SYMBOL | COMMON_NAME | aka. SYNONYMS |
GOLD CABIN is a financially motivated cybercriminal threat group operating a malware distribution service on behalf of numerous customers since 2018. GOLD CABIN uses malicious documents, often contained in password-protected archives, delivered through email to download and execute payloads. The second-stage payloads are most frequently Gozi ISFB (Ursnif) or IcedID (Bokbot), sometimes using intermediary malware like Valak. GOLD CABIN infrastructure relies on artificial appearing and frequently changing URLs created with a domain generation algorithm (DGA). The URLs host a PHP object that returns the malware as a DLL file.
2024-07-29
⋅
Mandiant
⋅
UNC4393 Goes Gently into the SILENTNIGHT Black Basta QakBot sRDI SystemBC Zloader UNC4393 |
2024-07-09
⋅
Spamhaus
⋅
Spamhaus Botnet Threat Update January to June 2024 Coper FluBot Hook Bashlite Mirai FAKEUPDATES AsyncRAT BianLian Cobalt Strike DCRat Havoc NjRAT QakBot Quasar RAT RedLine Stealer Remcos Rhadamanthys RisePro Sliver |
2024-07-02
⋅
Sekoia
⋅
Exposing FakeBat loader: distribution methods and adversary infrastructure BlackCat Royal Ransom EugenLoader Carbanak Cobalt Strike DICELOADER Gozi IcedID Lumma Stealer NetSupportManager RAT Pikabot RedLine Stealer SectopRAT Sliver SmokeLoader Vidar |
2024-05-30
⋅
Europol
⋅
Largest ever operation against botnets hits dropper malware ecosystem BumbleBee IcedID SmokeLoader SystemBC TrickBot |
2024-05-26
⋅
ZW01f
⋅
QakBOT v5 Deep Malware Analysis QakBot |
2024-05-16
⋅
Elastic
⋅
Spring Cleaning with LATRODECTUS: A Potential Replacement for ICEDID IcedID Latrodectus |
2024-05-15
⋅
X (@bryceabdo)
⋅
Tweet on UNC5449 exploiting CVE-2024-30051 to deliver QAKBOT QakBot |
2024-05-15
⋅
Microsoft
⋅
Threat actors misusing Quick Assist in social engineering attacks leading to ransomware Black Basta Cobalt Strike QakBot |
2024-05-14
⋅
Kaspersky
⋅
QakBot attacks with Windows zero-day (CVE-2024-30051) Cobalt Strike QakBot |
2024-04-29
⋅
The DFIR Report
⋅
From IcedID to Dagon Locker Ransomware in 29 Days IcedID Mount Locker |
2024-04-24
⋅
kienmanowar Blog
⋅
[QuickNote] Qakbot 5.0 – Decrypt strings and configuration QakBot |
2024-04-08
⋅
0x0d4y
⋅
IcedID – Technical Analysis of an IcedID Lightweight x64 DLL IcedID |
2024-04-04
⋅
Proofpoint
⋅
Latrodectus: This Spider Bytes Like Ice IcedID Latrodectus |
2024-04-01
⋅
The DFIR Report
⋅
From OneNote to RansomNote: An Ice Cold Intrusion Cobalt Strike IcedID Nokoyawa Ransomware PhotoLoader |
2024-03-26
⋅
Medium zyadlzyatsoc
⋅
Comprehensive Analysis of EMOTET Malware: Part 1 Emotet |
2024-03-17
⋅
Technical Evolution
⋅
Carving the IcedId - Part 3 IcedID |
2024-02-28
⋅
Security Intelligence
⋅
X-Force data reveals top spam trends, campaigns and senior superlatives in 2023 404 Keylogger Agent Tesla Black Basta DarkGate Formbook IcedID Loki Password Stealer (PWS) Pikabot QakBot Remcos |
2024-02-21
⋅
Invoke RE
⋅
Automating Qakbot Malware Analysis with Binary Ninja QakBot |
2024-02-21
⋅
YouTube (Invoke RE)
⋅
Analyzing Qakbot Using Binary Ninja Automation Part 3 QakBot |
2024-02-16
⋅
Malcat
⋅
Writing a Qakbot 5.0 config extractor with Malcat QakBot |
2024-02-15
⋅
Bleeping Computer
⋅
Zeus, IcedID malware gangs leader pleads guilty, faces 40 years in prison Egregor IcedID Maze Zeus |
2024-02-15
⋅
Department of Justice
⋅
Foreign National Pleads Guilty to Role in Cybercrime Schemes Involving Tens of Millions of Dollars in Losses Egregor IcedID Maze Zeus |
2024-02-13
⋅
Proofpoint
⋅
Bumblebee Buzzes Back in Black BumbleBee |
2024-02-11
⋅
Estrellas's Blog
⋅
Unpacking an Emotet trojan Emotet |
2024-02-09
⋅
Censys
⋅
A Beginners Guide to Tracking Malware Infrastructure AsyncRAT BianLian Cobalt Strike QakBot |
2024-02-09
⋅
YouTube (Invoke RE)
⋅
Analyzing and Unpacking Qakbot Using Binary Ninja Automation Part 2 QakBot |
2024-01-31
⋅
Zscaler
⋅
Tracking 15 Years of Qakbot Development QakBot |
2024-01-23
⋅
YouTube (Invoke RE)
⋅
Analyzing and Unpacking Qakbot using Binary Ninja Automation QakBot |
2024-01-16
⋅
Medium walmartglobaltech
⋅
Keyhole Analysis IcedID Keyhole |
2024-01-12
⋅
Spamhaus
⋅
