Click here to download all references as Bib-File.•
| 2026-09-10
⋅
Fortinet
⋅
Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers Metamorfo |
| 2026-09-09
⋅
⋅
Orange CERT
⋅
Koktevrat – a multi-stage Android RAT distributed under the guise of the MandatGO app Koktevrat |
| 2026-09-02
⋅
Malware INFO
⋅
Fake GlobalProtect MSI Targets Myanmar Using Cloudflare and Google Sheets as C2 Unidentified 126 (GoogleSheets C2) |
| 2026-08-30
⋅
Medium 0xzyadelzyat
⋅
Reverse Engineering the Auto-Color Linux Backdoor Auto-Color |
| 2026-08-27
⋅
Proofpoint
⋅
Carry-On Compromise: TA4922 Packs PackClient donut_injector |
| 2026-08-24
⋅
Field Effect
⋅
A ClickFix cluster: Observed activity from recent ClickFix campaigns Lorem Ipsum |
| 2026-08-21
⋅
Bitso Quetzal Team
⋅
North Korea’s Crypt: Hunting Ghosts StoatWaffle |
| 2026-08-21
⋅
Netresec
⋅
CNCMachineRMS C2 Protocol Babadeda |
| 2026-08-20
⋅
trendai
⋅
Prompting the Payload: How an npm Supply Chain Attack Delivers the RedC2 AI-Powered Linux Implant redshell |
| 2026-08-19
⋅
zimperium
⋅
The ToxicPanda Never Sleeps: ToxicPanda 2.0 Prepares its Next Strike on Mobile ToxicPanda |
| 2026-08-19
⋅
Bitdefender
⋅
SilkParasite: Tracking a China-Nexus APT Across Central Asia BloodAlchemy ShadowPad SNAPPYBEE SilkParasite |
| 2026-08-18
⋅
Gen
⋅
WordlistLoader Delivering Amatera via ClearFake Campaigns ACR Stealer Amatera |
| 2026-08-17
⋅
Zscaler
⋅
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2 C2Looper |
| 2026-08-15
⋅
neso.re
⋅
Borrowed Machinery: SnappyClient, HijackLoader, and a Shared Codebase? HijackLoader SnappyClient |
| 2026-08-14
⋅
QUIRSO GmbH
⋅
Global Exploitation of CVE-2026–59310 by Suspected Chinese-Nexus APT & Related CVE-2026–59309 Activity |
| 2026-08-11
⋅
Aryaka Network
⋅
Beyond the Batch File Analysis of a Multi-Stage DonutLoader Infection Chain donut_injector |
| 2026-08-10
⋅
AhnLab
⋅
Attack Cases for Domestic Web Servers Running SoftEther VPN in Korea Larva-26010 |
| 2026-08-10
⋅
sonatype
⋅
Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads JADESNOW |
| 2026-08-07
⋅
⋅
Kaspersky
⋅
The APT group Head Mare exploits vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph malware to video conferencing participants PhantomCore PhantomGraph |
| 2026-08-05
⋅
SOC Prime
⋅
SmartApeSG Pushes an Unknown RAT Through ClickFix Lures SmartApeSG |