SYMBOLCOMMON_NAMEaka. SYNONYMS

GOLD CABIN  (Back to overview)

aka: ATK236, G0127, Monster Libra, Shakthak, TA551

GOLD CABIN is a financially motivated cybercriminal threat group operating a malware distribution service on behalf of numerous customers since 2018. GOLD CABIN uses malicious documents, often contained in password-protected archives, delivered through email to download and execute payloads. The second-stage payloads are most frequently Gozi ISFB (Ursnif) or IcedID (Bokbot), sometimes using intermediary malware like Valak. GOLD CABIN infrastructure relies on artificial appearing and frequently changing URLs created with a domain generation algorithm (DGA). The URLs host a PHP object that returns the malware as a DLL file.


Associated Families
win.bumblebee win.emotet win.icedid win.isfb win.qakbot

References
2026-06-29 ⋅ The DFIR Report ⋅ Ahmed Farouk, Angelo Violetti, Dino, Jake, Mattison Schuch, Renzon Cruz
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
Akira AdaptixC2 Akira BumbleBee
2025-12-16 ⋅ R3dy's Blog ⋅ Paul Viard
Gozi Gozi Gozi - String Decryption
Gozi ISFB
2025-12-10 ⋅ Netresec ⋅ Erik Hjelmvik
Latrodectus BackConnect
IcedID Keyhole Latrodectus
2025-08-05 ⋅ The DFIR Report ⋅ The DFIR Report
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
AdaptixC2 Akira BumbleBee
2025-07-29 ⋅ Lumu ⋅ Antonio Gomez
Advisory Alert: BumbleBee Malware in the Spotlight
BumbleBee
2025-07-14 ⋅ Spamhaus ⋅ Spamhaus Malware Labs
Spamhaus Botnet Threat Update January to June 2025
Coper FluBot Hook Joker Mirai AsyncRAT BianLian BumbleBee Chaos Cobalt Strike DanaBot DCRat Havoc Latrodectus NjRAT Quasar RAT RedLine Stealer Remcos Rhadamanthys Sliver ValleyRAT WarmCookie XWorm
2025-06-17 ⋅ DARKReading ⋅ James Shank
Operation Endgame: Do Takedowns and Arrests Matter?
BumbleBee Emotet Pikabot SmokeLoader TrickBot
2025-05-19 ⋅ cyjax ⋅ Joe Wrieden
A Sting on Bing: Bumblebee delivered through Bing SEO poisoning campaign
BumbleBee
2024-11-20 ⋅ Intrinsec ⋅ Equipe CTI
PROSPERO & Proton66: Tracing Uncovering the links between bulletproof networks
Coper SpyNote FAKEUPDATES GootLoader EugenLoader IcedID Matanbuchus Nokoyawa Ransomware Pikabot
2024-10-28 ⋅ Medium shaddy43 ⋅ Shayan Ahmed Khan
Emotet Malware Analysis
Emotet
2024-10-18 ⋅ Netskope ⋅ Leandro Froes
New Bumblebee Loader Infection Chain Signals Possible Resurgence
BumbleBee
2024-07-29 ⋅ Mandiant ⋅ Ashley Pearson, Jake Nicastro, Joseph Pisano, Josh Murchie, Joshua Shilko, Raymond Leong
UNC4393 Goes Gently into the SILENTNIGHT
Black Basta QakBot sRDI SystemBC Zloader UNC3973 UNC4393
2024-07-09 ⋅ Spamhaus ⋅ Spamhaus Malware Labs
Spamhaus Botnet Threat Update January to June 2024
Coper FluBot Hook Bashlite Mirai FAKEUPDATES AsyncRAT BianLian Cobalt Strike DCRat Havoc NjRAT QakBot Quasar RAT RedLine Stealer Remcos Rhadamanthys RisePro Sliver
2024-07-02 ⋅ Sekoia ⋅ Quentin Bourgue
Exposing FakeBat loader: distribution methods and adversary infrastructure
BlackCat Royal Ransom EugenLoader Carbanak Cobalt Strike DICELOADER Gozi IcedID Lumma Stealer NetSupportManager RAT Pikabot RedLine Stealer SectopRAT Sliver SmokeLoader Vidar
2024-05-30 ⋅ Europol ⋅ Europol
Largest ever operation against botnets hits dropper malware ecosystem
BumbleBee IcedID SmokeLoader SystemBC TrickBot
2024-05-26 ⋅ ZW01f ⋅ Mohamed Ezat
QakBOT v5 Deep Malware Analysis
QakBot
2024-05-16 ⋅ Elastic ⋅ Daniel Stepanic, Samir Bousseaden
Spring Cleaning with LATRODECTUS: A Potential Replacement for ICEDID
IcedID Latrodectus
2024-05-15 ⋅ X (@bryceabdo) ⋅ Bryce Abdo
Tweet on UNC5449 exploiting CVE-2024-30051 to deliver QAKBOT
QakBot
2024-05-15 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
Threat actors misusing Quick Assist in social engineering attacks leading to ransomware
Black Basta Cobalt Strike QakBot UNC4393
2024-05-15 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
Threat actors misusing Quick Assist in social engineering attacks leading to ransomware
Black Basta Cobalt Strike QakBot SystemBC
2024-05-14 ⋅ Kaspersky ⋅ Boris Larin, Mert Degirmenci
QakBot attacks with Windows zero-day (CVE-2024-30051)
Cobalt Strike QakBot
2024-04-29 ⋅ The DFIR Report ⋅ The DFIR Report
From IcedID to Dagon Locker Ransomware in 29 Days
IcedID Mount Locker
2024-04-24 ⋅ kienmanowar Blog ⋅ m4n0w4r, Tran Trung Kien
[QuickNote] Qakbot 5.0 – Decrypt strings and configuration
QakBot
2024-04-08 ⋅ 0x0d4y ⋅ 0x0d4y
IcedID – Technical Analysis of an IcedID Lightweight x64 DLL
IcedID
2024-04-04 ⋅ Proofpoint ⋅ Proofpoint Threat Research Team, Team Cymru, TEAM CYMRU S2 THREAT RESEARCH
Latrodectus: This Spider Bytes Like Ice
IcedID Latrodectus
2024-04-01 ⋅ The DFIR Report ⋅ The DFIR Report
From OneNote to RansomNote: An Ice Cold Intrusion
Cobalt Strike IcedID Nokoyawa Ransomware PhotoLoader
2024-03-26 ⋅ Medium zyadlzyatsoc ⋅ Zyad Elzyat
Comprehensive Analysis of EMOTET Malware: Part 1
Emotet
2024-03-17 ⋅ Technical Evolution ⋅ Simon
Carving the IcedId - Part 3
IcedID
2024-02-28 ⋅ Security Intelligence ⋅ Golo Mühr, Ole Villadsen
X-Force data reveals top spam trends, campaigns and senior superlatives in 2023
404 Keylogger Agent Tesla Black Basta DarkGate Formbook IcedID Loki Password Stealer (PWS) Pikabot QakBot Remcos
2024-02-21 ⋅ Invoke RE ⋅ Josh Reynolds
Automating Qakbot Malware Analysis with Binary Ninja
QakBot
2024-02-21 ⋅ YouTube (Invoke RE) ⋅ Josh Reynolds
Analyzing Qakbot Using Binary Ninja Automation Part 3
QakBot
2024-02-16 ⋅ Malcat ⋅ malcat team
Writing a Qakbot 5.0 config extractor with Malcat
QakBot
2024-02-15 ⋅ Bleeping Computer ⋅ Sergiu Gatlan
Zeus, IcedID malware gangs leader pleads guilty, faces 40 years in prison
Egregor IcedID Maze Zeus
2024-02-15 ⋅ Department of Justice ⋅ Office of Public Affairs
Foreign National Pleads Guilty to Role in Cybercrime Schemes Involving Tens of Millions of Dollars in Losses
Egregor IcedID Maze Zeus
2024-02-13 ⋅ Proofpoint ⋅ Axel F, Selena Larson
Bumblebee Buzzes Back in Black
BumbleBee
2024-02-11 ⋅ Estrellas's Blog ⋅ Otávio M.
Unpacking an Emotet trojan
Emotet
2024-02-09 ⋅ Censys ⋅ Censys, Embee_research
A Beginners Guide to Tracking Malware Infrastructure
AsyncRAT BianLian Cobalt Strike QakBot
2024-02-09 ⋅ YouTube (Invoke RE) ⋅ Josh Reynolds
Analyzing and Unpacking Qakbot Using Binary Ninja Automation Part 2
QakBot
2024-01-31 ⋅ Zscaler ⋅ Javier Vicente
Tracking 15 Years of Qakbot Development
QakBot
2024-01-23 ⋅ YouTube (Invoke RE) ⋅ Josh Reynolds
Analyzing and Unpacking Qakbot using Binary Ninja Automation
QakBot
2024-01-16 ⋅ Medium walmartglobaltech ⋅ Jason Reaves, Jonathan Mccay, Joshua Platt
Keyhole Analysis
IcedID Keyhole
2024-01-12 ⋅ Spamhaus ⋅ Spamhaus Malware Labs
Spamhaus Botnet Threat Update Q4 2023
FluBot Hook FAKEUPDATES AsyncRAT BianLian Cobalt Strike DCRat Havoc IcedID Lumma Stealer Meterpreter NjRAT Pikabot QakBot Quasar RAT RecordBreaker RedLine Stealer Remcos Rhadamanthys Sliver
2024-01-12 ⋅ YouTube (BSides Cambridge UK) ⋅ Cian Heasley
Slipping The Net: Qakbot, Emotet And Defense Evasion
Emotet QakBot
2024-01-09 ⋅ Recorded Future ⋅ Insikt Group
2023 Adversary Infrastructure Report
AsyncRAT Cobalt Strike Emotet PlugX ShadowPad
2024-01-09 ⋅ 0x0d4y ⋅ 0x0d4y
IcedID – Technical Malware Analysis [Second Stage]
IcedID PhotoLoader
2024-01-04 ⋅ K7 Security ⋅ Saikumaravel
Qakbot Returns
QakBot
2023-12-10 ⋅ cocomelonc ⋅ cocomelonc
Malware development: persistence - part 23. LNK files. Simple Powershell example.
Emotet
2023-12-05 ⋅ YouTube (SecureWorks) ⋅ Austin Graham
Emulating Qakbot with Austin Graham
QakBot
2023-11-30 ⋅ Twitter (@embee_research) ⋅ Embee_research
Advanced Threat Intel Queries - Catching 83 Qakbot Servers with Regex, Censys and TLS Certificates
QakBot
2023-11-22 ⋅ Twitter (@embee_research) ⋅ Embee_research
Practical Queries for Malware Infrastructure - Part 3 (Advanced Examples)
BianLian Xtreme RAT NjRAT QakBot RedLine Stealer Remcos
2023-11-20 ⋅ Cofense ⋅ Dylan Duncan
Are DarkGate and PikaBot the new QakBot?
DarkGate Pikabot QakBot
2023-10-13 ⋅ Twitter (@JAMESWT_MHT) ⋅ JamesWT
Tweets on Wikiloader delivering ISFB
ISFB WikiLoader
2023-10-12 ⋅ Spamhaus ⋅ Spamhaus Malware Labs
Spamhaus Botnet Threat Update Q3 2023
FluBot AsyncRAT Ave Maria Cobalt Strike DCRat Havoc IcedID ISFB Nanocore RAT NjRAT QakBot Quasar RAT RecordBreaker RedLine Stealer Remcos Rhadamanthys Sliver Stealc Tofsee Vidar
2023-10-12 ⋅ Netresec ⋅ Erik Hjelmvik
Forensic Timeline of an IcedID Infection
Cobalt Strike IcedID IcedID Downloader
2023-10-05 ⋅ Talos ⋅ Guilherme Venere
Qakbot-affiliated actors distribute Ransom Knight malware despite infrastructure takedown
QakBot
2023-10-04 ⋅ Twitter (@Intrisec) ⋅ CTI Intrinsec
Tweet about new Bumblebee campaign leveraging CVE-2023-38831
BumbleBee
2023-09-15 ⋅ Johannes Bader's Blog ⋅ Johannes Bader
The DGA of BumbleBee
BumbleBee
2023-09-11 ⋅ Github (m4now4r) ⋅ m4n0w4r
Unveiling Qakbot Exploring one of the Most Active Threat Actors
QakBot
2023-09-11 ⋅ Twitter (@Artilllerie) ⋅ @Artilllerie
Tweet on BumbleBee sample containing a DGA
BumbleBee
2023-09-07 ⋅ Twitter (@Intrisec) ⋅ CTI Intrinsec
Tweets on Bumblebee campaign spreading via Html smuggling downloading RAR archive with European Central Bank PDF lure and folder containing Bumblebee EXE payload.
BumbleBee
2023-09-01 ⋅ VMRay ⋅ Emre Güler
Understanding BumbleBee: BumbleBee’s malware configuration and clusters
BumbleBee
2023-09-01 ⋅ Trellix ⋅ Adithya Chandra, Joao Marques, Raghav Kapoor
ICYMI: Emotet Reappeared Early This Year, Unfortunately
Emotet
2023-08-29 ⋅ US Department of Justice ⋅ US Department of Justice
Qakbot Malware Disrupted in International Cyber Takedown
QakBot
2023-08-29 ⋅ Secureworks ⋅ Counter Threat Unit ResearchTeam
Law Enforcement Takes Down QakBot
QakBot
2023-08-29 ⋅ FBI ⋅ FBI
FBI, Partners Dismantle Qakbot Infrastructure in Multinational Cyber Takedown
QakBot
2023-08-29 ⋅ KrebsOnSecurity ⋅ Brian Krebs
U.S. Hacks QakBot, Quietly Removes Botnet Infections
QakBot
2023-08-29 ⋅ The Shadowserver Foundation ⋅ Shadowserver Foundation
Qakbot Botnet Disruption
QakBot
2023-08-29 ⋅ US Department of Justice ⋅ Department of Justice
Documents and Resources related to the Disruption of the QakBot Malware and Botnet
QakBot
2023-08-29 ⋅ Spamhaus ⋅ Spamhaus Team
Qakbot - the takedown and the remediation
QakBot
2023-08-28 ⋅ The DFIR Report ⋅ The DFIR Report
HTML Smuggling Leads to Domain Wide Ransomware
Cobalt Strike IcedID Nokoyawa Ransomware
2023-08-23 ⋅ Department of Justice ⋅ United States District Court for the Central District of California
Application and Affidavit for a Seizure Warrant by Telephone or other Reliable Electronic Means
QakBot
2023-08-21 ⋅ Department of Justice ⋅ United States District Court for the Central District of California
Application for a Warrant by Telephone or other reliable Electronic Means
QakBot
2023-08-18 ⋅ VMRay ⋅ Emre Güler
Understanding BumbleBee: The malicious behavior of BumbleBee
BumbleBee
2023-08-09 ⋅ VMRay ⋅ Emre Güler
Understanding BumbleBee: The delivery of Bumblee
BumbleBee
2023-08-07 ⋅ Team Cymru ⋅ S2 Research Team
Visualizing Qakbot Infrastructure Part II: Uncharted Territory
QakBot
2023-08-03 ⋅ Kaspersky ⋅ Kaspersky
What’s happening in the world of crimeware: Emotet, DarkGate and LokiBot
LokiBot DarkGate Emotet
2023-07-31 ⋅ Proofpoint ⋅ Kelsey Merriman, Pim Trouerbach
Out of the Sandbox: WikiLoader Digs Sophisticated Evasion
ISFB WikiLoader
2023-07-31 ⋅ d01a ⋅ Mohamed Adel
Pikabot deep analysis
Pikabot QakBot
2023-07-28 ⋅ Red Canary ⋅ Stef Rand
Drop It Like It's Qbot: Separating malicious droppers, loaders, and crypters from their payloads
CloudEyE QakBot
2023-07-28 ⋅ YouTube (SANS Cyber Defense) ⋅ Stef Rand
Drop It Like It's Qbot: Separating malicious droppers, loaders, and crypters from their payloads
CloudEyE QakBot
2023-07-28 ⋅ Team Cymru ⋅ S2 Research Team
Inside the IcedID BackConnect Protocol (Part 2)
IcedID
2023-07-25 ⋅ Zscaler ⋅ Meghraj Nandanwar, Pradeep Mahato, Satyam Singh
Hibernating Qakbot: A Comprehensive Study and In-depth Campaign Analysis
QakBot
2023-07-23 ⋅ Medium infoSec Write-ups ⋅ mov_eax_27
Unpacking an Emotet Trojan
Emotet
2023-07-18 ⋅ Kostas TS ⋅ Kostas
Ursnif VS Italy: Il PDF del Destino
Gozi ISFB Snifula
2023-07-11 ⋅ Spamhaus ⋅ Spamhaus Malware Labs
Spamhaus Botnet Threat Update Q2 2023
Hydra AsyncRAT Aurora Stealer Ave Maria BumbleBee Cobalt Strike DCRat Havoc IcedID ISFB NjRAT QakBot Quasar RAT RecordBreaker RedLine Stealer Remcos Rhadamanthys Sliver Tofsee
2023-07-06 ⋅ WeLiveSecurity ⋅ Jakub Kaloč
What’s up with Emotet?