Spamhaus Botnet Threat Update Q4 2023 FluBot Hook FAKEUPDATES AsyncRAT BianLian Cobalt Strike DCRat Havoc IcedID Lumma Stealer Meterpreter NjRAT Pikabot QakBot Quasar RAT RecordBreaker RedLine Stealer Remcos Rhadamanthys Sliver |
2024-01-12
⋅
YouTube (BSides Cambridge UK)
⋅
Slipping The Net: Qakbot, Emotet And Defense Evasion Emotet QakBot |
2024-01-09
⋅
Recorded Future
⋅
2023 Adversary Infrastructure Report AsyncRAT Cobalt Strike Emotet PlugX ShadowPad |
2024-01-09
⋅
0x0d4y
⋅
IcedID – Technical Malware Analysis [Second Stage] IcedID PhotoLoader |
2024-01-04
⋅
K7 Security
⋅
Qakbot Returns QakBot |
2023-12-10
⋅
cocomelonc
⋅
Malware development: persistence - part 23. LNK files. Simple Powershell example. Emotet |
2023-12-05
⋅
YouTube (SecureWorks)
⋅
Emulating Qakbot with Austin Graham QakBot |
2023-11-30
⋅
Twitter (@embee_research)
⋅
Advanced Threat Intel Queries - Catching 83 Qakbot Servers with Regex, Censys and TLS Certificates QakBot |
2023-11-22
⋅
Twitter (@embee_research)
⋅
Practical Queries for Malware Infrastructure - Part 3 (Advanced Examples) BianLian Xtreme RAT NjRAT QakBot RedLine Stealer Remcos |
2023-11-20
⋅
Cofense
⋅
Are DarkGate and PikaBot the new QakBot? DarkGate Pikabot QakBot |
2023-10-13
⋅
Twitter (@JAMESWT_MHT)
⋅
Tweets on Wikiloader delivering ISFB ISFB WikiLoader |
2023-10-12
⋅
Spamhaus
⋅
Spamhaus Botnet Threat Update Q3 2023 FluBot AsyncRAT Ave Maria Cobalt Strike DCRat Havoc IcedID ISFB Nanocore RAT NjRAT QakBot Quasar RAT RecordBreaker RedLine Stealer Remcos Rhadamanthys Sliver Stealc Tofsee Vidar |
2023-10-12
⋅
Netresec
⋅
Forensic Timeline of an IcedID Infection Cobalt Strike IcedID IcedID Downloader |
2023-10-05
⋅
Talos
⋅
Qakbot-affiliated actors distribute Ransom Knight malware despite infrastructure takedown QakBot |
2023-10-04
⋅
Twitter (@Intrisec)
⋅
Tweet about new Bumblebee campaign leveraging CVE-2023-38831 BumbleBee |
2023-09-15
⋅
Johannes Bader's Blog
⋅
The DGA of BumbleBee BumbleBee |
2023-09-11
⋅
Github (m4now4r)
⋅
Unveiling Qakbot Exploring one of the Most Active Threat Actors QakBot |
2023-09-11
⋅
Twitter (@Artilllerie)
⋅
Tweet on BumbleBee sample containing a DGA BumbleBee |
2023-09-07
⋅
Twitter (@Intrisec)
⋅
Tweets on Bumblebee campaign spreading via Html smuggling downloading RAR archive with European Central Bank PDF lure and folder containing Bumblebee EXE payload. BumbleBee |
2023-09-01
⋅
VMRay
⋅
Understanding BumbleBee: BumbleBee’s malware configuration and clusters BumbleBee |
2023-08-29
⋅
US Department of Justice
⋅
Qakbot Malware Disrupted in International Cyber Takedown QakBot |
2023-08-29
⋅
Secureworks
⋅
Law Enforcement Takes Down QakBot QakBot |
2023-08-29
⋅
FBI
⋅
FBI, Partners Dismantle Qakbot Infrastructure in Multinational Cyber Takedown QakBot |
2023-08-29
⋅
KrebsOnSecurity
⋅
U.S. Hacks QakBot, Quietly Removes Botnet Infections QakBot |
2023-08-29
⋅
The Shadowserver Foundation
⋅
Qakbot Botnet Disruption QakBot |
2023-08-29
⋅
US Department of Justice
⋅
Documents and Resources related to the Disruption of the QakBot Malware and Botnet QakBot |
2023-08-29
⋅
Spamhaus
⋅
Qakbot - the takedown and the remediation QakBot |
2023-08-28
⋅
The DFIR Report
⋅
HTML Smuggling Leads to Domain Wide Ransomware Cobalt Strike IcedID Nokoyawa Ransomware |
2023-08-23
⋅
Department of Justice
⋅
Application and Affidavit for a Seizure Warrant by Telephone or other Reliable Electronic Means QakBot |
2023-08-21
⋅
Department of Justice
⋅
Application for a Warrant by Telephone or other reliable Electronic Means QakBot |
2023-08-18
⋅
VMRay
⋅
Understanding BumbleBee: The malicious behavior of BumbleBee BumbleBee |
2023-08-09
⋅
VMRay
⋅
Understanding BumbleBee: The delivery of Bumblee BumbleBee |
2023-08-07
⋅
Team Cymru
⋅
Visualizing Qakbot Infrastructure Part II: Uncharted Territory QakBot |
2023-08-03
⋅
Kaspersky
⋅
What’s happening in the world of crimeware: Emotet, DarkGate and LokiBot LokiBot DarkGate Emotet |
2023-07-31
⋅
Proofpoint
⋅
Out of the Sandbox: WikiLoader Digs Sophisticated Evasion ISFB WikiLoader |
2023-07-31
⋅
d01a
⋅
Pikabot deep analysis Pikabot QakBot |
2023-07-28
⋅
Red Canary
⋅
Drop It Like It's Qbot: Separating malicious droppers, loaders, and crypters from their payloads CloudEyE QakBot |
2023-07-28
⋅
YouTube (SANS Cyber Defense)
⋅
