Click here to download all references as Bib-File.•
| 2026-09-10
⋅
Fortinet
⋅
Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers Metamorfo |
| 2026-08-30
⋅
Medium 0xzyadelzyat
⋅
Reverse Engineering the Auto-Color Linux Backdoor Auto-Color |
| 2026-08-27
⋅
Proofpoint
⋅
Carry-On Compromise: TA4922 Packs PackClient donut_injector |
| 2026-08-24
⋅
Field Effect
⋅
A ClickFix cluster: Observed activity from recent ClickFix campaigns Lorem Ipsum |
| 2026-08-21
⋅
Netresec
⋅
CNCMachineRMS C2 Protocol Babadeda |
| 2026-08-20
⋅
trendai
⋅
Prompting the Payload: How an npm Supply Chain Attack Delivers the RedC2 AI-Powered Linux Implant redshell |
| 2026-08-19
⋅
Bitdefender
⋅
SilkParasite: Tracking a China-Nexus APT Across Central Asia BloodAlchemy ShadowPad SNAPPYBEE SilkParasite |
| 2026-08-18
⋅
BitSight
⋅
Who Invited Aisuru to the LAN Party? Kimwolf Aisuru |
| 2026-08-17
⋅
Zscaler
⋅
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2 C2Looper |
| 2026-08-15
⋅
neso.re
⋅
Borrowed Machinery: SnappyClient, HijackLoader, and a Shared Codebase? HijackLoader SnappyClient |
| 2026-08-14
⋅
QUIRSO GmbH
⋅
Global Exploitation of CVE-2026–59310 by Suspected Chinese-Nexus APT & Related CVE-2026–59309 Activity |
| 2026-08-14
⋅
⋅
Ministere de l'Economie et des Finances
⋅
Illegitimate access to the information system of the Directorate General of Public Finances ZeroBytes |
| 2026-08-10
⋅
AhnLab
⋅
Attack Cases for Domestic Web Servers Running SoftEther VPN in Korea Larva-26010 |
| 2026-08-10
⋅
LevelBlue
⋅
CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain Babadeda |
| 2026-08-10
⋅
sonatype
⋅
Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads JADESNOW |
| 2026-08-03
⋅
AhnLab
⋅
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005) CRAT DRATzarus Larva-26005 |
| 2026-08-02
⋅
AhnLab
⋅
Analysis of a Phishing Email Attack Case by the Larva-24009 Threat Actor Quasar RAT Larva-24009 |
| 2026-07-31
⋅
StealthMole
⋅
The Many Faces of ModernStealer: Tracing an Underground Military Data Network ModernStealer |
| 2026-07-30
⋅
AhnLab
⋅
[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group) Gunra |
| 2026-07-29
⋅
SafeDep
⋅
Joyfill npm Packages Compromised with Blockchain C2 Loader JADESNOW |