Click here to download all references as Bib-File.•
| 2026-06-01
⋅
Nextron Systems
⋅
Detecting Nimbus Manticore and their sideloading infection chains MiniFast |
| 2026-05-31
⋅
Socket
⋅
Famous Chollima Targets PHP Developers Through Compromised Packagist Package JADESNOW |
| 2026-05-27
⋅
bluecyber
⋅
MUSTANG PANDA x PLUGX - Analysis of the January 2026 sample: a multi-layer execution chain PlugX |
| 2026-05-26
⋅
Intrinsec
⋅
Pivoting on a malspam infrastructure delivering JS malware backed by bulletproof networks |
| 2026-05-24
⋅
cocomelonc
⋅
Malware shellcode delivery via signal - part 1. FSK Basics. Simple python script |
| 2026-05-22
⋅
Check Point
⋅
Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict MiniFast |
| 2026-05-22
⋅
Trend Micro
⋅
Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware BeaverTail InvisibleFerret |
| 2026-05-21
⋅
PWC
⋅
Inside Red Lamassu’s JFMBackdoor JFMBackdoor |
| 2026-05-20
⋅
K7 Security
⋅
Fake Microsoft Teams download sites are being used to deliver ValleyRAT via DLL sideloading ValleyRAT |
| 2026-05-18
⋅
Zynap
⋅
Zynap’s Next-Gen Sandbox Redefines Automatic Malware Analysis Black Basta HijackLoader |
| 2026-05-18
⋅
Gen Threat Labs
⋅
X.com - Gen Threat Labs - AuraStealer (version 1.8.0) Aura Stealer |
| 2026-05-17
⋅
Github (zanez)
⋅
Analysis on Malware that attacks Israel's Water treatment facilities ZionSiphon |
| 2026-05-14
⋅
ESET Research
⋅
FrostyNeighbor: Fresh mischief and digital shenanigans Cobalt Strike PicassoLoader |
| 2026-05-14
⋅
ANY.RUN
⋅
LATAM Under Siege: Agent Tesla’s 18-Month Credential Theft Campaign Against Chilean Enterprises Agent Tesla |
| 2026-05-14
⋅
Microsoft
⋅
Kazuar: Anatomy of a nation-state botnet Kazuar |
| 2026-05-13
⋅
Check Point Research
⋅
THUS SPOKE…THE GENTLEMEN Gentlemen |
| 2026-05-13
⋅
0x3oBAD
⋅
MustangPanda New Backdoor LotusLite LOTUSLITE |
| 2026-05-11
⋅
Tweet about Lalia Ransomware Lalia Ransomware |
| 2026-05-11
⋅
urlscan.io
⋅
Darcula aka. "Magic Cat" |
| 2026-05-11
⋅
ThreatFabric
⋅
New TrickMo Variant: Device Take Over malware targeting Banking, Fintech, Wallet & Auth apps TrickMo |