Drop It Like It's Qbot: Separating malicious droppers, loaders, and crypters from their payloads CloudEyE QakBot |
2023-07-28
⋅
Team Cymru
⋅
Inside the IcedID BackConnect Protocol (Part 2) IcedID |
2023-07-25
⋅
Zscaler
⋅
Hibernating Qakbot: A Comprehensive Study and In-depth Campaign Analysis QakBot |
2023-07-23
⋅
Medium infoSec Write-ups
⋅
Unpacking an Emotet Trojan Emotet |
2023-07-18
⋅
Kostas TS
⋅
Ursnif VS Italy: Il PDF del Destino Gozi ISFB Snifula |
2023-07-11
⋅
Spamhaus
⋅
Spamhaus Botnet Threat Update Q2 2023 Hydra AsyncRAT Aurora Stealer Ave Maria BumbleBee Cobalt Strike DCRat Havoc IcedID ISFB NjRAT QakBot Quasar RAT RecordBreaker RedLine Stealer Remcos Rhadamanthys Sliver Tofsee |
2023-07-06
⋅
WeLiveSecurity
⋅
What’s up with Emotet? Emotet |
2023-06-22
⋅
DeepInstinct
⋅
PindOS: New JavaScript Dropper Delivering Bumblebee and IcedID PindOS BumbleBee PhotoLoader |
2023-06-10
⋅
The DFIR Report
⋅
IcedID Brings ScreenConnect and CSharp Streamer to ALPHV Ransomware Deployment BlackCat Cobalt Strike IcedID |
2023-06-08
⋅
Twitter (@embee_research)
⋅
Practical Queries for Identifying Malware Infrastructure: An informal page for storing Censys/Shodan queries Amadey AsyncRAT Cobalt Strike QakBot Quasar RAT Sliver solarmarker |
2023-06-08
⋅
VMRay
⋅
Busy Bees - The Transformation of BumbleBee BumbleBee Cobalt Strike Conti Meterpreter Sliver |
2023-06-01
⋅
Lumen
⋅
Qakbot: Retool, Reinfect, Recycle QakBot |
2023-05-30
⋅
Palo Alto Networks Unit 42
⋅
Cold as Ice: Answers to Unit 42 Wireshark Quiz for IcedID IcedID PhotoLoader |
2023-05-22
⋅
The DFIR Report
⋅
IcedID Macro Ends in Nokoyawa Ransomware IcedID Nokoyawa Ransomware PhotoLoader |
2023-05-21
⋅
Github (0xThiebaut)
⋅
PCAPeek IcedID QakBot |
2023-05-18
⋅
Intezer
⋅
How Hackers Use Binary Padding to Outsmart Sandboxes and Infiltrate Your Systems Emotet |
2023-05-17
⋅
Team Cymru
⋅
Visualizing QakBot Infrastructure QakBot |
2023-05-10
⋅
Bridewell
⋅
Hunting for Ursnif ISFB Royal Ransom |
2023-05-04
⋅
Elastic
⋅
Unpacking ICEDID IcedID PhotoLoader |
2023-05-03
⋅
unpac.me
⋅
UnpacMe Weekly: New Version of IcedId Loader IcedID PhotoLoader |
2023-05-03
⋅
Palo Alto Networks Unit 42
⋅
Teasing the Secrets From Threat Actors: Malware Configuration Parsing at Scale IcedID PhotoLoader |
2023-05-02
⋅
loginsoft
⋅
IcedID Malware: Traversing Through its Various Incarnations IcedID |
2023-04-28
⋅
DISCARDED Podcast
⋅
Beyond Banking: IcedID Gets Forked IcedID PhotoLoader |
2023-04-21
⋅
Sophos
⋅
IcedID: Defrosting a Recent Campaign Illustrating evolving tactics and shared infrastructure IcedID PhotoLoader |
2023-04-20
⋅
Secureworks
⋅
Bumblebee Malware Distributed Via Trojanized Installer Downloads BumbleBee Cobalt Strike |
2023-04-18
⋅
Rapid7 Labs
⋅
Automating Qakbot Detection at Scale With Velociraptor QakBot |
2023-04-18
⋅
Twitter (@threatinsight)
⋅
Tweet on TA581 using Keitaro TDS URL to download a .MSI file to deliver BumbleBee malware BumbleBee |
2023-04-18
⋅
Mandiant
⋅
M-Trends 2023 QUIETEXIT AppleJeus Black Basta BlackCat CaddyWiper Cobalt Strike Dharma HermeticWiper Hive INDUSTROYER2 Ladon LockBit Meterpreter PartyTicket PlugX QakBot REvil Royal Ransom SystemBC WhisperGate |
2023-04-16
⋅
Botconf
⋅
Tracking Bumblebee’s Development BumbleBee |
2023-04-16
⋅
YouTube (botconf eu)
⋅
Tracking Bumblebee’s Development BumbleBee |
2023-04-13
⋅
Sublime
⋅
Detecting QakBot: WSF attachments, OneNote files, and generic attack surface reduction QakBot |
2023-04-12
⋅
SANS ISC
⋅
Recent IcedID (Bokbot) activity IcedID |
2023-04-12
⋅
loginsoft
⋅
Maximizing Threat Detections of Qakbot with Osquery QakBot |
2023-04-12
⋅
InfoSec Handlers Diary Blog
⋅
Recent IcedID (Bokbot) activity IcedID PhotoLoader |
2023-04-12
⋅
Spamhaus
⋅
Spamhaus Botnet Threat Update Q1 2023 FluBot Amadey AsyncRAT Aurora Ave Maria BumbleBee Cobalt Strike DCRat Emotet IcedID ISFB NjRAT QakBot RecordBreaker RedLine Stealer Remcos Rhadamanthys Sliver Tofsee Vidar |
2023-04-11
⋅
Twitter (@Unit42_Intel)
⋅
Tweet on change of IcedID backconnect traffic port from 8080 to 443 IcedID |
2023-04-11
⋅
SEC Consult
⋅
BumbleBee hunting with a Velociraptor BumbleBee |
2023-04-10
⋅
Check Point
⋅