Emotet
2023-06-22 ⋅ DeepInstinct ⋅ Deep Instinct Threat Lab, Mark Vaitzman, Shaul Vilkomir-Preisman
PindOS: New JavaScript Dropper Delivering Bumblebee and IcedID
PindOS BumbleBee PhotoLoader
2023-06-10 ⋅ The DFIR Report ⋅ The DFIR Report
IcedID Brings ScreenConnect and CSharp Streamer to ALPHV Ransomware Deployment
BlackCat Cobalt Strike IcedID
2023-06-08 ⋅ Twitter (@embee_research) ⋅ Embee_research
Practical Queries for Identifying Malware Infrastructure: An informal page for storing Censys/Shodan queries
Amadey AsyncRAT Cobalt Strike QakBot Quasar RAT Sliver solarmarker
2023-06-08 ⋅ VMRay ⋅ Patrick Staubmann
Busy Bees - The Transformation of BumbleBee
BumbleBee Cobalt Strike Conti Meterpreter Sliver
2023-06-01 ⋅ Lumen ⋅ Black Lotus Labs
Qakbot: Retool, Reinfect, Recycle
QakBot
2023-05-30 ⋅ Palo Alto Networks Unit 42 ⋅ Brad Duncan
Cold as Ice: Answers to Unit 42 Wireshark Quiz for IcedID
IcedID PhotoLoader
2023-05-22 ⋅ The DFIR Report ⋅ The DFIR Report
IcedID Macro Ends in Nokoyawa Ransomware
IcedID Nokoyawa Ransomware PhotoLoader
2023-05-21 ⋅ Github (0xThiebaut) ⋅ Maxime Thiebaut
PCAPeek
IcedID QakBot
2023-05-18 ⋅ Intezer ⋅ Ryan Robinson
How Hackers Use Binary Padding to Outsmart Sandboxes and Infiltrate Your Systems
Emotet
2023-05-17 ⋅ Team Cymru ⋅ Team Cymru
Visualizing QakBot Infrastructure
QakBot
2023-05-10 ⋅ Bridewell ⋅ Bridewell
Hunting for Ursnif
ISFB Royal Ransom
2023-05-04 ⋅ Elastic ⋅ Cyril François
Unpacking ICEDID
IcedID PhotoLoader
2023-05-03 ⋅ unpac.me ⋅ Sean Wilson
UnpacMe Weekly: New Version of IcedId Loader
IcedID PhotoLoader
2023-05-03 ⋅ Palo Alto Networks Unit 42 ⋅ Bob Jung, Daniel Raygoza, Mark Lim
Teasing the Secrets From Threat Actors: Malware Configuration Parsing at Scale
IcedID PhotoLoader
2023-05-02 ⋅ loginsoft ⋅ System-41
IcedID Malware: Traversing Through its Various Incarnations
IcedID
2023-04-28 ⋅ DISCARDED Podcast ⋅ Joe Wise, Pim Trouerbach
Beyond Banking: IcedID Gets Forked
IcedID PhotoLoader
2023-04-21 ⋅ Sophos ⋅ Colin Cowie, Paul Jaramillo
IcedID: Defrosting a Recent Campaign Illustrating evolving tactics and shared infrastructure
IcedID PhotoLoader
2023-04-20 ⋅ Secureworks ⋅ Counter Threat Unit ResearchTeam
Bumblebee Malware Distributed Via Trojanized Installer Downloads
BumbleBee Cobalt Strike
2023-04-18 ⋅ Rapid7 Labs ⋅ Matt Green
Automating Qakbot Detection at Scale With Velociraptor
QakBot
2023-04-18 ⋅ Twitter (@threatinsight) ⋅ Threat Insight
Tweet on TA581 using Keitaro TDS URL to download a .MSI file to deliver BumbleBee malware
BumbleBee
2023-04-18 ⋅ Mandiant ⋅ Mandiant
M-Trends 2023
QUIETEXIT AppleJeus Black Basta BlackCat CaddyWiper Cobalt Strike Dharma HermeticWiper Hive INDUSTROYER2 Ladon LockBit Meterpreter PartyTicket PlugX QakBot REvil Royal Ransom SystemBC WhisperGate
2023-04-16 ⋅ Botconf ⋅ Suweera De Souza
Tracking Bumblebee’s Development
BumbleBee
2023-04-16 ⋅ YouTube (botconf eu) ⋅ Crowdstrike Technical Analysis Cell (TAC), Suweera De Souza
Tracking Bumblebee’s Development
BumbleBee
2023-04-13 ⋅ Sublime ⋅ Sam Scholten
Detecting QakBot: WSF attachments, OneNote files, and generic attack surface reduction
QakBot
2023-04-12 ⋅ SANS ISC ⋅ Brad Duncan
Recent IcedID (Bokbot) activity
IcedID
2023-04-12 ⋅ loginsoft ⋅ Bhargav koduru
Maximizing Threat Detections of Qakbot with Osquery
QakBot
2023-04-12 ⋅ InfoSec Handlers Diary Blog ⋅ Brad Duncan
Recent IcedID (Bokbot) activity
IcedID PhotoLoader
2023-04-12 ⋅ Spamhaus ⋅ Spamhaus Malware Labs
Spamhaus Botnet Threat Update Q1 2023
FluBot Amadey AsyncRAT Aurora Ave Maria BumbleBee Cobalt Strike DCRat Emotet IcedID ISFB NjRAT QakBot RecordBreaker RedLine Stealer Remcos Rhadamanthys Sliver Tofsee Vidar
2023-04-11 ⋅ Twitter (@Unit42_Intel) ⋅ Unit42
Tweet on change of IcedID backconnect traffic port from 8080 to 443
IcedID
2023-04-11 ⋅ SEC Consult ⋅ Angelo Violetti
BumbleBee hunting with a Velociraptor
BumbleBee
2023-04-10 ⋅ Check Point ⋅ Check Point
March 2023’s Most Wanted Malware: New Emotet Campaign Bypasses Microsoft Blocks to Distribute Malicious OneNote Files
Agent Tesla CloudEyE Emotet Formbook Nanocore RAT NjRAT QakBot Remcos Tofsee
2023-04-05 ⋅ velociraptor ⋅ Matt Green
Automating Qakbot Decode At Scale
QakBot
2023-04-03 ⋅ The DFIR Report ⋅ The DFIR Report
Malicious ISO File Leads to Domain Wide Ransomware
Cobalt Strike IcedID Mount Locker
2023-03-30 ⋅ United States District Court (Eastern District of New York) ⋅ Fortra, HEALTH-ISAC, Microsoft
Cracked Cobalt Strike (1:23-cv-02447)
Black Basta BlackCat LockBit RagnarLocker LockBit Black Basta BlackCat Cobalt Strike Cuba Emotet LockBit Mount Locker PLAY QakBot RagnarLocker Royal Ransom Zloader
2023-03-30 ⋅ loginsoft ⋅ Saharsh Agrawal
From Innocence to Malice: The OneNote Malware Campaign Uncovered
Agent Tesla AsyncRAT DOUBLEBACK Emotet Formbook IcedID NetWire RC QakBot Quasar RAT RedLine Stealer XWorm
2023-03-30 ⋅ eSentire ⋅ eSentire Threat Response Unit (TRU)
eSentire Threat Intelligence Malware Analysis: BatLoader
BATLOADER Cobalt Strike ISFB SystemBC Vidar
2023-03-29 ⋅ Krakz ⋅ Pierre Le Bourhis
BumbleBee notes
BumbleBee
2023-03-28 ⋅ Cerbero ⋅ Erik Pistelli
Reversing Complex PowerShell Malware
BumbleBee
2023-03-27 ⋅ Proofpoint ⋅ Joe Wise, Kelsey Merriman, Pim Trouerbach
Fork in the Ice: The New Era of IcedID
IcedID PHOTOFORK PHOTOLITE PhotoLoader
2023-03-24 ⋅ Lab52 ⋅ peko
Bypassing Qakbot Anti-Analysis
QakBot
2023-03-22 ⋅ Cisco Talos ⋅ Edmund Brumaghin, Jaeson Schultz
Emotet Resumes Spam Operations, Switches to OneNote
Emotet
2023-03-20 ⋅ NVISO Labs ⋅ Maxime Thiebaut
IcedID’s VNC Backdoors: Dark Cat, Anubis & Keyhole
IcedID
2023-03-19 ⋅ 0xToxin Labs ⋅ @0xToxin
Gozi - Italian ShellCode Dance
Gozi ISFB
2023-03-17 ⋅ Elastic ⋅ Cyril François, Daniel Stepanic
Thawing the permafrost of ICEDID Summary
IcedID PhotoLoader
2023-03-15 ⋅ Reliaquest ⋅ RELIAQUEST THREAT RESEARCH TEAM
QBot: Laying the Foundations for Black Basta Ransomware Activity
Black Basta QakBot
2023-03-13 ⋅ Trendmicro ⋅ Ian Kenefick
Emotet Returns, Now Adopts Binary Padding for Evasion
Emotet
2023-03-09 ⋅ eSentire ⋅ eSentire Threat Response Unit (TRU)
BatLoader Continues to Abuse Google Search Ads to Deliver Vidar Stealer and Ursnif
BATLOADER ISFB Vidar
2023-03-07 ⋅ BleepingComputer ⋅ Lawrence Abrams
Emotet malware attacks return after three-month break
Emotet
2023-03-07 ⋅ Trellix ⋅ Alejandro Houspanossian, John Fokker, Mathanraj Thangaraju, Pham Duy Phuc, Raghav Kapoor
Qakbot Evolves to OneNote Malware Distribution
QakBot
2023-03-07 ⋅ Cofense ⋅ Cofense
Emotet Sending Malicious Emails After Three-Month Hiatus
Emotet
2023-03-04 ⋅ 0xToxin Labs ⋅ @0xToxin
Bumblebee DocuSign Campaign
BumbleBee
2023-03-02 ⋅ Netresec ⋅ Erik Hjelmvik
QakBot C2 Traffic
QakBot
2023-03-02 ⋅ Youtube (Microsoft Security Response Center (MSRC)) ⋅ Ben Magee, Daniel Taylor
BlueHat 2023: Hunting Qakbot with Daniel Taylor & Ben Magee
QakBot
2023-03-01 ⋅ Zscaler ⋅ Meghraj Nandanwar, Shatak Jain
OneNote: A Growing Threat for Malware Distribution
AsyncRAT Cobalt Strike IcedID QakBot RedLine Stealer
2023-02-28 ⋅ Intel 471 ⋅ Intel 471
Malvertising Surges to Distribute Malware
EugenLoader BATLOADER IcedID
2023-02-27 ⋅ PRODAFT Threat Intelligence ⋅ PRODAFT
RIG Exploit Kit: In-Depth Analysis
Dridex IcedID ISFB PureCrypter Raccoon RecordBreaker RedLine Stealer Royal Ransom Silence SmokeLoader Zloader
2023-02-26 ⋅ Medium Ilandu ⋅ Ilan Duhin, Yossi Poberezsky
Emotet Campaign
Emotet
2023-02-24 ⋅ Medium walmartglobaltech ⋅ Jason Reaves, Jonathan Mccay, Joshua Platt, Kirk Sayre
Qbot testing malvertising campaigns?
QakBot
2023-02-24 ⋅ Team Cymru ⋅ Team Cymru
Desde Chile con Malware (From Chile with Malware)
IcedID PhotoLoader
2023-02-17 ⋅ cyble ⋅ Cyble
The Many Faces of Qakbot Malware: A Look at Its Diverse Distribution Methods
QakBot
2023-02-15 ⋅ Netresec ⋅ Erik Hjelmvik
How to Identify IcedID Network Traffic
IcedID
2023-02-14 ⋅ ⋅ DSIH ⋅ Charles Blanc-Rolin
Comment Qbot revient en force avec OneNote ?
QakBot
2023-02-08 ⋅ NTT Security ⋅ Ryu Hiyoshi
SteelClover Attacks Distributing Malware Via Google Ads Increased
BATLOADER ISFB RedLine Stealer
2023-02-06 ⋅ Sophos ⋅ Andrew Brandt
Qakbot mechanizes distribution of malicious OneNote notebooks
QakBot
2023-02-03 ⋅ Mandiant ⋅ Genevieve Stark, Kimberly Goody
Float Like a Butterfly Sting Like a Bee
BazarBackdoor BumbleBee Cobalt Strike
2023-01-30 ⋅ Checkpoint ⋅ Arie Olshtein
Following the Scent of TrickGate: 6-Year-Old Packer Used to Deploy the Most Wanted Malware
Agent Tesla Azorult Buer Cerber Cobalt Strike Emotet Formbook HawkEye Keylogger Loki Password Stealer (PWS) Maze NetWire RC Remcos REvil TrickBot
2023-01-26 ⋅ Acronis ⋅ Ilan Duhin
Unpacking Emotet Malware
Emotet
2023-01-23 ⋅ Kroll ⋅ Elio Biasiotto, Stephen Green
Black Basta – Technical Analysis
Black Basta Cobalt Strike MimiKatz QakBot SystemBC
2023-01-20 ⋅ Blackberry ⋅ BlackBerry Research & Intelligence Team
Emotet Returns With New Methods of Evasion
Emotet IcedID
2023-01-19 ⋅ Cisco ⋅ Guilherme Venere
Following the LNK metadata trail
BumbleBee PhotoLoader QakBot
2023-01-12 ⋅ EclecticIQ ⋅ EclecticIQ Threat Research Team
QakBot Malware Used Unpatched Vulnerability to Bypass Windows OS Security Feature
QakBot
2023-01-09 ⋅ Intrinsec ⋅ CTI Intrinsec, Intrinsec
Emotet returns and deploys loaders
BumbleBee Emotet IcedID PHOTOLITE
2023-01-09 ⋅ The DFIR Report ⋅ The DFIR Report
Unwrapping Ursnifs Gifts
ISFB
2022-12-28 ⋅ Micah Babinski
HTML Smuggling Detection
QakBot
2022-12-23 ⋅ Trendmicro ⋅ Ian Kenefick
IcedID Botnet Distributors Abuse Google PPC to Distribute Malware
IcedID
2022-12-22 ⋅ AhnLab ⋅ ASEC
Qakbot Being Distributed via Virtual Disk Files (*.vhd)
QakBot
2022-12-21 ⋅ Team Cymru ⋅ S2 Research Team
Inside the IcedID BackConnect Protocol
IcedID
2022-12-19 ⋅ kienmanowar Blog ⋅ m4n0w4r, Tran Trung Kien
[Z2A]Bimonthly malware challege – Emotet (Back From the Dead)
Emotet
2022-12-18 ⋅ ZAYOTEM ⋅ Berkay DOĞAN, Dilara BEHAR, Rabia EKŞİ, Zafer Yiğithan DERECİ
IcedID Technical Analysis Report
IcedID
2022-12-15 ⋅ ISC ⋅ Brad Duncan
Google ads lead to fake software pages pushing IcedID (Bokbot)
IcedID
2022-12-06 ⋅ EuRepoC ⋅ Camille Borrett, Kerstin Zettl-Schabath, Lena Rottinger
Conti/Wizard Spider
BazarBackdoor Cobalt Strike Conti Emotet IcedID Ryuk TrickBot WIZARD SPIDER
2022-12-05 ⋅ Cybereason ⋅ Kotaro Ogino, Ralph Villanueva, Robin Plumer
Threat Analysis: MSI - Masquerading as a Software Installer
Magniber Matanbuchus QakBot
2022-12-02 ⋅ Github (binref) ⋅ Jesko Hüttenhain
The Refinery Files 0x06: Qakbot Decoder
QakBot
2022-12-01 ⋅ splunk ⋅ Splunk Threat Research Team
From Macros to No Macros: Continuous Malware Improvements by QakBot
QakBot
2022-11-30 ⋅ Tidal Cyber Inc. ⋅ Scott Small
Identifying and Defending Against QakBot's Evolving TTPs
QakBot
2022-11-28 ⋅ The DFIR Report ⋅ The DFIR Report
Emotet Strikes Again – LNK File Leads to Domain Wide Ransomware
Emotet Mount Locker
2022-11-23 ⋅ Cybereason ⋅ Cybereason Global SOC Team
THREAT ALERT: Aggressive Qakbot Campaign and the Black Basta Ransomware Group Targeting U.S. Companies
Black Basta QakBot
2022-11-21 ⋅ BSides Sydney ⋅ Thomas Roccia
X-Ray of Malware Evasion Techniques - Analysis, Dissection, Cure?
Emotet
2022-11-16 ⋅ Proofpoint ⋅ Axel F, Pim Trouerbach
A Comprehensive Look at Emotet Virus’ Fall 2022 Return
BumbleBee Emotet PHOTOLITE
2022-11-14 ⋅ Twitter (@embee_research) ⋅ Matthew
Twitter thread on Yara Signatures for Qakbot Encryption Routines
IcedID QakBot
2022-11-10 ⋅ Intezer ⋅ Nicole Fishbein
How LNK Files Are Abused by Threat Actors
BumbleBee Emotet Mount Locker QakBot
2022-11-03 ⋅ SentinelOne ⋅ SentinelLabs
Black Basta Ransomware | Attacks deploy Custom EDR Evasion Tools tied to FIN7 Threat Actor
Black Basta QakBot SocksBot
2022-10-31 ⋅ Cynet ⋅ Max Malyutin
Orion Threat Alert: Qakbot TTPs Arsenal and the Black Basta Ransomware
Black Basta Cobalt Strike QakBot
2022-10-31 ⋅ Elastic ⋅ Andrew Pease, Daniel Stepanic, Derek Ditch, Seth Goodwin
ICEDIDs network infrastructure is alive and well
IcedID
2022-10-31 ⋅ Security homework ⋅ Christophe Rieunier
QakBot CCs prioritization and new record types
QakBot
2022-10-28 ⋅ Elastic ⋅ @rsprooten, Elastic Security Intelligence & Analytics Team
EMOTET dynamic config extraction
Emotet
2022-10-27 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
Raspberry Robin worm part of larger ecosystem facilitating pre-ransomware activity
FAKEUPDATES BumbleBee Clop Fauppod Raspberry Robin Roshtyak Silence DEV-0950 Mustard Tempest
2022-10-27 ⋅ Microsoft ⋅ Microsoft Security Threat Intelligence
Raspberry Robin worm part of larger ecosystem facilitating pre-ransomware activity
FAKEUPDATES BumbleBee Fauppod PhotoLoader Raspberry Robin Roshtyak
2022-10-24 ⋅ Medium CSIS Techblog ⋅ Benoît Ancel
Chapter 1 — From Gozi to ISFB: The history of a mythical malware family.
