Click here to download all references as Bib-File.•
| 2026-08-03
⋅
AhnLab
⋅
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005) CRAT DRATzarus |
| 2026-07-31
⋅
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft ChocoShell CornFlake Storm-2945 |
| 2026-07-30
⋅
AhnLab
⋅
[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group) Gunra |
| 2026-07-28
⋅
StepSecurity
⋅
Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan JADESNOW |
| 2026-07-28
⋅
Hunt.io
⋅
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon |
| 2026-07-27
⋅
Netresec
⋅
PureLogs, PureRAT and misleading zgRAT PureLogs Stealer PureRAT zgRAT |
| 2026-07-23
⋅
NSA
⋅
NSA and Partners Alert Zimbra Collaboration Suite Users of a Russian State-Supported Phishing Campaign ZimReaper |
| 2026-07-23
⋅
Proofpoint
⋅
Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458 SpyPress |
| 2026-07-23
⋅
Proofpoint
⋅
TA488 Targets Zimbra Mailservers with Half-Click Exploits ZimReaper |
| 2026-07-23
⋅
Group-IB
⋅
JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake AdaptixC2 reGeorg |
| 2026-07-22
⋅
Prophet Security
⋅
EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain |
| 2026-07-22
⋅
Huntress Labs
⋅
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT SectopRAT |
| 2026-07-20
⋅
Medium Ireneusz Tarnowski
⋅
INC Ransom: Infrastructure Analysis, Operational Tradecraft, and Detection Opportunities INC INC |
| 2026-07-15
⋅
Zscaler
⋅
ClaudeFix: Shared Claude Chats Meet ClickFix MacSync |
| 2026-07-15
⋅
Symantec
⋅
Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor Daxin |
| 2026-07-14
⋅
Ctrl-Alt-Intel
⋅
Burnt by Burgers: Highlighting Void Blizzard’s Russian State Links |
| 2026-07-13
⋅
kienmanowar Blog
⋅
[QuickNote] SolidPDFCreator – Mustang Panda Stage-1 Backdoor (Target India) |
| 2026-07-12
⋅
OX Security
⋅
Malware-Slop: Crypto Stealer Impersonating Polymarket Exposes Its Own Credentials OtterCandy |
| 2026-07-07
⋅
Proofpoint
⋅
One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation IceCube |
| 2026-07-07
⋅
Cisco Talos
⋅
UAT-7810 continues building ORB networks using new malware DOGLEASH LONGLEASH JARLEASH UAT-7810 |