March 2023’s Most Wanted Malware: New Emotet Campaign Bypasses Microsoft Blocks to Distribute Malicious OneNote Files Agent Tesla CloudEyE Emotet Formbook Nanocore RAT NjRAT QakBot Remcos Tofsee |
2023-04-05
⋅
velociraptor
⋅
Automating Qakbot Decode At Scale QakBot |
2023-04-03
⋅
The DFIR Report
⋅
Malicious ISO File Leads to Domain Wide Ransomware Cobalt Strike IcedID Mount Locker |
2023-03-30
⋅
United States District Court (Eastern District of New York)
⋅
Cracked Cobalt Strike (1:23-cv-02447) Black Basta BlackCat LockBit RagnarLocker LockBit Black Basta BlackCat Cobalt Strike Cuba Emotet LockBit Mount Locker PLAY QakBot RagnarLocker Royal Ransom Zloader |
2023-03-30
⋅
loginsoft
⋅
From Innocence to Malice: The OneNote Malware Campaign Uncovered Agent Tesla AsyncRAT DOUBLEBACK Emotet Formbook IcedID NetWire RC QakBot Quasar RAT RedLine Stealer XWorm |
2023-03-30
⋅
eSentire
⋅
eSentire Threat Intelligence Malware Analysis: BatLoader BATLOADER Cobalt Strike ISFB SystemBC Vidar |
2023-03-29
⋅
Krakz
⋅
BumbleBee notes BumbleBee |
2023-03-28
⋅
Cerbero
⋅
Reversing Complex PowerShell Malware BumbleBee |
2023-03-27
⋅
Proofpoint
⋅
Fork in the Ice: The New Era of IcedID IcedID PHOTOFORK PHOTOLITE PhotoLoader |
2023-03-24
⋅
Lab52
⋅
Bypassing Qakbot Anti-Analysis QakBot |
2023-03-22
⋅
Cisco Talos
⋅
Emotet Resumes Spam Operations, Switches to OneNote Emotet |
2023-03-20
⋅
NVISO Labs
⋅
IcedID’s VNC Backdoors: Dark Cat, Anubis & Keyhole IcedID |
2023-03-19
⋅
0xToxin Labs
⋅
Gozi - Italian ShellCode Dance Gozi ISFB |
2023-03-17
⋅
Elastic
⋅
Thawing the permafrost of ICEDID Summary IcedID PhotoLoader |
2023-03-15
⋅
Reliaquest
⋅
QBot: Laying the Foundations for Black Basta Ransomware Activity Black Basta QakBot |
2023-03-13
⋅
Trendmicro
⋅
Emotet Returns, Now Adopts Binary Padding for Evasion Emotet |
2023-03-09
⋅
eSentire
⋅
BatLoader Continues to Abuse Google Search Ads to Deliver Vidar Stealer and Ursnif BATLOADER ISFB Vidar |
2023-03-07
⋅
BleepingComputer
⋅
Emotet malware attacks return after three-month break Emotet |
2023-03-07
⋅
Trellix
⋅
Qakbot Evolves to OneNote Malware Distribution QakBot |
2023-03-07
⋅
Cofense
⋅
Emotet Sending Malicious Emails After Three-Month Hiatus Emotet |
2023-03-04
⋅
0xToxin Labs
⋅
Bumblebee DocuSign Campaign BumbleBee |
2023-03-02
⋅
Netresec
⋅
QakBot C2 Traffic QakBot |
2023-03-02
⋅
Youtube (Microsoft Security Response Center (MSRC))
⋅
BlueHat 2023: Hunting Qakbot with Daniel Taylor & Ben Magee QakBot |
2023-03-01
⋅
Zscaler
⋅
OneNote: A Growing Threat for Malware Distribution AsyncRAT Cobalt Strike IcedID QakBot RedLine Stealer |
2023-02-28
⋅
Intel 471
⋅
Malvertising Surges to Distribute Malware EugenLoader BATLOADER IcedID |
2023-02-27
⋅
PRODAFT Threat Intelligence
⋅
RIG Exploit Kit: In-Depth Analysis Dridex IcedID ISFB PureCrypter Raccoon RecordBreaker RedLine Stealer Royal Ransom Silence SmokeLoader Zloader |
2023-02-26
⋅
Medium Ilandu
⋅
Emotet Campaign Emotet |
2023-02-24
⋅
Medium walmartglobaltech
⋅
Qbot testing malvertising campaigns? QakBot |
2023-02-24
⋅
Team Cymru
⋅
Desde Chile con Malware (From Chile with Malware) IcedID PhotoLoader |
2023-02-17
⋅
cyble
⋅
The Many Faces of Qakbot Malware: A Look at Its Diverse Distribution Methods QakBot |
2023-02-15
⋅
Netresec
⋅
How to Identify IcedID Network Traffic IcedID |
2023-02-14
⋅
⋅
DSIH
⋅
Comment Qbot revient en force avec OneNote ? QakBot |
2023-02-08
⋅
NTT Security
⋅
SteelClover Attacks Distributing Malware Via Google Ads Increased BATLOADER ISFB RedLine Stealer |
2023-02-06
⋅
Sophos
⋅
Qakbot mechanizes distribution of malicious OneNote notebooks QakBot |
2023-02-03
⋅
Mandiant
⋅
Float Like a Butterfly Sting Like a Bee BazarBackdoor BumbleBee Cobalt Strike |
2023-01-30
⋅
Checkpoint
⋅
Following the Scent of TrickGate: 6-Year-Old Packer Used to Deploy the Most Wanted Malware Agent Tesla Azorult Buer Cerber Cobalt Strike Emotet Formbook HawkEye Keylogger Loki Password Stealer (PWS) Maze NetWire RC Remcos REvil TrickBot |
2023-01-26
⋅
Acronis
⋅
Unpacking Emotet Malware Emotet |
2023-01-23
⋅
Kroll
⋅
Black Basta – Technical Analysis Black Basta Cobalt Strike MimiKatz QakBot SystemBC |
2023-01-20
⋅
Blackberry
⋅
Emotet Returns With New Methods of Evasion Emotet IcedID |
2023-01-19
⋅
Cisco
⋅
Following the LNK metadata trail BumbleBee PhotoLoader QakBot |
