Click here to download all references as Bib-File.

Enter keywords to filter the library entries below or Propose new Entry
2026-09-10FortinetRachael Liao
Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers
Metamorfo
2026-08-30Medium 0xzyadelzyatZyad Elzyat
Reverse Engineering the Auto-Color Linux Backdoor
Auto-Color
2026-08-27ProofpointKyle Cucci, Proofpoint Threat Research Team, Rob Kinner, Tony Robinson
Carry-On Compromise: TA4922 Packs PackClient
donut_injector
2026-08-24Field EffectDamon Toumbourou, Hugh Whitewood
A ClickFix cluster: Observed activity from recent ClickFix campaigns
Lorem Ipsum
2026-08-21NetresecErik Hjelmvik
CNCMachineRMS C2 Protocol
Babadeda
2026-08-20trendaiAliakbar Zahravi
Prompting the Payload: How an npm Supply Chain Attack Delivers the RedC2 AI-Powered Linux Implant
redshell
2026-08-19BitdefenderMartin Zugec
SilkParasite: Tracking a China-Nexus APT Across Central Asia
BloodAlchemy ShadowPad SNAPPYBEE SilkParasite
2026-08-18BitSightBitsight TRACE
Who Invited Aisuru to the LAN Party?
Kimwolf Aisuru
2026-08-17ZscalerZscaler ThreatLabz
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
C2Looper
2026-08-15neso.reneso
Borrowed Machinery: SnappyClient, HijackLoader, and a Shared Codebase?
HijackLoader SnappyClient
2026-08-14QUIRSO GmbHÇağatay Yürekli, Denis Szadkowski, Maike Orlikowski
Global Exploitation of CVE-2026–59310 by Suspected Chinese-Nexus APT & Related CVE-2026–59309 Activity
2026-08-14Ministere de l'Economie et des FinancesElvire MACE
Illegitimate access to the information system of the Directorate General of Public Finances
ZeroBytes
2026-08-10AhnLabASEC
Attack Cases for Domestic Web Servers Running SoftEther VPN in Korea
Larva-26010
2026-08-10LevelBlueRodel Mendrez
CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain
Babadeda
2026-08-10sonatypeSonatype Research Team
Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads
JADESNOW
2026-08-03AhnLabASEC
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)
CRAT DRATzarus Larva-26005
2026-08-02AhnLabASEC
Analysis of a Phishing Email Attack Case by the Larva-24009 Threat Actor
Quasar RAT Larva-24009
2026-07-31StealthMoleStealthMole
The Many Faces of ModernStealer: Tracing an Underground Military Data Network
ModernStealer
2026-07-30AhnLabAhnLab
[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)
Gunra
2026-07-29SafeDepSafeDep Team
Joyfill npm Packages Compromised with Blockchain C2 Loader
JADESNOW