Click here to download all references as Bib-File.•
| 2026-07-28
⋅
Hunt.io
⋅
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon |
| 2026-07-22
⋅
Huntress Labs
⋅
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT SectopRAT |
| 2026-07-15
⋅
Symantec
⋅
Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor Daxin |
| 2026-06-18
⋅
Politie NL
⋅
International law enforcement initiate hunt on malware group SocGholish FAKEUPDATES |
| 2026-06-16
⋅
Huntress Labs
⋅
Potemkin Loader & RMMProject - The Anatomy of a ClickFix Attack EtherRAT Chisel Potemkin |
| 2026-06-15
⋅
Medium (@mrtiepolo)
⋅
Operation Turb00 — Part 1: Analyzing and Hunting a Vidar Campaign Vidar |
| 2026-05-16
⋅
Symantec
⋅
Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations fast16 |
| 2026-05-05
⋅
Red Asgard
⋅
Hunting Lazarus Part VII: The Server That Was Not Just FTP BeaverTail OtterCookie |
| 2026-03-17
⋅
Hunt.io
⋅
Iranian Botnet Exposed via Open Directory: 15-Node Relay Network and Active C2 |
| 2026-03-11
⋅
Hunt.io
⋅
Operation Roundish: Uncovering an APT28 Roundcube Toolkit Used Against Ukrainian Government Targets |
| 2026-03-05
⋅
Symantec
⋅
Seedworm: Iranian APT on Networks of U.S. Bank, Airport, Software Company Tsundere |
| 2026-03-04
⋅
Huntress Labs
⋅
"Malware, from the Outside!": How a Threat Actor Used Fake OpenClaw Installers to Infect Systems with GhostSocks and Information Stealers GhostSocks Vidar |
| 2026-03-04
⋅
Hunt.io
⋅
Iranian APT Infrastructure in Focus: Mapping State-Aligned Clusters During Geopolitical Escalation |
| 2026-02-24
⋅
Symantec
⋅
North Korean Lazarus Group Now Working With Medusa Ransomware ComeBacker Medusa |
| 2026-02-17
⋅
Hunt.io
⋅
Fake Homebrew Typosquats Used to Deliver Cuckoo Stealer via ClickFix |
| 2026-02-16
⋅
Huntress Labs
⋅
ClickFix Won't Die. Neither Will Matanbuchus. A New RAT and a Hands-on-Keyboard Intrusion AstarionRAT Matanbuchus |
| 2026-02-05
⋅
Symantec
⋅
Reynolds: Defense Evasion Capability Embedded in Ransomware Payload Reynolds |
| 2026-01-30
⋅
Google
⋅
Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft UNC6671 |
| 2026-01-28
⋅
Hunt.io
⋅
Exposed Open Directory Leaks a Full BYOB Deployment Across Windows, Linux, and macOS |
| 2026-01-22
⋅
Red Asgard
⋅
Hunting Lazarus Part II: When the Dead Drop Moved to the Blockchain StoatWaffle |