2023-01-12
⋅
EclecticIQ
⋅
QakBot Malware Used Unpatched Vulnerability to Bypass Windows OS Security Feature QakBot |
2023-01-09
⋅
Intrinsec
⋅
Emotet returns and deploys loaders BumbleBee Emotet IcedID PHOTOLITE |
2023-01-09
⋅
The DFIR Report
⋅
Unwrapping Ursnifs Gifts ISFB |
2022-12-28
⋅
HTML Smuggling Detection QakBot |
2022-12-23
⋅
Trendmicro
⋅
IcedID Botnet Distributors Abuse Google PPC to Distribute Malware IcedID |
2022-12-22
⋅
AhnLab
⋅
Qakbot Being Distributed via Virtual Disk Files (*.vhd) QakBot |
2022-12-21
⋅
Team Cymru
⋅
Inside the IcedID BackConnect Protocol IcedID |
2022-12-19
⋅
kienmanowar Blog
⋅
[Z2A]Bimonthly malware challege – Emotet (Back From the Dead) Emotet |
2022-12-18
⋅
ZAYOTEM
⋅
IcedID Technical Analysis Report IcedID |
2022-12-15
⋅
ISC
⋅
Google ads lead to fake software pages pushing IcedID (Bokbot) IcedID |
2022-12-06
⋅
EuRepoC
⋅
Conti/Wizard Spider BazarBackdoor Cobalt Strike Conti Emotet IcedID Ryuk TrickBot WIZARD SPIDER |
2022-12-05
⋅
Cybereason
⋅
Threat Analysis: MSI - Masquerading as a Software Installer Magniber Matanbuchus QakBot |
2022-12-02
⋅
Github (binref)
⋅
The Refinery Files 0x06: Qakbot Decoder QakBot |
2022-12-01
⋅
splunk
⋅
From Macros to No Macros: Continuous Malware Improvements by QakBot QakBot |
2022-11-30
⋅
Tidal Cyber Inc.
⋅
Identifying and Defending Against QakBot's Evolving TTPs QakBot |
2022-11-28
⋅
The DFIR Report
⋅
Emotet Strikes Again – LNK File Leads to Domain Wide Ransomware Emotet Mount Locker |
2022-11-23
⋅
Cybereason
⋅
THREAT ALERT: Aggressive Qakbot Campaign and the Black Basta Ransomware Group Targeting U.S. Companies Black Basta QakBot |
2022-11-21
⋅
BSides Sydney
⋅
X-Ray of Malware Evasion Techniques - Analysis, Dissection, Cure? Emotet |
2022-11-16
⋅
Proofpoint
⋅
A Comprehensive Look at Emotet Virus’ Fall 2022 Return BumbleBee Emotet PHOTOLITE |
2022-11-14
⋅
Twitter (@embee_research)
⋅
Twitter thread on Yara Signatures for Qakbot Encryption Routines IcedID QakBot |
2022-11-10
⋅
Intezer
⋅
How LNK Files Are Abused by Threat Actors BumbleBee Emotet Mount Locker QakBot |
2022-11-03
⋅
SentinelOne
⋅
Black Basta Ransomware | Attacks deploy Custom EDR Evasion Tools tied to FIN7 Threat Actor Black Basta QakBot SocksBot |
2022-10-31
⋅
Cynet
⋅
Orion Threat Alert: Qakbot TTPs Arsenal and the Black Basta Ransomware Black Basta Cobalt Strike QakBot |
2022-10-31
⋅
Elastic
⋅
ICEDIDs network infrastructure is alive and well IcedID |
2022-10-31
⋅
Security homework
⋅
QakBot CCs prioritization and new record types QakBot |
2022-10-28
⋅
Elastic
⋅
EMOTET dynamic config extraction Emotet |
2022-10-27
⋅
Microsoft
⋅
Raspberry Robin worm part of larger ecosystem facilitating pre-ransomware activity FAKEUPDATES BumbleBee Clop Fauppod Raspberry Robin Roshtyak Silence DEV-0950 Mustard Tempest |
2022-10-27
⋅
Microsoft
⋅
Raspberry Robin worm part of larger ecosystem facilitating pre-ransomware activity FAKEUPDATES BumbleBee Fauppod PhotoLoader Raspberry Robin Roshtyak |
2022-10-24
⋅
Medium CSIS Techblog
⋅
Chapter 1 — From Gozi to ISFB: The history of a mythical malware family. Gozi ISFB Snifula |
2022-10-13
⋅
Spamhaus
⋅
Spamhaus Botnet Threat Update Q3 2022 FluBot Arkei Stealer AsyncRAT Ave Maria BumbleBee Cobalt Strike DCRat Dridex Emotet Loki Password Stealer (PWS) Nanocore RAT NetWire RC NjRAT QakBot RecordBreaker RedLine Stealer Remcos Socelars Tofsee Vjw0rm |
2022-10-13
⋅
Syrion
⋅
QAKBOT BB Configuration and C2 IPs List QakBot |
2022-10-12
⋅
Trend Micro
⋅
Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike Black Basta Brute Ratel C4 Cobalt Strike QakBot |
2022-10-12
⋅
Netresec
⋅
IcedID BackConnect Protocol IcedID |
2022-10-07
⋅
Team Cymru
⋅
A Visualizza into Recent IcedID Campaigns: Reconstructing Threat Actor Metrics with Pure Signal™ Recon IcedID PhotoLoader |
2022-10-06
⋅
Twitter (@ESETresearch)
⋅
Tweet on Bumblebee being modularized like trickbot BumbleBee |
2022-10-03
⋅
Check Point
⋅
Bumblebee: increasing its capacity and evolving its TTPs BumbleBee Cobalt Strike Meterpreter Sliver Vidar |
2022-10-03
⋅
vmware
⋅
Emotet Exposed: A Look Inside the Cybercriminal Supply Chain Emotet |
2022-09-26
⋅
The DFIR Report
⋅
BumbleBee: Round Two BumbleBee Cobalt Strike Meterpreter |