Gozi ISFB Snifula
2022-10-13 ⋅ Spamhaus ⋅ Spamhaus Malware Labs
Spamhaus Botnet Threat Update Q3 2022
FluBot Arkei Stealer AsyncRAT Ave Maria BumbleBee Cobalt Strike DCRat Dridex Emotet Loki Password Stealer (PWS) Nanocore RAT NetWire RC NjRAT QakBot RecordBreaker RedLine Stealer Remcos Socelars Tofsee Vjw0rm
2022-10-13 ⋅ Syrion ⋅ Raffaele Sabato
QAKBOT BB Configuration and C2 IPs List
QakBot
2022-10-12 ⋅ Trend Micro ⋅ Ian Kenefick, Lucas Silva, Nicole Hernandez
Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike
Black Basta Brute Ratel C4 Cobalt Strike QakBot
2022-10-12 ⋅ Netresec ⋅ Erik Hjelmvik
IcedID BackConnect Protocol
IcedID
2022-10-07 ⋅ Team Cymru ⋅ S2 Research Team
A Visualizza into Recent IcedID Campaigns: Reconstructing Threat Actor Metrics with Pure Signal™ Recon
IcedID PhotoLoader
2022-10-06 ⋅ Twitter (@ESETresearch) ⋅ ESET Research
Tweet on Bumblebee being modularized like trickbot
BumbleBee
2022-10-03 ⋅ Check Point ⋅ Marc Salinas Fernandez
Bumblebee: increasing its capacity and evolving its TTPs
BumbleBee Cobalt Strike Meterpreter Sliver Vidar
2022-10-03 ⋅ vmware ⋅ Threat Analysis Unit
Emotet Exposed: A Look Inside the Cybercriminal Supply Chain
Emotet
2022-09-26 ⋅ The DFIR Report ⋅ The DFIR Report
BumbleBee: Round Two
BumbleBee Cobalt Strike Meterpreter
2022-09-13 ⋅ AdvIntel ⋅ Advanced Intelligence
AdvIntel's State of Emotet aka "SpmTools" Displays Over Million Compromised Machines Through 2022
Conti Cobalt Strike Emotet Ryuk TrickBot
2022-09-12 ⋅ The DFIR Report ⋅ The DFIR Report
Dead or Alive? An Emotet Story
Cobalt Strike Emotet
2022-09-07 ⋅ Google ⋅ Google Threat Analysis Group, Pierre-Marc Bureau
Initial access broker repurposing techniques in targeted attacks against Ukraine
AnchorMail Cobalt Strike IcedID
2022-09-07 ⋅ cyble ⋅ Cyble
Bumblebee Returns With New Infection Technique
BumbleBee Cobalt Strike
2022-09-06 ⋅ Zscaler ⋅ Brett Stone-Gross
The Ares Banking Trojan Learns Old Tricks: Adds the Defunct Qakbot DGA
Ares QakBot
2022-09-05 ⋅ Infinitum IT ⋅ Arda Büyükkaya
Bumblebee Loader Malware Analysis
BumbleBee
2022-09-01 ⋅ Medium michaelkoczwara ⋅ Michael Koczwara
Hunting C2/Adversaries Infrastructure with Shodan and Censys
Brute Ratel C4 Cobalt Strike Deimos GRUNT IcedID Merlin Meterpreter Nighthawk PoshC2 Sliver
2022-09-01 ⋅ Trend Micro ⋅ Trend Micro
Ransomware Spotlight Black Basta
Black Basta Cobalt Strike MimiKatz QakBot
2022-08-25 ⋅ Palo Alto Networks Unit 42 ⋅ Amer Elsad
Threat Assessment: Black Basta Ransomware
Black Basta QakBot
2022-08-24 ⋅ Elastic ⋅ Cyril François
QBOT Malware Analysis
QakBot
2022-08-24 ⋅ Microsoft ⋅ Microsoft Security Experts
Looking for the ‘Sliver’ lining: Hunting for emerging command-and-control frameworks
BumbleBee Sliver
2022-08-24 ⋅ Trellix ⋅ Adithya Chandra, Sushant Kumar Arya
Demystifying Qbot Malware
QakBot
2022-08-24 ⋅ Deep instinct ⋅ Deep Instinct Threat Lab
The Dark Side of Bumblebee Malware Loader
BumbleBee
2022-08-23 ⋅ Darktrace ⋅ Eugene Chua, Hanah Darley, Paul Jennings
Emotet Resurgence: Cross-Industry Campaign Analysis
Emotet
2022-08-19 ⋅ vmware ⋅ Oleg Boyarchuk, Stefano Ortolani
How to Replicate Emotet Lateral Movement
Emotet
2022-08-18 ⋅ IBM ⋅ Charlotte Hammond, Ole Villadsen
From Ramnit To Bumblebee (via NeverQuest): Similarities and Code Overlap Shed Light On Relationships Between Malware Developers
BumbleBee Karius Ramnit TrickBot Vawtrak
2022-08-17 ⋅ Cybereason ⋅ Cybereason Global SOC Team
Bumblebee Loader – The High Road to Enterprise Domain Control
BumbleBee Cobalt Strike
2022-08-12 ⋅ SANS ISC ⋅ Brad Duncan
Monster Libra (TA551/Shathak) pushes IcedID (Bokbot) with Dark VNC and Cobalt Strike
Cobalt Strike DarkVNC IcedID
2022-08-10 ⋅ BitSight ⋅ João Batista
Emotet SMB Spreader is Back
Emotet
2022-08-10 ⋅ ⋅ Weixin ⋅ Red Raindrop Team
Operation(верность) mercenary: a torrent of steel trapped in the plains of Eastern Europe
BumbleBee Cobalt Strike
2022-08-08 ⋅ Medium CSIS Techblog ⋅ Benoît Ancel
An inside view of domain anonymization as-a-service — the BraZZZerSFF infrastructure
Riltok magecart Anubis Azorult BetaBot Buer CoalaBot CryptBot DiamondFox DreamBot GCleaner ISFB Loki Password Stealer (PWS) MedusaLocker MeguminTrojan Nemty PsiX RedLine Stealer SmokeLoader STOP TinyNuke Vidar Zloader
2022-08-08 ⋅ The DFIR Report ⋅ The DFIR Report
BumbleBee Roasts Its Way to Domain Admin
BumbleBee Cobalt Strike
2022-08-04 ⋅ Medium walmartglobaltech ⋅ Jason Reaves, Joshua Platt
IcedID leverages PrivateLoader
IcedID PrivateLoader
2022-08-04 ⋅ Cloudsek ⋅ Aastha Mittal, Anandeshwar Unnikrishnan
Technical Analysis of Bumblebee Malware Loader
BumbleBee
2022-08-03 ⋅ Palo Alto Networks Unit 42 ⋅ Brad Duncan
Flight of the Bumblebee: Email Lures and File Sharing Services Lead to Malware
BazarBackdoor BumbleBee Cobalt Strike Conti
2022-07-27 ⋅ Elastic ⋅ Andrew Pease, Cyril François, Seth Goodwin
Exploring the QBOT Attack Pattern
QakBot
2022-07-27 ⋅ Elastic ⋅ Cyril François, Derek Ditch
QBOT Configuration Extractor
QakBot
2022-07-27 ⋅ SANS ISC ⋅ Brad Duncan
IcedID (Bokbot) with Dark VNC and Cobalt Strike
DarkVNC IcedID
2022-07-27 ⋅ cyble ⋅ Cyble Research Labs
Targeted Attacks Being Carried Out Via DLL SideLoading
Cobalt Strike QakBot
2022-07-24 ⋅ Bleeping Computer ⋅ Bill Toulas
QBot phishing uses Windows Calculator sideloading to infect devices
QakBot
2022-07-19 ⋅ Fortinet ⋅ Xiaopeng Zhang
New Variant of QakBot Being Spread by HTML File Attached to Phishing Emails
QakBot
2022-07-18 ⋅ Palo Alto Networks Unit 42 ⋅ Unit 42
Monster Libra
Valak IcedID GOLD CABIN
2022-07-17 ⋅ Resecurity ⋅ Resecurity
Shortcut-Based (LNK) Attacks Delivering Malicious Code On The Rise
AsyncRAT BumbleBee Emotet IcedID QakBot
2022-07-12 ⋅ Zscaler ⋅ Aditya Sharma, Tarun Dewan
Rise in Qakbot attacks traced to evolving threat techniques
QakBot
2022-07-12 ⋅ Cyren ⋅ Kervin Alintanahin
Example Analysis of Multi-Component Malware
Emotet Formbook
2022-07-07 ⋅ SANS ISC ⋅ Brad Duncan
Emotet infection with Cobalt Strike
Cobalt Strike Emotet
2022-07-07 ⋅ Fortinet ⋅ Erin Lin
Notable Droppers Emerge in Recent Threat Campaigns
BumbleBee Emotet PhotoLoader QakBot
2022-07-07 ⋅ IBM ⋅ Charlotte Hammond, Kat Weinberger, Ole Villadsen
Unprecedented Shift: The Trickbot Group is Systematically Attacking Ukraine
AnchorMail BumbleBee Cobalt Strike IcedID Meterpreter
2022-07-05 ⋅ Soc Investigation ⋅ Priyadharshini Balaji
QBot Spreads via LNK Files – Detection & Response
QakBot
2022-06-30 ⋅ Trend Micro ⋅ Emmanuel Panopio, James Panlilio, John Kenneth Reyes, Kenneth Adrian Apostol, Melvin Singwa, Mirah Manlapig, Paolo Ronniel Labrador
Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
Black Basta Cobalt Strike QakBot
2022-06-28 ⋅ Symantec ⋅ Threat Hunter Team, Vishal Kamble
Bumblebee: New Loader Rapidly Assuming Central Position in Cyber-crime Ecosystem
BumbleBee
2022-06-27 ⋅ Netskope ⋅ Gustavo Palazolo
Emotet: Still Abusing Microsoft Office Macros
Emotet
2022-06-24 ⋅ Group-IB ⋅ Albert Priego
We see you, Gozi Hunting the latest TTPs used for delivering the Trojan
ISFB
2022-06-24 ⋅ Soc Investigation ⋅ BalaGanesh
IcedID Banking Trojan returns with new TTPS – Detection & Response
IcedID
2022-06-21 ⋅ McAfee ⋅ Lakshya Mathur
Rise of LNK (Shortcut files) Malware
BazarBackdoor Emotet IcedID QakBot
2022-06-17 ⋅ Github (NtQuerySystemInformation) ⋅ Twitter (@kasua02)
A reverse engineer primer on Qakbot Dll Stager: From initial execution to multithreading.
QakBot
2022-06-16 ⋅ ESET Research ⋅ Rene Holt
How Emotet is changing tactics in response to Microsoft’s tightening of Office macro security
Emotet
2022-06-14 ⋅ RiskIQ ⋅ Jordan Herman
RiskIQ: Identifying BumbleBee Command and Control Servers
BumbleBee
2022-06-13 ⋅ Sekoia ⋅ Pierre Le Bourhis, Quentin Bourgue, Threat & Detection Research Team
BumbleBee: a new trendy loader for Initial Access Brokers
BumbleBee
2022-06-09 ⋅ InfoSec Handlers Diary Blog ⋅ Brad Duncan
TA570 Qakbot (Qbot) tries CVE-2022-30190 (Follina) exploit (ms-msdt)
QakBot
2022-06-07 ⋅ McAfee ⋅ Jyothi Naveen, Kiran Raj
Phishing Campaigns featuring Ursnif Trojan on the Rise
ISFB
2022-06-07 ⋅ cyble ⋅ Cyble
Bumblebee Loader on The Rise
BumbleBee Cobalt Strike
2022-06-02 ⋅ Mandiant ⋅ Mandiant
TRENDING EVIL Q2 2022
CloudEyE Cobalt Strike CryptBot Emotet IsaacWiper QakBot
2022-05-30 ⋅ Matthieu Walter
Automatically Unpacking IcedID Stage 1 with Angr
IcedID
2022-05-27 ⋅ Kroll ⋅ Cole Manaster, Elio Biasiotto, George Glass
Emotet Analysis: New LNKs in the Infection Chain – The Monitor, Issue 20
Emotet
2022-05-25 ⋅ Logpoint ⋅ Logpoint
Buzz of the Bumblebee – A new malicious loader
BumbleBee
2022-05-25 ⋅ Team Cymru ⋅ S2 Research Team
Bablosoft; Lowering the Barrier of Entry for Malicious Actors
BlackGuard BumbleBee RedLine Stealer
2022-05-25 ⋅ vmware ⋅ Oleg Boyarchuk, Stefano Ortolani
Emotet Config Redux
Emotet
2022-05-24 ⋅ Deep instinct ⋅ Bar Block
Blame the Messenger: 4 Types of Dropper Malware in Microsoft Office & How to Detect Them
Dridex Emotet
2022-05-24 ⋅ BitSight ⋅ BitSight, João Batista, Pedro Umbelino
Emotet Botnet Rises Again
Cobalt Strike Emotet QakBot SystemBC
2022-05-19 ⋅ InfoSec Handlers Diary Blog ⋅ Brad Duncan
Bumblebee Malware from TransferXL URLs
BumbleBee Cobalt Strike
2022-05-19 ⋅ InfoSec Handlers Diary Blog ⋅ Brad Duncan
Bumblebee Malware from TransferXL URLs
BumbleBee Cobalt Strike
2022-05-19 ⋅ IBM ⋅ Charlotte Hammond, Golo Mühr, Ole Villadsen
ITG23 Crypters Highlight Cooperation Between Cybercriminal Groups
IcedID ISFB Mount Locker WIZARD SPIDER
2022-05-19 ⋅ Trend Micro ⋅ Adolph Christian Silverio, Jeric Miguel Abordo, Khristian Joseph Morales, Maria Emreen Viray
Bruised but Not Broken: The Resurgence of the Emotet Botnet Malware
Emotet QakBot
2022-05-17 ⋅ Palo Alto Networks Unit 42 ⋅ Brad Duncan
Emotet Summary: November 2021 Through January 2022
Emotet
2022-05-17 ⋅ Trend Micro ⋅ Trend Micro Research
Ransomware Spotlight: RansomEXX
LaZagne Cobalt Strike IcedID MimiKatz PyXie RansomEXX TrickBot
2022-05-16 ⋅ vmware ⋅ Jason Zhang, Oleg Boyarchuk, Stefano Ortolani, Threat Analysis Unit
Emotet Moves to 64 bit and Updates its Loader
Emotet
2022-05-12 ⋅ Intel 471 ⋅ Intel 471
What malware to look for if you want to prevent a ransomware attack
Conti BumbleBee Cobalt Strike IcedID Sliver
2022-05-12 ⋅ OALabs ⋅ Sergei Frankoff
Taking a look at Bumblebee loader
BumbleBee
2022-05-11 ⋅ InfoSec Handlers Diary Blog ⋅ Brad Duncan
TA578 using thread-hijacked emails to push ISO files for Bumblebee malware
BumbleBee Cobalt Strike IcedID PhotoLoader
2022-05-11 ⋅ SANS ISC ⋅ Brad Duncan
TA578 using thread-hijacked emails to push ISO files for Bumblebee malware
BumbleBee
2022-05-11 ⋅ HP ⋅ HP Wolf Security
Threat Insights Report Q1 - 2022
AsyncRAT Emotet Mekotio Vjw0rm
2022-05-11 ⋅ IronNet ⋅ Blake Cahen, IronNet Threat Research
Detecting a MUMMY SPIDER campaign and Emotet infection
Emotet
2022-05-09 ⋅ Microsoft ⋅ Microsoft 365 Defender Threat Intelligence Team, Microsoft Threat Intelligence Center (MSTIC)
Ransomware-as-a-service: Understanding the cybercrime gig economy and how to protect yourself
AnchorDNS BlackCat BlackMatter Conti DarkSide HelloKitty Hive LockBit REvil FAKEUPDATES Griffon ATOMSILO BazarBackdoor BlackCat BlackMatter Blister Cobalt Strike Conti DarkSide Emotet FiveHands Gozi HelloKitty Hive IcedID ISFB JSSLoader LockBit LockFile Maze NightSky Pandora Phobos Phoenix Locker PhotoLoader QakBot REvil Rook Ryuk SystemBC TrickBot WastedLocker BRONZE STARLIGHT
2022-05-09 ⋅ Cybereason ⋅ Lior Rochberger
Cybereason vs. Quantum Locker Ransomware
IcedID Mount Locker
2022-05-09 ⋅ Netresec ⋅ Erik Hjelmvik
Emotet C2 and Spam Traffic Video
Emotet
2022-05-08 ⋅ Qualys ⋅ Amit Gadhave
Ursnif Malware Banks on News Events for Phishing Attacks
ISFB
2022-05-08 ⋅ Threat hunting with hints of incident response ⋅ Jouni Mikkola
Bzz.. Bzz.. Bumblebee loader
BumbleBee
2022-05-06 ⋅ Netskope ⋅ Gustavo Palazolo
Emotet: New Delivery Mechanism to Bypass VBA Protection
Emotet
2022-05-04 ⋅ Twitter (@felixw3000) ⋅ Felix
Twitter Thread with info on infection chain with IcedId, Cobalt Strike, and Hidden VNC.
Cobalt Strike IcedID PhotoLoader
2022-05-04 ⋅ Sophos ⋅ Andreas Klopsch
Attacking Emotet’s Control Flow Flattening
Emotet
2022-04-29 ⋅ NCC Group ⋅ Mike Stokkel, Nikolaos Pantazopoulos, Nikolaos Totosis
Adventures in the land of BumbleBee – a new malicious loader
BazarBackdoor BumbleBee Conti
2022-04-28 ⋅ Proofpoint ⋅ Kelsey Merriman, Pim Trouerbach
This isn't Optimus Prime's Bumblebee but it's Still Transforming
BumbleBee TA578 TA579
2022-04-28 ⋅ Symantec ⋅ Karthikeyan C Kasiviswanathan, Vishal Kamble
Ransomware: How Attackers are Breaching Corporate Networks
AvosLocker Conti Emotet Hive IcedID PhotoLoader QakBot TrickBot
2022-04-28 ⋅ Bleeping Computer ⋅ Ionut Ilascu
New Bumblebee malware replaces Conti's BazarLoader in cyberattacks
BumbleBee
2022-04-27 ⋅ Cybleinc ⋅ Cyble
Emotet Returns With New TTPs And Delivers .Lnk Files To Its Victims
Emotet
2022-04-27 ⋅ Medium elis531989 ⋅ Eli Salem
The chronicles of Bumblebee: The Hook, the Bee, and the Trickbot connection
BumbleBee TrickBot
2022-04-26 ⋅ Intel 471 ⋅ Intel 471
Conti and Emotet: A constantly destructive duo
Cobalt Strike Conti Emotet IcedID QakBot TrickBot
2022-04-26 ⋅ Proofpoint ⋅ Axel F
Emotet Tests New Delivery Techniques
Emotet
2022-04-26 ⋅ Bleeping Computer ⋅ Ionut Ilascu
Emotet malware now installs via PowerShell in Windows shortcut files
Emotet
2022-04-25 ⋅ The DFIR Report ⋅ The DFIR Report
Quantum Ransomware
Cobalt Strike IcedID
2022-04-24 ⋅ forensicitguy ⋅ Tony Lambert
Shortcut to Emotet, an odd TTP change
Emotet
2022-04-20 ⋅ CISA ⋅ Australian Cyber Security Centre (ACSC), Canadian Centre for Cyber Security (CCCS), CISA, FBI, Government Communications Security Bureau, National Crime Agency (NCA), NCSC UK, NSA
AA22-110A Joint CSA: Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure
VPNFilter BlackEnergy DanaBot DoppelDridex Emotet EternalPetya GoldMax Industroyer Sality SmokeLoader TrickBot Triton Zloader
2022-04-20 ⋅ CISA ⋅ CISA
Alert (AA22-110A): Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure
VPNFilter BlackEnergy DanaBot DoppelDridex Emotet EternalPetya GoldMax Industroyer Sality SmokeLoader TrickBot Triton Zloader Killnet
2022-04-20 ⋅ cocomelonc ⋅ cocomelonc
Malware development: persistence - part 1. Registry run keys. C++ example.
