (@cglyer)
⋅
Thread on DEV-0401, a china based ransomware operator exploiting VMware Horizon with log4shell and deploying NightSky ransomware Cobalt Strike NightSky |
2022-01-11
⋅
Cybereason
⋅
Threat Analysis Report: DatopLoader Exploits ProxyShell to Deliver QBOT and Cobalt Strike Cobalt Strike QakBot Squirrelwaffle |
2022-01-09
⋅
forensicitguy
⋅
Inspecting a PowerShell Cobalt Strike Beacon Cobalt Strike |
2022-01-06
⋅
Cyber And Ramen blog
⋅
A “GULP” of PlugX PlugX |
2022-01-06
⋅
Sekoia
⋅
NOBELIUM’s EnvyScout infection chain goes in the registry, targeting embassies Cobalt Strike EnvyScout |
2022-01-01
⋅
Silent Push
⋅
Consequences- The Conti Leaks and future problems Cobalt Strike Conti |
2021-12-29
⋅
CrowdStrike
⋅
OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt Cobalt Strike |
2021-12-29
⋅
Blake's R&D
⋅
Cobalt Strike DFIR: Listening to the Pipes Cobalt Strike |
2021-12-28
⋅
Morphus Labs
⋅
Attackers are abusing MSBuild to evade defenses and implant Cobalt Strike beacons Cobalt Strike |
2021-12-22
⋅
Telsy
⋅
Phishing Campaign targeting citizens abroad using COVID-19 theme lures Cobalt Strike |
2021-12-16
⋅
TEAMT5
⋅
Winnti is Coming - Evolution after Prosecution Cobalt Strike FishMaster FunnySwitch HIGHNOON ShadowPad Spyder |
2021-12-16
⋅
Red Canary
⋅
Intelligence Insights: December 2021 Cobalt Strike QakBot Squirrelwaffle |
2021-12-14
⋅
Trend Micro
⋅
Collecting In the Dark: Tropic Trooper Targets Transportation and Government ChiserClient Ghost RAT Lilith Quasar RAT xPack APT23 |
2021-12-10
⋅
Accenture
⋅
Karakurt rises from its lair Cobalt Strike Karakurt |
2021-12-07
⋅
Bleeping Computer
⋅
Emotet now drops Cobalt Strike, fast forwards ransomware attacks Cobalt Strike Emotet |
2021-12-06
⋅
CERT-FR
⋅
Phishing campaigns by the Nobelium intrusion set Cobalt Strike |
2021-12-06
⋅
Mandiant
⋅
Suspected Russian Activity Targeting Government and Business Entities Around the Globe (UNC2452) Cobalt Strike CryptBot |
2021-12-02
⋅
CERT-FR
⋅
Phishing Campaigns by the Nobelium Intrusion Set Cobalt Strike |
2021-12-01
⋅
ESET Research
⋅
Jumping the air gap: 15 years of nation‑state effort Agent.BTZ Fanny Flame Gauss PlugX Ramsay Retro Stuxnet USBCulprit USBferry |
2021-11-30
⋅
Symantec
⋅
Yanluowang: Further Insights on New Ransomware Threat BazarBackdoor Cobalt Strike FiveHands |
2021-11-29
⋅
The DFIR Report
⋅
CONTInuing the Bazar Ransomware Story BazarBackdoor Cobalt Strike Conti |
2021-11-29
⋅
Mandiant
⋅
Kitten.gif: Meet the Sabbath Ransomware Affiliate Program, Again Cobalt Strike ROLLCOAST |
2021-11-19
⋅
Trend Micro
⋅
Squirrelwaffle Exploits ProxyShell and ProxyLogon to Hijack Email Chains Cobalt Strike QakBot Squirrelwaffle |
2021-11-18
⋅
Cisco
⋅
BlackMatter, LockBit, and THOR BlackMatter LockBit PlugX |
2021-11-17
⋅
nviso
⋅
Cobalt Strike: Decrypting Obfuscated Traffic – Part 4 Cobalt Strike |
2021-11-17
⋅
Black Hills Information Security
⋅
DNS Over HTTPS for Cobalt Strike Cobalt Strike |
2021-11-17
⋅
Twitter (@Unit42_Intel)
⋅
Tweet on Matanbuchus Loader used to deliver Qakbot (tag obama128b) and follow-up CobaltStrike Cobalt Strike QakBot |
2021-11-17
⋅
Trend Micro
⋅
Analyzing ProxyShell-related Incidents via Trend Micro Managed XDR Cobalt Strike Cotx RAT |
2021-11-16
⋅
Cisco
⋅
Attackers use domain fronting technique to target Myanmar with Cobalt Strike Cobalt Strike |
2021-11-16
⋅
IronNet
⋅
How IronNet's Behavioral Analytics Detect REvil and Conti Ransomware Cobalt Strike Conti IcedID REvil |
2021-11-16
⋅
Blackberry
⋅
Finding Beacons in the dark Cobalt Strike |
2021-11-15
⋅
TRUESEC
⋅
ProxyShell, QBot, and Conti Ransomware Combined in a Series of Cyberattacks Cobalt Strike Conti QakBot |
2021-11-13
⋅
Just Still
⋅
Threat Spotlight - Domain Fronting Cobalt Strike |
2021-11-12
⋅
Malwarebytes
⋅
A multi-stage PowerShell based attack targets Kazakhstan Cobalt Strike |
2021-11-11
⋅
Cynet
⋅
A Duck Nightmare Quakbot Strikes with QuakNightmare Exploitation Cobalt Strike QakBot |
2021-11-10
⋅
AT&T
⋅
Stories from the SOC - Powershell, Proxyshell, Conti TTPs OH MY! Cobalt Strike Conti |
2021-11-10
⋅
Sekoia
⋅
Walking on APT31 infrastructure footprints Rekoobe Unidentified ELF 004 Cobalt Strike |
2021-11-09
⋅
Cybereason
⋅
THREAT ANALYSIS REPORT: From Shatak Emails to the Conti Ransomware Cobalt Strike Conti |
2021-11-05
⋅
Blackberry
⋅
Hunter Becomes Hunted: Zebra2104 Hides a Herd of Malware Cobalt Strike DoppelDridex Mount Locker Phobos StrongPity |
2021-11-05
⋅
Twitter (@Unit42_Intel)
⋅
Tweet on TA551 (Shathak) BazarLoader infection with CobaltStrike and DarkVNC drops BazarBackdoor Cobalt Strike |
2021-11-04
⋅
Youtube (Virus Bulletin)
⋅
ShadowPad: the masterpiece of privately sold malware in Chinese espionage PlugX ShadowPad |
2021-11-03
⋅
Cisco Talos
⋅
Microsoft Exchange vulnerabilities exploited once again for ransomware, this time with Babuk Babuk CHINACHOPPER |
2021-11-03
⋅
Didier Stevens
⋅
New Tool: cs-extract-key.py Cobalt Strike |
2021-11-03
⋅
nviso
⋅
Cobalt Strike: Using Process Memory To Decrypt Traffic – Part 3 Cobalt Strike |
2021-11-02
⋅
Intel 471
⋅
Cybercrime underground flush with shipping companies’ credentials Cobalt Strike Conti |
2021-11-02
⋅
unh4ck
⋅
Detecting CONTI CobaltStrike Lateral Movement Techniques - Part 2 Cobalt Strike Conti |
2021-11-02
⋅
boschko.ca blog
⋅
Cobalt Strike Process Injection Cobalt Strike |
2021-11-01
⋅
The DFIR Report
⋅
From Zero to Domain Admin Cobalt Strike Hancitor |
2021-11-01
⋅
Accenture
⋅
Diving into double extortion campaigns Cobalt Strike MimiKatz |
2021-10-29
⋅
Europol
⋅
12 targeted for involvement in ransomware attacks against critical infrastructure Cobalt Strike Dharma LockerGoga MegaCortex TrickBot |
2021-10-29
⋅
⋅
Національна поліція України
⋅
Cyberpolice exposes transnational criminal group in causing $ 120 million in damage to foreign companies Cobalt Strike Dharma LockerGoga MegaCortex TrickBot |
2021-10-27
⋅
nviso
⋅
Cobalt Strike: Using Known Private Keys To Decrypt Traffic – Part 2 Cobalt Strike |
2021-10-26
⋅
unh4ck
⋅
Detecting CONTI CobaltStrike Lateral Movement Techniques - Part 1 Cobalt Strike Conti |
2021-10-26
⋅
Cisco Talos
⋅
SQUIRRELWAFFLE Leverages malspam to deliver Qakbot, Cobalt Strike Cobalt Strike QakBot Squirrelwaffle |
2021-10-26
⋅
Identification of a new cyber criminal group: Lockean Cobalt Strike DoppelPaymer Egregor Maze PwndLocker QakBot REvil |
2021-10-21
⋅
CrowdStrike
⋅
Stopping GRACEFUL SPIDER: Falcon Complete’s Fast Response to Recent SolarWinds Serv-U Exploit Campaign Cobalt Strike FlawedGrace TinyMet |
2021-10-21
⋅
nviso
⋅
Cobalt Strike: Using Known Private Keys To Decrypt Traffic – Part 1 Cobalt Strike |
2021-10-18
⋅
The DFIR Report
⋅
IcedID to XingLocker Ransomware in 24 hours Cobalt Strike IcedID Mount Locker |
2021-10-18
⋅
NortonLifeLock
⋅
Operation Exorcist - 7 Years of Targeted Attacks against the Roman Catholic Church NewBounce PlugX Zupdax |
2021-10-18
⋅
Symantec
⋅
Harvester: Nation-state-backed group uses new toolset to target victims in South Asia Cobalt Strike Graphon |
2021-10-18
⋅
paloalto Netoworks: Unit42
⋅
Case Study: From BazarLoader to Network Reconnaissance BazarBackdoor Cobalt Strike |
2021-10-14
⋅
Medium walmartglobaltech
⋅
Investigation into the state of NIM malware Part 2 Cobalt Strike NimGrabber Nimrev Unidentified 088 (Nim Ransomware) |
2021-10-13
⋅
Blackberry
⋅
BlackBerry Shines Spotlight on Evolving Cobalt Strike Threat in New Book Cobalt Strike |
2021-10-12
⋅
Mandiant
⋅
Defining Cobalt Strike Components So You Can BEA-CONfident in Your Analysis Cobalt Strike |
2021-10-11
⋅
Accenture
⋅
Moving Left of the Ransomware Boom REvil Cobalt Strike MimiKatz RagnarLocker REvil |
2021-10-08
⋅
0ffset Blog
⋅
SQUIRRELWAFFLE – Analysing The Main Loader Cobalt Strike Squirrelwaffle |
2021-10-07
⋅
Netskope
⋅
SquirrelWaffle: New Malware Loader Delivering Cobalt Strike and QakBot Cobalt Strike QakBot Squirrelwaffle |
2021-10-07
⋅
Mandiant
⋅
FIN12 Group Profile: FIN12 Priotizes Speed to Deploy Ransomware Aginst High-Value Targets Cobalt Strike Empire Downloader TrickBot |
2021-10-07
⋅
Microsoft
⋅
Microsoft Digital Defense Report - October 2021 APT15 APT31 APT40 APT5 Earth Lusca HAFNIUM |
2021-10-06
⋅
Blackberry
⋅
Finding Beacons in the Dark Cobalt Strike |
2021-10-05
⋅
Blackberry
⋅
Drawing a Dragon: Connecting the Dots to Find APT41 Cobalt Strike Ghost RAT |
2021-10-04
⋅
JPCERT/CC
⋅
Malware Gh0stTimes Used by BlackTech Gh0stTimes Ghost RAT |
2021-10-04
⋅
Sophos
⋅
Atom Silo ransomware actors use Confluence exploit, DLL side-load for stealthy attack ATOMSILO Cobalt Strike |
2021-10-04
⋅
The DFIR Report
⋅
BazarLoader and the Conti Leaks BazarBackdoor Cobalt Strike Conti |
2021-10-03
⋅
Github (0xjxd)
⋅
SquirrelWaffle - From Maldoc to Cobalt Strike Cobalt Strike Squirrelwaffle |
2021-10-01
⋅
0ffset Blog
⋅
SQUIRRELWAFFLE – Analysing the Custom Packer Cobalt Strike Squirrelwaffle |
2021-09-30
⋅
PTSecurity
⋅
Masters of Mimicry: new APT group ChamelGang and its arsenal Cobalt Strike |
2021-09-30
⋅
Masters of Mimicry: new APT group ChamelGang and its arsenal Cobalt Strike |
2021-09-30
⋅
CrowdStrike
⋅
Hunting for the Confluence Exploitation: When Falcon OverWatch Becomes the First Line of Defense Cobalt Strike |
2021-09-29
⋅
Advanced Intelligence
⋅
Backup “Removal” Solutions - From Conti Ransomware With Love Cobalt Strike Conti |
2021-09-29
⋅
Malware Traffic Analysis
⋅
2021-09-29 (Wednesday) - Hancitor with Cobalt Strike Cobalt Strike Hancitor |
2021-09-29
⋅
Malware Traffic Analysis
⋅
Hancitor with Cobalt Strike Cobalt Strike Hancitor |
2021-09-28
⋅
Recorded Future
⋅
4 Chinese APT Groups Identified Targeting Mail Server of Afghan Telecommunications Firm Roshan PlugX Winnti |
2021-09-28
⋅
Zscaler
⋅
Squirrelwaffle: New Loader Delivering Cobalt Strike Cobalt Strike Squirrelwaffle |
2021-09-27
⋅
Cynet
⋅
A Virtual Baffle to Battle Squirrelwaffle Cobalt Strike Squirrelwaffle |
2021-09-26
⋅
NSFOCUS
⋅
Insights into Ransomware Spread Using Exchange 1-Day Vulnerabilities 1-2 Cobalt Strike LockFile |
2021-09-24
⋅
Trend Micro
⋅
Examining the Cring Ransomware Techniques Cobalt Strike Cring MimiKatz |
2021-09-22
⋅
CISA
⋅
Alert (AA21-265A) Conti Ransomware Cobalt Strike Conti |
2021-09-21
⋅
Medium elis531989
⋅
The Squirrel Strikes Back: Analysis of the newly emerged cobalt-strike loader “SquirrelWaffle” Cobalt Strike Squirrelwaffle |
2021-09-21
⋅
skyblue.team blog
⋅
Scanning VirusTotal's firehose Cobalt Strike |
2021-09-21
⋅
GuidePoint Security
⋅
A Ransomware Near Miss: ProxyShell, a RAT, and Cobalt Strike Cobalt Strike |
2021-09-21
⋅
Sophos
⋅