2022-09-13
⋅
AdvIntel
⋅
AdvIntel's State of Emotet aka "SpmTools" Displays Over Million Compromised Machines Through 2022 Conti Cobalt Strike Emotet Ryuk TrickBot |
2022-09-12
⋅
The DFIR Report
⋅
Dead or Alive? An Emotet Story Cobalt Strike Emotet |
2022-09-07
⋅
Google
⋅
Initial access broker repurposing techniques in targeted attacks against Ukraine AnchorMail Cobalt Strike IcedID |
2022-09-07
⋅
cyble
⋅
Bumblebee Returns With New Infection Technique BumbleBee Cobalt Strike |
2022-09-06
⋅
Zscaler
⋅
The Ares Banking Trojan Learns Old Tricks: Adds the Defunct Qakbot DGA Ares QakBot |
2022-09-05
⋅
Infinitum IT
⋅
Bumblebee Loader Malware Analysis BumbleBee |
2022-09-01
⋅
Medium michaelkoczwara
⋅
Hunting C2/Adversaries Infrastructure with Shodan and Censys Brute Ratel C4 Cobalt Strike Deimos GRUNT IcedID Merlin Meterpreter Nighthawk PoshC2 Sliver |
2022-09-01
⋅
Trend Micro
⋅
Ransomware Spotlight Black Basta Black Basta Cobalt Strike MimiKatz QakBot |
2022-08-25
⋅
Palo Alto Networks Unit 42
⋅
Threat Assessment: Black Basta Ransomware Black Basta QakBot |
2022-08-24
⋅
Elastic
⋅
QBOT Malware Analysis QakBot |
2022-08-24
⋅
Microsoft
⋅
Looking for the ‘Sliver’ lining: Hunting for emerging command-and-control frameworks BumbleBee Sliver |
2022-08-24
⋅
Trellix
⋅
Demystifying Qbot Malware QakBot |
2022-08-24
⋅
Deep instinct
⋅
The Dark Side of Bumblebee Malware Loader BumbleBee |
2022-08-23
⋅
Darktrace
⋅
Emotet Resurgence: Cross-Industry Campaign Analysis Emotet |
2022-08-19
⋅
vmware
⋅
How to Replicate Emotet Lateral Movement Emotet |
2022-08-18
⋅
IBM
⋅
From Ramnit To Bumblebee (via NeverQuest): Similarities and Code Overlap Shed Light On Relationships Between Malware Developers BumbleBee Karius Ramnit TrickBot Vawtrak |
2022-08-17
⋅
Cybereason
⋅
Bumblebee Loader – The High Road to Enterprise Domain Control BumbleBee Cobalt Strike |
2022-08-12
⋅
SANS ISC
⋅
Monster Libra (TA551/Shathak) pushes IcedID (Bokbot) with Dark VNC and Cobalt Strike Cobalt Strike DarkVNC IcedID |
2022-08-10
⋅
BitSight
⋅
Emotet SMB Spreader is Back Emotet |
2022-08-10
⋅
⋅
Weixin
⋅
Operation(верность) mercenary: a torrent of steel trapped in the plains of Eastern Europe BumbleBee Cobalt Strike |
2022-08-08
⋅
Medium CSIS Techblog
⋅
An inside view of domain anonymization as-a-service — the BraZZZerSFF infrastructure Riltok magecart Anubis Azorult BetaBot Buer CoalaBot CryptBot DiamondFox DreamBot GCleaner ISFB Loki Password Stealer (PWS) MedusaLocker MeguminTrojan Nemty PsiX RedLine Stealer SmokeLoader STOP TinyNuke Vidar Zloader |
2022-08-08
⋅
The DFIR Report
⋅
BumbleBee Roasts Its Way to Domain Admin BumbleBee Cobalt Strike |
2022-08-04
⋅
Medium walmartglobaltech
⋅
IcedID leverages PrivateLoader IcedID PrivateLoader |
2022-08-04
⋅
Cloudsek
⋅
Technical Analysis of Bumblebee Malware Loader BumbleBee |
2022-08-03
⋅
Palo Alto Networks Unit 42
⋅
Flight of the Bumblebee: Email Lures and File Sharing Services Lead to Malware BazarBackdoor BumbleBee Cobalt Strike Conti |
2022-07-27
⋅
Elastic
⋅
Exploring the QBOT Attack Pattern QakBot |
2022-07-27
⋅
Elastic
⋅
QBOT Configuration Extractor QakBot |
2022-07-27
⋅
SANS ISC
⋅
IcedID (Bokbot) with Dark VNC and Cobalt Strike DarkVNC IcedID |
2022-07-27
⋅
cyble
⋅
Targeted Attacks Being Carried Out Via DLL SideLoading Cobalt Strike QakBot |
2022-07-24
⋅
Bleeping Computer
⋅
QBot phishing uses Windows Calculator sideloading to infect devices QakBot |
2022-07-19
⋅
Fortinet
⋅
New Variant of QakBot Being Spread by HTML File Attached to Phishing Emails QakBot |
2022-07-18
⋅
Palo Alto Networks Unit 42
⋅
Monster Libra Valak IcedID GOLD CABIN |
2022-07-17
⋅
Resecurity
⋅
Shortcut-Based (LNK) Attacks Delivering Malicious Code On The Rise AsyncRAT BumbleBee Emotet IcedID QakBot |
2022-07-12
⋅
Zscaler
⋅
Rise in Qakbot attacks traced to evolving threat techniques QakBot |
2022-07-12
⋅
Cyren
⋅
Example Analysis of Multi-Component Malware Emotet Formbook |
2022-07-07
⋅
SANS ISC
⋅
Emotet infection with Cobalt Strike Cobalt Strike Emotet |
2022-07-07
⋅
Fortinet
⋅
Notable Droppers Emerge in Recent Threat Campaigns BumbleBee Emotet PhotoLoader QakBot |
2022-07-07
⋅
IBM
⋅
Unprecedented Shift: The Trickbot Group is Systematically Attacking Ukraine AnchorMail BumbleBee Cobalt Strike IcedID Meterpreter |