Agent Tesla Amadey BlackEnergy Cobian RAT COZYDUKE Emotet Empire Downloader Kimsuky
2022-04-20 ⋅ SANS ISC ⋅ Brad Duncan
'aa' distribution Qakbot (Qbot) infection with DarkVNC traffic
QakBot
2022-04-19 ⋅ Bleeping Computer ⋅ Bill Toulas
Emotet botnet switches to 64-bit modules, increases activity
Emotet
2022-04-19 ⋅ Twitter (@Cryptolaemus1) ⋅ Cryptolaemus
#Emotet Update: 64 bit upgrade of Epoch 5
Emotet
2022-04-18 ⋅ Fortinet ⋅ Erin Lin
Trends in the Recent Emotet Maldoc Outbreak
Emotet
2022-04-17 ⋅ Malwarology ⋅ Gaetano Pellegrino
Qakbot Series: API Hashing
QakBot
2022-04-17 ⋅ BushidoToken Blog ⋅ BushidoToken
Lessons from the Conti Leaks
BazarBackdoor Conti Emotet IcedID Ryuk TrickBot
2022-04-16 ⋅ Malwarology ⋅ Gaetano Pellegrino
Qakbot Series: Process Injection
QakBot
2022-04-14 ⋅ Avast Decoded ⋅ Vladimir Martyanov
Zloader 2: The Silent Night
ISFB Raccoon Zloader
2022-04-14 ⋅ Bleeping Computer ⋅ Bill Toulas
Hackers target Ukrainian govt with IcedID malware, Zimbra exploits
IcedID
2022-04-14 ⋅ ⋅ Cert-UA ⋅ Cert-UA
Cyberattack on Ukrainian state organizations using IcedID malware (CERT-UA#4464)
IcedID
2022-04-14 ⋅ Cynet ⋅ Max Malyutin
Orion Threat Alert: Flight of the BumbleBee
BumbleBee Cobalt Strike
2022-04-13 ⋅ Kaspersky ⋅ AMR
Emotet modules and recent attacks
Emotet
2022-04-13 ⋅ Malwarology ⋅ Gaetano Pellegrino
Qakbot Series: Configuration Extraction
QakBot
2022-04-12 ⋅ Check Point ⋅ Check Point Research
March 2022’s Most Wanted Malware: Easter Phishing Scams Help Emotet Assert its Dominance
Alien FluBot Agent Tesla Emotet
2022-04-12 ⋅ AhnLab ⋅ ASEC Analysis Team
SystemBC Being Used by Various Attackers
Emotet SmokeLoader SystemBC
2022-04-12 ⋅ Tech Times ⋅ Joseph Henry
Qbot Botnet Deploys Malware Payloads Through Malicious Windows Installers
QakBot
2022-04-11 ⋅ Bleeping Computer ⋅ Sergiu Gatlan
Qbot malware switches to new Windows Installer infection vector
QakBot
2022-04-10 ⋅ Malwarology ⋅ Gaetano Pellegrino
Qakbot Series: String Obfuscation
QakBot
2022-04-08 ⋅ ReversingLabs ⋅ Paul Roberts
ConversingLabs Ep. 2: Conti pivots as ransomware as a service struggles
Conti Emotet TrickBot
2022-04-04 ⋅ The DFIR Report ⋅ @0xtornado, @MettalicHack, @yatinwad, @_pete_0
Stolen Images Campaign Ends in Conti Ransomware
Conti IcedID
2022-04-02 ⋅ Github (pl-v) ⋅ Player-V
Emotet Analysis Part 1: Unpacking
Emotet
2022-03-31 ⋅ Trellix ⋅ Jambul Tologonov, John Fokker
Conti Leaks: Examining the Panama Papers of Ransomware
LockBit Amadey Buer Conti IcedID LockBit Mailto Maze PhotoLoader Ryuk TrickBot
2022-03-31 ⋅ nccgroup ⋅ Alex Jessop, Nikolaos Pantazopoulos, RIFT: Research and Intelligence Fusion Team, Simon Biggs
Conti-nuation: methods and techniques observed in operations post the leaks
Cobalt Strike Conti QakBot
2022-03-30 ⋅ Prevailion ⋅ Prevailion
Wizard Spider continues to confound
BazarBackdoor Cobalt Strike Emotet
2022-03-29 ⋅ vmware ⋅ Jason Zhang, Oleg Boyarchuk, Threat Analysis Unit
Emotet C2 Configuration Extraction and Analysis
Emotet
2022-03-29 ⋅ Threat Post ⋅ Elizabeth Montalbano
Exchange Servers Speared in IcedID Phishing Campaign
IcedID
2022-03-28 ⋅ Fortinet ⋅ Fred Gutierrez, James Slaughter, Val Saengphaibul
Spoofed Invoice Used to Drop IcedID
IcedID
2022-03-28 ⋅ Bleeping Computer ⋅ Bill Toulas
Microsoft Exchange targeted for IcedID reply-chain hijacking attacks
IcedID
2022-03-28 ⋅ Intezer ⋅ Joakim Kennedy, Ryan Robinson
New Conversation Hijacking Campaign Delivering IcedID
IcedID PhotoLoader
2022-03-28 ⋅ Cisco ⋅ Adela Jezkova, María José Erquiaga, Onur Erdogan
Emotet is Back
Emotet
2022-03-25 ⋅ SANS ISC ⋅ Xavier Mertens
XLSB Files: Because Binary is Stealthier Than XML
QakBot
2022-03-23 ⋅ Fortinet ⋅ Shunichi Imano, Val Saengphaibul
Bad Actors Trying to Capitalize on Current Events via Shameless Email Scams
Emotet
2022-03-23 ⋅ Secureworks ⋅ Counter Threat Unit ResearchTeam
GOLD ULRICK Leaks Reveal Organizational Structure and Relationships
Conti Emotet IcedID TrickBot
2022-03-23 ⋅ NVISO Labs ⋅ Bart Parys
Hunting Emotet campaigns with Kusto
Emotet
2022-03-23 ⋅ Secureworks ⋅ Counter Threat Unit ResearchTeam
Threat Intelligence Executive Report Volume 2022, Number 2
Conti Emotet IcedID TrickBot
2022-03-23 ⋅ Fortinet ⋅ Xiaopeng Zhang
MS Office Files Involved Again in Recent Emotet Trojan Campaign – Part II
Emotet
2022-03-21 ⋅ Info Security ⋅ Vinugayathri Chinnasamy
Emotet Is Back and Is Deadlier Than Ever! A Rundown of the Emotet Malware
Emotet
2022-03-21 ⋅ eSentire ⋅ eSentire Threat Response Unit (TRU)
Conti Affiliate Exposed: New Domain Names, IP Addresses and Email Addresses Uncovered
HelloKitty BazarBackdoor Cobalt Strike Conti FiveHands HelloKitty IcedID
2022-03-17 ⋅ Github (eln0ty) ⋅ Abdallah Elnoty
IcedID Analysis
IcedID
2022-03-17 ⋅ Trend Micro ⋅ Trend Micro Research
Navigating New Frontiers Trend Micro 2021 Annual Cybersecurity Report
REvil BazarBackdoor Buer IcedID QakBot REvil
2022-03-17 ⋅ Google ⋅ Benoit Sevens, Vladislav Stolyarov
Exposing initial access broker with ties to Conti
BazarBackdoor BumbleBee Conti EXOTIC LILY
2022-03-17 ⋅ Google ⋅ Benoit Sevens, Google Threat Analysis Group, Vladislav Stolyarov
Exposing initial access broker with ties to Conti
BazarBackdoor BumbleBee Cobalt Strike Conti
2022-03-16 ⋅ Symantec ⋅ Symantec Threat Hunter Team
The Ransomware Threat Landscape: What to Expect in 2022
AvosLocker BlackCat BlackMatter Conti DarkSide DoppelPaymer Emotet Hive Karma Mespinoza Nemty Squirrelwaffle VegaLocker WastedLocker Yanluowang Zeppelin
2022-03-16 ⋅ Dragos ⋅ Josh Hanrahan
Suspected Conti Ransomware Activity in the Auto Manufacturing Sector
Conti Emotet
2022-03-16 ⋅ SANS ISC ⋅ Brad Duncan
Qakbot infection with Cobalt Strike and VNC activity
Cobalt Strike QakBot
2022-03-16 ⋅ InfoSec Handlers Diary Blog ⋅ Brad Duncan
Qakbot infection with Cobalt Strike and VNC activity
Cobalt Strike QakBot
2022-03-09 ⋅ nikpx ⋅ xors
BokBot Technical Analysis
IcedID
2022-03-08 ⋅ Lumen ⋅ Black Lotus Labs
What Global Network Visibility Reveals about the Resurgence of One of the World’s Most Notorious Botnets
Emotet
2022-03-07 ⋅ Fortinet ⋅ Xiaopeng Zhang
MS Office Files Involved Again in Recent Emotet Trojan Campaign – Part I
Emotet
2022-03-03 ⋅ Trend Micro ⋅ Trend Micro Research
Cyberattacks are Prominent in the Russia-Ukraine Conflict
BazarBackdoor Cobalt Strike Conti Emotet WhisperGate
2022-03-02 ⋅ KrebsOnSecurity ⋅ Brian Krebs
Conti Ransomware Group Diaries, Part II: The Office
Conti Emotet Ryuk TrickBot
2022-03-01 ⋅ Twitter (@ContiLeaks) ⋅ ContiLeaks
Tweet on Emotet final server scheme
Emotet
2022-02-26 ⋅ LinkedIn (Zayed AlJaberi) ⋅ Zayed AlJaberi
Hunting Recent QakBot Malware
QakBot
2022-02-26 ⋅ Mandiant ⋅ Mandiant
TRENDING EVIL Q1 2022
KEYPLUG FAKEUPDATES GootLoader BazarBackdoor QakBot
2022-02-25 ⋅ CyberScoop ⋅ Joe Warminsky
TrickBot malware suddenly got quiet, researchers say, but it's hardly the end for its operators
BazarBackdoor Emotet TrickBot
2022-02-24 ⋅ Cynet ⋅ Max Malyutin
New Wave of Emotet – When Project X Turns Into Y
Cobalt Strike Emotet
2022-02-24 ⋅ The Hacker News ⋅ Ravie Lakshmanan
TrickBot Gang Likely Shifting Operations to Switch to New Malware
BazarBackdoor Emotet QakBot TrickBot
2022-02-24 ⋅ The Hacker News ⋅ Ravie Lakshmanan
Notorious TrickBot Malware Gang Shuts Down its Botnet Infrastructure
BazarBackdoor Emotet TrickBot
2022-02-23 ⋅ cyber.wtf blog ⋅ Luca Ebach
What the Pack(er)?
Cobalt Strike Emotet
2022-02-22 ⋅ eSentire ⋅ eSentire Threat Response Unit (TRU)
IcedID to Cobalt Strike In Under 20 Minutes
Cobalt Strike IcedID PhotoLoader
2022-02-21 ⋅ The DFIR Report
Qbot and Zerologon Lead To Full Domain Compromise
Cobalt Strike QakBot
2022-02-16 ⋅ Threat Post ⋅ Elizabeth Montalbano
Emotet Now Spreading Through Malicious Excel Files
Emotet
2022-02-16 ⋅ SOC Prime ⋅ Alla Yurchenko
QBot Malware Detection: Old Dog New Tricks
QakBot
2022-02-16 ⋅ Security Onion ⋅ Doug Burks
Quick Malware Analysis: Emotet Epoch 5 and Cobalt Strike pcap from 2022-02-08
Cobalt Strike Emotet
2022-02-15 ⋅ Palo Alto Networks Unit 42 ⋅ Brad Duncan, Micah Yates, Saqib Khanzada, Tyler Halfpop
New Emotet Infection Method
Emotet
2022-02-15 ⋅ eSentire ⋅ eSentire Threat Response Unit (TRU)
Increase in Emotet Activity and Cobalt Strike Deployment
Cobalt Strike Emotet
2022-02-13 ⋅ NetbyteSEC ⋅ Fareed, Rosamira, Taqi
Technical Malware Analysis: The Return of Emotet
Emotet
2022-02-10 ⋅ Cybereason ⋅ Cybereason Global SOC Team
Threat Analysis Report: All Paths Lead to Cobalt Strike - IcedID, Emotet and QBot
Cobalt Strike Emotet IcedID QakBot
2022-02-08 ⋅ BleepingComputer ⋅ Bill Toulas
Qbot needs only 30 minutes to steal your credentials, emails
QakBot
2022-02-07 ⋅ The DFIR Report ⋅ The DFIR Report
Qbot Likes to Move It, Move It
QakBot
2022-02-07 ⋅ vmware ⋅ Jason Zhang, Threat Analysis Unit
Emotet Is Not Dead (Yet) – Part 2
Emotet
2022-02-02 ⋅ VMRay ⋅ Mateusz Lukaszewski, VMRay Labs Team
Malware Analysis Spotlight: Emotet’s Use of Cryptography
Emotet
2022-01-27 ⋅ ⋅ Threat Lab Indonesia ⋅ Threat Lab Indonesia
Malware Analysis Emotet Infection
Emotet
2022-01-25 ⋅ SANS ISC ⋅ Brad Duncan
Emotet Stops Using 0.0.0.0 in Spambot Traffic
Emotet
2022-01-23 ⋅ kienmanowar Blog ⋅ m4n0w4r, Tran Trung Kien
[QuickNote] Emotet epoch4 & epoch5 tactics
Emotet
2022-01-22 ⋅ Atomic Matryoshka ⋅ z3r0day_504
Malware Headliners: Emotet
Emotet
2022-01-21 ⋅ vmware ⋅ Jason Zhang, Threat Analysis Unit
Emotet Is Not Dead (Yet)
Emotet
2022-01-21 ⋅ Trend Micro ⋅ Ian Kenefick
Emotet Spam Abuses Unconventional IP Address Formats to Spread Malware
Emotet
2022-01-19 ⋅ Gdata ⋅ Karsten Hahn
Malware vaccines can prevent pandemics, yet are rarely used
Emotet STOP
2022-01-19 ⋅ Blackberry ⋅ The BlackBerry Research & Intelligence Team
Kraken the Code on Prometheus
Prometheus Backdoor BlackMatter Cerber Cobalt Strike DCRat Ficker Stealer QakBot REvil Ryuk
2022-01-19 ⋅ InfoSec Handlers Diary Blog ⋅ Brad Duncan
0.0.0.0 in Emotet Spambot Traffic
Emotet
2022-01-18 ⋅ Recorded Future ⋅ Insikt Group®
2021 Adversary Infrastructure Report
BazarBackdoor Cobalt Strike Dridex IcedID QakBot TrickBot
2022-01-17 ⋅ forensicitguy ⋅ Tony Lambert
Emotet's Excel 4.0 Macros Dropping DLLs
Emotet
2022-01-15 ⋅ Atomic Matryoshka ⋅ z3r0day_504
Malware Headliners: Qakbot
QakBot
2022-01-14 ⋅ RiskIQ ⋅ Jordan Herman
RiskIQ: Unique SSL Certificates and JARM Hash Connected to Emotet and Dridex C2 Servers
Dridex Emotet
2022-01-13 ⋅ Trustwave ⋅ Lloyd Macrohon, Rodel Mendrez
Decrypting Qakbot’s Encrypted Registry Keys
QakBot
2022-01-11 ⋅ Medium walmartglobaltech ⋅ Jason Reaves, Joshua Platt
Signed DLL campaigns as a service
BATLOADER Cobalt Strike ISFB Zloader
2022-01-11 ⋅ Cybereason ⋅ Chen Erlich, Daichi Shimabukuro, Niv Yona, Ofir Ozer, Omri Refaeli
Threat Analysis Report: DatopLoader Exploits ProxyShell to Deliver QBOT and Cobalt Strike
Cobalt Strike QakBot Squirrelwaffle
2022-01-07 ⋅ muha2xmad ⋅ Muhammad Hasan Ali
Unpacking Emotet malware part 02
Emotet
2022-01-06 ⋅ muha2xmad ⋅ Muhammad Hasan Ali
Unpacking Emotet malware part 01
Emotet
2022-01-01 ⋅ aspirets ⋅ Michael Lamb
Bumblebee Malware Loader: Threat Analysis
BumbleBee
2022-01-01 ⋅ forensicitguy ⋅ Tony Lambert
Analyzing an IcedID Loader Document
IcedID
2021-12-22 ⋅ Cloudsek ⋅ Anandeshwar Unnikrishnan
Emotet 2.0: Everything you need to know about the new Variant of the Banking Trojan
Emotet
2021-12-17 ⋅ Trend Micro ⋅ Abraham Camba, Gilbert Sison, Jay Yaneza, Jonna Santos
Staging a Quack: Reverse Analyzing a Fileless QAKBOT Stager
QakBot
2021-12-16 ⋅ InfoSec Handlers Diary Blog ⋅ Brad Duncan
How the "Contact Forms" campaign tricks people
IcedID
2021-12-16 ⋅ Red Canary ⋅ The Red Canary Team
Intelligence Insights: December 2021
Cobalt Strike QakBot Squirrelwaffle
2021-12-13 ⋅ Zscaler ⋅ Avinash Kumar, Dennis Schwarz
Return of Emotet: Malware Analysis
Emotet
2021-12-11 ⋅ YouTube (AGDC Services) ⋅ AGDC Services
How To Extract & Decrypt Qbot Configs Across Variants
QakBot
2021-12-09 ⋅ HP ⋅ Patrick Schläpfer
Emotet’s Return: What’s Different?
Emotet
2021-12-09 ⋅ Microsoft ⋅ Microsoft 365 Defender Threat Intelligence Team
A closer look at Qakbot’s latest building blocks (and how to knock them down)
QakBot
2021-12-08 ⋅ Check Point Research ⋅ Aliaksandr Trafimchuk, David Driker, Raman Ladutska, Yali Magiel
When old friends meet again: why Emotet chose Trickbot for rebirth
Emotet TrickBot
2021-12-07 ⋅ Bleeping Computer ⋅ Lawrence Abrams
Emotet now drops Cobalt Strike, fast forwards ransomware attacks
Cobalt Strike Emotet
2021-12-03 ⋅ SANS ISC InfoSec Forums ⋅ Brad Duncan
TA551 (Shathak) pushes IcedID (Bokbot)
IcedID
2021-11-30 ⋅ Deep instinct ⋅ Ron Ben Yizhak
The Re-Emergence of Emotet
Emotet
2021-11-25 ⋅ ⋅ DSIH ⋅ Charles Blanc-Rolin
Emotet de retour, POC Exchange, 0-day Windows : à quelle sauce les attaquants prévoient de nous manger cette semaine?