Cring ransomware group exploits ancient ColdFusion server Cobalt Strike Cring |
2021-09-21
⋅
eSentire
⋅
Ransomware Hackers Attack a Top Safety Testing Org. Using Tactics and Techniques Borrowed from Chinese Espionage Groups Cobalt Strike MimiKatz UNC215 |
2021-09-17
⋅
CrowdStrike
⋅
Falcon OverWatch Hunts Down Adversaries Where They Hide BazarBackdoor Cobalt Strike |
2021-09-17
⋅
Medium inteloperator
⋅
The default: 63 6f 62 61 6c 74 strike Cobalt Strike |
2021-09-17
⋅
Malware Traffic Analysis
⋅
2021-09-17 - SQUIRRELWAFFLE Loader with Cobalt Strike Cobalt Strike Squirrelwaffle |
2021-09-16
⋅
Twitter (@GossiTheDog)
⋅
Tweet on some unknown threat actor dropping Mgbot, custom IIS modular backdoor and cobalstrike using exploiting ProxyShell Cobalt Strike MgBot |
2021-09-16
⋅
Medium Shabarkin
⋅
Pointer: Hunting Cobalt Strike globally Cobalt Strike |
2021-09-16
⋅
RiskIQ
⋅
Untangling the Spider Web: The Curious Connection Between WIZARD SPIDER’s Ransomware Infrastructure and a Windows Zero-Day Exploit Cobalt Strike Ryuk |
2021-09-15
⋅
Microsoft
⋅
Analyzing attacks that exploit the CVE-2021-40444 MSHTML vulnerability Cobalt Strike |
2021-09-14
⋅
McAfee
⋅
Operation ‘Harvest’: A Deep Dive into a Long-term Campaign MimiKatz PlugX Winnti |
2021-09-14
⋅
Recorded Future
⋅
Full-Spectrum Cobalt Strike Detection Cobalt Strike |
2021-09-13
⋅
The DFIR Report
⋅
BazarLoader to Conti Ransomware in 32 Hours BazarBackdoor Cobalt Strike Conti |
2021-09-12
⋅
Medium michaelkoczwara
⋅
Mapping and Pivoting from Cobalt Strike C2 Infrastructure Attributed to CVE-2021-40444 Cobalt Strike |
2021-09-10
⋅
Gigamon
⋅
Rendering Threats: A Network Perspective BumbleBee Cobalt Strike |
2021-09-10
⋅
The Record
⋅
Indonesian intelligence agency compromised in suspected Chinese hack PlugX |
2021-09-09
⋅
Trend Micro
⋅
Remote Code Execution 0-Day (CVE-2021-40444) Hits Windows, Triggered Via Office Docs BumbleBee Cobalt Strike |
2021-09-08
⋅
Arash's Blog
⋅
Hook Heaps and Live Free Cobalt Strike |
2021-09-07
⋅
Medium michaelkoczwara
⋅
Cobalt Strike C2 Hunting with Shodan Cobalt Strike |
2021-09-06
⋅
kienmanowar Blog
⋅
Quick analysis CobaltStrike loader and shellcode Cobalt Strike |
2021-09-03
⋅
FireEye
⋅
PST, Want a Shell? ProxyShell Exploiting Microsoft Exchange Servers CHINACHOPPER HTran |
2021-09-03
⋅
Sophos
⋅
Conti affiliates use ProxyShell Exchange exploit in ransomware attacks Cobalt Strike Conti |
2021-09-03
⋅
Trend Micro
⋅
The State of SSL/TLS Certificate Usage in Malware C&C Communications AdWind ostap AsyncRAT BazarBackdoor BitRAT Buer Chthonic CloudEyE Cobalt Strike DCRat Dridex FindPOS GootKit Gozi IcedID ISFB Nanocore RAT Orcus RAT PandaBanker Qadars QakBot Quasar RAT Rockloader ServHelper Shifu SManager TorrentLocker TrickBot Vawtrak Zeus Zloader |
2021-09-02
⋅
Medium michaelkoczwara
⋅
Cobalt Strike PowerShell Payload Analysis Cobalt Strike |
2021-09-02
⋅
Twitter (@th3_protoCOL)
⋅
Tweet on Confluence Server exploitation (CVE-2021-26084) in the wild and cobaltsrike activity (mentioned in replies by GaborSzappanos) Cobalt Strike |
2021-09-01
⋅
YouTube (Black Hat)
⋅
Mem2Img: Memory-Resident Malware Detection via Convolution Neural Network Cobalt Strike PlugX Waterbear |
2021-09-01
⋅
YouTube (Hack In The Box Security Conference)
⋅
SHADOWPAD: Chinese Espionage Malware-as-a-Service PlugX ShadowPad |
2021-08-31
⋅
BreakPoint Labs
⋅
Cobalt Strike and Ransomware – Tracking An Effective Ransomware Campaign Cobalt Strike |
2021-08-30
⋅
⋅
Qianxin
⋅
Operation (Thủy Tinh) OceanStorm: The evil lotus hidden under the abyss Cobalt Strike MimiKatz |
2021-08-29
⋅
The DFIR Report
⋅
Cobalt Strike, a Defender’s Guide Cobalt Strike |
2021-08-27
⋅
Aon
⋅
Cobalt Strike Configuration Extractor and Parser Cobalt Strike |
2021-08-27
⋅
Morphisec
⋅
ProxyShell Exchange Exploitation Now Leads To An Increasing Amount Of Cobaltstrike Backdoors Cobalt Strike |
2021-08-25
⋅
Trend Micro
⋅
Earth Baku An APT Group Targeting Indo-Pacific Countries With New Stealth Loaders and Backdoor Cobalt Strike DUSTPAN SideWalk |
2021-08-24
⋅
Trend Micro
⋅
Earth Baku Returns Cobalt Strike CROSSWALK DUSTPAN SideWalk |
2021-08-24
⋅
ESET Research
⋅
The SideWalk may be as dangerous as the CROSSWALK Cobalt Strike CROSSWALK SideWalk SparklingGoblin |
2021-08-23
⋅
Youtube (SANS Digital Forensics and Incident Response)
⋅
Keynote: Cobalt Strike Threat Hunting Cobalt Strike |
2021-08-23
⋅
FBI
⋅
Indicators of Compromise Associated with OnePercent Group Ransomware Cobalt Strike MimiKatz |
2021-08-23
⋅
SentinelOne
⋅
ShadowPad: the Masterpiece of Privately Sold Malware in Chinese Espionage PlugX ShadowPad |
2021-08-19
⋅
Blackberry
⋅
BlackBerry Prevents: Threat Actor Group TA575 and Dridex Malware Cobalt Strike Dridex TA575 |
2021-08-19
⋅
Sekoia
⋅
An insider insights into Conti operations – Part two Cobalt Strike Conti |
2021-08-18
⋅
Intezer
⋅
Cobalt Strike: Detect this Persistent Threat Cobalt Strike |
2021-08-17
⋅
Advanced Intelligence
⋅
Hunting for Corporate Insurance Policies: Indicators of [Ransom] Exfiltration Cobalt Strike Conti |
2021-08-17
⋅
Sekoia
⋅
An insider insights into Conti operations – Part one Cobalt Strike Conti |
2021-08-17
⋅
Medium michaelkoczwara
⋅
Cobalt Strike Hunting — DLL Hijacking/Attack Analysis Cobalt Strike |
2021-08-15
⋅
Symantec
⋅
The Ransomware Threat Babuk BlackMatter DarkSide Avaddon Babuk BADHATCH BazarBackdoor BlackMatter Clop Cobalt Strike Conti DarkSide DoppelPaymer Egregor Emotet FiveHands FriedEx Hades IcedID LockBit Maze MegaCortex MimiKatz QakBot RagnarLocker REvil Ryuk TrickBot WastedLocker |
2021-08-11
⋅
Advanced Intelligence
⋅
Secret "Backdoor" Behind Conti Ransomware Operation: Introducing Atera Agent Cobalt Strike Conti |
2021-08-09
⋅
IstroSec
⋅
APT Cobalt Strike Campaign targeting Slovakia (DEF CON talk) Cobalt Strike |
2021-08-05
⋅
Secureworks
⋅
Detecting Cobalt Strike: Government-Sponsored Threat Groups (APT32) Cobalt Strike |
2021-08-05
⋅
Red Canary
⋅
When Dridex and Cobalt Strike give you Grief Cobalt Strike DoppelDridex DoppelPaymer |
2021-08-04
⋅
Sentinel LABS
⋅
Hotcobalt – New Cobalt Strike DoS Vulnerability That Lets You Halt Operations Cobalt Strike |
2021-08-04
⋅
Secureworks
⋅
Detecting Cobalt Strike: Cybercrime Attacks (GOLD LAGOON) Cobalt Strike |
2021-08-04
⋅
CrowdStrike
⋅
PROPHET SPIDER Exploits Oracle WebLogic to Facilitate Ransomware Activity Cobalt Strike Egregor Mount Locker Prophet Spider |
2021-08-03
⋅
Cybereason
⋅
DeadRinger: Exposing Chinese Threat Actors Targeting Major Telcos CHINACHOPPER Cobalt Strike MimiKatz Nebulae |
2021-08-02
⋅
Youtube (Forschungsinstitut Cyber Defense)
⋅
The CODE 2021: Workshop presentation and demonstration about CobaltStrike Cobalt Strike |
2021-08-01
⋅
The DFIR Report
⋅
BazarCall to Conti Ransomware via Trickbot and Cobalt Strike BazarBackdoor Cobalt Strike Conti TrickBot |
2021-07-30
⋅
Twitter (@Unit42_Intel)
⋅
Tweet on BazarLoader infection leading to cobaltstrike and Powershell script file for PrintNightmare vulnerability BazarBackdoor Cobalt Strike |
2021-07-29
⋅
Rasta Mouse
⋅
NTLM Relaying via Cobalt Strike Cobalt Strike |
2021-07-29
⋅
Microsoft
⋅
BazaCall: Phony call centers lead to exfiltration and ransomware BazarBackdoor Cobalt Strike |
2021-07-27
⋅
Blackberry
⋅
Old Dogs New Tricks: Attackers Adopt Exotic Programming Languages elf.wellmess ElectroRAT BazarNimrod Buer Cobalt Strike Remcos Snake TeleBot WellMess Zebrocy |
2021-07-27
⋅
Palo Alto Networks Unit 42
⋅
THOR: Previously Unseen PlugX Variant Deployed During Microsoft Exchange Server Attacks by PKPLUG Group PlugX |
2021-07-25
⋅
Medium svch0st
⋅
Guide to Named Pipes and Hunting for Cobalt Strike Pipes Cobalt Strike |
2021-07-22
⋅
Medium michaelkoczwara
⋅
Cobalt Strike Hunting — simple PCAP and Beacon Analysis Cobalt Strike |
2021-07-21
⋅
Bitdefender
⋅
LuminousMoth – PlugX, File Exfiltration and Persistence Revisited PlugX |
2021-07-20
⋅
Secureworks
⋅
Ongoing Campaign Leveraging Exchange Vulnerability Potentially Linked to Iran CHINACHOPPER MimiKatz RGDoor |
2021-07-20
⋅
Government points finger at China over cyber attacks APT40 HAFNIUM |
2021-07-19
⋅
The DFIR Report
⋅
IcedID and Cobalt Strike vs Antivirus Cobalt Strike IcedID |
2021-07-19
⋅
Department of Justice
⋅
Four Chinese Nationals Working with the Ministry of State Security Charged with Global Computer Intrusion Campaign Targeting Intellectual Property and Confidential Business Information, Including Infectious Disease Research APT40 |
2021-07-19
⋅
Council of the European Union
⋅
China: Declaration by the High Representative on behalf of the European Union urging Chinese authorities to take action against malicious cyber activities undertaken from its territory APT40 |
2021-07-19
⋅
Ministry of Foreign Affairs of Japan
⋅
Cases of cyberattacks including those by a group known as APT40 which the Chinese government is behind (Statement by Press Secretary YOSHIDA Tomoyuki) APT40 |
2021-07-19
⋅
Minister for Foreign Affairs of Australia
⋅
Australia joins international partners in attribution of malicious cyber activity to China APT31 APT40 HAFNIUM |
2021-07-19
⋅
NCSC UK
⋅
UK and allies hold Chinese state responsible for pervasive pattern of hacking APT31 APT40 |
2021-07-19
⋅
GOV.UK
⋅
UK and allies hold Chinese state responsible for a pervasive pattern of hacking APT31 APT40 HAFNIUM |
2021-07-19
⋅
CISA
⋅
Alert (AA21-200B): Chinese State-Sponsored Cyber Operations: Observed TTPs APT40 |
2021-07-19
⋅
Government of Canada
⋅
Statement on China’s cyber campaigns APT40 |
2021-07-14
⋅
Google
⋅
How We Protect Users From 0-Day Attacks (CVE-2021-21166, CVE-2021-30551, CVE-2021-33742, CVE-2021-1879) Cobalt Strike |
2021-07-14
⋅
MDSec
⋅
Investigating a Suspicious Service Cobalt Strike |
2021-07-14
⋅
Kaspersky
⋅
LuminousMoth APT: Sweeping attacks for the chosen few Cobalt Strike |
2021-07-13
⋅
YouTube ( Matt Soseman)
⋅
Solarwinds and SUNBURST attacks compromised my lab! Cobalt Strike Raindrop SUNBURST TEARDROP |
2021-07-09
⋅
InfoSec Handlers Diary Blog
⋅
Hancitor tries XLL as initial malware file Cobalt Strike Hancitor |
2021-07-08
⋅
Avast Decoded
⋅
Decoding Cobalt Strike: Understanding Payloads Cobalt Strike Empire Downloader |
2021-07-08
⋅
Recorded Future
⋅
Chinese State-Sponsored Activity Group TAG-22 Targets Nepal, the Philippines, and Taiwan Using Winnti and Other Tooling Cobalt Strike Earth Lusca |
2021-07-07
⋅
Trustwave
⋅
Diving Deeper Into the Kaseya VSA Attack: REvil Returns and Other Hackers Are Riding Their Coattails Cobalt Strike REvil |
2021-07-07
⋅
Trend Micro
⋅
BIOPASS RAT: New Malware Sniffs Victims via Live Streaming BIOPASS Cobalt Strike Derusbi |
