Click here to download all references as Bib-File.

Enter keywords to filter the library entries below or Propose new Entry
2026-03-03MicrosoftMicrosoft
Signed malware impersonating workplace apps deploys RMM backdoors
TrustConnect RAT
2026-03-02abuse.chabuse.ch
MalwareBazaar | SHA256 8011996692048501c1eccb66a2771546ade084806f48994104d199e28af82a4c (ArcaneStealer)
ArcaneStealer
2026-02-27IntrinsecGilbert Kallenborn
Analysis of AuraStealer, an emerging infostealer
Aura Stealer
2026-02-26kmsecKieran Miyamoto
Novel DPRK stager using Pastebin and text steganography
2026-02-25Hive ProHive Pro
SANDWORM_MODE: npm Supply Chain Attack Targeting AI Development Tools
2026-02-25FortiGuard LabsAriel Davidpur
Unmasking Agent Tesla: A Deep Dive into a Multi-Stage Campaign
Agent Tesla
2026-02-25Abstract SecurityAbstract Security Threat Research Organization (ASTRO)
Contagious Interview: Evolution of VS Code and Cursor Tasks Infection Chains - Part 1
BeaverTail PylangGhost GolangGhost
2026-02-25Twitter (@anyrun_app)Achmad Adhikara, ANY.RUN
Tweet about KarstoRAT
KarstoRAT
2026-02-24BlueVoyantJoshua Green, Patrick Mchale
Mercenary Akula Hits Ukraine-Supporting Financial Institution
RMS
2026-02-24SymantecThreat Hunter Team
North Korean Lazarus Group Now Working With Medusa Ransomware
ComeBacker Medusa
2026-02-24MicrosoftMicrosoft Defender Experts
Developer-targeting campaign using malicious Next.js repositories
2026-02-24abuse.chabuse.ch
MalwareBazaar | SHA256 63deffbdd4053a38c95221589cc2ddd0595d451808a79432fa9f5476c4542390 (WalkLoader)
WalkLoader
2026-02-23Twitter (@Manu_De_Lucia)Emanuele De Lucia
Tweet about IronZero
IronZero
2026-02-23DisInfoDisInfo
Technical attack, public discredit and isolation! The history of an IT company in Moldova, pushed outside the European market
2026-02-23abuse.chabuse.ch
MalwareBazaar | SHA256 be2db69fbde37ce4b0dbd51a85cb18f78a1bfda70ef2f4ed7dcde75051f3659b (RatonRAT)
RatonRAT
2026-02-22Securite360.netMuffin
OPSEC on a Budget: What BadAudio Reveals About APT24
BADAUDIO
2026-02-22kmsecKieran Miyamoto
Tracking DPRK operator IPs over time
2026-02-21kmsecKieran Miyamoto
DPRK tests Google Drive as a malware stager
2026-02-19ElasticElastic Security Labs
MIMICRAT: ClickFix Campaign Delivers Custom RAT via Compromised Legitimate Websites
AstarionRAT
2026-02-19ProofpointProofpoint
(Don't) TrustConnect: It's a RAT in an RMM hat
TrustConnect RAT