Emotet
2021-11-23 ⋅ Anomali ⋅ Anomali Threat Research
Mummy Spider’s Emotet Malware is Back After a Year Hiatus; Wizard Spider’s TrickBot Observed in Its Return
Emotet
2021-11-21 ⋅ Twitter (@tylabs) ⋅ Twitter (@ffforward), Tyler McLellan
Twitter Thread about UNC1500 phishing using QAKBOT
QakBot
2021-11-20 ⋅ Advanced Intelligence ⋅ Vitali Kremez, Yelisey Boguslavskiy
Corporate Loader "Emotet": History of "X" Project Return for Ransomware
Emotet
2021-11-20 ⋅ Youtube (HEXORCIST) ⋅ Nicolas Brulez
Unpacking Emotet and Reversing Obfuscated Word Document
Emotet
2021-11-20 ⋅ Twitter (@eduardfir) ⋅ Eduardo Mattos
Tweet on Velociraptor artifact analysis for Emotet
Emotet
2021-11-19 ⋅ Trend Micro ⋅ Abdelrhman Sharshar, Mohamed Fahmy, Sherif Magdy
Squirrelwaffle Exploits ProxyShell and ProxyLogon to Hijack Email Chains
Cobalt Strike QakBot Squirrelwaffle
2021-11-19 ⋅ ⋅ CRONUP ⋅ Germán Fernández
La Botnet de EMOTET reinicia ataques en Chile y LATAM
Emotet
2021-11-19 ⋅ LAC WATCH ⋅ LAC WATCH
Malware Emotet resumes its activities for the first time in 10 months, and Japan is also the target of the attack
Emotet
2021-11-18 ⋅ Netskope ⋅ Ghanashyam Satpathy, Gustavo Palazolo
Netskope Threat Coverage: The Return of Emotet
Emotet
2021-11-18 ⋅ Red Canary ⋅ The Red Canary Team
Intelligence Insights: November 2021
Andromeda Conti LockBit QakBot Squirrelwaffle
2021-11-18 ⋅ eSentire ⋅ eSentire
Emotet Activity Identified
Emotet
2021-11-17 ⋅ Twitter (@Unit42_Intel) ⋅ Unit 42
Tweet on Matanbuchus Loader used to deliver Qakbot (tag obama128b) and follow-up CobaltStrike
Cobalt Strike QakBot
2021-11-16 ⋅ InfoSec Handlers Diary Blog ⋅ Brad Duncan
Emotet Returns
Emotet
2021-11-16 ⋅ Hornetsecurity ⋅ Security Lab
Comeback of Emotet
Emotet
2021-11-16 ⋅ Zscaler ⋅ Deepen Desai
Return of Emotet malware
Emotet
2021-11-16 ⋅ Twitter (@kienbigmummy) ⋅ m4n0w4r
Tweet on short analysis of QakBot
QakBot
2021-11-16 ⋅ Malwarebytes ⋅ Malwarebytes Threat Intelligence Team
TrickBot helps Emotet come back from the dead
Emotet TrickBot
2021-11-16 ⋅ IronNet ⋅ IronNet Threat Research, Joey Fitzpatrick, Morgan Demboski, Peter Rydzynski
How IronNet's Behavioral Analytics Detect REvil and Conti Ransomware
Cobalt Strike Conti IcedID REvil
2021-11-15 ⋅ cyber.wtf blog ⋅ Luca Ebach
Guess who’s back
Emotet
2021-11-15 ⋅ Bleeping Computer ⋅ Lawrence Abrams
Emotet malware is back and rebuilding its botnet via TrickBot
Emotet
2021-11-15 ⋅ TRUESEC ⋅ Fabio Viggiani
ProxyShell, QBot, and Conti Ransomware Combined in a Series of Cyberattacks
Cobalt Strike Conti QakBot
2021-11-13 ⋅ Trend Micro ⋅ Ian Kenefick, Vladimir Kropotov
QAKBOT Loader Returns With New Techniques and Tools
QakBot
2021-11-13 ⋅ YouTube (AGDC Services) ⋅ AGDC Services
Automate Qbot Malware String Decryption With Ghidra Script
QakBot
2021-11-12 ⋅ Recorded Future ⋅ Insikt Group®
The Business of Fraud: Botnet Malware Dissemination
Mozi Dridex IcedID QakBot TrickBot
2021-11-12 ⋅ Trend Micro ⋅ Ian Kenefick, Vladimir Kropotov
The Prelude to Ransomware: A Look into Current QAKBOT Capabilities and Global Activities
QakBot
2021-11-11 ⋅ Cynet ⋅ Max Malyutin
A Duck Nightmare Quakbot Strikes with QuakNightmare Exploitation
Cobalt Strike QakBot
2021-11-11 ⋅ vmware ⋅ Giovanni Vigna, Jason Zhang, Stefano Ortolani, Threat Analysis Unit
Research Recap: How To Automate Malware Campaign Detection With Telemetry Peak Analyzer
Phorpiex QakBot
2021-11-10 ⋅ CIRCL ⋅ CIRCL
TR-64 - Exploited Exchange Servers - Mails with links to malware from known/valid senders
QakBot
2021-11-09 ⋅ MinervaLabs ⋅ Minerva Labs
A New DatopLoader Delivers QakBot Trojan
QakBot Squirrelwaffle
2021-11-04 ⋅ splunk ⋅ Splunk Threat Research Team
Detecting IcedID... Could It Be A Trickbot Copycat?
IcedID
2021-11-03 ⋅ Twitter (@Corvid_Cyber) ⋅ CORVID
Tweet on a unique Qbot debugger dropped by an actor after compromise
QakBot
2021-11-03 ⋅ Team Cymru ⋅ tcblogposts
Webinject Panel Administration: A Vantage Point into Multiple Threat Actor Campaigns - A Case Study on the Value of Threat Reconnaisance
DoppelDridex IcedID QakBot Zloader
2021-10-26 ⋅ Cisco Talos ⋅ Edmund Brumaghin, Mariano Graziano, Nick Mavis
SQUIRRELWAFFLE Leverages malspam to deliver Qakbot, Cobalt Strike
Cobalt Strike QakBot Squirrelwaffle
2021-10-26 ⋅ ANSSI
Identification of a new cyber criminal group: Lockean
Cobalt Strike DoppelPaymer Egregor Maze PwndLocker QakBot REvil
2021-10-25 ⋅ Cleafy ⋅ Cleafy
Digital banking fraud: how the Gozi malware works
ISFB
2021-10-18 ⋅ The DFIR Report ⋅ The DFIR Report
IcedID to XingLocker Ransomware in 24 hours
Cobalt Strike IcedID Mount Locker
2021-10-15 ⋅ Trend Micro ⋅ Fernando Mercês
Ransomware Operators Found Using New "Franchise" Business Model
Glupteba IcedID Mount Locker
2021-10-07 ⋅ Netskope ⋅ Ghanashyam Satpathy, Gustavo Palazolo
SquirrelWaffle: New Malware Loader Delivering Cobalt Strike and QakBot
Cobalt Strike QakBot Squirrelwaffle
2021-09-29 ⋅ Proofpoint ⋅ Proofpoint Staff, Selena Larson
TA544 Targets Italian Organizations with Ursnif Malware
ISFB
2021-09-10 ⋅ Gigamon ⋅ Joe Slowik
Rendering Threats: A Network Perspective
BumbleBee Cobalt Strike
2021-09-09 ⋅ Trend Micro ⋅ Trend Micro
Remote Code Execution 0-Day (CVE-2021-40444) Hits Windows, Triggered Via Office Docs
BumbleBee Cobalt Strike
2021-09-03 ⋅ IBM ⋅ Andrew Gorecki, Camille Singleton, John Dwyer
Dissecting Sodinokibi Ransomware Attacks: Bringing Incident Response and Intelligence Together in the Fight
Valak QakBot REvil
2021-09-03 ⋅ Trend Micro ⋅ Mohamad Mokbel
The State of SSL/TLS Certificate Usage in Malware C&C Communications
AdWind ostap AsyncRAT BazarBackdoor BitRAT Buer Chthonic CloudEyE Cobalt Strike DCRat Dridex FindPOS GootKit Gozi IcedID ISFB Nanocore RAT Orcus RAT PandaBanker Qadars QakBot Quasar RAT Rockloader ServHelper Shifu SManager TorrentLocker TrickBot Vawtrak Zeus Zloader
2021-09-02 ⋅ Kaspersky ⋅ Anton Kuzmenko, Haim Zigel, Oleg Kupreev
QakBot Technical Analysis
QakBot
2021-08-15 ⋅ Symantec ⋅ Threat Hunter Team
The Ransomware Threat
Babuk BlackMatter DarkSide Avaddon Babuk BADHATCH BazarBackdoor BlackMatter Clop Cobalt Strike Conti DarkSide DoppelPaymer Egregor Emotet FiveHands FriedEx Hades IcedID LockBit Maze MegaCortex MimiKatz QakBot RagnarLocker REvil Ryuk TrickBot WastedLocker
2021-08-05 ⋅ Group-IB ⋅ Nikita Rostovcev, Viktor Okorokov
Prometheus TDS The key to success for Campo Loader, Hancitor, IcedID, and QBot
Prometheus Backdoor Buer campoloader Hancitor IcedID QakBot
2021-08-05 ⋅ The Record ⋅ Catalin Cimpanu
Meet Prometheus, the secret TDS behind some of today’s malware campaigns
Buer campoloader IcedID QakBot
2021-07-30 ⋅ HP ⋅ Patrick Schläpfer
Detecting TA551 domains
Valak Dridex IcedID ISFB QakBot
2021-07-26 ⋅ vmware ⋅ Pavankumar Chaudhari, Quentin Fois
Hunting IcedID and unpacking automation with Qiling
IcedID
2021-07-24 ⋅ 0ffset Blog ⋅ Daniel Bunce
Quack Quack: Analysing Qakbot’s Browser Hooking Module – Part 1
QakBot
2021-07-23 ⋅ Github (Lastline-Inc) ⋅ Pavankumar Chaudhari, Quentin Fois
YARA rules, IOCs and Scripts for extracting IcedID C2s
IcedID
2021-07-19 ⋅ The DFIR Report ⋅ The DFIR Report
IcedID and Cobalt Strike vs Antivirus
Cobalt Strike IcedID
2021-07-14 ⋅ Cerium Networks ⋅ Blumira
Threat of the Month: IcedID Malware
IcedID
2021-07-12 ⋅ The Record ⋅ Catalin Cimpanu
Over 780,000 email accounts compromised by Emotet have been secured
Emotet
2021-07-08 ⋅ vmware ⋅ Pavankumar Chaudhari, Quentin Fois
IcedID: Analysis and Detection
IcedID
2021-06-30 ⋅ Cynet ⋅ Max Malyutin
Shelob Moonlight – Spinning a Larger Web From IcedID to CONTI, a Trojan and Ransomware collaboration
Conti IcedID
2021-06-30 ⋅ The Record ⋅ Catalin Cimpanu
Gozi malware gang member arrested in Colombia
Gozi ISFB
2021-06-24 ⋅ SentinelOne ⋅ Marco Figueroa
Evasive Maneuvers | Massive IcedID Campaign Aims For Stealth with Benign Macros
IcedID
2021-06-24 ⋅ Kaspersky ⋅ Anton Kuzmenko
Malicious spam campaigns delivering banking Trojans
IcedID QakBot
2021-06-23 ⋅ IBM ⋅ Itzik Chimino
Ursnif Leverages Cerberus to Automate Fraudulent Bank Transfers in Italy
ISFB
2021-06-20 ⋅ The DFIR Report ⋅ The DFIR Report
From Word to Lateral Movement in 1 Hour
Cobalt Strike IcedID
2021-06-16 ⋅ Twitter (@ChouchWard) ⋅ ch0uch ward
Tweet on Qbot operators left their web server's access.log file unsecured
QakBot
2021-06-16 ⋅ Proofpoint ⋅ Daniel Blackford, Garrett M. Graff, Selena Larson
The First Step: Initial Access Leads to Ransomware
BazarBackdoor Egregor IcedID Maze QakBot REvil Ryuk TrickBot WastedLocker TA570 TA575 TA577
2021-06-16 ⋅ ⋅ S2 Grupo ⋅ CSIRT-CV (the ICT Security Center of the Valencian Community)
Emotet campaign analysis
Emotet QakBot
2021-06-15 ⋅ Perception Point ⋅ Shai Golderman
Insights Into an Excel 4.0 Macro Attack using Qakbot Malware
QakBot
2021-06-10 ⋅ ZEIT Online ⋅ Astrid Geisler, Herwig G. Höller, Karsten Polke-Majewski, Von Kai Biermann, Zachary Kamel
On the Trail of the Internet Extortionists
Emotet Mailto
2021-06-10 ⋅ ZAYOTEM ⋅ Abdulkadir Binan, Emrah Sarıdağ, Emre Doğan, İlker Verimoğlu, Kaan Binen
QakBot Technical Analysis Report
QakBot
2021-06-10 ⋅ Tagesschau ⋅ Hakan Tanriverdi, Maximilian Zierer
Schadsoftware Emotet: BKA befragt Schlüsselfigur
Emotet
2021-06-08 ⋅ Advanced Intelligence ⋅ Vitali Kremez, Yelisey Boguslavskiy
From QBot...with REvil Ransomware: Initial Attack Exposure of JBS
QakBot REvil
2021-06-02 ⋅ Bleeping Computer ⋅ Lawrence Abrams
FUJIFILM shuts down network after suspected ransomware attack
QakBot
2021-05-29 ⋅ Youtube (AhmedS Kasmani) ⋅ AhmedS Kasmani
Analysis of ICEID Malware Installer DLL
IcedID
2021-05-26 ⋅ Check Point ⋅ Alex Ilgayev
Melting Ice – Tracking IcedID Servers with a few simple steps
IcedID
2021-05-26 ⋅ DeepInstinct ⋅ Ron Ben Yizhak
A Deep Dive into Packing Software CryptOne
Cobalt Strike Dridex Emotet Gozi ISFB Mailto QakBot SmokeLoader WastedLocker Zloader
2021-05-19 ⋅ Team Cymru ⋅ Andy Kraus, Josh Hopkins, Nick Byers
Tracking BokBot Infrastructure Mapping a Vast and Currently Active BokBot Network
IcedID
2021-05-19 ⋅ Intel 471 ⋅ Intel 471
Look how many cybercriminals love Cobalt Strike
BazarBackdoor Cobalt Strike Hancitor QakBot SmokeLoader SystemBC TrickBot
2021-05-18 ⋅ RECON INFOSEC ⋅ Andrew Cook
An Encounter With TA551/Shathak
IcedID
2021-05-17 ⋅ Telekom ⋅ Thomas Barabosch
Let’s set ice on fire: Hunting and detecting IcedID infections
IcedID
2021-05-17 ⋅ Github (telekom-security) ⋅ Deutsche Telekom Security GmbH
icedid_analysis
IcedID
2021-05-12 ⋅ The DFIR Report
Conti Ransomware
Cobalt Strike Conti IcedID
2021-05-10 ⋅ MALWATION ⋅ malwation
IcedID Malware Technical Analysis Report
IcedID
2021-05-10 ⋅ Mal-Eats ⋅ mal_eats
Overview of Campo, a new attack campaign targeting Japan
AnchorDNS BazarBackdoor Cobalt Strike ISFB Phobos TrickBot Zloader
2021-05-10 ⋅ ⋅ Wirtschaftswoche ⋅ Thomas Kuhn
How one of the largest hacker networks in the world was paralyzed
Emotet
2021-05-04 ⋅ Fox-IT ⋅ Fox IT, fumik0, the RIFT Team
RM3 – Curiosities of the wildest banking malware
ISFB
2021-05-04 ⋅ Seguranca Informatica ⋅ Pedro Tavares
A taste of the latest release of QakBot
QakBot
2021-05-04 ⋅ NCC Group ⋅ fumik0, NCC RIFT
RM3 – Curiosities of the wildest banking malware
ISFB RM3
2021-04-30 ⋅ MADRID Labs ⋅ Odin Bernstein
Qbot: Analyzing PHP Proxy Scripts from Compromised Web Server
QakBot
2021-04-28 ⋅ Reversing Labs ⋅ Karlo Zanki
Spotting malicious Excel4 macros
QakBot
2021-04-28 ⋅ IBM ⋅ David Bisson
QBot Malware Spotted Using Windows Defender Antivirus Lure
QakBot
2021-04-22 ⋅ Github (@cecio) ⋅ @red5heep
EMOTET: a State-Machine reversing exercise
Emotet
2021-04-22 ⋅ Spamhaus ⋅ Spamhaus Malware Labs
Spamhaus Botnet Threat Update Q1 2021
Emotet Ficker Stealer Raccoon
2021-04-19 ⋅ Twitter (@_alex_il_) ⋅ Alex Ilgayev
Tweet on QakBot's additional decryption mechanism
QakBot
2021-04-19 ⋅ Netresec ⋅ Erik Hjelmvik
Analysing a malware PCAP with IcedID and Cobalt Strike traffic
Cobalt Strike IcedID
2021-04-17 ⋅ YouTube (Worcester DEFCON Group) ⋅ Joel Snape, Nettitude
Inside IcedID: Anatomy Of An Infostealer
IcedID
2021-04-15 ⋅ AT&T ⋅ Dax Morrow, Ofer Caspi
The rise of QakBot
QakBot
2021-04-13 ⋅ Silent Push ⋅ Martijn Grooten
Malicious infrastructure as a service
IcedID PhotoLoader QakBot
2021-04-12 ⋅ PTSecurity ⋅ PTSecurity
PaaS, or how hackers evade antivirus software
Amadey Bunitu Cerber Dridex ISFB KPOT Stealer Mailto Nemty Phobos Pony Predator The Thief QakBot Raccoon RTM SmokeLoader Zloader
2021-04-12 ⋅ Twitter (@elisalem9) ⋅ Eli Salem
Tweets on QakBot
QakBot
2021-04-12 ⋅ Trend Micro ⋅ Don Ovid Ladores, Frankylnn Uy, Junestherry Salvador, Lala Manly, Raphael Centeno
A Spike in BazarCall and IcedID Activity Detected in March
BazarBackdoor IcedID
2021-04-11 ⋅ 4rchibld ⋅ 4rchibld
IcedID on my neck I’m the coolest
IcedID
2021-04-10 ⋅ Youtube (AhmedS Kasmani) ⋅ AhmedS Kasmani
Malware Analysis: IcedID Banking Trojan JavaScript Dropper
IcedID
2021-04-09 ⋅ Microsoft ⋅ Emily Hacker, Justin Carroll, Microsoft 365 Defender Threat Intelligence Team
Investigating a unique “form” of email delivery for IcedID malware
IcedID
2021-04-09 ⋅ aaqeel01 ⋅ Ali Aqeel
IcedID Analysis
IcedID
2021-04-09 ⋅ Palo Alto Networks Unit 42 ⋅ Chris Navarrete, Yanhui Jia
Emotet Command and Control Case Study
Emotet
2021-04-07 ⋅ Uptycs ⋅ Abhijit Mohanta, Ashwin Vamshi
IcedID campaign spotted being spiced with Excel 4 Macros
IcedID
2021-04-07 ⋅ Minerva ⋅ Minerva Labs
IcedID - A New Threat In Office Attachments
IcedID
2021-04-06 ⋅ Intel 471 ⋅ Intel 471
EtterSilent: the underground’s new favorite maldoc builder
BazarBackdoor ISFB QakBot TrickBot
2021-04-01 ⋅ Reversing Labs ⋅ Robert Simmons
Code Reuse Across Packers and DLL Loaders
IcedID SystemBC
2021-03-31 ⋅ Kaspersky SAS ⋅ Kaspersky
Financial Cyberthreats in 2020
BetaBot DanaBot Emotet Gozi Ramnit RTM SpyEye TrickBot Zeus
2021-03-31 ⋅ Silent Push ⋅ Martijn Grooten
IcedID Command and Control Infrastructure
IcedID PhotoLoader
2021-03-31 ⋅ Red Canary ⋅ Red Canary
2021 Threat Detection Report
Shlayer Andromeda Cobalt Strike Dridex Emotet IcedID MimiKatz QakBot TrickBot
2021-03-29 ⋅ The DFIR Report ⋅ The DFIR Report
Sodinokibi (aka REvil) Ransomware
Cobalt Strike IcedID REvil