2021-07-07
⋅
McAfee
⋅
Ryuk Ransomware Now Targeting Webservers Cobalt Strike Ryuk |
2021-07-06
⋅
Twitter (@MBThreatIntel)
⋅
Tweet on a malspam campaign that is taking advantage of Kaseya VSA ransomware attack to drop CobaltStrike Cobalt Strike |
2021-07-05
⋅
Trend Micro
⋅
Tracking Cobalt Strike: A Trend Micro Vision One Investigation Cobalt Strike |
2021-07-03
⋅
Medium AK1001
⋅
Analyzing Cobalt Strike PowerShell Payload Cobalt Strike |
2021-07-02
⋅
MalwareBookReports
⋅
Skip the Middleman: Dridex Document to Cobalt Strike Cobalt Strike Dridex |
2021-07-01
⋅
The Record
⋅
Mongolian certificate authority hacked eight times, compromised with malware Cobalt Strike |
2021-07-01
⋅
Avast Decoded
⋅
Backdoored Client from Mongolian CA MonPass Cobalt Strike Earth Lusca |
2021-07-01
⋅
Avast Decoded
⋅
Backdoored Client from Mongolian CA MonPass Cobalt Strike FishMaster |
2021-06-30
⋅
Group-IB
⋅
REvil Twins Deep Dive into Prolific RaaS Affiliates' TTPs Cobalt Strike REvil |
2021-06-29
⋅
Accenture
⋅
HADES ransomware operators continue attacks Cobalt Strike Hades MimiKatz |
2021-06-29
⋅
Proofpoint
⋅
Cobalt Strike: Favorite Tool from APT to Crimeware Cobalt Strike |
2021-06-28
⋅
The DFIR Report
⋅
Hancitor Continues to Push Cobalt Strike Cobalt Strike Hancitor |
2021-06-22
⋅
CrowdStrike
⋅
Response When Minutes Matter: Falcon Complete Disrupts WIZARD SPIDER eCrime Operators Cobalt Strike |
2021-06-22
⋅
Twitter (@Cryptolaemus1)
⋅
Tweet on TA575, a Dridex affiliate delivering cobaltstrike (packed withe Cryptone) directly via the macro docs Cobalt Strike Dridex |
2021-06-20
⋅
The DFIR Report
⋅
From Word to Lateral Movement in 1 Hour Cobalt Strike IcedID |
2021-06-19
⋅
CISA
⋅
Alert (AA21-200A): Tactics, Techniques, and Procedures of Indicted APT40 Actors Associated with China’s MSS Hainan State Security Department APT40 |
2021-06-18
⋅
SecurityScorecard
⋅
SecurityScorecard Finds USAID Hack Much Larger Than Initially Thought Cobalt Strike |
2021-06-17
⋅
Binary Defense
⋅
Analysis of Hancitor – When Boring Begets Beacon Cobalt Strike Ficker Stealer Hancitor |
2021-06-16
⋅
Mandiant
⋅
Smoking Out a DARKSIDE Affiliate’s Supply Chain Software Compromise Cobalt Strike SMOKEDHAM |
2021-06-16
⋅
Recorded Future
⋅
Threat Activity Group RedFoxtrot Linked to China’s PLA Unit 69010; Targets Bordering Asian Countries Icefog PcShare PlugX Poison Ivy QuickHeal DAGGER PANDA |
2021-06-16
⋅
⋅
Національної поліції України
⋅
Cyberpolice exposes hacker group in spreading encryption virus and causing half a billion dollars in damage to foreign companies Clop Cobalt Strike FlawedAmmyy |
2021-06-16
⋅
FireEye
⋅
Smoking Out a DARKSIDE Affiliate’s Supply Chain Software Compromise Cobalt Strike SMOKEDHAM |
2021-06-15
⋅
Secureworks
⋅
Hades Ransomware Operators Use Distinctive Tactics and Infrastructure Cobalt Strike Hades |
2021-06-12
⋅
Twitter (@AltShiftPrtScn)
⋅
A thread on RagnarLocker ransomware group's TTP seen in an Incident Response Cobalt Strike RagnarLocker |
2021-06-10
⋅
Group-IB
⋅
Big airline heist APT41 likely behind massive supply chain attack Cobalt Strike |
2021-06-10
⋅
ESET Research
⋅
BackdoorDiplomacy: Upgrading from Quarian to Turian CHINACHOPPER DoublePulsar EternalRocks turian BackdoorDiplomacy |
2021-06-09
⋅
Twitter (@RedDrip7)
⋅
Tweet on in the wild exploit of CVE-2021-26868 (according to @_clem1) Cobalt Strike |
2021-06-04
⋅
Twitter (@alex_lanstein)
⋅
Tweet on UNC2652/NOBELIUM targeting IOS users exploiting CVE-2021-1879 Cobalt Strike |
2021-06-04
⋅
Inky
⋅
Colonial Pipeline Ransomware Hack Unleashes Flood of Related Phishing Attempts Cobalt Strike |
2021-06-02
⋅
Sophos
⋅
AMSI bypasses remain tricks of the malware trade Agent Tesla Cobalt Strike Meterpreter |
2021-06-02
⋅
Medium CyCraft
⋅
China-Linked Threat Group Targets Taiwan Critical Infrastructure, Smokescreen Ransomware Cobalt Strike ColdLock |
2021-06-02
⋅
Twitter (@xorhex)
⋅
Tweet on new variant of PlugX from RedDelta Group PlugX |
2021-06-02
⋅
xorhex blog
⋅
RedDelta PlugX Undergoing Changes and Overlapping Again with Mustang Panda PlugX Infrastructure PlugX |
2021-06-01
⋅
Department of Justice
⋅
Justice Department Announces Court-Authorized Seizure of Domain Names Used in Furtherance of Spear-Phishing Campaign Posing as U.S. Agency for International Development Cobalt Strike |
2021-06-01
⋅
SentinelOne
⋅
NobleBaron | New Poisoned Installers Could Be Used In Supply Chain Attacks Cobalt Strike |
2021-06-01
⋅
SANS
⋅
A Contrarian View on SolarWinds Cobalt Strike Raindrop SUNBURST TEARDROP |
2021-06-01
⋅
Microsoft
⋅
New sophisticated email-based attack from NOBELIUM Cobalt Strike |
2021-05-29
⋅
Twitter (@elisalem9)
⋅
Tweet on obfuscation mechanism and extraction procedure of COBALTSTRIKE beacon module used by NOBELIUM/UNC2452 Cobalt Strike |
2021-05-28
⋅
CISA
⋅
Malware Analysis Report (AR21-148A): Cobalt Strike Beacon Cobalt Strike |
2021-05-28
⋅
United States of America vs Ding Xiaoyang, Cheng Qingmin, Zhu Yunmin, Wu Shurong APT40 |
2021-05-28
⋅
Wanted by the FBI: Zhu Yunmin, Wu Shurong, Ding Xiaoyang, Cheng Qingmin APT40 |
2021-05-28
⋅
CISA
⋅
Alert (AA21-148A): Sophisticated Spearphishing Campaign Targets Government Organizations, IGOs, and NGOs Cobalt Strike |
2021-05-28
⋅
Microsoft
⋅
Breaking down NOBELIUM’s latest early-stage toolset BOOMBOX Cobalt Strike |
2021-05-27
⋅
Volexity
⋅
Suspected APT29 Operation Launches Election Fraud Themed Phishing Campaigns Cobalt Strike |
2021-05-27
⋅
xorhex blog
⋅
Mustang Panda PlugX - Reused Mutex and Folder Found in the Extracted Config PlugX |
2021-05-26
⋅
DeepInstinct
⋅
A Deep Dive into Packing Software CryptOne Cobalt Strike Dridex Emotet Gozi ISFB Mailto QakBot SmokeLoader WastedLocker Zloader |
2021-05-25
⋅
Huntress Labs
⋅
Cobalt Strikes Again: An Analysis of Obfuscated Malware Cobalt Strike |
2021-05-21
⋅
⋅
LAC
⋅
Targeted attack by 'Cobalt Strike loader' that exploits Microsoft's digital signature-Attacker group APT41 Cobalt Strike DUSTPAN |
2021-05-21
⋅
blackarrow
⋅
Leveraging Microsoft Teams to persist and cover up Cobalt Strike traffic Cobalt Strike |
2021-05-19
⋅
Intel 471
⋅
Look how many cybercriminals love Cobalt Strike BazarBackdoor Cobalt Strike Hancitor QakBot SmokeLoader SystemBC TrickBot |
2021-05-19
⋅
Medium Mehmet Ergene
⋅
Enterprise Scale Threat Hunting: Network Beacon Detection with Unsupervised ML and KQL — Part 2 Cobalt Strike |
2021-05-18
⋅
Sophos
⋅
The Active Adversary Playbook 2021 Cobalt Strike MimiKatz |
2021-05-17
⋅
Talos
⋅
Case Study: Incident Response is a relationship-driven business Cobalt Strike |
2021-05-17
⋅
xorhex blog
⋅
Mustang Panda PlugX - 45.251.240.55 Pivot PlugX |
2021-05-16
⋅
NCSC Ireland
⋅
Ransomware Attack on Health Sector - UPDATE 2021-05-16 Cobalt Strike Conti |
2021-05-14
⋅
GuidePoint Security
⋅
From ZLoader to DarkSide: A Ransomware Story DarkSide Cobalt Strike Zloader |
2021-05-14
⋅
Blue Team Blog
⋅
DarkSide Ransomware Operations – Preventions and Detections. Cobalt Strike DarkSide |
2021-05-13
⋅
AWAKE
⋅
Catching the White Stork in Flight Cobalt Strike MimiKatz RMS |
2021-05-12
⋅
Medium Mehmet Ergene
⋅
Enterprise Scale Threat Hunting: Network Beacon Detection with Unsupervised ML and KQL — Part 1 Cobalt Strike |
2021-05-12
⋅
Conti Ransomware Cobalt Strike Conti IcedID |
2021-05-11
⋅
Mal-Eats
⋅
Campo, a New Attack Campaign Targeting Japan AnchorDNS BazarBackdoor campoloader Cobalt Strike Phobos Snifula TrickBot Zloader |
2021-05-11
⋅
FireEye
⋅
Shining a Light on DARKSIDE Ransomware Operations Cobalt Strike DarkSide |
2021-05-10
⋅
Mal-Eats
⋅
Overview of Campo, a new attack campaign targeting Japan AnchorDNS BazarBackdoor Cobalt Strike ISFB Phobos TrickBot Zloader |
2021-05-10
⋅
ZERO.BS
⋅
Cobaltstrike-Beacons analyzed Cobalt Strike |
2021-05-07
⋅
Cisco Talos
⋅
Lemon Duck spreads its wings: Actors target Microsoft Exchange servers, incorporate new TTPs CHINACHOPPER Cobalt Strike Lemon Duck |
2021-05-07
⋅
Medium svch0st
⋅
Stats from Hunting Cobalt Strike Beacons Cobalt Strike |
2021-05-07
⋅
TEAMT5
⋅
Mem2Img: Memory-Resident Malware Detection via Convolution Neural Network Cobalt Strike PlugX Waterbear |
2021-05-07
⋅
SophosLabs Uncut
⋅
New Lemon Duck variants exploiting Microsoft Exchange Server CHINACHOPPER Cobalt Strike Lemon Duck |
2021-05-06
⋅
Trend Micro
⋅
Proxylogon: A Coinminer, a Ransomware, and a Botnet Join the Party BlackKingdom Ransomware CHINACHOPPER Lemon Duck Prometei |
2021-05-05
⋅
TRUESEC
⋅
Are The Notorious Cyber Criminals Evil Corp actually Russian Spies? Cobalt Strike Hades WastedLocker |
2021-05-05
⋅
Symantec
⋅
Multi-Factor Authentication: Headache for Cyber Actors Inspires New Attack Techniques CHINACHOPPER |
2021-05-05
⋅
Zscaler
⋅
Catching RATs Over Custom Protocols Analysis of top non-HTTP/S threats Agent Tesla AsyncRAT Crimson RAT CyberGate Ghost RAT Nanocore RAT NetWire RC NjRAT Quasar RAT Remcos |
2021-05-05
⋅
SophosLabs Uncut
⋅
Intervention halts a ProxyLogon-enabled attack Cobalt Strike |
2021-05-04
⋅
Medium sergiusechel
⋅
Improving the network-based detection of Cobalt Strike C2 servers in the wild while reducing the risk of false positives Cobalt Strike |
2021-05-02
⋅
The DFIR Report
⋅
Trickbot Brief: Creds and Beacons Cobalt Strike TrickBot |
2021-04-29
⋅
FireEye
⋅
UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat Cobalt Strike FiveHands HelloKitty |
2021-04-29
⋅
NTT
⋅
The Operations of Winnti group Cobalt Strike ShadowPad Spyder Winnti Earth Lusca |
2021-04-28
⋅
Trend Micro
⋅
Water Pamola Attacked Online Shops Via Malicious Orders Ghost RAT |
2021-04-27
⋅
Trend Micro
⋅
Legitimate Tools Weaponized for Ransomware in 2021 Cobalt Strike MimiKatz |
2021-04-27
⋅
Trend Micro
⋅
Hello Ransomware Uses Updated China Chopper Web Shell, SharePoint Vulnerability CHINACHOPPER Cobalt Strike |
2021-04-26
⋅
nviso
⋅
Anatomy of Cobalt Strike’s DLL Stager Cobalt Strike |
2021-04-26
⋅
getrevue
⋅
Hunting Cobalt Strike DNS redirectors by using ZoomEye Cobalt Strike |
2021-04-24
⋅
⋅
Non-offensive security
⋅
Detect Cobalt Strike server through DNS protocol Cobalt Strike |
2021-04-23
⋅
Twitter (@vikas891)
⋅
Tweet on DOPPEL SPIDER using Intensive/Multiple Injected Cobalt Strike Beacons with varied polling intervals Cobalt Strike DoppelPaymer |
2021-04-22
⋅
Twitter (@AltShiftPrtScn)
⋅
Twwet On TTPs seen in IR used by DOPPEL SPIDER Cobalt Strike DoppelPaymer |
2021-04-21
⋅
SophosLabs Uncut
⋅
Nearly half of malware now use TLS to conceal communications Agent Tesla Cobalt Strike Dridex SystemBC |
2021-04-20
⋅
Medium walmartglobaltech
⋅
CobaltStrike Stager Utilizing Floating Point Math Cobalt Strike |