2022-07-05
⋅
Soc Investigation
⋅
QBot Spreads via LNK Files – Detection & Response QakBot |
2022-06-30
⋅
Trend Micro
⋅
Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit Black Basta Cobalt Strike QakBot |
2022-06-28
⋅
Symantec
⋅
Bumblebee: New Loader Rapidly Assuming Central Position in Cyber-crime Ecosystem BumbleBee |
2022-06-27
⋅
Netskope
⋅
Emotet: Still Abusing Microsoft Office Macros Emotet |
2022-06-24
⋅
Group-IB
⋅
We see you, Gozi Hunting the latest TTPs used for delivering the Trojan ISFB |
2022-06-24
⋅
Soc Investigation
⋅
IcedID Banking Trojan returns with new TTPS – Detection & Response IcedID |
2022-06-21
⋅
McAfee
⋅
Rise of LNK (Shortcut files) Malware BazarBackdoor Emotet IcedID QakBot |
2022-06-17
⋅
Github (NtQuerySystemInformation)
⋅
A reverse engineer primer on Qakbot Dll Stager: From initial execution to multithreading. QakBot |
2022-06-16
⋅
ESET Research
⋅
How Emotet is changing tactics in response to Microsoft’s tightening of Office macro security Emotet |
2022-06-14
⋅
RiskIQ
⋅
RiskIQ: Identifying BumbleBee Command and Control Servers BumbleBee |
2022-06-13
⋅
Sekoia
⋅
BumbleBee: a new trendy loader for Initial Access Brokers BumbleBee |
2022-06-09
⋅
InfoSec Handlers Diary Blog
⋅
TA570 Qakbot (Qbot) tries CVE-2022-30190 (Follina) exploit (ms-msdt) QakBot |
2022-06-07
⋅
McAfee
⋅
Phishing Campaigns featuring Ursnif Trojan on the Rise ISFB |
2022-06-07
⋅
cyble
⋅
Bumblebee Loader on The Rise BumbleBee Cobalt Strike |
2022-06-02
⋅
Mandiant
⋅
TRENDING EVIL Q2 2022 CloudEyE Cobalt Strike CryptBot Emotet IsaacWiper QakBot |
2022-05-30
⋅
Automatically Unpacking IcedID Stage 1 with Angr IcedID |
2022-05-27
⋅
Kroll
⋅
Emotet Analysis: New LNKs in the Infection Chain – The Monitor, Issue 20 Emotet |
2022-05-25
⋅
Logpoint
⋅
Buzz of the Bumblebee – A new malicious loader BumbleBee |
2022-05-25
⋅
Team Cymru
⋅
Bablosoft; Lowering the Barrier of Entry for Malicious Actors BlackGuard BumbleBee RedLine Stealer |
2022-05-25
⋅
vmware
⋅
Emotet Config Redux Emotet |
2022-05-24
⋅
Deep instinct
⋅
Blame the Messenger: 4 Types of Dropper Malware in Microsoft Office & How to Detect Them Dridex Emotet |
2022-05-24
⋅
BitSight
⋅
Emotet Botnet Rises Again Cobalt Strike Emotet QakBot SystemBC |
2022-05-19
⋅
InfoSec Handlers Diary Blog
⋅
Bumblebee Malware from TransferXL URLs BumbleBee Cobalt Strike |
2022-05-19
⋅
InfoSec Handlers Diary Blog
⋅
Bumblebee Malware from TransferXL URLs BumbleBee Cobalt Strike |
2022-05-19
⋅
IBM
⋅
ITG23 Crypters Highlight Cooperation Between Cybercriminal Groups IcedID ISFB Mount Locker WIZARD SPIDER |
2022-05-19
⋅
Trend Micro
⋅
Bruised but Not Broken: The Resurgence of the Emotet Botnet Malware Emotet QakBot |
2022-05-17
⋅
Palo Alto Networks Unit 42
⋅
Emotet Summary: November 2021 Through January 2022 Emotet |
2022-05-17
⋅
Trend Micro
⋅
Ransomware Spotlight: RansomEXX LaZagne Cobalt Strike IcedID MimiKatz PyXie RansomEXX TrickBot |
2022-05-16
⋅
vmware
⋅
Emotet Moves to 64 bit and Updates its Loader Emotet |
2022-05-12
⋅
Intel 471
⋅
What malware to look for if you want to prevent a ransomware attack Conti BumbleBee Cobalt Strike IcedID Sliver |
2022-05-12
⋅
OALabs
⋅
Taking a look at Bumblebee loader BumbleBee |
2022-05-11
⋅
InfoSec Handlers Diary Blog
⋅
TA578 using thread-hijacked emails to push ISO files for Bumblebee malware BumbleBee Cobalt Strike IcedID PhotoLoader |
2022-05-11
⋅
SANS ISC
⋅
TA578 using thread-hijacked emails to push ISO files for Bumblebee malware BumbleBee |
2022-05-11
⋅
HP
⋅
Threat Insights Report Q1 - 2022 AsyncRAT Emotet Mekotio Vjw0rm |
2022-05-11
⋅
IronNet
⋅
Detecting a MUMMY SPIDER campaign and Emotet infection Emotet |
2022-05-09
⋅
Microsoft
⋅
Ransomware-as-a-service: Understanding the cybercrime gig economy and how to protect yourself AnchorDNS BlackCat BlackMatter Conti DarkSide HelloKitty Hive LockBit REvil FAKEUPDATES Griffon ATOMSILO BazarBackdoor BlackCat BlackMatter Blister Cobalt Strike Conti DarkSide Emotet FiveHands Gozi HelloKitty Hive IcedID ISFB JSSLoader LockBit LockFile Maze NightSky Pandora Phobos Phoenix Locker PhotoLoader QakBot REvil Rook Ryuk SystemBC TrickBot WastedLocker BRONZE STARLIGHT |
2022-05-09