2021-03-26 ⋅ Trend Micro ⋅ Trend Micro
Alleged Members of Egregor Ransomware Cartel Arrested
Egregor QakBot
2021-03-21 ⋅ Blackberry ⋅ Blackberry Research
2021 Threat Report
Bashlite FritzFrog IPStorm Mirai Tsunami elf.wellmess AppleJeus Dacls EvilQuest Manuscrypt Astaroth BazarBackdoor Cerber Cobalt Strike Emotet FinFisher RAT Kwampirs MimiKatz NjRAT Ryuk SmokeLoader TrickBot
2021-03-19 ⋅ MITRE ⋅ MITRE ATT&CK
TA551
GOLD CABIN
2021-03-18 ⋅ VinCSS ⋅ m4n0w4r, Tran Trung Kien
[RE021] Qakbot analysis – Dangerous malware has been around for more than a decade
QakBot
2021-03-17 ⋅ HP ⋅ HP Bromium
Threat Insights Report Q4-2020
Agent Tesla BitRAT ComodoSec Dridex Emotet Ficker Stealer Formbook Zloader
2021-03-12 ⋅ Binary Defense ⋅ James Quinn
IcedID GZIPLOADER Analysis
IcedID
2021-03-08 ⋅ Palo Alto Networks Unit 42 ⋅ Chris Navarrete, Durgesh Sangvikar, Matthew Tennis, Rongbo Shao, Yanhui Jia
Attack Chain Overview: Emotet in December 2020 and January 2021
Emotet
2021-03-04 ⋅ F5 ⋅ Dor Nizar, Roy Moshailov
IcedID Banking Trojan Uses COVID-19 Pandemic to Lure New Victims
IcedID
2021-03-01 ⋅ Group-IB ⋅ Oleg Skulkin, Roman Rezvukhin, Semyon Rogachev
Ransomware Uncovered 2020/2021
RansomEXX BazarBackdoor Buer Clop Conti DoppelPaymer Dridex Egregor IcedID Maze PwndLocker QakBot RansomEXX REvil Ryuk SDBbot TrickBot Zloader
2021-02-28 ⋅ NetbyteSEC
Deobfuscating Emotet Macro Document and Powershell Command
Emotet
2021-02-28 ⋅ PWC UK ⋅ PWC UK
Cyber Threats 2020: A Year in Retrospect
elf.wellmess FlowerPower PowGoop 8.t Dropper Agent.BTZ Agent Tesla Appleseed Ave Maria Bankshot BazarBackdoor BLINDINGCAN Chinoxy Conti Cotx RAT Crimson RAT DUSTMAN Emotet FriedEx FunnyDream Hakbit Mailto Maze METALJACK Nefilim Oblique RAT Pay2Key PlugX QakBot REvil Ryuk StoneDrill StrongPity SUNBURST SUPERNOVA TrickBot TurlaRPC Turla SilentMoon WastedLocker WellMess Winnti ZeroCleare APT10 APT23 APT27 APT31 APT41 BlackTech BRONZE EDGEWOOD Inception Framework MUSTANG PANDA Red Charon Red Nue Sea Turtle Tonto Team
2021-02-26 ⋅ CrowdStrike ⋅ Eric Loui, Sergei Frankoff
Hypervisor Jackpotting: CARBON SPIDER and SPRITE SPIDER Target ESXi Servers With Ransomware to Maximize Impact
DarkSide RansomEXX Griffon Carbanak Cobalt Strike DarkSide IcedID MimiKatz PyXie RansomEXX REvil
2021-02-25 ⋅ Mandiant ⋅ Brendan McKeague, Bryce Abdo, Van Ta
So Unchill: Melting UNC2198 ICEDID to Ransomware Operations
IcedID TA2101
2021-02-25 ⋅ ANSSI ⋅ CERT-FR
Ryuk Ransomware
BazarBackdoor Buer Conti Emotet Ryuk TrickBot
2021-02-25 ⋅ FireEye ⋅ Brendan McKeague, Bryce Abdo, Van Ta
So Unchill: Melting UNC2198 ICEDID to Ransomware Operations
MOUSEISLAND Cobalt Strike Egregor IcedID Maze SystemBC
2021-02-25 ⋅ JPCERT/CC ⋅ Ken Sajo
Emotet Disruption and Outreach to Affected Users
Emotet
2021-02-24 ⋅ Allsafe ⋅ Hara Hiroaki, Shota Nakajima
Malware Analysis at Scale - Defeating Emotet by Ghidra
Emotet
2021-02-24 ⋅ IBM ⋅ IBM SECURITY X-FORCE
X-Force Threat Intelligence Index 2021
Emotet QakBot Ramnit REvil TrickBot
2021-02-23 ⋅ CrowdStrike ⋅ CrowdStrike
2021 Global Threat Report
RansomEXX Amadey Anchor Avaddon BazarBackdoor Clop Cobalt Strike Conti Cutwail DanaBot DarkSide DoppelPaymer Dridex Egregor Emotet Hakbit IcedID JSOutProx KerrDown LockBit Mailto Maze MedusaLocker Mespinoza Mount Locker NedDnLoader Nemty Pay2Key PlugX Pushdo PwndLocker PyXie QakBot Quasar RAT RagnarLocker Ragnarok RansomEXX REvil Ryuk Sekhmet ShadowPad SmokeLoader Snake SUNBURST SunCrypt TEARDROP TrickBot WastedLocker Winnti Zloader Evilnum OUTLAW SPIDER RIDDLE SPIDER SOLAR SPIDER VIKING SPIDER
2021-02-17 ⋅ ⋅ Politie NL ⋅ Politie NL
Politie bestrijdt cybercrime via Nederlandse infrastructuur
Emotet
2021-02-17 ⋅ YouTube (AGDC Services) ⋅ AGDC Services
How Malware Can Resolve APIs By Hash
Emotet Mailto
2021-02-16 ⋅ Proofpoint ⋅ Proofpoint Threat Research Team
Q4 2020 Threat Report: A Quarterly Analysis of Cybersecurity Trends, Tactics and Themes
Emotet Ryuk NARWHAL SPIDER TA800
2021-02-15 ⋅ Twitter (@TheDFIRReport) ⋅ The DFIR Report
Tweet on Qakbot post infection discovery activity
QakBot
2021-02-12 ⋅ CERT-FR ⋅ CERT-FR
The Malware-Aa-A-Service Emotet
Emotet
2021-02-08 ⋅ GRNET CERT ⋅ Dimitris Kolotouros, Marios Levogiannis
Reverse engineering Emotet – Our approach to protect GRNET against the trojan
Emotet
2021-02-03 ⋅ Mimecast, Nettitude
TA551/Shathak Threat Research
IcedID
2021-02-03 ⋅ Digital Shadows ⋅ Stefano De Blasi
Emotet Disruption: what it means for the cyber threat landscape
Emotet
2021-02-03 ⋅ ZDNet ⋅ Charlie Osborne
Ursnif Trojan has targeted over 100 Italian banks
ISFB Snifula
2021-02-02 ⋅ ⋅ CRONUP ⋅ Germán Fernández
De ataque con Malware a incidente de Ransomware
Avaddon BazarBackdoor Buer Clop Cobalt Strike Conti DanaBot Dharma Dridex Egregor Emotet Empire Downloader FriedEx GootKit IcedID MegaCortex Nemty Phorpiex PwndLocker PyXie QakBot RansomEXX REvil Ryuk SDBbot SmokeLoader TrickBot Zloader
2021-02-01 ⋅ Microsoft ⋅ Microsoft 365 Defender Threat Intelligence Team
What tracking an attacker email infrastructure tells us about persistent cybercriminal operations
Dridex Emotet Makop Ransomware SmokeLoader TrickBot
2021-01-29 ⋅ Malwarebytes ⋅ Threat Intelligence Team
Cleaning up after Emotet: the law enforcement file
Emotet
2021-01-28 ⋅ NTT ⋅ Dan Saunders
Emotet disruption - Europol counterattack
Emotet
2021-01-28 ⋅ InfoSec Handlers Diary Blog ⋅ Daniel Wesemann
Emotet vs. Windows Attack Surface Reduction
Emotet
2021-01-28 ⋅ Youtube (Virus Bulletin) ⋅ Benoît Ancel
The Bagsu banker case
Azorult DreamBot Emotet Pony TrickBot ZeusAction
2021-01-28 ⋅ Hornetsecurity ⋅ Hornetsecurity Security Lab
Emotet Botnet Takedown
Emotet
2021-01-28 ⋅ Department of Homeland Security ⋅ Department of Justice
Emotet Botnet Disrupted in International Cyber Operation
Emotet
2021-01-27 ⋅ Intel 471 ⋅ Intel 471
Emotet takedown is not like the Trickbot takedown
Emotet
2021-01-27 ⋅ ⋅ Youtube (Національна поліція України) ⋅ Національна поліція України
Кіберполіція викрила транснаціональне угруповання хакерів у розповсюдженні вірусу EMOTET
Emotet
2021-01-27 ⋅ Eurojust ⋅ Eurojust
World’s most dangerous malware EMOTET disrupted through global action
Emotet
2021-01-27 ⋅ KrebsOnSecurity ⋅ Brian Krebs
International Action Targets Emotet Crimeware
Emotet
2021-01-27 ⋅ Twitter (@milkr3am) ⋅ milkream
Tweet on all Emotet epoch pushing payload to self remove emotet malware on 2021-04-25
Emotet
2021-01-27 ⋅ ⋅ Bundeskriminalamt ⋅ Bundeskriminalamt
In­fra­struk­tur der Emo­tet-Schad­soft­wa­re zer­schla­gen
Emotet
2021-01-27 ⋅ Team Cymru ⋅ James Shank
Taking Down Emotet How Team Cymru Leveraged Visibility and Relationships to Coordinate Community Efforts
Emotet
2021-01-22 ⋅ Thomas Barabosch
The malware analyst’s guide to PE timestamps
Azorult Gozi IcedID ISFB LOLSnif SUNBURST TEARDROP
2021-01-19 ⋅ Medium elis531989 ⋅ Eli Salem
Funtastic Packers And Where To Find Them
Get2 IcedID QakBot
2021-01-19 ⋅ Palo Alto Networks Unit 42 ⋅ Brad Duncan
Wireshark Tutorial: Examining Emotet Infection Traffic
Emotet GootKit IcedID QakBot TrickBot
2021-01-18 ⋅ tccontre Blog ⋅ tcontre
Extracting Shellcode in ICEID .PNG Steganography
IcedID
2021-01-14 ⋅ Netskope ⋅ Dagmawi Mulugeta, Ghanashyam Satpathy
You Can Run, But You Can’t Hide: Advanced Emotet Updates
Emotet
2021-01-13 ⋅ VinCSS ⋅ m4n0w4r, Tran Trung Kien
[RE019] From A to X analyzing some real cases which used recent Emotet samples
Emotet
2021-01-12 ⋅ Fortinet ⋅ Xiaopeng Zhang
New Variant of Ursnif Continuously Targeting Italy
ISFB
2021-01-09 ⋅ Marco Ramilli's Blog ⋅ Marco Ramilli
Command and Control Traffic Patterns
ostap LaZagne Agent Tesla Azorult Buer Cobalt Strike DanaBot DarkComet Dridex Emotet Formbook IcedID ISFB NetWire RC PlugX Quasar RAT SmokeLoader TrickBot
2021-01-08 ⋅ 0xC0DECAFE ⋅ Thomas Barabosch
The malware analyst’s guide to aPLib decompression
ISFB Rovnix
2021-01-07 ⋅ Palo Alto Networks Unit 42 ⋅ Brad Duncan
TA551: Email Attack Campaign Switches from Valak to IcedID
IcedID
2021-01-06 ⋅ FBI ⋅ FBI
PIN Number 20210106-001: Egregor Ransomware Targets Businesses Worldwide, Attempting to Extort Businesses by Publicly Releasing Exfiltrated Data
Egregor QakBot
2021-01-05 ⋅ r3mrum blog ⋅ R3MRUM
Manual analysis of new PowerSplit maldocs delivering Emotet
Emotet
2021-01-01 ⋅ AWAKE ⋅ Awake Security
Breaking the Ice: Detecting IcedID and Cobalt Strike Beacon with Network Detection and Response (NDR)
Cobalt Strike IcedID PhotoLoader
2021-01-01 ⋅ Secureworks ⋅ SecureWorks
Threat Profile: GOLD LAGOON
QakBot MALLARD SPIDER
2021-01-01 ⋅ Secureworks ⋅ SecureWorks
Threat Profile: GOLD CABIN
GOLD CABIN
2020-12-31 ⋅ ⋅ Cert-AgID ⋅ Cert-AgID
Simplify Emotet parsing with Python and iced x86
Emotet
2020-12-30 ⋅ Bleeping Computer ⋅ Sergiu Gatlan
Emotet malware hits Lithuania's National Public Health Center
Emotet
2020-12-21 ⋅ Cisco Talos ⋅ JON MUNSHAW
2020: The year in malware
WolfRAT Prometei Poet RAT Agent Tesla Astaroth Ave Maria CRAT Emotet Gozi IndigoDrop JhoneRAT Nanocore RAT NjRAT Oblique RAT SmokeLoader StrongPity WastedLocker Zloader
2020-12-15 ⋅ Hornetsecurity ⋅ Hornetsecurity Security Lab
QakBot reducing its on disk artifacts
Egregor PwndLocker QakBot
2020-12-12 ⋅ Medium 0xthreatintel ⋅ 0xthreatintel
Reversing QakBot [ TLP: White]
QakBot
2020-12-10 ⋅ Youtube (OALabs) ⋅ Sergei Frankoff
Malware Triage Analyzing PrnLoader Used To Drop Emotet
Emotet
2020-12-10 ⋅ ⋅ NRI SECURE ⋅ NeoSOC
マルウェア「IcedID」の検知傾向と感染に至るプロセスを徹底解説
IcedID
2020-12-09 ⋅ InfoSec Handlers Diary Blog ⋅ Brad Duncan
Recent Qakbot (Qbot) activity
Cobalt Strike QakBot
2020-12-09 ⋅ Cisco ⋅ Caitlin Huey, David Liebenberg
Quarterly Report: Incident Response trends from Fall 2020
Cobalt Strike IcedID Maze RansomEXX Ryuk
2020-12-09 ⋅ FireEye ⋅ Mitchell Clarke, Tom Hall
It's not FINished The Evolving Maturity in Ransomware Operations (SLIDES)
Cobalt Strike DoppelPaymer QakBot REvil
2020-12-09 ⋅ Microsoft ⋅ Microsoft 365 Defender Research Team
EDR in block mode stops IcedID cold
IcedID
2020-12-04 ⋅ Kaspersky Labs ⋅ Oleg Kupreev
The chronicles of Emotet
Emotet
2020-12-03 ⋅ Recorded Future ⋅ Insikt Group®
Egregor Ransomware, Used in a String of High-Profile Attacks, Shows Connections to QakBot
Egregor QakBot
2020-12-02 ⋅ Red Canary ⋅ twitter (@redcanary)
Tweet on increased #Qbot activity delivering Cobalt Strike & #Egregor ransomware
Cobalt Strike Egregor QakBot
2020-12-02 ⋅ CyberInt ⋅ Cyberint Research
IcedID Stealer Man-in-the-browser Banking Trojan
IcedID
2020-12-01 ⋅ Group-IB ⋅ Group-IB, Oleg Skulkin, Roman Rezvukhin, Semyon Rogachev
Egregor ransomware: The legacy of Maze lives on
Egregor QakBot
2020-11-30 ⋅ FireEye ⋅ Mitchell Clarke, Tom Hall
It's not FINished The Evolving Maturity in Ransomware Operations
Cobalt Strike DoppelPaymer MimiKatz QakBot REvil
2020-11-27 ⋅ malware.love ⋅ Robert Giczewski
Having fun with a Ursnif VBS dropper
ISFB Snifula
2020-11-27 ⋅ Fiducia & GAD IT AG ⋅ Frank Boldewin
When ransomware hits an ATM giant - The Diebold Nixdorf case dissected
PwndLocker QakBot
2020-11-26 ⋅ VirusTotal ⋅ Emiliano Martinez
Using similarity to expand context and map out threat campaigns
Emotet
2020-11-26 ⋅ Cybereason ⋅ Cybereason Nocturnus, Lior Rochberger
Cybereason vs. Egregor Ransomware
Cobalt Strike Egregor IcedID ISFB QakBot
2020-11-22 ⋅ Irshad's Blog ⋅ Irshad Muhammad
Analyzing an Emotet Dropper and Writing a Python Script to Statically Unpack Payload.
Emotet
2020-11-20 ⋅ ZDNet ⋅ Catalin Cimpanu
The malware that usually installs ransomware and you need to remove right away
Avaddon BazarBackdoor Buer Clop Cobalt Strike Conti DoppelPaymer Dridex Egregor Emotet FriedEx MegaCortex Phorpiex PwndLocker QakBot Ryuk SDBbot TrickBot Zloader
2020-11-20 ⋅ Group-IB ⋅ Oleg Skulkin, Roman Rezvukhin, Semyon Rogachev
The Locking Egregor
Egregor QakBot
2020-11-18 ⋅ Cisco ⋅ Edmund Brumaghin, Jaeson Schultz, Nick Biasini
Back from vacation: Analyzing Emotet’s activity in 2020
Emotet
2020-11-12 ⋅ Intrinsec ⋅ Jean Bichet
Egregor – Prolock: Fraternal Twins ?
Egregor PwndLocker QakBot
2020-11-06 ⋅ Security Soup Blog ⋅ Ryan Campbell
Quick Post: Spooky New PowerShell Obfuscation in Emotet Maldocs
Emotet
2020-11-06 ⋅ ⋅ LAC WATCH ⋅ Ishikawa, Matsumoto, Takagen
分析レポート:Emotetの裏で動くバンキングマルウェア「Zloader」に注意
Emotet Zloader
2020-11-05 ⋅ Brim Security ⋅ Oliver Rochford
Hunting Emotet with Brim and Zeek
Emotet
2020-10-29 ⋅ Palo Alto Networks Unit 42 ⋅ Janos Szurdi, Jingwei Fan, Ruian Duan, Seokkyung Chung, Zhanhao Chen
Domain Parking: A Gateway to Attackers Spreading Emotet and Impersonating McAfee
Emotet
2020-10-29 ⋅ CERT-FR ⋅ CERT-FR
LE MALWARE-AS-A-SERVICE EMOTET
Dridex Emotet ISFB QakBot
2020-10-28 ⋅ Bitdefender ⋅ Ruben Andrei Condor
A Decade of WMI Abuse – an Overview of Techniques in Modern Malware
sLoad Emotet Maze
2020-10-20 ⋅ ⋅ Bundesamt für Sicherheit in der Informationstechnik ⋅ BSI
Die Lage der IT-Sicherheit in Deutschland 2020
Clop Emotet REvil Ryuk TrickBot
2020-10-19 ⋅ SPAM Auditor ⋅ Thomas
The Many Faces of Emotet
Emotet
2020-10-16 ⋅ Proofpoint ⋅ Cassandra A., Proofpoint Threat Research Team
Geofenced Amazon Japan Credential Phishing Volumes Rival Emotet
Emotet
2020-10-15 ⋅ Department of Justice ⋅ Department of Justice
Officials Announce International Operation Targeting Transnational Criminal Organization QQAAZZ that Provided Money Laundering Services to High-Level Cybercriminals
Dridex ISFB TrickBot
2020-10-14 ⋅ CrowdStrike ⋅ The Falcon Complete Team
Duck Hunting with Falcon Complete: Remediating a Fowl Banking Trojan, Part 3
QakBot
2020-10-12 ⋅ DeepInstinct ⋅ Ron Ben Yizhak
Why Emotet’s Latest Wave is Harder to Catch Than Ever Before – Part 2
Emotet
2020-10-07 ⋅ CrowdStrike ⋅ The Falcon Complete Team
Duck Hunting with Falcon Complete: Analyzing a Fowl Banking Trojan, Part 2
QakBot Zloader
2020-10-01 ⋅ Proofpoint ⋅ Axel F, Proofpoint Threat Research Team
Emotet Makes Timely Adoption of Political and Elections Lures
Emotet
2020-10-01 ⋅ CrowdStrike ⋅ Dylan Barker, Quinten Bowen, Ryan Campbell
Duck Hunting with Falcon Complete: Analyzing a Fowl Banking Trojan, Part 1
QakBot MALLARD SPIDER
2020-09-29 ⋅ PWC UK ⋅ Andy Auld
What's behind the increase in ransomware attacks this year?