2021-04-19
⋅
Netresec
⋅
Analysing a malware PCAP with IcedID and Cobalt Strike traffic Cobalt Strike IcedID |
2021-04-18
⋅
YouTube (dist67)
⋅
Decoding Cobalt Strike Traffic Cobalt Strike |
2021-04-16
⋅
Trend Micro
⋅
Could the Microsoft Exchange breach be stopped? CHINACHOPPER |
2021-04-15
⋅
Palo Alto Networks Unit 42
⋅
Actor Exploits Microsoft Exchange Server Vulnerabilities, Cortex XDR Blocks Harvesting of Credentials CHINACHOPPER |
2021-04-14
⋅
InfoSec Handlers Diary Blog
⋅
April 2021 Forensic Quiz: Answers and Analysis Anchor BazarBackdoor Cobalt Strike |
2021-04-12
⋅
Inde
⋅
A Different Kind of Zoombomb Cobalt Strike |
2021-04-09
⋅
F-Secure
⋅
Detecting Exposed Cobalt Strike DNS Redirectors Cobalt Strike |
2021-04-07
⋅
Medium sixdub
⋅
Using Kaitai Struct to Parse Cobalt Strike Beacon Configs Cobalt Strike |
2021-04-05
⋅
Medium walmartglobaltech
⋅
TrickBot Crews New CobaltStrike Loader Cobalt Strike TrickBot |
2021-04-02
⋅
Dr.Web
⋅
Study of targeted attacks on Russian research institutes Cotx RAT Ghost RAT TA428 |
2021-04-01
⋅
DomainTools
⋅
COVID-19 Phishing With a Side of Cobalt Strike Cobalt Strike |
2021-04-01
⋅
Palo Alto Networks Unit 42
⋅
Hancitor’s Use of Cobalt Strike and a Noisy Network Ping Tool Cobalt Strike Hancitor Moskalvzapoe |
2021-03-31
⋅
Red Canary
⋅
2021 Threat Detection Report Shlayer Andromeda Cobalt Strike Dridex Emotet IcedID MimiKatz QakBot TrickBot |
2021-03-30
⋅
GuidePoint Security
⋅
Yet Another Cobalt Strike Stager: GUID Edition Cobalt Strike |
2021-03-29
⋅
The Record
⋅
RedEcho group parks domains after public exposure PlugX ShadowPad RedEcho |
2021-03-29
⋅
The DFIR Report
⋅
Sodinokibi (aka REvil) Ransomware Cobalt Strike IcedID REvil |
2021-03-26
⋅
Imperva
⋅
Imperva Observes Hive of Activity Following Hafnium Microsoft Exchange Disclosures CHINACHOPPER |
2021-03-25
⋅
Microsoft
⋅
Web Shell Threat Hunting with Azure Sentinel CHINACHOPPER |
2021-03-25
⋅
Recorded Future
⋅
Suspected Chinese Group Calypso APT Exploiting Vulnerable Microsoft Exchange Servers Meterpreter PlugX |
2021-03-25
⋅
Microsoft
⋅
Analyzing attacks taking advantage of the Exchange Server vulnerabilities CHINACHOPPER |
2021-03-21
⋅
Twitter (@CyberRaiju)
⋅
Twitter Thread with analysis of .NET China Chopper CHINACHOPPER |
2021-03-21
⋅
YouTube (dist67)
⋅
Finding Metasploit & Cobalt Strike URLs Cobalt Strike |
2021-03-21
⋅
Blackberry
⋅
2021 Threat Report Bashlite FritzFrog IPStorm Mirai Tsunami elf.wellmess AppleJeus Dacls EvilQuest Manuscrypt Astaroth BazarBackdoor Cerber Cobalt Strike Emotet FinFisher RAT Kwampirs MimiKatz NjRAT Ryuk SmokeLoader TrickBot |
2021-03-19
⋅
Bundesamt für Sicherheit in der Informationstechnik
⋅
Microsoft Exchange Schwachstellen Detektion und Reaktion (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065) CHINACHOPPER MimiKatz |
2021-03-18
⋅
DeepInstinct
⋅
Cobalt Strike – Post-Exploitation Attackers Toolkit Cobalt Strike |
2021-03-18
⋅
PRODAFT Threat Intelligence
⋅
SilverFish GroupThreat Actor Report Cobalt Strike Dridex Koadic |
2021-03-17
⋅
Recorded Future
⋅
China-linked TA428 Continues to Target Russia and Mongolia IT Companies PlugX Poison Ivy TA428 |
2021-03-16
⋅
Elastic
⋅
Detecting Cobalt Strike with memory signatures Cobalt Strike |
2021-03-16
⋅
McAfee
⋅
Technical Analysis of Operation Diànxùn Cobalt Strike |
2021-03-15
⋅
Trustwave
⋅
HAFNIUM, China Chopper and ASP.NET Runtime CHINACHOPPER |
2021-03-11
⋅
Cyborg Security
⋅
You Don't Know the HAFNIUM of it... CHINACHOPPER Cobalt Strike PowerCat |
2021-03-11
⋅
Qurium
⋅
Myanmar – Multi-stage malware attack targets elected lawmakers Cobalt Strike |
2021-03-11
⋅
Palo Alto Networks Unit 42
⋅
Microsoft Exchange Server Attack Timeline CHINACHOPPER |
2021-03-11
⋅
DEVO
⋅
Detection and Investigation Using Devo: HAFNIUM 0-day Exploits on Microsoft Exchange Service CHINACHOPPER MimiKatz |
2021-03-10
⋅
Lemon's InfoSec Ramblings
⋅
Microsoft Exchange & the HAFNIUM Threat Actor CHINACHOPPER |
2021-03-10
⋅
PICUS Security
⋅
Tactics, Techniques, and Procedures (TTPs) Used by HAFNIUM to Target Microsoft Exchange Servers CHINACHOPPER |
2021-03-10
⋅
ESET Research
⋅
Exchange servers under siege from at least 10 APT groups Microcin MimiKatz PlugX Winnti APT27 APT41 Calypso Tick ToddyCat Tonto Team Vicious Panda |
2021-03-10
⋅
DomainTools
⋅
Examining Exchange Exploitation and its Lessons for Defenders CHINACHOPPER |
2021-03-10
⋅
Proofpoint
⋅
NimzaLoader: TA800’s New Initial Access Malware BazarNimrod Cobalt Strike |
2021-03-09
⋅
Palo Alto Networks Unit 42
⋅
Remediation Steps for the Microsoft Exchange Server Vulnerabilities CHINACHOPPER |
2021-03-09
⋅
splunk
⋅
Cloud Federated Credential Abuse & Cobalt Strike: Threat Research February 2021 Cobalt Strike |
2021-03-09
⋅
Red Canary
⋅
Microsoft Exchange server exploitation: how to detect, mitigate, and stay calm CHINACHOPPER |
2021-03-09
⋅
PRAETORIAN
⋅
Reproducing the Microsoft Exchange Proxylogon Exploit Chain CHINACHOPPER |
2021-03-09
⋅
YouTube (John Hammond)
⋅
HAFNIUM - Post-Exploitation Analysis from Microsoft Exchange CHINACHOPPER |
2021-03-08
⋅
Youtube (SANS Digital Forensics and Incident Response)
⋅
STAR Webcast: Making sense of SolarWinds through the lens of MITRE ATT&CK(R) Cobalt Strike SUNBURST TEARDROP |
2021-03-08
⋅
Symantec
⋅
How Symantec Stops Microsoft Exchange Server Attacks CHINACHOPPER MimiKatz |
2021-03-08
⋅
Palo Alto Networks Unit 42
⋅
Analyzing Attacks Against Microsoft Exchange Server With China Chopper Webshells CHINACHOPPER |
2021-03-08
⋅
The DFIR Report
⋅
Bazar Drops the Anchor Anchor BazarBackdoor Cobalt Strike |
2021-03-07
⋅
TRUESEC
⋅
Tracking Microsoft Exchange Zero-Day ProxyLogon and HAFNIUM CHINACHOPPER |
2021-03-07
⋅
InfoSec Handlers Diary Blog
⋅
PCAPs and Beacons Cobalt Strike |
2021-03-05
⋅
Wired
⋅
Chinese Hacking Spree Hit an ‘Astronomical’ Number of Victims CHINACHOPPER |
2021-03-05
⋅
Huntress Labs
⋅
Operation Exchange Marauder CHINACHOPPER |
2021-03-04
⋅
Huntress Labs
⋅
Operation Exchange Marauder CHINACHOPPER |
2021-03-04
⋅
FireEye
⋅
Detection and Response to Exploitation of Microsoft Exchange Zero-Day Vulnerabilities CHINACHOPPER HAFNIUM |
2021-03-04
⋅
CrowdStrike
⋅
Falcon Complete Stops Microsoft Exchange Server Zero-Day Exploits CHINACHOPPER HAFNIUM |
2021-03-03
⋅
Huntress Labs
⋅
Rapid Response: Mass Exploitation of On-Prem Exchange Servers CHINACHOPPER HAFNIUM |
2021-03-03
⋅
Huntress Labs
⋅
Mass exploitation of on-prem Exchange servers :( CHINACHOPPER HAFNIUM |
2021-03-03
⋅
MITRE
⋅
HAFNIUM CHINACHOPPER HAFNIUM |
2021-03-02
⋅
Twitter (@ESETresearch)
⋅
Tweet on Exchange RCE CHINACHOPPER HAFNIUM |
2021-03-02
⋅
Volexity
⋅
Operation Exchange Marauder: Active Exploitation of Multiple Zero-Day Microsoft Exchange Vulnerabilities CHINACHOPPER HAFNIUM |
2021-03-02
⋅
Rapid7 Labs
⋅
Rapid7’s InsightIDR Enables Detection And Response to Microsoft Exchange Zero-Day CHINACHOPPER HAFNIUM |
2021-03-02
⋅
Microsoft
⋅
HAFNIUM targeting Exchange Servers with 0-day exploits CHINACHOPPER HAFNIUM |
2021-03-01
⋅
Medium walmartglobaltech
⋅
Investigation into the state of Nim malware BazarNimrod Cobalt Strike |
2021-03-01
⋅
Medium walmartglobaltech
⋅
Nimar Loader BazarBackdoor BazarNimrod Cobalt Strike |
2021-02-28
⋅
Recorded Future
⋅
China-Linked Group RedEcho Targets the Indian Power Sector Amid Heightened Border Tensions Icefog PlugX ShadowPad |
2021-02-28
⋅
PWC UK
⋅
Cyber Threats 2020: A Year in Retrospect elf.wellmess FlowerPower PowGoop 8.t Dropper Agent.BTZ Agent Tesla Appleseed Ave Maria Bankshot BazarBackdoor BLINDINGCAN Chinoxy Conti Cotx RAT Crimson RAT DUSTMAN Emotet FriedEx FunnyDream Hakbit Mailto Maze METALJACK Nefilim Oblique RAT Pay2Key PlugX QakBot REvil Ryuk StoneDrill StrongPity SUNBURST SUPERNOVA TrickBot TurlaRPC Turla SilentMoon WastedLocker WellMess Winnti ZeroCleare APT10 APT23 APT27 APT31 APT41 BlackTech BRONZE EDGEWOOD Inception Framework MUSTANG PANDA Red Charon Red Nue Sea Turtle Tonto Team |
2021-02-28
⋅
Recorded Future
⋅
China-linked Group RedEcho Targets the Indian Power Sector Amid Heightened Border Tensions PlugX ShadowPad RedEcho |
2021-02-26
⋅
CrowdStrike
⋅
Hypervisor Jackpotting: CARBON SPIDER and SPRITE SPIDER Target ESXi Servers With Ransomware to Maximize Impact DarkSide RansomEXX Griffon Carbanak Cobalt Strike DarkSide IcedID MimiKatz PyXie RansomEXX REvil |
2021-02-25
⋅
Proofpoint
⋅
TA413 Leverages New FriarFox Browser Extension to Target the Gmail Accounts of Global Tibetan Organizations scanbox Sepulcher Lucky Cat |
2021-02-25
⋅
FireEye
⋅
So Unchill: Melting UNC2198 ICEDID to Ransomware Operations MOUSEISLAND Cobalt Strike Egregor IcedID Maze SystemBC |
2021-02-24
⋅
Github (AmnestyTech)
⋅
Overview of Ocean Lotus Samples used to target Vietnamese Human Rights Defenders OceanLotus Cobalt Strike KerrDown |
2021-02-24
⋅
⋅
VMWare Carbon Black
⋅
Knock, knock, Neo. - Active C2 Discovery Using Protocol Emulation Cobalt Strike |
2021-02-23
⋅
CrowdStrike
⋅
2021 Global Threat Report RansomEXX Amadey Anchor Avaddon BazarBackdoor Clop Cobalt Strike Conti Cutwail DanaBot DarkSide DoppelPaymer Dridex Egregor Emotet Hakbit IcedID JSOutProx KerrDown LockBit Mailto Maze MedusaLocker Mespinoza Mount Locker NedDnLoader Nemty Pay2Key PlugX Pushdo PwndLocker PyXie QakBot Quasar RAT RagnarLocker Ragnarok RansomEXX REvil Ryuk Sekhmet ShadowPad SmokeLoader Snake SUNBURST SunCrypt TEARDROP TrickBot WastedLocker Winnti Zloader Evilnum OUTLAW SPIDER RIDDLE SPIDER SOLAR SPIDER VIKING SPIDER |
2021-02-22
⋅
tccontre Blog
⋅
Gh0stRat Anti-Debugging: Nested SEH (try - catch) to Decrypt and Load its Payload Ghost RAT |
2021-02-11
⋅
Twitter (@TheDFIRReport)
⋅
Tweet on Hancitor Activity followed by cobaltsrike beacon Cobalt Strike Hancitor |
2021-02-09
⋅
Securehat
⋅
Extracting the Cobalt Strike Config from a TEARDROP Loader Cobalt Strike TEARDROP |
2021-02-09
⋅
Cobalt Strike
⋅
Learn Pipe Fitting for all of your Offense Projects Cobalt Strike |
2021-02-08
⋅
Myanmar Computer Emergency Response Team
⋅
PlugX Removal Guide Version 1.2 PlugX |
2021-02-03
⋅
InfoSec Handlers Diary Blog
⋅
Excel spreadsheets push SystemBC malware Cobalt Strike SystemBC |
2021-02-02
⋅
Twitter (@TheDFIRReport)
⋅
Tweet on recent dridex post infection activity Cobalt Strike Dridex |
2021-02-02
⋅
⋅
CRONUP
⋅
De ataque con Malware a incidente de Ransomware Avaddon BazarBackdoor Buer Clop Cobalt Strike Conti DanaBot Dharma Dridex Egregor Emotet Empire Downloader FriedEx GootKit IcedID MegaCortex Nemty Phorpiex PwndLocker PyXie QakBot RansomEXX REvil Ryuk SDBbot SmokeLoader TrickBot Zloader |
2021-02-02
⋅
Committee to Protect Journalists