⋅
Cybereason
⋅
Cybereason vs. Quantum Locker Ransomware IcedID Mount Locker |
2022-05-09
⋅
Netresec
⋅
Emotet C2 and Spam Traffic Video Emotet |
2022-05-08
⋅
Qualys
⋅
Ursnif Malware Banks on News Events for Phishing Attacks ISFB |
2022-05-08
⋅
Threat hunting with hints of incident response
⋅
Bzz.. Bzz.. Bumblebee loader BumbleBee |
2022-05-06
⋅
Netskope
⋅
Emotet: New Delivery Mechanism to Bypass VBA Protection Emotet |
2022-05-04
⋅
Twitter (@felixw3000)
⋅
Twitter Thread with info on infection chain with IcedId, Cobalt Strike, and Hidden VNC. Cobalt Strike IcedID PhotoLoader |
2022-05-04
⋅
Sophos
⋅
Attacking Emotet’s Control Flow Flattening Emotet |
2022-04-29
⋅
NCC Group
⋅
Adventures in the land of BumbleBee – a new malicious loader BazarBackdoor BumbleBee Conti |
2022-04-28
⋅
Proofpoint
⋅
This isn't Optimus Prime's Bumblebee but it's Still Transforming BumbleBee TA578 TA579 |
2022-04-28
⋅
Symantec
⋅
Ransomware: How Attackers are Breaching Corporate Networks AvosLocker Conti Emotet Hive IcedID PhotoLoader QakBot TrickBot |
2022-04-28
⋅
Bleeping Computer
⋅
New Bumblebee malware replaces Conti's BazarLoader in cyberattacks BumbleBee |
2022-04-27
⋅
Cybleinc
⋅
Emotet Returns With New TTPs And Delivers .Lnk Files To Its Victims Emotet |
2022-04-27
⋅
Medium elis531989
⋅
The chronicles of Bumblebee: The Hook, the Bee, and the Trickbot connection BumbleBee TrickBot |
2022-04-26
⋅
Intel 471
⋅
Conti and Emotet: A constantly destructive duo Cobalt Strike Conti Emotet IcedID QakBot TrickBot |
2022-04-26
⋅
Proofpoint
⋅
Emotet Tests New Delivery Techniques Emotet |
2022-04-26
⋅
Bleeping Computer
⋅
Emotet malware now installs via PowerShell in Windows shortcut files Emotet |
2022-04-25
⋅
The DFIR Report
⋅
Quantum Ransomware Cobalt Strike IcedID |
2022-04-24
⋅
forensicitguy
⋅
Shortcut to Emotet, an odd TTP change Emotet |
2022-04-20
⋅
CISA
⋅
AA22-110A Joint CSA: Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure VPNFilter BlackEnergy DanaBot DoppelDridex Emotet EternalPetya GoldMax Industroyer Sality SmokeLoader TrickBot Triton Zloader |
2022-04-20
⋅
CISA
⋅
Alert (AA22-110A): Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure VPNFilter BlackEnergy DanaBot DoppelDridex Emotet EternalPetya GoldMax Industroyer Sality SmokeLoader TrickBot Triton Zloader Killnet |
2022-04-20
⋅
cocomelonc
⋅
Malware development: persistence - part 1. Registry run keys. C++ example. Agent Tesla Amadey BlackEnergy Cobian RAT COZYDUKE Emotet Empire Downloader Kimsuky |
2022-04-20
⋅
SANS ISC
⋅
'aa' distribution Qakbot (Qbot) infection with DarkVNC traffic QakBot |
2022-04-19
⋅
Bleeping Computer
⋅
Emotet botnet switches to 64-bit modules, increases activity Emotet |
2022-04-19
⋅
Twitter (@Cryptolaemus1)
⋅
#Emotet Update: 64 bit upgrade of Epoch 5 Emotet |
2022-04-18
⋅
Fortinet
⋅
Trends in the Recent Emotet Maldoc Outbreak Emotet |
2022-04-17
⋅
Malwarology
⋅
Qakbot Series: API Hashing QakBot |
2022-04-17
⋅
BushidoToken Blog
⋅
Lessons from the Conti Leaks BazarBackdoor Conti Emotet IcedID Ryuk TrickBot |
2022-04-16
⋅
Malwarology
⋅
Qakbot Series: Process Injection QakBot |
2022-04-14
⋅
Avast Decoded
⋅
Zloader 2: The Silent Night ISFB Raccoon Zloader |
2022-04-14
⋅
Bleeping Computer
⋅
Hackers target Ukrainian govt with IcedID malware, Zimbra exploits IcedID |
2022-04-14
⋅
⋅
Cert-UA
⋅
Cyberattack on Ukrainian state organizations using IcedID malware (CERT-UA#4464) IcedID |
2022-04-14
⋅
Cynet
⋅
Orion Threat Alert: Flight of the BumbleBee BumbleBee Cobalt Strike |
2022-04-13
⋅
Kaspersky
⋅
Emotet modules and recent attacks Emotet |
2022-04-13
⋅
Malwarology
⋅
Qakbot Series: Configuration Extraction QakBot |
2022-04-12
⋅
Check Point
⋅
March 2022’s Most Wanted Malware: Easter Phishing Scams Help Emotet Assert its Dominance Alien FluBot Agent Tesla Emotet |
2022-04-12
⋅
AhnLab
⋅
SystemBC Being Used by Various Attackers Emotet SmokeLoader SystemBC |
2022-04-12
⋅
Tech Times
⋅
Qbot Botnet Deploys Malware Payloads Through Malicious Windows Installers QakBot |
2022-04-11
⋅
Bleeping Computer
⋅
Qbot malware switches to new Windows Installer infection vector QakBot |
2022-04-10
⋅
Malwarology
⋅
Qakbot Series: String Obfuscation QakBot |
2022-04-08 ⋅ ReversingLabs ⋅ |