DarkSide Avaddon Clop Conti DoppelPaymer Dridex Emotet FriedEx Mailto PwndLocker QakBot REvil Ryuk SMAUG SunCrypt TrickBot WastedLocker
2020-09-29 ⋅ Microsoft ⋅ Microsoft
Microsoft Digital Defense Report
Emotet IcedID Mailto Maze QakBot REvil RobinHood TrickBot
2020-09-29 ⋅ Seqrite ⋅ Prashant Tilekar
The return of the Emotet as the world unlocks!
Emotet
2020-09-23 ⋅ paloalto Netoworks: Unit42 ⋅ Brad Duncan
Case Study: Emotet Thread Hijacking, an Email Attack Technique
Emotet
2020-09-11 ⋅ ThreatConnect ⋅ ThreatConnect Research Team
Research Roundup: Activity on Previously Identified APT33 Domains
Emotet PlugX APT33
2020-09-10 ⋅ Group-IB ⋅ Oleg Skulkin, Semyon Rogachev
Lock Like a Pro: Dive in Recent ProLock's Big Game Hunting
PwndLocker QakBot
2020-09-10 ⋅ QuoSec GmbH ⋅ Quosec Blog
grap: Automating QakBot strings decryption
QakBot
2020-09-07 ⋅ CERT NZ ⋅ CERT NZ
Emotet Malware being spread via email
Emotet
2020-09-07 ⋅ CERT-FR ⋅ CERT-FR
Bulletin d'alerte du CERT-FR: Recrudescence d’activité Emotet en France
Emotet
2020-09-04 ⋅ QuoSec GmbH ⋅ Quosec Blog
Navigating QakBot samples with grap
QakBot
2020-09-02 ⋅ Cisco Talos ⋅ Edmund Brumaghin, Holger Unterbrink
Salfram: Robbing the place without removing your name tag
Ave Maria ISFB SmokeLoader Zloader
2020-08-31 ⋅ Inde ⋅ Chris Campbell
Analysis of the latest wave of Emotet malicious documents
Emotet
2020-08-28 ⋅ Checkpoint ⋅ Check Point Research
Gozi: The Malware with a Thousand Faces
DreamBot ISFB LOLSnif SaiGon
2020-08-28 ⋅ Proofpoint ⋅ Axel F, Proofpoint Threat Research Team
A Comprehensive Look at Emotet’s Summer 2020 Return
Emotet MUMMY SPIDER
2020-08-27 ⋅ Checkpoint ⋅ Alex Ilgayev
An Old Bot’s Nasty New Tricks: Exploring Qbot’s Latest Attack Methods
QakBot
2020-08-24 ⋅ Hornetsecurity ⋅ Security Lab
Emotet Update increases Downloads
Emotet
2020-08-20 ⋅ Morphisec ⋅ Arnold Osipov
QakBot (QBot) Maldoc Campaign Introduces Two New Techniques into Its Arsenal
QakBot
2020-08-16 ⋅ kienmanowar Blog ⋅ m4n0w4r
Manual Unpacking IcedID Write-up
IcedID
2020-08-14 ⋅ Binary Defense ⋅ James Quinn
EmoCrash: Exploiting a Vulnerability in Emotet Malware for Defense
Emotet
2020-08-12 ⋅ Juniper ⋅ Paul Kimayong
IcedID Campaign Strikes Back
IcedID
2020-08-12 ⋅ DeepInstinct ⋅ Ron Ben Yizhak
Why Emotet’s Latest Wave is Harder to Catch than Ever Before
Emotet
2020-08-10 ⋅ tccontre Blog ⋅ tccontre
Learning From ICEID loader - Including its Steganography Payload Parsing
IcedID
2020-08-09 ⋅ F5 Labs ⋅ Debbie Walkowski, Remi Cohen
Banking Trojans: A Reference Guide to the Malware Family Tree
BackSwap Carberp Citadel DanaBot Dridex Dyre Emotet Gozi Kronos PandaBanker Ramnit Shylock SpyEye Tinba TrickBot Vawtrak Zeus
2020-08-05 ⋅ Github (mauronz) ⋅ Francesco Muroni
Emotet API+string deobfuscator (v0.1)
Emotet
2020-08-01 ⋅ ⋅ TG Soft ⋅ TG Soft
TG Soft Cyber - Threat Report
DarkComet Darktrack RAT Emotet ISFB
2020-07-31 ⋅ Hornetsecurity ⋅ Hornetsecurity Security Lab
The webshells powering Emotet
Emotet
2020-07-30 ⋅ Spamhaus ⋅ Spamhaus Malware Labs
Spamhaus Botnet Threat Update Q2 2020
AdWind Agent Tesla Arkei Stealer AsyncRAT Ave Maria Azorult DanaBot Emotet IcedID ISFB KPOT Stealer Loki Password Stealer (PWS) Nanocore RAT NetWire RC NjRAT Pony Raccoon RedLine Stealer Remcos Zloader
2020-07-29 ⋅ ESET Research ⋅ welivesecurity
THREAT REPORT Q2 2020
DEFENSOR ID HiddenAd Bundlore Pirrit Agent.BTZ Cerber ClipBanker CROSSWALK Cryptowall CTB Locker DanaBot Dharma Formbook Gandcrab Grandoreiro Houdini ISFB LockBit Locky Mailto Maze Microcin Nemty NjRAT Phobos PlugX Pony REvil Socelars STOP Tinba TrickBot WannaCryptor
2020-07-29 ⋅ Sophos Labs ⋅ Andrew Brandt
Emotet’s return is the canary in the coal mine
Emotet
2020-07-28 ⋅ Bleeping Computer ⋅ Sergiu Gatlan
Emotet malware now steals your email attachments to attack contacts
Emotet
2020-07-23 ⋅ Darktrace ⋅ Max Heinemeyer
The resurgence of the Ursnif banking trojan
ISFB Snifula
2020-07-22 ⋅ SentinelOne ⋅ Jason Reaves, Joshua Platt
Enter the Maze: Demystifying an Affiliate Involved in Maze (SNOW)
ISFB Maze TrickBot Zloader
2020-07-20 ⋅ Bleeping Computer ⋅ Lawrence Abrams
Emotet-TrickBot malware duo is back infecting Windows machines
Emotet TrickBot
2020-07-20 ⋅ NTT ⋅ Security division of NTT Ltd.
Shellbot victim overlap with Emotet network infrastructure
Emotet
2020-07-20 ⋅ Hornetsecurity ⋅ Hornetsecurity Security Lab
Emotet is back
Emotet
2020-07-18 ⋅ Hornetsecurity ⋅ Hornetsecurity Security Lab
Firefox Send sends Ursnif malware
ISFB
2020-07-17 ⋅ CERT-FR ⋅ CERT-FR
The Malware Dridex: Origins and Uses
Andromeda CryptoLocker Cutwail DoppelPaymer Dridex Emotet FriedEx Gameover P2P Gandcrab ISFB Murofet Necurs Predator The Thief Zeus
2020-07-15 ⋅ N1ght-W0lf Blog ⋅ Abdallah Elshinbary
Deep Analysis of QBot Banking Trojan
QakBot
2020-07-01 ⋅ ⋅ TG Soft ⋅ TG Soft
Cyber-Threat Report on the cyber attacks of June 2020 in Italy
Avaddon ISFB
2020-07-01 ⋅ Cisco Talos ⋅ Edmund Brumaghin, Mariano Graziano, Nick Biasini
Threat Spotlight: Valak Slithers Its Way Into Manufacturing and Transportation Networks
Valak IcedID ISFB MyKings Spreader
2020-06-24 ⋅ Morphisec ⋅ Arnold Osipov
Obfuscated VBScript Drops Zloader, Ursnif, Qakbot, Dridex
Dridex ISFB QakBot Zloader
2020-06-23 ⋅ NCC Group ⋅ Michael Sandee, Nikolaos Pantazopoulos, Stefano Antenucci
WastedLocker: A New Ransomware Variant Developed By The Evil Corp Group
Cobalt Strike ISFB WastedLocker
2020-06-22 ⋅ zero2auto ⋅ Daniel Bunce
Unpacking Visual Basic Packers – IcedID
IcedID
2020-06-21 ⋅ Malware and Stuff ⋅ Andreas Klopsch
UpnP – Messing up Security since years
QakBot
2020-06-18 ⋅ Juniper ⋅ Paul Kimayong
COVID-19 and FMLA Campaigns used to install new IcedID banking malware
IcedID
2020-06-18 ⋅ NTT Security ⋅ Security division of NTT Ltd.
Behind the scenes of the Emotet Infrastructure
Emotet
2020-06-17 ⋅ Youtube (Red Canary) ⋅ Adam Pennington, David Kaplan, Erika Noerenberg, Matt Graeber
ATT&CK® Deep Dive: Process Injection
ISFB Ramnit TrickBot
2020-06-17 ⋅ Github (f0wl) ⋅ Marius Genheimer
deICEr: A Go tool for extracting config from IcedID second stage Loaders
IcedID
2020-06-16 ⋅ Hornetsecurity ⋅ Security Lab
QakBot malspam leading to ProLock: Nothing personal just business
PwndLocker QakBot
2020-06-12 ⋅ ThreatConnect ⋅ ThreatConnect Research Team
Probable Sandworm Infrastructure
Avaddon Emotet Kimsuky
2020-06-11 ⋅ F5 Labs ⋅ Doron Voolf
Qbot Banking Trojan Still Up to Its Old Tricks
QakBot
2020-06-02 ⋅ Morphisec ⋅ Arnold Osipov
Ursnif/Gozi Delivery - Excel Macro 4.0 Utilization Uptick & OCR Bypass
ISFB
2020-06-02 ⋅ Lastline Labs ⋅ James Haughom, Stefano Ortolani
Evolution of Excel 4.0 Macro Weaponization
Agent Tesla DanaBot ISFB TrickBot Zloader
2020-05-29 ⋅ Group-IB ⋅ Ivan Pisarev
IcedID: When ice burns through bank accounts
IcedID
2020-05-28 ⋅ VMWare Carbon Black ⋅ Ryan Murphy, Tom Kellermann
Modern Bank Heists 3.0
Emotet
2020-05-24 ⋅ Palo Alto Networks Unit 42 ⋅ Ajaya Neupane, Stefan Achleitner
Using AI to Detect Malicious C2 Traffic
Emotet Sality
2020-05-21 ⋅ PICUS Security ⋅ Süleyman Özarslan
T1055 Process Injection
BlackEnergy Cardinal RAT Downdelph Emotet Kazuar RokRAT SOUNDBITE
2020-05-07 ⋅ Github (mlodic) ⋅ Matteo Lodi
Ursnif beacon decryptor
Gozi ISFB
2020-05-05 ⋅ Hornetsecurity ⋅ Security Lab
Awaiting the Inevitable Return of Emotet
Emotet
2020-05-05 ⋅ Malware and Stuff ⋅ Andreas Klopsch
An old enemy – Diving into QBot part 3
QakBot
2020-04-22 ⋅ Youtube (Infosec Alpha) ⋅ Raashid Bhat
FlattenTheCurve - Emotet Control Flow Unflattening | Episode 2
Emotet
2020-04-14 ⋅ Intel 471 ⋅ Intel 471
Understanding the relationship between Emotet, Ryuk and TrickBot
Emotet Ryuk TrickBot
2020-04-03 ⋅ Bleeping Computer ⋅ Sergiu Gatlan
Microsoft: Emotet Took Down a Network by Overheating All Computers
Emotet
2020-03-31 ⋅ Youtube (Infosec Alpha) ⋅ Raashid Bhat
Emotet Binary Deobfuscation | Coconut Paradise | Episode 1
Emotet
2020-03-30 ⋅ Symantec ⋅ Mingwei Zhang, Nguyen Hoang Giang
Emotet: Dangerous Malware Keeps on Evolving
Emotet
2020-03-30 ⋅ Intezer ⋅ Michael Kajiloti
Fantastic payloads and where we find them
Dridex Emotet ISFB TrickBot
2020-03-30 ⋅ Malware and Stuff ⋅ Andreas Klopsch
An old enemy – Diving into QBot part 1
QakBot
2020-03-18 ⋅ Proofpoint ⋅ Axel F, Sam Scholten
Coronavirus Threat Landscape Update
Agent Tesla Get2 ISFB Remcos
2020-03-12 ⋅ Digital Shadows ⋅ Alex Guirakhoo
How cybercriminals are taking advantage of COVID-19: Scams, fraud, and misinformation
Emotet
2020-03-11 ⋅ Twitter (@raashidbhatt) ⋅ Raashid Bhat
Tweet on Emotet Deobfuscation with Video
Emotet
2020-03-06 ⋅ Telekom ⋅ Thomas Barabosch
Dissecting Emotet - Part 2
Emotet
2020-03-06 ⋅ Binary Defense ⋅ James Quinn
Emotet Wi-Fi Spreader Upgraded
Emotet
2020-03-04 ⋅ CrowdStrike ⋅ CrowdStrike
2020 CrowdStrike Global Threat Report
MESSAGETAP More_eggs 8.t Dropper Anchor BabyShark BadNews Clop Cobalt Strike CobInt Cobra Carbon System Cutwail DanaBot Dharma DoppelDridex DoppelPaymer Dridex Emotet FlawedAmmyy FriedEx Gandcrab Get2 IcedID ISFB KerrDown LightNeuron LockerGoga Maze MECHANICAL Necurs Nokki Outlook Backdoor Phobos Predator The Thief QakBot REvil RobinHood Ryuk SDBbot Skipper SmokeLoader TerraRecon TerraStealer TerraTV TinyLoader TrickBot Vidar Winnti ANTHROPOID SPIDER APT23 APT31 APT39 APT40 BlackTech BuhTrap Charming Kitten CLOCKWORK SPIDER DOPPEL SPIDER FIN7 Gamaredon Group GOBLIN PANDA MONTY SPIDER MUSTANG PANDA NARWHAL SPIDER NOCTURNAL SPIDER PINCHY SPIDER SALTY SPIDER SCULLY SPIDER SMOKY SPIDER Thrip VENOM SPIDER VICEROY TIGER
2020-03-03 ⋅ PWC UK ⋅ PWC UK
Cyber Threats 2019:A Year in Retrospect
KevDroid MESSAGETAP magecart AndroMut Cobalt Strike CobInt Crimson RAT DNSpionage Dridex Dtrack Emotet FlawedAmmyy FlawedGrace FriedEx Gandcrab Get2 GlobeImposter Grateful POS ISFB Kazuar LockerGoga Nokki QakBot Ramnit REvil Rifdoor RokRAT Ryuk shadowhammer ShadowPad Shifu Skipper StoneDrill Stuxnet TrickBot Winnti ZeroCleare APT41 MUSTANG PANDA Sea Turtle
2020-03-02 ⋅ ⋅ c't ⋅ Christian Wölbert
Was Emotet anrichtet – und welche Lehren die Opfer daraus ziehen
Emotet Ryuk
2020-02-29 ⋅ ZDNet ⋅ Catalin Cimpanu
Meet the white-hat group fighting Emotet, the world's most dangerous malware
Emotet
2020-02-19 ⋅ FireEye ⋅ FireEye
M-Trends 2020
Cobalt Strike Grateful POS LockerGoga QakBot TrickBot
2020-02-18 ⋅ CERT.PL ⋅ Michał Praszmo
What’s up Emotet?
Emotet
2020-02-18 ⋅ Sophos Labs ⋅ Luca Nagy
Nearly a quarter of malware now communicates using TLS
Dridex IcedID TrickBot
2020-02-13 ⋅ Palo Alto Networks Unit 42 ⋅ Brad Duncan
Wireshark Tutorial: Examining Qakbot Infections
QakBot
2020-02-13 ⋅ Talos ⋅ Edmund Brumaghin, Nick Biasini
Threat actors attempt to capitalize on coronavirus outbreak
Emotet Nanocore RAT Parallax RAT
2020-02-10 ⋅ Malwarebytes ⋅ Adam Kujawa, Chris Boyd, David Ruiz, Jérôme Segura, Jovi Umawing, Nathan Collier, Pieter Arntz, Thomas Reed, Wendy Zamora
2020 State of Malware Report
magecart Emotet QakBot REvil Ryuk TrickBot WannaCryptor
2020-02-08 ⋅ PICUS Security ⋅ Süleyman Özarslan
Emotet Technical Analysis - Part 2 PowerShell Unveiled
Emotet
2020-02-07 ⋅ Binary Defense ⋅ James Quinn
Emotet Evolves With New Wi-Fi Spreader
Emotet
2020-02-03 ⋅ Telekom ⋅ Thomas Barabosch
Dissecting Emotet – Part 1
Emotet
2020-01-30 ⋅ PICUS Security ⋅ Süleyman Özarslan
Emotet Technical Analysis - Part 1 Reveal the Evil Code
Emotet
2020-01-30 ⋅ IBM X-Force Exchange ⋅ Ashkan Vila, Golo Mühr
Coronavirus Goes Cyber With Emotet
Emotet
2020-01-27 ⋅ ⋅ T-Systems ⋅ T-Systems
Vorläufiger forensischer Abschlussbericht zur Untersuchung des Incidents beim Berliner Kammergericht
Emotet TrickBot
2020-01-23 ⋅ SANS ISC InfoSec Forums ⋅ Brad Duncan
German language malspam pushes Ursnif
ISFB
2020-01-17 ⋅ Hiroaki Ogawa, Manabu Niseki
100 more behind cockroaches?