⋅
How Vietnam-based hacking operation OceanLotus targets journalists Cobalt Strike |
2021-02-01
⋅
pkb1s.github.io
⋅
Relay Attacks via Cobalt Strike Beacons Cobalt Strike |
2021-02-01
⋅
ESET Research
⋅
Operation NightScout: Supply‑chain attack targets online gaming in Asia Ghost RAT NoxPlayer Poison Ivy Red Dev 17 |
2021-02-01
⋅
AhnLab
⋅
BlueCrab ransomware, CobaltStrike hacking tool installed in corporate environment Cobalt Strike REvil |
2021-01-31
⋅
The DFIR Report
⋅
Bazar, No Ryuk? BazarBackdoor Cobalt Strike Ryuk |
2021-01-29
⋅
Trend Micro
⋅
Chopper ASPX web shell used in targeted attack CHINACHOPPER MimiKatz |
2021-01-28
⋅
⋅
AhnLab
⋅
BlueCrab ransomware constantly trying to bypass detection Cobalt Strike REvil |
2021-01-28
⋅
TrustedSec
⋅
Tailoring Cobalt Strike on Target Cobalt Strike |
2021-01-26
⋅
Twitter (@swisscom_csirt)
⋅
Tweet on Cring Ransomware groups using customized Mimikatz sample followed by CobaltStrike and dropping Cring rasomware Cobalt Strike Cring MimiKatz |
2021-01-20
⋅
Microsoft
⋅
Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop Cobalt Strike SUNBURST TEARDROP |
2021-01-20
⋅
Trend Micro
⋅
XDR investigation uncovers PlugX, unique technique in APT attack PlugX |
2021-01-18
⋅
Symantec
⋅
Raindrop: New Malware Discovered in SolarWinds Investigation Cobalt Strike Raindrop SUNBURST TEARDROP |
2021-01-17
⋅
Twitter (@AltShiftPrtScn)
⋅
Tweet on Conti Ransomware group exploiting FortiGate VPNs to drop in CobaltStrike loaders Cobalt Strike Conti |
2021-01-15
⋅
Swisscom
⋅
Cracking a Soft Cell is Harder Than You Think Ghost RAT MimiKatz PlugX Poison Ivy Trochilus RAT |
2021-01-15
⋅
Medium Dansec
⋅
Detecting Malicious C2 Activity -SpawnAs & SMB Lateral Movement in CobaltStrike Cobalt Strike |
2021-01-14
⋅
PTSecurity
⋅
Higaisa or Winnti? APT41 backdoors, old and new Cobalt Strike CROSSWALK FunnySwitch PlugX ShadowPad |
2021-01-12
⋅
BrightTALK (FireEye)
⋅
UNC2452: What We Know So Far Cobalt Strike SUNBURST TEARDROP |
2021-01-12
⋅
Fox-IT
⋅
Abusing cloud services to fly under the radar Cobalt Strike |
2021-01-11
⋅
SolarWinds
⋅
New Findings From Our Investigation of SUNBURST Cobalt Strike SUNBURST TEARDROP |
2021-01-11
⋅
The DFIR Report
⋅
Trickbot Still Alive and Well Cobalt Strike TrickBot |
2021-01-10
⋅
Medium walmartglobaltech
⋅
MAN1, Moskal, Hancitor and a side of Ransomware Cobalt Strike Hancitor SendSafe VegaLocker Moskalvzapoe |
2021-01-09
⋅
Marco Ramilli's Blog
⋅
Command and Control Traffic Patterns ostap LaZagne Agent Tesla Azorult Buer Cobalt Strike DanaBot DarkComet Dridex Emotet Formbook IcedID ISFB NetWire RC PlugX Quasar RAT SmokeLoader TrickBot |
2021-01-09
⋅
Connor McGarr's Blog
⋅
Malware Development: Leveraging Beacon Object Files for Remote Process Injection via Thread Hijacking Cobalt Strike |
2021-01-07
⋅
Recorded Future
⋅
Aversary Infrastructure Report 2020: A Defender's View Octopus pupy Cobalt Strike Empire Downloader Meterpreter PoshC2 |
2021-01-06
⋅
Red Canary
⋅
Hunting for GetSystem in offensive security tools Cobalt Strike Empire Downloader Meterpreter PoshC2 |
2021-01-05
⋅
Trend Micro
⋅
Earth Wendigo Injects JavaScript Backdoor to Service Worker for Mailbox Exfiltration Cobalt Strike Earth Wendigo |
2021-01-04
⋅
Bleeping Computer
⋅
China's APT hackers move to ransomware attacks Clambling PlugX |
2021-01-04
⋅
Medium haggis-m
⋅
Malleable C2 Profiles and You Cobalt Strike |
2021-01-01
⋅
AWAKE
⋅
Breaking the Ice: Detecting IcedID and Cobalt Strike Beacon with Network Detection and Response (NDR) Cobalt Strike IcedID PhotoLoader |
2021-01-01
⋅
DomainTools
⋅
Conceptualizing a Continuum of Cyber Threat Attribution CHINACHOPPER SUNBURST |
2021-01-01
⋅
Secureworks
⋅
Threat Profile: GOLD WATERFALL Cobalt Strike DarkSide GOLD WATERFALL |
2021-01-01
⋅
Mandiant
⋅
M-TRENDS 2021 Cobalt Strike SUNBURST |
2021-01-01
⋅
⋅
Github (WBGlIl)
⋅
A book on cobaltstrike Cobalt Strike |
2021-01-01
⋅
Symantec
⋅
Supply Chain Attacks:Cyber Criminals Target the Weakest Link Cobalt Strike Raindrop SUNBURST TEARDROP |
2021-01-01
⋅
Secureworks
⋅
Threat Profile: GOLD WINTER Cobalt Strike Hades Meterpreter GOLD WINTER |
2021-01-01
⋅
Talos
⋅
Evicting Maze Cobalt Strike Maze |
2021-01-01
⋅
Threat Profile: GOLD DRAKE Cobalt Strike Dridex FriedEx Koadic MimiKatz WastedLocker Evil Corp |
2021-01-01
⋅
Talos
⋅
Cobalt Strikes Out Cobalt Strike |
2020-12-26
⋅
Medium grimminck
⋅
Spoofing JARM signatures. I am the Cobalt Strike server now! Cobalt Strike |
2020-12-26
⋅
CYBER GEEKS All Things Infosec
⋅
Analyzing APT19 malware using a step-by-step method Derusbi |
2020-12-24
⋅
IronNet
⋅
China cyber attacks: the current threat landscape PLEAD TSCookie FlowCloud Lookback PLEAD PlugX Quasar RAT Winnti |
2020-12-22
⋅
TRUESEC
⋅
Collaboration between FIN7 and the RYUK group, a Truesec Investigation Carbanak Cobalt Strike Ryuk |
2020-12-21
⋅
Fortinet
⋅
What We Have Learned So Far about the “Sunburst”/SolarWinds Hack Cobalt Strike SUNBURST TEARDROP |
2020-12-20
⋅
Randhome
⋅
Analyzing Cobalt Strike for Fun and Profit Cobalt Strike |
2020-12-18
⋅
Seqrite
⋅
RAT used by Chinese cyberspies infiltrating Indian businesses Ghost RAT |
2020-12-15
⋅
Github (sophos-cybersecurity)
⋅
solarwinds-threathunt Cobalt Strike SUNBURST |
2020-12-15
⋅
PICUS Security
⋅
Tactics, Techniques, and Procedures (TTPs) Used in the SolarWinds Breach Cobalt Strike SUNBURST |
2020-12-14
⋅
Palo Alto Networks Unit 42
⋅
Threat Brief: SolarStorm and SUNBURST Customer Coverage Cobalt Strike SUNBURST |
2020-12-11
⋅
Blackberry
⋅
MountLocker Ransomware-as-a-Service Offers Double Extortion Capabilities to Affiliates Cobalt Strike Mount Locker |
2020-12-10
⋅
ESET Research
⋅
Operation StealthyTrident: corporate software under attack HyperBro PlugX Tmanger TA428 |
2020-12-10
⋅
ESET Research
⋅
Operation StealthyTrident: corporate software under attack HyperBro PlugX ShadowPad Tmanger |
2020-12-10
⋅
Palo Alto Networks Unit 42
⋅
Threat Brief: FireEye Red Team Tool Breach Cobalt Strike |
2020-12-10
⋅
Intel 471
⋅
No pandas, just people: The current state of China’s cybercrime underground Anubis SpyNote AsyncRAT Cobalt Strike Ghost RAT NjRAT |
2020-12-10
⋅
US-CERT
⋅
Alert (AA20-345A): Cyber Actors Target K-12 Distance Learning Education to Cause Disruptions and Steal Data PerlBot Shlayer Agent Tesla Cerber Dridex Ghost RAT Kovter Maze MedusaLocker Nanocore RAT Nefilim REvil Ryuk Zeus |
2020-12-09
⋅
InfoSec Handlers Diary Blog
⋅
Recent Qakbot (Qbot) activity Cobalt Strike QakBot |
2020-12-09
⋅
Avast Decoded
⋅
APT Group Targeting Governmental Agencies in East Asia Albaniiutas HyperBro PlugX PolPo Tmanger |
2020-12-09
⋅
Cisco
⋅
Quarterly Report: Incident Response trends from Fall 2020 Cobalt Strike IcedID Maze RansomEXX Ryuk |
2020-12-09
⋅
FireEye
⋅
It's not FINished The Evolving Maturity in Ransomware Operations (SLIDES) Cobalt Strike DoppelPaymer QakBot REvil |
2020-12-09
⋅
Avast Decoded
⋅
APT Group Targeting Governmental Agencies in East Asia Albaniiutas HyperBro PlugX Tmanger TA428 |
2020-12-08
⋅
Cobalt Strike
⋅
A Red Teamer Plays with JARM Cobalt Strike |
2020-12-02
⋅
Red Canary
⋅
Tweet on increased #Qbot activity delivering Cobalt Strike & #Egregor ransomware Cobalt Strike Egregor QakBot |
2020-12-01
⋅
mez0.cc
⋅
Cobalt Strike PowerShell Execution Cobalt Strike |
2020-12-01
⋅
360.cn
⋅
Hunting Beacons Cobalt Strike |
2020-11-30
⋅
FireEye
⋅
It's not FINished The Evolving Maturity in Ransomware Operations Cobalt Strike DoppelPaymer MimiKatz QakBot REvil |
2020-11-30
⋅
Microsoft
⋅
Threat actor (BISMUTH) leverages coin miner techniques to stay under the radar – here’s how to spot them Cobalt Strike |
2020-11-27
⋅
⋅
Macnica
⋅
Analyzing Organizational Invasion Ransom Incidents Using Dtrack Cobalt Strike Dtrack |
2020-11-27
⋅
PTSecurity
⋅
Investigation with a twist: an accidental APT attack and averted data destruction TwoFace CHINACHOPPER HyperBro MegaCortex MimiKatz |
2020-11-26
⋅
Cybereason
⋅
Cybereason vs. Egregor Ransomware Cobalt Strike Egregor IcedID ISFB QakBot |
2020-11-25
⋅
SentinelOne
⋅
Egregor RaaS Continues the Chaos with Cobalt Strike and Rclone Cobalt Strike Egregor |
2020-11-23
⋅
Proofpoint
⋅
TA416 Goes to Ground and Returns with a Golang PlugX Malware Loader PlugX MUSTANG PANDA |
2020-11-20
⋅
ZDNet
⋅
The malware that usually installs ransomware and you need to remove right away Avaddon BazarBackdoor Buer Clop Cobalt Strike Conti DoppelPaymer Dridex Egregor Emotet FriedEx MegaCortex Phorpiex PwndLocker QakBot Ryuk SDBbot TrickBot Zloader |
2020-11-20
⋅
F-Secure Labs
⋅
Detecting Cobalt Strike Default Modules via Named Pipe Analysis Cobalt Strike |
2020-11-20
⋅
Trend Micro
⋅
Weaponizing Open Source Software for Targeted Attacks LaZagne Defray PlugX |
2020-11-20
⋅
⋅
360 netlab
⋅
Blackrota, a highly obfuscated backdoor developed by Go Cobalt Strike |
2020-11-17
⋅
Salesforce Engineering
⋅
Easily Identify Malicious Servers on the Internet with JARM Cobalt Strike TrickBot |
2020-11-17
⋅
cyble
⋅
OceanLotus Continues With Its Cyber Espionage Operations Cobalt Strike Meterpreter |
2020-11-15
⋅
Trustnet
⋅
From virus alert to PowerShell Encrypted Loader Cobalt Strike |
2020-11-09
⋅
Bleeping Computer
⋅
Fake Microsoft Teams updates lead to Cobalt Strike deployment Cobalt Strike DoppelPaymer NjRAT Predator The Thief Zloader |
2020-11-06
⋅
Cobalt Strike
⋅
Cobalt Strike 4.2 – Everything but the kitchen sink Cobalt Strike |
2020-11-06
⋅
Palo Alto Networks Unit 42
⋅
Indicators of Compromise related to Cobaltstrike, PyXie Lite, Vatet and Defray777 Cobalt Strike PyXie RansomEXX |
2020-11-06
⋅
Advanced Intelligence
⋅
Anatomy of Attack: Inside BazarBackdoor to Ryuk Ransomware "one" Group via Cobalt Strike BazarBackdoor Cobalt Strike Ryuk |
2020-11-06
⋅
Volexity
⋅
OceanLotus: Extending Cyber Espionage Operations Through Fake Websites Cobalt Strike KerrDown APT32 |
2020-11-05
⋅
Twitter (@ffforward)
⋅
Tweet on Zloader infection leads to Cobaltstrike Installation and deployment of RYUK Cobalt Strike Ryuk Zloader |
2020-11-05
⋅
The DFIR Report
⋅
Ryuk Speed Run, 2 Hours to Ransom BazarBackdoor Cobalt Strike Ryuk |
2020-11-04
⋅
Sophos
⋅
A new APT uses DLL side-loads to “KilllSomeOne” KilllSomeOne PlugX |
2020-11-04
⋅
VMRay
⋅
Trick or Threat: Ryuk ransomware targets the health care industry BazarBackdoor Cobalt Strike Ryuk TrickBot |
2020-11-03
⋅
InfoSec Handlers Diary Blog
⋅
Attackers Exploiting WebLogic Servers via CVE-2020-14882 to install Cobalt Strike Cobalt Strike |
2020-11-03
⋅
Kaspersky Labs
⋅
APT trends report Q3 2020 WellMail EVILNUM Janicab Poet RAT AsyncRAT Ave Maria Cobalt Strike Crimson RAT CROSSWALK Dtrack LODEINFO MoriAgent Okrum PlugX poisonplug Rover ShadowPad SoreFang Winnti |
