Click here to download all references as Bib-File.•
| 2025-09-16
            
            ⋅
            
            Proofpoint
            ⋅ Going Underground: China-aligned TA415 Conducts U.S.-China Economic Relations Targeting Using VS Code Remote Tunnels | 
| 2025-05-13
            
            ⋅
            
            Proofpoint
            ⋅ TA406 Pivots to the Front TA406 | 
| 2025-04-17
            
            ⋅
            
            Proofpoint
            ⋅ Around the World in 90 Days: State-Sponsored Actors Try ClickFix Quasar RAT UNK_RemoteRogue | 
| 2024-02-27
            
            ⋅
            
            Twitter (@greglesnewich)
            ⋅ Tweet with context on TA421 / APT29 / Midnight Blizzard / BlueBravo / Cozy Bear WINELOADER | 
| 2024-01-05
            
            ⋅
            
            Twitter (@greglesnewich)
            ⋅ Tweets about a SpectralBlur a macOS sample SpectralBlur | 
| 2023-12-05
            
            ⋅
            
            Proofpoint
            ⋅ TA422’s Dedicated Exploitation Loop—the Same Week After Week | 
| 2023-01-25
            
            ⋅
            
            Proofpoint
            ⋅ TA444: The APT Startup Aimed at Acquisition (of Your Funds) CageyChameleon Lazarus Group TA444 |