MoqHao Emotet Predator The Thief
2020-01-17 ⋅ Ken Sajo, Yasuhiro Takeda, Yusuke Niwa
Battle Against Ursnif Malspam Campaign targeting Japan
Cutwail ISFB TrickBot UrlZone
2020-01-17 ⋅ JPCERT/CC ⋅ Takayoshi Shiigi
Looking back on the incidents in 2019
TSCookie NodeRAT Emotet PoshC2 Quasar RAT
2020-01-14 ⋅ Bleeping Computer ⋅ Lawrence Abrams
United Nations Targeted With Emotet Malware Phishing Attack
Emotet
2020-01-13 ⋅ Gigamon ⋅ Ed Miles, William Peteroy
Emotet: Not your Run-of-the-mill Malware
Emotet
2020-01-10 ⋅ CSIS ⋅ CSIS
Threat Matrix H1 2019
Gustuff magecart Emotet Gandcrab Ramnit TrickBot
2020-01-07 ⋅ Hatching.io ⋅ Team
Powershell Static Analysis & Emotet results
Emotet
2020-01-03 ⋅ Youtube (BSides Belfast) ⋅ Jorge Rodriguez, Nick Summerlin
Demystifying QBot Banking Trojan
QakBot
2020-01-01 ⋅ Secureworks ⋅ SecureWorks
GOLD LAGOON
QakBot
2020-01-01 ⋅ Secureworks ⋅ SecureWorks
GOLD SWATHMORE
GlobeImposter Gozi IcedID TrickBot LUNAR SPIDER
2020-01-01 ⋅ University of Malta ⋅ Steve Borg
Memory Forensics of Qakbot
QakBot
2020-01-01 ⋅ Secureworks ⋅ SecureWorks
GOLD CRESTWOOD
Emotet MUMMY SPIDER
2019-12-24 ⋅ Sophos ⋅ SophosLabs Threat Research
Gozi V3: tracked by their own stealth
ISFB
2019-12-23 ⋅ Palo Alto Networks Unit 42 ⋅ Brad Duncan
Wireshark Tutorial: Examining Ursnif Infections
ISFB
2019-12-18 ⋅ Github (psrok1) ⋅ Paweł Srokosz
IcedID PNG Extractor
IcedID
2019-12-12 ⋅ FireEye ⋅ Chi-en Shen, Oleg Bondarenko
Cyber Threat Landscape in Japan – Revealing Threat in the Shadow
Cerberus TSCookie Cobalt Strike Dtrack Emotet Formbook IcedID Icefog IRONHALO Loki Password Stealer (PWS) PandaBanker PLEAD POISONPLUG TrickBot BlackTech
2019-12-10 ⋅ JPCERT/CC ⋅ JPCERT/CC
[Updated] Alert Regarding Emotet Malware Infection
Emotet
2019-12-07 ⋅ Secureworks ⋅ Keith Jarvis, Kevin O’Reilly
End-to-end Botnet Monitoring... Botconf 2019
Emotet ISFB QakBot
2019-12-04 ⋅ JPCERT/CC ⋅ Ken Sajo
How to Respond to Emotet Infection (FAQ)
Emotet
2019-12-03 ⋅ Malwarebytes ⋅ Threat Intelligence Team
New version of IcedID Trojan uses steganographic payloads
IcedID
2019-11-12 ⋅ Hatching.io ⋅ Markel Picado
Reversing Qakbot
QakBot
2019-11-06 ⋅ ⋅ Heise Security ⋅ Thomas Hungenberg
Emotet, Trickbot, Ryuk – ein explosiver Malware-Cocktail
Emotet Ryuk TrickBot
2019-10-30 ⋅ Zscaler ⋅ Abhay Yadav, Atinderpal Singh
Emotet is back in action after a short break
Emotet
2019-10-14 ⋅ Marco Ramilli
Is Emotet gang targeting companies with external SOC?
Emotet
2019-09-24 ⋅ Dissecting Malware ⋅ Marius Genheimer
Return of the Mummy - Welcome back, Emotet
Emotet
2019-09-16 ⋅ Malwarebytes ⋅ Threat Intelligence Team
Emotet is back: botnet springs back to life with new spam campaign
Emotet
2019-08-13 ⋅ Adalogics ⋅ David Korczynski
The state of advanced code injections
Dridex Emotet Tinba
2019-08-12 ⋅ ⋅ Schweizerische Eidgenossenschaft ⋅ Schweizerische Eidgenossenschaft
Trojaner Emotet greift Unternehmensnetzwerke an
Emotet
2019-08-07 ⋅ Fortinet ⋅ Xiaopeng Zhang
New Ursnif Variant Spreading by Word Document
ISFB
2019-07-11 ⋅ Proofpoint ⋅ Proofpoint Threat Insight Team
Threat Actor Profile: TA544 targets geographies from Italy to Japan with a range of malware
ISFB PandaBanker UrlZone NARWHAL SPIDER
2019-07-09 ⋅ Fortinet ⋅ Kai Lu
A Deep Dive Into IcedID Malware: Part I - Unpacking, Hooking and Process Injection
IcedID
2019-06-25 ⋅ Dawid Golak
IcedID aka #Bokbot Analysis with Ghidra
IcedID
2019-06-25 ⋅ VMRay ⋅ Tamas Boczan
Analyzing Ursnif’s Behavior Using a Malware Sandbox
ISFB
2019-06-19 ⋅ Proofpoint ⋅ Proofpoint Threat Insight Team
URLZone top malware in Japan, while Emotet and LINE Phishing round out the landscape
ISFB UrlZone NARWHAL SPIDER
2019-06-16 ⋅ Fortinet ⋅ Kai Lu
A Deep Dive Into IcedID Malware: Part II - Analysis of the Core IcedID Payload (Parent Process)
IcedID
2019-06-06 ⋅ Fortinet ⋅ Kai Lu
A Deep Dive into the Emotet Malware
Emotet
2019-06-03 ⋅ Varonis ⋅ Dolev Taler, Eric Saraga
Varonis Exposes Global Cyber Campaign: C2 Server Actively Compromising Thousands of Victims
QakBot
2019-05-25 ⋅ 0ffset Blog ⋅ 0verfl0w_
Analyzing ISFB – The Second Loader
ISFB
2019-05-15 ⋅ Proofpoint ⋅ Axel F, Proofpoint Threat Insight Team
Threat Actor Profile: TA542, From Banker to Malware Distribution Service
Emotet MUMMY SPIDER
2019-05-09 ⋅ GovCERT.ch ⋅ GovCERT.ch
Severe Ransomware Attacks Against Swiss SMEs
Emotet LockerGoga Ryuk TrickBot
2019-05-02 ⋅ Cisco Talos ⋅ Ashlee Benge, Nick Randolph
Qakbot levels up with new obfuscation techniques
QakBot
2019-04-29 ⋅ Blueliv ⋅ Blueliv Labs Team
Where is Emotet? Latest geolocation data
Emotet
2019-04-25 ⋅ Trend Micro ⋅ Trendmicro
Emotet Adds New Evasion Technique
Emotet
2019-04-22 ⋅ int 0xcc blog ⋅ Raashid Bhat
Dissecting Emotet’s network communication protocol
Emotet
2019-04-12 ⋅ SpamTitan ⋅ titanadmin
Emotet Malware Revives Old Email Conversations Threads to Increase Infection Rates
Emotet
2019-04-07 ⋅ Sveatoslav Persianov
Emotet malware analysis. Part 2
Emotet
2019-04-06 ⋅ Youtube (hasherezade) ⋅ hasherezade
Unpacking ISFB (including the custom 'PX' format)
ISFB
2019-04-05 ⋅ Yoroi ⋅ Antonio Pirozzi, Davide Testa
Ursnif: The Latest Evolution of the Most Popular Banking Malware
ISFB
2019-04-04 ⋅ SecurityIntelligence ⋅ Limor Kessem, Nir Somech
IcedID Banking Trojan Spruces Up Injection Tactics to Add Stealth
IcedID
2019-04-01 ⋅ Cafe Babe
Analyzing Emotet with Ghidra — Part 1
Emotet
2019-03-27 ⋅ Spamhaus ⋅ Spamhaus Malware Labs
Emotet adds a further layer of camouflage
Emotet
2019-03-26 ⋅ Yoroi ⋅ Davide Testa, Luca Mella, Luigi Martire
The Ursnif Gangs keep Threatening Italy
ISFB
2019-03-21 ⋅ CrowdStrike ⋅ James Scalise, Shaun Hurley
Interception: Dissecting BokBot’s “Man in the Browser”
IcedID
2019-03-17 ⋅ Persianov on Security ⋅ Sveatoslav Persianov
Emotet malware analysis. Part 1
Emotet
2019-03-15 ⋅ Cofense ⋅ Threat Intelligence
Flash Bulletin: Emotet Epoch 1 Changes its C2 Communication
Emotet
2019-03-13 ⋅ 0ffset Blog ⋅ 0verfl0w_
Analysing ISFB – The First Loader
ISFB
2019-03-12 ⋅ Cybereason ⋅ Assaf Dahan, Cybereason Nocturnus
New Ursnif Variant targets Japan packed with new Features
ISFB UrlZone
2019-03-11 ⋅ Minerva ⋅ Minerva Labs
Attackers Insert Themselves into the Email Conversation to Spread Malware
ISFB
2019-03-08 ⋅ The Daily Swig ⋅ James Walker
Emotet trojan implicated in Wolverine Solutions ransomware attack
Emotet
2019-02-16 ⋅ Max Kersten's Blog ⋅ Max Kersten
Emotet droppers
Emotet
2019-02-15 ⋅ CrowdStrike ⋅ Bex Hartley, Brendon Feeley
“Sin”-ful SPIDERS: WIZARD SPIDER and LUNAR SPIDER Sharing the Same Web
Dyre IcedID TrickBot Vawtrak LUNAR SPIDER WIZARD SPIDER
2019-02-07 ⋅ Yoroi ⋅ Antonio Farina, Antonio Pirozzi, Davide Testa
Ursnif: Long Live the Steganography!
ISFB
2019-02-06 ⋅ SecurityIntelligence ⋅ Itzik Chimino, Limor Kessem, Ophir Harpaz
IcedID Operators Using ATSEngine Injection Panel to Hit E-Commerce Sites
IcedID
2019-01-30 ⋅ Cyberbit ⋅ Hod Gavriel
New Ursnif Malware Variant – a Stunning Matryoshka (Матрёшка)
ISFB
2019-01-24 ⋅ Cisco Talos ⋅ John Arneson
Cisco AMP tracks new campaign that delivers Ursnif
ISFB
2019-01-17 ⋅ SANS ISC InfoSec Forums ⋅ Brad Duncan
Emotet infections and follow-up malware
Emotet
2019-01-15 ⋅ 0ffset Blog ⋅ 0verfl0w_
Analyzing COMmunication in Malware
ISFB
2019-01-05 ⋅ Github (d00rt) ⋅ d00rt
Emotet Research
Emotet
2019-01-03 ⋅ CrowdStrike ⋅ James Scalise, Shaun Hurley
Digging into BokBot’s Core Module
IcedID
2019-01-01 ⋅ D00RT_RM
Emutet
Emotet
2019-01-01 ⋅ CSIS ⋅ Benoît Ancel, Peter Kruse
Dreambot Business overview 2019
ISFB
2018-12-18 ⋅ Trend Micro ⋅ Trendmicro
URSNIF, EMOTET, DRIDEX and BitPaymer Gangs Linked by a Similar Loader
Dridex Emotet FriedEx ISFB
2018-11-16 ⋅ Trend Micro ⋅ Trend Micro
Exploring Emotet: Examining Emotet’s Activities, Infrastructure
Emotet
2018-11-09 ⋅ Youtube (OALabs) ⋅ Sean Wilson, Sergei Frankoff
Reverse Engineering IcedID / Bokbot Malware Part 2
IcedID
2018-11-09 ⋅ ESET Research ⋅ ESET Research
Emotet launches major new spam campaign
Emotet
2018-10-31 ⋅ Kryptos Logic ⋅ Kryptos Logic
Emotet Awakens With New Campaign of Mass Email Exfiltration
Emotet
2018-10-26 ⋅ Youtube (OALabs) ⋅ Sergei Frankoff
Unpacking Bokbot / IcedID Malware - Part 1
IcedID
2018-09-12 ⋅ Cryptolaemus Pastedump ⋅ Cryptolaemus
Emotet IOC
Emotet
2018-09-07 ⋅ Vitali Kremez
Let's Learn: Deeper Dive into "IcedID"/"BokBot" Banking Malware: Part 1
IcedID
2018-08-09 ⋅ Fox-IT ⋅ Alfred Klason
Bokbot: The (re)birth of a banker
IcedID Vawtrak
2018-08-01 ⋅ Kryptos Logic ⋅ Kryptos Logic
Inside Look at Emotet's Global Victims and Malspam Qakbot Payloads
Emotet
2018-07-29 ⋅ Vitali Kremez Blog ⋅ Vitali Kremez
Let's Learn: In-Depth Reversing of Qakbot "qbot" Banker Part 1
QakBot
2018-07-26 ⋅ Intezer ⋅ Itai Tevet
Mitigating Emotet, The Most Common Banking Trojan
Emotet
2018-07-24 ⋅ Check Point ⋅ Ben Herzog, Ofer Caspi
Emotet: The Tricky Trojan that ‘Git Clones’
Emotet
2018-07-23 ⋅ MalFind ⋅ Lasq
Deobfuscating Emotet’s powershell payload
Emotet
2018-07-20 ⋅ NCCIC ⋅ Communications Integration Center, National Cybersecurity
Alert (TA18-201A) Emotet Malware
Emotet
2018-07-18 ⋅ Symantec ⋅ Security Response Attack Investigation Team
The Evolution of Emotet: From Banking Trojan to Threat Distributor
Emotet
2018-05-17 ⋅ Fidelis ⋅ Threat Research Team
Gozi V3 Technical Update
ISFB
2018-04-10 ⋅ Cisco Talos ⋅ Daphne Galme, Michael Gorelik, Ross Gibb
IcedID Banking Trojan Teams up with Ursnif/Dreambot for Distribution
IcedID
2018-03-19 ⋅ hasherezade
Unpacking Ursnif
ISFB
2018-03-18 ⋅ YouTube (BSidesBudapest - IT Security Conference) ⋅ Sandor Nemes
Spying on botnets
Corebot QakBot
2018-03-06 ⋅ Cisco Talos ⋅ Adam Weller, Edmund Brumaghin, Holger Unterbrink
Gozi ISFB Remains Active in 2018, Leverages "Dark Cloud" Botnet For Distribution
ISFB
2018-02-08 ⋅ CrowdStrike ⋅ Adam Meyers
Meet CrowdStrike’s Adversary of the Month for February: MUMMY SPIDER
Emotet MUMMY SPIDER
2018-02-07 ⋅ Cylance ⋅ Threat Research Team
Threat Spotlight: URSNIF Infostealer Malware
ISFB
2018-01-17 ⋅ SANS ISC ⋅ brad
Reviewing the spam filters: Malspam pushing Gozi-ISFB
ISFB
2018-01-12 ⋅ Proofpoint ⋅ Proofpoint Staff
Holiday lull? Not so much
Dridex Emotet GlobeImposter ISFB Necurs PandaBanker UrlZone NARWHAL SPIDER
2018-01-01 ⋅ Quick Heal ⋅ Quick Heal
The Complete story of EMOTET Most prominent Malware of 2018
Emotet
2017-11-28 ⋅ FireEye ⋅ Abhay Vaish, Sandor Nemes
Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection
ISFB
2017-11-15 ⋅ Trend Micro ⋅ Rubio Wu
New EMOTET Hijacks a Windows API, Evades Sandbox and Analysis
Emotet
2017-11-14 ⋅ Digital Guardian ⋅ Chris Brook
IceID Banking Trojan Targeting Banks, Payment Card Providers, E-Commerce Sites
IcedID
2017-11-13 ⋅ Intezer ⋅ Jay Rosenberg
IcedID Banking Trojan Shares Code with Pony 2.0 Trojan
IcedID IcedID Downloader
2017-11-13 ⋅ SecurityIntelligence ⋅ Limor Kessem, Maor Wiesen, Tal Darsan, Tomer Agayev
New Banking Trojan IcedID Discovered by IBM X-Force Research
IcedID IcedID Downloader
2017-11-06 ⋅ Microsoft ⋅ Microsoft Defender ATP Research Team
Mitigating and eliminating info-stealing Qakbot and Emotet in corporate networks
Emotet QakBot
2017-11-06 ⋅ Microsoft ⋅ Microsoft Defender ATP Research Team
Mitigating and eliminating info-stealing Qakbot and Emotet in corporate networks
Emotet
2017-10-12 ⋅ G Data ⋅ G Data
Emotet beutet Outlook aus
Emotet
2017-10-06 ⋅ CERT.PL ⋅ Jarosław Jedynak, Maciej Kotowicz
Peering into spam botnets
Emotet Kelihos Necurs SendSafe Tofsee
2017-09-07 ⋅ Trend Micro ⋅ Don Ladores
EMOTET Returns, Starts Spreading via Spam Botnet
Emotet
2017-07-17 ⋅ Malwarebytes ⋅ Threat Intelligence Team
It’s baaaack: Public cyber enemy Emotet has returned
Emotet
2017-07-02 ⋅ CERT.PL ⋅ Maciej Kotowicz
ISFB: Still Live and Kicking
ISFB
2017-06-02 ⋅ SecurityIntelligence ⋅ Kevin Zuk, Limor Kessem, Matan Meir, Mike Oppenheim
QakBot Banking Trojan Causes Massive Active Directory Lockouts
QakBot
2017-05-31 ⋅ ropgadget.com ⋅ Jeff White
Writing PCRE's for applied passive network defense [Emotet]
Emotet
2017-05-29 ⋅ Lokalhost.pl ⋅ Maciej Kotowicz
Gozi Tree
DreamBot Gozi ISFB Powersniff
2017-05-24 ⋅ CERT.PL ⋅ Paweł Srokosz
Analysis of Emotet v4
Emotet
2017-05-23 ⋅ ThreatVector ⋅ Cylance Threat Research Team
Quakbot
QakBot
2017-05-03 ⋅ Fortinet ⋅ Xiaopeng Zhang
Deep Analysis of New Emotet Variant - Part 1
Emotet
2017-04-20 ⋅ Malwarebytes ⋅ Jérôme Segura
Binary Options malvertising campaign drops ISFB banking Trojan
ISFB
2016-11-01 ⋅ Ariel Koren's Blog ⋅ Ariel Koren
Ursnif Malware: Deep Technical Dive
ISFB
2016-08-01 ⋅ Intel Security ⋅ Guilherme Venere, Mark Olea, Sanchit Karve
DIVING INTO PINKSLIPBOT’S LATEST CAMPAIGN
QakBot
2016-04-28 ⋅ Cisco Talos ⋅ Ben Baker
Research Spotlight: The Resurgence of Qbot
QakBot
2016-04-14 ⋅ SecurityIntelligence ⋅ Limor Kessem, Lior Keshet
Meet GozNym: The Banking Malware Offspring of Gozi ISFB and Nymaim
ISFB Nymaim GozNym
2016-03-23 ⋅ Github (gbrindisi) ⋅ gbrindisi
Gozi ISFB Sourceccode
ISFB
2016-02-24 ⋅ Johannes Bader Blog ⋅ Johannes Bader
The DGA of Qakbot.T
QakBot
2016-01-01 ⋅ BAE Systems ⋅ BAE Systems
The Return of Qbot
QakBot
2015-04-09 ⋅ Kaspersky Labs ⋅ Alexey Shulmin
The Banking Trojan Emotet: Detailed Analysis
Emotet
2013-01-18 ⋅ abuse.ch ⋅ abuse.ch
Feodo Tracker
Emotet
2012-01-01 ⋅ Symantec ⋅ Nicolas Falliere
W32.Qakbot in Detail
QakBot
2011-12-11 ⋅ Open Security Research ⋅ Michael G. Spohn.
Intro. To Reversing - W32Pinkslipbot
QakBot
2011-05-25 ⋅ Contagio Dump ⋅ Mila Parkour
W32.Qakbot aka W32/Pinkslipbot or infostealer worm
QakBot
2010-10-25 ⋅ RSA ⋅ RSA FraudAction Research Labs
Businesses Beware: Qakbot Spreads like a Worm, Stings like a Trojan
QakBot
2010-05-11 ⋅ Symantec ⋅ Shunichi Imano
Qakbot, Data Thief Unmasked: Part I
QakBot
2010-04-22 ⋅ Symantec ⋅ Patrick Fitzgerald
Qakbot Steals 2GB of Confidential Data per Week
QakBot
2009-12-22 ⋅ Symantec ⋅ John McDonald, Masaki Suenaga, Takayoshi Nakayama
Qakbot, Data Thief Unmasked: Part II
QakBot
2009-05-07 ⋅ Symantec ⋅ Angela Thigpen, Eric Chien
W32.Qakbot
QakBot

Credits: MISP Project