2020-10-30
⋅
Github (ThreatConnect-Inc)
⋅
UNC 1878 Indicators from Threatconnect BazarBackdoor Cobalt Strike Ryuk |
2020-10-30
⋅
YouTube (Kaspersky Tech)
⋅
Around the world in 80 days 4.2bn packets Cobalt Strike Derusbi HyperBro Poison Ivy ShadowPad Winnti |
2020-10-29
⋅
RiskIQ
⋅
Ryuk Ransomware: Extensive Attack Infrastructure Revealed Cobalt Strike Ryuk |
2020-10-29
⋅
Red Canary
⋅
A Bazar start: How one hospital thwarted a Ryuk ransomware outbreak Cobalt Strike Ryuk TrickBot |
2020-10-29
⋅
Github (Swisscom)
⋅
List of CobaltStrike C2's used by RYUK Cobalt Strike |
2020-10-28
⋅
FireEye
⋅
Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser BazarBackdoor Cobalt Strike Ryuk UNC1878 |
2020-10-27
⋅
Sophos Managed Threat Response (MTR)
⋅
MTR Casebook: An active adversary caught in the act Cobalt Strike |
2020-10-27
⋅
Dr.Web
⋅
Study of the ShadowPad APT backdoor and its relation to PlugX Ghost RAT PlugX ShadowPad |
2020-10-18
⋅
The DFIR Report
⋅
Ryuk in 5 Hours BazarBackdoor Cobalt Strike Ryuk |
2020-10-14
⋅
RiskIQ
⋅
A Well-Marked Trail: Journeying through OceanLotus's Infrastructure Cobalt Strike |
2020-10-14
⋅
Sophos
⋅
They’re back: inside a new Ryuk ransomware attack Cobalt Strike Ryuk SystemBC |
2020-10-12
⋅
Advanced Intelligence
⋅
"Front Door" into BazarBackdoor: Stealthy Cybercrime Weapon BazarBackdoor Cobalt Strike Ryuk |
2020-10-11
⋅
Github (StrangerealIntel)
⋅
Chimera, APT19 under the radar ? Cobalt Strike Meterpreter |
2020-10-08
⋅
Bayerischer Rundfunk
⋅
There is no safe place Cobalt Strike |
2020-10-08
⋅
The DFIR Report
⋅
Ryuk’s Return BazarBackdoor Cobalt Strike Ryuk |
2020-10-02
⋅
Health Sector Cybersecurity Coordination Center (HC3)
⋅
Report 202010021600: Recent Bazarloader Use in Ransomware Campaigns BazarBackdoor Cobalt Strike Ryuk TrickBot |
2020-10-01
⋅
Wired
⋅
Russia’s Fancy Bear Hackers Likely Penetrated a US Federal Agency Cobalt Strike Meterpreter |
2020-10-01
⋅
US-CERT
⋅
Alert (AA20-275A): Potential for China Cyber Response to Heightened U.S.-China Tensions CHINACHOPPER Cobalt Strike Empire Downloader MimiKatz Poison Ivy |
2020-09-29
⋅
Github (Apr4h)
⋅
CobaltStrikeScan Cobalt Strike |
2020-09-29
⋅
CrowdStrike
⋅
Getting the Bacon from the Beacon Cobalt Strike |
2020-09-24
⋅
Microsoft
⋅
Microsoft Security—detecting empires in the cloud CACTUSTORCH LazyCat APT40 |
2020-09-24
⋅
US-CERT
⋅
Analysis Report (AR20-268A): Federal Agency Compromised by Malicious Cyber Actor Cobalt Strike Meterpreter |
2020-09-23
⋅
Seqrite
⋅
Operation SideCopy: An insight into Transparent Tribe’s sub-division which has been incorrectly attributed for years CACTUSTORCH AllaKore |
2020-09-21
⋅
Cisco Talos
⋅
The art and science of detecting Cobalt Strike Cobalt Strike |
2020-09-18
⋅
Symantec
⋅
APT41: Indictments Put Chinese Espionage Group in the Spotlight CROSSWALK PlugX poisonplug ShadowPad Winnti |
2020-09-18
⋅
Trend Micro
⋅
U.S. Justice Department Charges APT41 Hackers over Global Cyberattacks Cobalt Strike ColdLock |
2020-09-15
⋅
US-CERT
⋅
Alert (AA20-259A): Iran-Based Threat Actor Exploits VPN Vulnerabilities CHINACHOPPER Fox Kitten |
2020-09-15
⋅
Recorded Future
⋅
Back Despite Disruption: RedDelta Resumes Operations PlugX |
2020-09-15
⋅
US-CERT
⋅
Malware Analysis Report (AR20-259A): Iranian Web Shells CHINACHOPPER |
2020-09-11
⋅
ThreatConnect
⋅
Research Roundup: Activity on Previously Identified APT33 Domains Emotet PlugX APT33 |
2020-09-03
⋅
⋅
Viettel Cybersecurity
⋅
APT32 deobfuscation arsenal: Deobfuscating một vài loại Obfucation Toolkit của APT32 (Phần 2) Cobalt Strike |
2020-09-01
⋅
Cisco Talos
⋅
Quarterly Report: Incident Response trends in Summer 2020 Cobalt Strike LockBit Mailto Maze Ryuk |
2020-08-31
⋅
The DFIR Report
⋅
NetWalker Ransomware in 1 Hour Cobalt Strike Mailto MimiKatz |
2020-08-20
⋅
⋅
Seebug Paper
⋅
Use ZoomEye to track multiple Redteam C&C post-penetration attack frameworks Cobalt Strike Empire Downloader PoshC2 |
2020-08-19
⋅
⋅
TEAMT5
⋅
調查局 08/19 公布中國對台灣政府機關駭侵事件說明 Cobalt Strike Waterbear |
2020-08-14
⋅
Twitter (@VK_intel)
⋅
Tweet on Zloader infection leading to Cobaltstrike Installation Cobalt Strike Zloader |
2020-08-06
⋅
Wired
⋅
Chinese Hackers Have Pillaged Taiwan's Semiconductor Industry Cobalt Strike MimiKatz Winnti Red Charon |
2020-08-04
⋅
BlackHat
⋅
Operation Chimera - APT Operation Targets Semiconductor Vendors Cobalt Strike MimiKatz Winnti Red Charon |
2020-07-29
⋅
Recorded Future
⋅
Chinese State-sponsored Group RedDelta Targets the Vatican and Catholic Organizations PlugX |
2020-07-29
⋅
ESET Research
⋅
THREAT REPORT Q2 2020 DEFENSOR ID HiddenAd Bundlore Pirrit Agent.BTZ Cerber ClipBanker CROSSWALK Cryptowall CTB Locker DanaBot Dharma Formbook Gandcrab Grandoreiro Houdini ISFB LockBit Locky Mailto Maze Microcin Nemty NjRAT Phobos PlugX Pony REvil Socelars STOP Tinba TrickBot WannaCryptor |
2020-07-29
⋅
Kaspersky Labs
⋅
APT trends report Q2 2020 PhantomLance Dacls Penquin Turla elf.wellmess AppleJeus Dacls AcidBox Cobalt Strike Dacls EternalPetya Godlike12 Olympic Destroyer PlugX shadowhammer ShadowPad Sinowal VHD Ransomware Volgmer WellMess X-Agent XTunnel |
2020-07-28
⋅
⋅
NTT
⋅
CraftyPanda 標的型攻撃解析レポート Ghost RAT PlugX |
2020-07-26
⋅
Shells.System blog
⋅
In-Memory shellcode decoding to evade AVs/EDRs Cobalt Strike |
2020-07-22
⋅
On the Hunt
⋅
Analysing Fileless Malware: Cobalt Strike Beacon Cobalt Strike |
2020-07-21
⋅
Department of Justice
⋅
Two Chinese Hackers Working with the Ministry of State Security Charged with Global Computer Intrusion Campaign Targeting Intellectual Property and Confidential Business Information, Including COVID-19 Research CHINACHOPPER BRONZE SPRING |
2020-07-21
⋅
Malwarebytes
⋅
Chinese APT group targets India and Hong Kong using new variant of MgBot malware KSREMOTE Cobalt Strike MgBot Evasive Panda |
2020-07-20
⋅
Dr.Web
⋅
Study of the APT attacks on state institutions in Kazakhstan and Kyrgyzstan Microcin Mirage PlugX WhiteBird |
2020-07-20
⋅
Risky.biz
⋅
What even is Winnti? CCleaner Backdoor Ghost RAT PlugX ZXShell |
2020-07-20
⋅
or10nlabs
⋅
Reverse Engineering the New Mustang Panda PlugX Downloader PlugX |
2020-07-15
⋅
ZDNet
⋅
Chinese state hackers target Hong Kong Catholic Church PlugX |
2020-07-10
⋅
ByteAtlas
⋅
Knowledge Fragment: Casting Sandbox Necromancy on DADSTACHE DADSTACHE |
2020-07-07
⋅
MWLab
⋅
Cobalt Strike stagers used by FIN6 Cobalt Strike |
2020-07-05
⋅
or10nlabs
⋅
Reverse Engineering the Mustang Panda PlugX RAT – Extracting the Config PlugX |
2020-07-01
⋅
Contextis
⋅
DLL Search Order Hijacking Cobalt Strike PlugX |
2020-06-25
⋅
Elastic
⋅
A close look at the advanced techniques used in a Malaysian-focused APT campaign DADSTACHE APT40 |
2020-06-23
⋅
NCC Group
⋅
WastedLocker: A New Ransomware Variant Developed By The Evil Corp Group Cobalt Strike ISFB WastedLocker |
2020-06-23
⋅
Symantec
⋅
Sodinokibi: Ransomware Attackers also Scanning for PoS Software, Leveraging Cobalt Strike Cobalt Strike REvil |
2020-06-22
⋅
Talos Intelligence
⋅
IndigoDrop spreads via military-themed lures to deliver Cobalt Strike Cobalt Strike IndigoDrop |
2020-06-22
⋅
Sentinel LABS
⋅
Inside a TrickBot Cobalt Strike Attack Server Cobalt Strike TrickBot |
2020-06-19
⋅
Zscaler
⋅
Targeted Attack Leverages India-China Border Dispute to Lure Victims Cobalt Strike |
2020-06-19
⋅
Youtube (Raphael Mudge)
⋅
Beacon Object Files - Luser Demo Cobalt Strike |
2020-06-18
⋅
Australian Cyber Security Centre
⋅
Advisory 2020-008: Copy-Paste Compromises –tactics, techniques and procedures used to target multiple Australian networks TwoFace Cobalt Strike Empire Downloader |
2020-06-17
⋅
Malwarebytes
⋅
Multi-stage APT attack drops Cobalt Strike using Malleable C2 feature Cobalt Strike |
2020-06-15
⋅
NCC Group
⋅
Striking Back at Retired Cobalt Strike: A look at a legacy vulnerability Cobalt Strike |
2020-06-14
⋅
BushidoToken
⋅
Deep-dive: The DarkHotel APT Asruex Ghost RAT Ramsay Retro Unidentified 076 (Higaisa LNK to Shellcode) |
2020-06-09
⋅
Github (Sentinel-One)
⋅
CobaltStrikeParser Cobalt Strike |
2020-06-05
⋅
Prevailion
⋅
The Gh0st Remains the Same Ghost RAT |
2020-06-04
⋅
PTSecurity
⋅
COVID-19 and New Year greetings: an investigation into the tools and methods used by the Higaisa group Ghost RAT SongXY |
2020-06-03
⋅
Kaspersky Labs
⋅
Cycldek: Bridging the (air) gap 8.t Dropper NewCore RAT PlugX USBCulprit GOBLIN PANDA Hellsing |
2020-06-02
⋅
Lab52
⋅
Mustang Panda Recent Activity: Dll-Sideloading trojans with temporal C2 servers PlugX |
2020-05-24
⋅
or10nlabs
⋅
Reverse Engineering the Mustang Panda PlugX Loader PlugX |
2020-05-20
⋅
Medium Asuna Amawaka
⋅
What happened between the BigBadWolf and the Tiger? Ghost RAT |
2020-05-15
⋅
Twitter (@stvemillertime)
⋅
Tweet on SOGU development timeline, including TIGERPLUG IOCs PlugX |
2020-05-14
⋅
Lab52
⋅
The energy reserves in the Eastern Mediterranean Sea and a malicious campaign of APT10 against Turkey Cobalt Strike HTran MimiKatz PlugX Quasar RAT |
2020-05-14
⋅
Avast Decoded
⋅
APT Group Planted Backdoors Targeting High Profile Networks in Central Asia BYEBY Ghost RAT Microcin MimiKatz Vicious Panda |
2020-05-11
⋅
SentinelOne
⋅
The Anatomy of an APT Attack and CobaltStrike Beacon’s Encoded Configuration Cobalt Strike |
2020-05-01
⋅
⋅
Viettel Cybersecurity
⋅
Chiến dịch của nhóm APT Trung Quốc Goblin Panda tấn công vào Việt Nam lợi dụng đại dịch Covid-19 (phần 1) NewCore RAT PlugX |
2020-04-24
⋅
The DFIR Report
⋅
Ursnif via LOLbins Cobalt Strike LOLSnif TeamSpy |
2020-04-16
⋅
Medium CyCraft
⋅
Taiwan High-Tech Ecosystem Targeted by Foreign APT Group: Digital Skeleton Key Bypasses Security Measures Cobalt Strike MimiKatz Red Charon |
2020-04-07
⋅
Blackberry
⋅
Decade of the RATS: Cross-Platform APT Espionage Attacks Targeting Linux, Windows and Android Penquin Turla XOR DDoS ZXShell |
2020-04-02
⋅
Darktrace
⋅
Catching APT41 exploiting a zero-day vulnerability Cobalt Strike |
2020-03-26
⋅
VMWare Carbon Black
⋅
The Dukes of Moscow Cobalt Strike LiteDuke MiniDuke OnionDuke PolyglotDuke PowerDuke |
2020-03-25
⋅
FireEye
⋅
This Is Not a Test: APT41 Initiates Global Intrusion Campaign Using Multiple Exploits Speculoos Cobalt Strike |
2020-03-25
⋅
Wilbur Security
⋅
Trickbot to Ryuk in Two Hours Cobalt Strike Ryuk TrickBot |
2020-03-22
⋅
Malware and Stuff
⋅
Mustang Panda joins the COVID-19 bandwagon Cobalt Strike |
2020-03-22
⋅
Anomali
⋅
COVID-19 Themes Are Being Utilized by Threat Actors of Varying Sophistication PlugX |
2020-03-20
⋅
RECON INFOSEC
⋅
Analysis Of Exploitation: CVE-2020-10189 ( exploited by APT41) Cobalt Strike |
2020-03-19
⋅
⋅
VinCSS
⋅
Analysis of malware taking advantage of the Covid-19 epidemic to spread fake "Directive of Prime Minister Nguyen Xuan Phuc" - Part 2 PlugX |
2020-03-15
⋅
insomniacs(Medium)
⋅
Dad! There’s A Rat In Here! DADSTACHE |
2020-03-10
⋅
insomniacs(Medium)
⋅
APT40 goes from Template Injections to OLE-Linkings for payload delivery DADSTACHE |
2020-03-10
⋅
⋅
VinCSS
⋅
[RE012] Analysis of malware taking advantage of the Covid-19 epidemic to spread fake "Directive of Prime Minister Nguyen Xuan Phuc" - Part 1 PlugX |
2020-03-05
⋅
SophosLabs
⋅
Cloud Snooper Attack Bypasses AWS Security Measures Cloud Snooper Ghost RAT |
2020-03-04
⋅
Cobalt Strike
⋅
Cobalt Strike joins Core Impact at HelpSystems, LLC Cobalt Strike |
2020-03-04
⋅
CrowdStrike
⋅
2020 CrowdStrike Global Threat Report MESSAGETAP More_eggs 8.t Dropper Anchor BabyShark BadNews Clop Cobalt Strike CobInt Cobra Carbon System Cutwail DanaBot Dharma DoppelDridex DoppelPaymer Dridex Emotet FlawedAmmyy FriedEx Gandcrab Get2 IcedID ISFB KerrDown LightNeuron LockerGoga Maze MECHANICAL Necurs Nokki Outlook Backdoor Phobos Predator The Thief QakBot REvil RobinHood Ryuk SDBbot Skipper SmokeLoader TerraRecon TerraStealer TerraTV TinyLoader TrickBot Vidar Winnti ANTHROPOID SPIDER APT23 APT31 APT39 APT40 BlackTech BuhTrap Charming Kitten CLOCKWORK SPIDER DOPPEL SPIDER FIN7 Gamaredon Group GOBLIN PANDA MONTY SPIDER MUSTANG PANDA NARWHAL SPIDER NOCTURNAL SPIDER PINCHY SPIDER SALTY SPIDER SCULLY SPIDER SMOKY SPIDER Thrip VENOM SPIDER VICEROY TIGER |
2020-03-03
⋅
PWC UK
⋅
Cyber Threats 2019:A Year in Retrospect KevDroid MESSAGETAP magecart AndroMut Cobalt Strike CobInt Crimson RAT DNSpionage Dridex Dtrack Emotet FlawedAmmyy FlawedGrace FriedEx Gandcrab Get2 GlobeImposter Grateful POS ISFB Kazuar LockerGoga Nokki QakBot Ramnit REvil Rifdoor RokRAT Ryuk shadowhammer ShadowPad Shifu Skipper StoneDrill Stuxnet TrickBot Winnti ZeroCleare APT41 MUSTANG PANDA Sea Turtle |
2020-03-02
⋅
Virus Bulletin
⋅
Pulling the PKPLUG: the adversary playbook for the long-standing espionage activity of a Chinese nation-state adversary HenBox Farseer PlugX Poison Ivy |
2020-02-21
⋅
ADEO DFIR
⋅
APT10 Threat Analysis Report CHINACHOPPER HTran MimiKatz PlugX Quasar RAT |
2020-02-20
⋅
McAfee
⋅
CSI: Evidence Indicators for Targeted Ransomware Attacks – Part II Cobalt Strike LockerGoga Maze MegaCortex |
2020-02-19
⋅
FireEye
⋅
M-Trends 2020 Cobalt Strike Grateful POS LockerGoga QakBot TrickBot |
2020-02-18
⋅
Cisco Talos
⋅
Building a bypass with MSBuild Cobalt Strike GRUNT MimiKatz |
2020-02-18
⋅
Trend Micro
⋅
Uncovering DRBControl: Inside the Cyberespionage Campaign Targeting Gambling Operations Cobalt Strike HyperBro PlugX Trochilus RAT |
2020-02-17
⋅
Talent-Jump Technologies
⋅
CLAMBLING - A New Backdoor Base On Dropbox HyperBro PlugX |
2020-02-13
⋅
Qianxin
⋅
APT Report 2019 Chrysaor Exodus Dacls VPNFilter DNSRat Griffon KopiLuwak More_eggs SQLRat AppleJeus BONDUPDATER Agent.BTZ Anchor AndroMut AppleJeus BOOSTWRITE Brambul Carbanak Cobalt Strike Dacls DistTrack DNSpionage Dtrack ELECTRICFISH FlawedAmmyy FlawedGrace Get2 Grateful POS HOPLIGHT Imminent Monitor RAT jason Joanap KerrDown KEYMARBLE Lambert LightNeuron LoJax MiniDuke PolyglotDuke PowerRatankba Rising Sun SDBbot ServHelper Snatch Stuxnet TinyMet tRat TrickBot Volgmer X-Agent Zebrocy |
2020-02-08
⋅
MyCERT
⋅
MA-774.022020: MyCERT Advisory - Espionage Campaign Based On Technical Indicators APT40 |
2020-02-07
⋅
Medium Sebdraven
⋅
APT 40 in Malaysia DADJOKE |
2020-01-31
⋅
Avira
⋅
New wave of PlugX targets Hong Kong PlugX |
2020-01-31
⋅
YouTube (Context Information Security)
⋅
New AVIVORE threat group – how they operate and managing the risk PlugX |
2020-01-29
⋅
nao_sec blog
⋅
An Overhead View of the Royal Road BLACKCOFFEE Cotx RAT Datper DDKONG Derusbi Icefog Korlia NewCore RAT PLAINTEE Poison Ivy Sisfader |
2020-01-15
⋅
Intrusiontruth
⋅
Hainan Xiandun Technology Company is APT40 APT40 |
2020-01-14
⋅
Intrusiontruth
⋅
Who is Mr Ding? APT40 |
2020-01-13
⋅
Lab52
⋅
APT27 ZxShell RootKit module updates ZXShell |
2020-01-13
⋅
Intrusiontruth
⋅
Who else works for this cover company network? APT40 |
2020-01-10
⋅
Intrusiontruth
⋅
Who is Mr Gu? APT40 |
2020-01-09
⋅
Intrusiontruth
⋅
What is the Hainan Xiandun Technology Development Company? APT40 |
2020-01-03
⋅
Youtube (BSides Belfast)
⋅
Nice One, Dad: Dissecting A Rare Malware Used By Leviathan DADJOKE |
2020-01-01
⋅
Secureworks
⋅
GOLD KINGSWOOD More_eggs ATMSpitter Cobalt Strike CobInt MimiKatz |
2020-01-01
⋅
Secureworks
⋅
BRONZE PRESIDENT CHINACHOPPER Cobalt Strike PlugX MUSTANG PANDA |
2020-01-01
⋅
FireEye
⋅
Mandiant IR Grab Bag of Attacker Activity TwoFace CHINACHOPPER HyperBro HyperSSL |
2020-01-01
⋅
Secureworks
⋅
BRONZE ATLAS Speculoos Winnti ACEHASH CCleaner Backdoor CHINACHOPPER Empire Downloader HTran MimiKatz PlugX Winnti APT41 |
2020-01-01
⋅
Secureworks
⋅
BRONZE EDISON Ghost RAT sykipot APT4 SAMURAI PANDA |
2020-01-01
⋅
Secureworks
⋅
BRONZE OLIVE ANGRYREBEL PlugX APT22 |
2020-01-01
⋅
Secureworks
⋅
BRONZE UNION 9002 RAT CHINACHOPPER Enfal Ghost RAT HttpBrowser HyperBro owaauth PlugX Poison Ivy ZXShell APT27 |
2020-01-01
⋅
Secureworks
⋅
BRONZE KEYSTONE 9002 RAT BLACKCOFFEE DeputyDog Derusbi HiKit PlugX Poison Ivy ZXShell APT17 |
2020-01-01
⋅
Secureworks
⋅
BRONZE RIVERSIDE Anel ChChes Cobalt Strike PlugX Poison Ivy Quasar RAT RedLeaves APT10 |
2020-01-01
⋅
Secureworks
⋅
BRONZE OVERBROOK Aveo DDKONG IsSpace PLAINTEE PlugX Rambo DragonOK |
2020-01-01
⋅
Secureworks
⋅
GOLD DUPONT Cobalt Strike Defray PyXie GOLD DUPONT |
2020-01-01
⋅
Secureworks
⋅
BRONZE FIRESTONE 9002 RAT Derusbi Empire Downloader PlugX Poison Ivy APT19 |
2020-01-01
⋅
Secureworks
⋅
GOLD NIAGARA Bateleur Griffon Carbanak Cobalt Strike DRIFTPIN TinyMet FIN7 |
2020-01-01
⋅
Secureworks
⋅
GOLD KINGSWOOD More_eggs ATMSpitter Cobalt Strike CobInt MimiKatz Cobalt |
2020-01-01
⋅
Secureworks
⋅
TIN WOODLAWN Cobalt Strike KerrDown MimiKatz PHOREAL RatSnif Remy SOUNDBITE APT32 |
2020-01-01
⋅
Dragos
⋅
Threat Intelligence and the Limits of Malware Analysis Exaramel Exaramel Industroyer Lookback NjRAT PlugX |
2020-01-01
⋅
Secureworks
⋅
BRONZE GLOBE EtumBot Ghost RAT APT12 |
2020-01-01
⋅
Secureworks
⋅
BRONZE FLEETWOOD Binanen Ghost RAT OrcaRAT APT5 |
2020-01-01
⋅
Secureworks
⋅
BRONZE MOHAWK AIRBREAK scanbox BLACKCOFFEE CHINACHOPPER Cobalt Strike Derusbi homefry murkytop SeDll APT40 |
2020-01-01
⋅
Secureworks
⋅
BRONZE WOODLAND PlugX Zeus Roaming Tiger |
2020-01-01
⋅
Secureworks
⋅
BRONZE EXPRESS 9002 RAT CHINACHOPPER IsSpace NewCT PlugX smac APT26 |
2019-12-29
⋅
Secureworks
⋅
BRONZE PRESIDENT Targets NGOs PlugX |
2019-12-17
⋅
Palo Alto Networks Unit 42
⋅
Rancor: Cyber Espionage Group Uses New Custom Malware to Attack Southeast Asia DDKONG Derusbi KHRAT |
2019-12-12
⋅
Microsoft
⋅
GALLIUM: Targeting global telecom CHINACHOPPER Ghost RAT HTran MimiKatz Poison Ivy GALLIUM |
2019-12-12
⋅
FireEye
⋅
Cyber Threat Landscape in Japan – Revealing Threat in the Shadow Cerberus TSCookie Cobalt Strike Dtrack Emotet Formbook IcedID Icefog IRONHALO Loki Password Stealer (PWS) PandaBanker PLEAD poisonplug TrickBot BlackTech |
2019-12-05
⋅
⋅
Github (blackorbird)
⋅
APT32 Report Cobalt Strike |
2019-12-05
⋅
Cobalt Strike 4.0 – Bring Your Own Weaponization Cobalt Strike |
2019-11-29
⋅
Deloitte
⋅
Cyber Threat Intelligence & Incident Response Cobalt Strike |
2019-11-28
⋅
Twitter (@cyb3rops)
⋅
Tweet on Signature Writing for DADJOKE DADSTACHE |
2019-11-19
⋅
FireEye
⋅
Achievement Unlocked: Chinese Cyber Espionage Evolves to Support Higher Level Missions MESSAGETAP TSCookie ACEHASH CHINACHOPPER Cobalt Strike Derusbi Empire Downloader Ghost RAT HIGHNOON HTran MimiKatz NetWire RC poisonplug Poison Ivy pupy Quasar RAT ZXShell |
2019-11-16
⋅
Silas Cutler's Blog
⋅
Fresh PlugX October 2019 PlugX |
2019-11-11
⋅
Virus Bulletin
⋅
APT cases exploiting vulnerabilities in region‑specific software NodeRAT Emdivi PlugX |
2019-11-05
⋅
tccontre Blog
⋅
CobaltStrike - beacon.dll : Your No Ordinary MZ Header Cobalt Strike |
2019-11-05
⋅
DADJOKE DADJOKE |
2019-11-04
⋅
⋅
Tencent
⋅
APT attack group "Higaisa" attack activity disclosed Ghost RAT Higaisa |
2019-10-31
⋅
PTSecurity
⋅
Calypso APT: new group attacking state institutions BYEBY FlyingDutchman Hussar PlugX |
2019-10-22
⋅
Contextis
⋅
AVIVORE - An overview of Tools, Techniques and Procedures (Whitepaper) PlugX Avivore |
2019-10-03
⋅
Palo Alto Networks Unit 42
⋅
PKPLUG: Chinese Cyber Espionage Group Attacking Asia HenBox Farseer PlugX |
2019-10-03
⋅
ComputerWeekly
⋅
New threat group behind Airbus cyber attacks, claim researchers PlugX Avivore |
2019-09-23
⋅
MITRE
⋅
APT41 Derusbi MESSAGETAP Winnti ASPXSpy BLACKCOFFEE CHINACHOPPER Cobalt Strike Derusbi Empire Downloader Ghost RAT MimiKatz NjRAT PlugX ShadowPad Winnti ZXShell APT41 |
2019-09-22
⋅
Check Point Research
⋅
Rancor: The Year of The Phish 8.t Dropper Cobalt Strike |
2019-09-19
⋅
Emissary Panda APT: Recent infrastructure and RAT analysis ZXShell |
2019-09-17
⋅
Talos
⋅
Cryptocurrency miners aren’t dead yet: Documenting the voracious but simple “Panda” Ghost RAT |
2019-09-02
⋅
Volexity
⋅
Digital Crackdown: Large-Scale Surveillance and Exploitation of Uyghurs scanbox POISON CARP |
2019-08-27
⋅
Cisco Talos
⋅
China Chopper still active 9 years later CHINACHOPPER |
2019-08-19
⋅
FireEye
⋅
GAME OVER: Detecting and Stopping an APT41 Operation ACEHASH CHINACHOPPER HIGHNOON |
2019-08-13
⋅
⋅
洞察人性:一起利用政治人物桃色丑闻的诱饵攻击活动披露 DADJOKE |
2019-07-26
⋅
Twitter (@a_tweeter_user)
⋅
Tweet on Malware DADJOKE |
2019-07-24
⋅
Intrusiontruth
⋅
APT17 is run by the Jinan bureau of the Chinese Ministry of State Security BLACKCOFFEE |
2019-06-25
⋅
Cybereason
⋅
OPERATION SOFT CELL: A WORLDWIDE CAMPAIGN AGAINST TELECOMMUNICATIONS PROVIDERS CHINACHOPPER HTran MimiKatz Poison Ivy Operation Soft Cell |
2019-06-19
⋅
YouTube (44CON Information Security Conference)
⋅
The Malware CAPE: Automated Extraction of Configuration and Payloads from Sophisticated Malware PlugX |
2019-06-13
⋅
Sekoia
⋅
Hunting and detecting Cobalt Strike Cobalt Strike |
2019-06-04
⋅
Bitdefender
⋅
An APT Blueprint: Gaining New Visibility into Financial Threats More_eggs Cobalt Strike |
2019-06-03
⋅
FireEye
⋅
Into the Fog - The Return of ICEFOG APT Icefog PlugX Sarhust |
2019-05-28
⋅
Palo Alto Networks Unit 42
⋅
Emissary Panda Attacks Middle East Government Sharepoint Servers CHINACHOPPER HyperSSL |
2019-05-24
⋅
Fortinet
⋅
Uncovering new Activity by APT10 PlugX Quasar RAT |
2019-05-08
⋅
Verizon Communications Inc.
⋅
2019 Data Breach Investigations Report BlackEnergy Cobalt Strike DanaBot Gandcrab GreyEnergy Mirai Olympic Destroyer SamSam |
2019-04-30
⋅
Council on Foreign Relations
⋅
APT 40 APT40 |
2019-04-25
⋅
⋅
DATANET
⋅
Chinese-based hackers attack domestic energy institutions CALMTHORN Ghost RAT |
2019-04-24
⋅
Weixin
⋅
"Sea Lotus" APT organization's attack techniques against China in the first quarter of 2019 revealed Cobalt Strike SOUNDBITE |
2019-04-22
⋅
Twitter (@killamjr)
⋅
Tweet on DADSTACHE payload DADSTACHE |
2019-04-15
⋅
PenTestPartners
⋅
Cobalt Strike. Walkthrough for Red Teamers Cobalt Strike |
2019-04-11
⋅
FireEye
⋅
M-Trend 2019 GRILLMARK |
2019-04-01
⋅
⋅
Macnica Networks
⋅
OceanLotus Attack on Southeast Asian Automotive Industry CACTUSTORCH Cobalt Strike |
2019-04-01
⋅
⋅
Macnica Networks
⋅
Trends in Cyber Espionage Targeting Japan 2nd Half of 2018 Anel Cobalt Strike Datper PLEAD Quasar RAT RedLeaves taidoor Zebrocy |
2019-03-27
⋅
Twitter (@ClearskySec)
⋅
Tweet on "Timelines - ECRL.docx" DADJOKE |
2019-03-24
⋅
One Night in Norfolk
⋅
JEShell: An OceanLotus (APT32) Backdoor Cobalt Strike KerrDown |
2019-03-19
⋅
NSHC
⋅
SectorM04 Targeting Singapore – An Analysis PlugX Termite |
2019-03-14
⋅
Trustwave
⋅
Attacker Tracking Users Seeking Pakistani Passport scanbox |
2019-03-05
⋅
Accenture
⋅
MUDCARP's Focus on Submarine Technologies 8.t Dropper APT40 |
2019-03-04
⋅
FireEye
⋅
APT40: Examining a China-Nexus Espionage Actor LunchMoney APT40 |
2019-02-27
⋅
Secureworks
⋅
A Peek into BRONZE UNION’s Toolbox Ghost RAT HyperBro ZXShell |
2019-02-27
⋅
Morphisec
⋅
New Global Cyber Attack on Point of Sale Sytem Cobalt Strike |
2019-02-26
⋅
Fox-IT
⋅
Identifying Cobalt Strike team servers in the wild Cobalt Strike |
2019-02-26
⋅
Yoroi
⋅
The Arsenal Behind the Australian Parliament Hack LazyCat powerkatz Unidentified 057 |
2019-02-19
⋅
Twitter (@MrDanPerez)
⋅
APT40 dropper LunchMoney |
2019-01-07
⋅
Intezer
⋅
ChinaZ Revelations: Revealing ChinaZ Relationships with other Chinese Threat Actor Groups Ghost RAT |
2019-01-01
⋅
MITRE
⋅
Group description: Leviathan APT40 |
2019-01-01
⋅
CrowdStrike
⋅
2019 CrowdStrike Global Threat Report APT40 BOSS SPIDER FIN6 Flash Kitten GURU SPIDER LUNAR SPIDER NOMAD PANDA PINCHY SPIDER RATPAK SPIDER SALTY SPIDER TINY SPIDER |
2019-01-01
⋅
MITRE
⋅
Tool description: NanHaiShu NanHaiShu |
2019-01-01
⋅
Virus Bulletin
⋅
A vine climbing over the Great Firewall: A long-term attack against China Poison Ivy ZXShell |
2019-01-01
⋅
MITRE
⋅
Tool description: BLACKCOFFEE BLACKCOFFEE |
2019-01-01
⋅
MITRE
⋅
Tool description: China Chopper CHINACHOPPER |
2018-12-20
⋅
⋅
Codercto
⋅
Analysis of the attack activities of Hailian Lotus APT group against large domestic investment companies CACTUSTORCH |
2018-12-14
⋅
Australian Cyber Security Centre
⋅
Investigationreport: Compromise of an Australian companyvia their Managed Service Provider PlugX RedLeaves |
2018-11-19
⋅
FireEye
⋅
Not So Cozy: An Uncomfortable Examination of a Suspected APT29 Phishing Campaign Cobalt Strike |
2018-11-18
⋅
Stranded on Pylos Blog
⋅
CozyBear – In from the Cold? Cobalt Strike APT29 |
2018-11-13
⋅
Recorded Future
⋅
Chinese Threat Actor TEMP.Periscope Targets UK-Based Engineering Company Using Russian APT Techniques SeDll APT40 |
2018-10-01
⋅
⋅
Macnica Networks
⋅
Trends in cyber espionage (targeted attacks) targeting Japan | First half of 2018 Anel Cobalt Strike Datper FlawedAmmyy Quasar RAT RedLeaves taidoor Winnti xxmm |
2018-10-01
⋅
FireEye
⋅
ATT&CKing FIN7 Bateleur BELLHOP Griffon ANTAK POWERPIPE POWERSOURCE HALFBAKED BABYMETAL Carbanak Cobalt Strike DNSMessenger DRIFTPIN PILLOWMINT SocksBot |
2018-10-01
⋅
Group-IB
⋅
Hi-Tech Crime Trends 2018 BackSwap Cobalt Strike Cutlet Meterpreter |
2018-09-19
⋅
Möbius Strip Reverse Engineering
⋅
Hex-Rays Microcode API vs. Obfuscating Compiler Ghost RAT |
2018-08-21
⋅
Trend Micro
⋅
Operation Red Signature Targets South Korean Companies 9002 RAT PlugX Operation Red Signature |
2018-08-03
⋅
JPCERT/CC
⋅
Volatility Plugin for Detecting Cobalt Strike Beacon Cobalt Strike |
2018-07-31
⋅
Medium Sebdraven
⋅
Malicious document targets Vietnamese officials 8.t Dropper PlugX 1937CN |
2018-07-31
⋅
Github (JPCERTCC)
⋅
Scanner for CobaltStrike Cobalt Strike |
2018-07-11
⋅
FireEye
⋅
Chinese Espionage Group TEMP.Periscope Targets Cambodia Ahead of July 2018 Elections and Reveals Broad Operations Globally AIRBREAK APT40 |
2018-05-21
⋅
⋅
LAC
⋅
Confirmed new attacks by APT attacker group menuPass (APT10) Cobalt Strike |
2018-05-09
⋅
COUNT UPON SECURITY
⋅
Malware Analysis - PlugX - Part 2 PlugX |
2018-04-20
⋅
NCC Group
⋅
Decoding network data from a Gh0st RAT variant Ghost RAT APT27 |
2018-04-17
⋅
NCC Group
⋅
Decoding network data from a Gh0st RAT variant Ghost RAT APT27 |
2018-03-30
⋅
Kahu Security
⋅
Reflow JavaScript Backdoor AIRBREAK |
2018-03-30
⋅
AmosSys
⋅
BADFLICK is not so bad! badflick |
2018-03-16
⋅
FireEye
⋅
Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries badflick BLACKCOFFEE CHINACHOPPER homefry murkytop SeDll APT40 |
2018-03-13
⋅
Kaspersky Labs
⋅
Time of death? A therapeutic postmortem of connected medicine PlugX |
2018-02-04
⋅
COUNT UPON SECURITY
⋅
MALWARE ANALYSIS – PLUGX PlugX |
2018-02-01
⋅
Bitdefender
⋅
Operation PZCHAO Inside a highly specialized espionage infrastructure Ghost RAT APT27 |
2018-01-04
⋅
Malware Traffic Analysis
⋅
MALSPAM PUSHING PCRAT/GH0ST Ghost RAT |
2017-12-20
⋅
CrowdStrike
⋅
An End to “Smash-and-Grab” and a Move to More Targeted Approaches CHINACHOPPER |
2017-12-19
⋅
Proofpoint
⋅
North Korea Bitten by Bitcoin Bug QUICKCAFE PowerSpritz Ghost RAT PowerRatankba |
2017-12-19
⋅
Proofpoint
⋅
North Korea Bitten by Bitcoin Bug: Financially motivated campaigns reveal new dimension of the Lazarus Group Ghost RAT |
2017-12-18
⋅
⋅
LAC
⋅
Relationship between PlugX and attacker group "DragonOK" PlugX |
2017-11-16
⋅
Github (mdsecactivebreach)
⋅
CACTUSTORCH: Payload Generation for Adversary Simulations CACTUSTORCH |
2017-10-16
⋅
Proofpoint
⋅
Leviathan: Espionage actor spearphishes maritime and defense targets NanHaiShu SeDll APT40 |
2017-06-27
⋅
Palo Alto Networks Unit 42
⋅
Paranoid PlugX PlugX |
2017-06-06
⋅
FireEye
⋅
Privileges and Credentials: Phished at the Request of Counsel Cobalt Strike |
2017-06-06
⋅
Mandiant
⋅
Privileges and Credentials: Phished at the Request of Counsel Cobalt Strike APT19 |
2017-05-31
⋅
MITRE
⋅
Axiom Derusbi 9002 RAT BLACKCOFFEE Derusbi Ghost RAT HiKit PlugX ZXShell APT17 |
2017-05-31
⋅
MITRE
⋅
PittyTiger Enfal Ghost RAT MimiKatz Poison Ivy APT24 |
2017-05-31
⋅
MITRE
⋅
APT18 Ghost RAT HttpBrowser APT18 |
2017-05-31
⋅
MITRE
⋅
APT17 BLACKCOFFEE APT17 |
2017-04-27
⋅
US-CERT
⋅
Alert (TA17-117A): Intrusions Affecting Multiple Victims Across Multiple Sectors PlugX RedLeaves |
2017-04-26
⋅
Youtube (Kaspersky)
⋅
China's Evolving Cyber Operations: A Look into APT19's Shift in Tactics Cobalt Strike APT19 |
2017-04-03
⋅
JPCERT/CC
⋅
RedLeaves - Malware Based on Open Source RAT PlugX RedLeaves Trochilus RAT |
2017-04-01
⋅
PricewaterhouseCoopers
⋅
Operation Cloud Hopper: Technical Annex ChChes PlugX Quasar RAT RedLeaves Trochilus RAT |
2017-02-25
⋅
Financial Security Institute
⋅
Silent RIFLE: Response Against Advanced Threat Ghost RAT |
2017-02-21
⋅
JPCERT/CC
⋅
PlugX + Poison Ivy = PlugIvy? - PlugX Integrating Poison Ivy’s Code PlugX |
2017-02-13
⋅
RSA
⋅
KINGSLAYER – A SUPPLY CHAIN ATTACK CodeKey PlugX |
2016-10-28
⋅
Github (smb01)
⋅
zxshell repository ZXShell |
2016-10-11
⋅
Symantec
⋅
Odinaff: New Trojan used in high level financial attacks Cobalt Strike KLRD MimiKatz Odinaff |
2016-08-25
⋅
Malwarebytes
⋅
Unpacking the spyware disguised as antivirus PlugX |
2016-08-05
⋅
F-Secure
⋅
NANHAISHU: RATing the South China Sea NanHaiShu |
2016-06-13
⋅
⋅
Macnica Networks
⋅
Survey of the actual situation of the large-scale cyber spy activity that hit Japan | 1st edition Emdivi PlugX |
2016-04-22
⋅
Cylance
⋅
The Ghost Dragon Ghost RAT |
2016-03-02
⋅
RSA Conference
⋅
Dissecting Derusbi Derusbi |
2016-01-22
⋅
RSA Link
⋅
PlugX APT Malware PlugX |
2015-12-15
⋅
Airbus Defence & Space
⋅
Newcomers in the Derusbi family Derusbi |
2015-10-08
⋅
Virus Bulletin
⋅
Catching the silent whisper: Understanding the Derusbi family tree Derusbi |
2015-09-15
⋅
Proofpoint
⋅
In Pursuit of Optical Fibers and Troop Intel: Targeted Attack Distributes PlugX in Russia PlugX |
2015-08-01
⋅
Arbor Networks
⋅
Uncovering the Seven Pointed Dagger 9002 RAT EvilGrab PlugX Trochilus RAT APT9 |
2015-06-24
⋅
Spiceworks
⋅
Stealthy Cyberespionage Campaign Attacks With Social Engineering NanHaiShu |
2015-05-18
⋅
⋅
TT Malware Log BLACKCOFFEE |
2015-05-01
⋅
FireEye
⋅
HIDING IN PLAIN SIGHT: FIREEYE AND MICROSOFT EXPOSE OBFUSCATION TACTIC BLACKCOFFEE |
2015-04-15
⋅
Kaspersky Labs
⋅
The Chronicles of the Hellsing APT: the Empire Strikes Back GRILLMARK Hellsing |
2015-04-14
⋅
Youtube (Kaspersky)
⋅
Following APT OpSec failures BLACKCOFFEE Mangzamel APT17 |
2015-02-27
⋅
ThreatConnect
⋅
The Anthem Hack: All Roads Lead to China Derusbi |
2015-02-27
⋅
InfoSec Institute
⋅
ScanBox Framework scanbox |
2015-02-06
⋅
CrowdStrike
⋅
CrowdStrike Global Threat Intel Report 2014 BlackPOS CryptoLocker Derusbi Elise Enfal EvilGrab Gameover P2P HttpBrowser Medusa Mirage Naikon NetTraveler pirpi PlugX Poison Ivy Sakula RAT Sinowal sykipot taidoor |
2015-01-29
⋅
JPCERT/CC
⋅
Analysis of a Recent PlugX Variant - “P2P PlugX” PlugX |
2014-11-01
⋅
Novetta
⋅
ZoxPNG Analysis BLACKCOFFEE |
2014-10-28
⋅
Cisco
⋅
Threat Spotlight: Group 72, Opening the ZxShell ZXShell |
2014-10-28
⋅
Novetta
⋅
Derusbi (Server Variant) Analysis Derusbi |
2014-08-28
⋅
AT&T
⋅
Scanbox: A Reconnaissance Framework Used with Watering Hole Attacks scanbox |
2014-06-27
⋅
SophosLabs
⋅
PlugX - The Next Generation PlugX |
2014-06-10
⋅
FireEye
⋅
Clandestine Fox, Part Deux PlugX |
2014-01-06
⋅
Airbus
⋅
PlugX: some uncovered points PlugX |
2014-01-01
⋅
RSA
⋅
RSA Incident Response: Emerging Threat Profile Shell_Crew Derusbi |
2013-08-07
⋅
FireEye
⋅
Breaking Down the China Chopper Web Shell - Part I CHINACHOPPER |
2013-03-29
⋅
Computer Incident Response Center Luxembourg
⋅
Analysis Report (TLP:WHITE) Analysis of a PlugX variant (PlugX version 7.0) PlugX |
2013-03-26
⋅
Contextis
⋅
PlugX–Payload Extraction PlugX |
2013-02-27
⋅
Trend Micro
⋅
BKDR_RARSTONE: New RAT to Watch Out For PlugX Naikon |
2012-02-10
⋅
tracker.h3x.eu
⋅
Info for Family: plugx PlugX |
2012-01-01
⋅
Cobalt Strike
⋅
Cobalt Strike Website Cobalt Strike |
2012-01-01
⋅
Norman ASA
⋅
The many faces of Gh0st Rat Ghost RAT |
2011-06-29
⋅
Symantec
⋅
Inside a Back Door Attack Ghost RAT Dust Storm |
2009-03-28
⋅
Infinitum Labs
⋅
Tracking GhostNet: Investigating a Cyber Espionage Network Ghost RAT GhostNet |