Click here to download all references as Bib-File.

Enter keywords to filter the library entries below or Propose new Entry
2026-09-10FortinetRachael Liao
Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers
Metamorfo
2026-09-09Orange CERTIreneusz Tarnowski, Olaf Grzybowski
Koktevrat – a multi-stage Android RAT distributed under the guise of the MandatGO app
Koktevrat
2026-09-02Malware INFOMalware INFO Research Team
Fake GlobalProtect MSI Targets Myanmar Using Cloudflare and Google Sheets as C2
Unidentified 126 (GoogleSheets C2)
2026-08-30Medium 0xzyadelzyatZyad Elzyat
Reverse Engineering the Auto-Color Linux Backdoor
Auto-Color
2026-08-27ProofpointKyle Cucci, Proofpoint Threat Research Team, Rob Kinner, Tony Robinson
Carry-On Compromise: TA4922 Packs PackClient
donut_injector
2026-08-24Field EffectDamon Toumbourou, Hugh Whitewood
A ClickFix cluster: Observed activity from recent ClickFix campaigns
Lorem Ipsum
2026-08-21Bitso Quetzal TeamMauro Eldritch, Nelson Colon
North Korea’s Crypt: Hunting Ghosts
StoatWaffle
2026-08-21NetresecErik Hjelmvik
CNCMachineRMS C2 Protocol
Babadeda
2026-08-20trendaiAliakbar Zahravi
Prompting the Payload: How an npm Supply Chain Attack Delivers the RedC2 AI-Powered Linux Implant
redshell
2026-08-19zimperiumVishnu Pratapagiri
The ToxicPanda Never Sleeps: ToxicPanda 2.0 Prepares its Next Strike on Mobile
ToxicPanda
2026-08-19BitdefenderMartin Zugec
SilkParasite: Tracking a China-Nexus APT Across Central Asia
BloodAlchemy ShadowPad SNAPPYBEE SilkParasite
2026-08-18GenVojtěch Krejsa
WordlistLoader Delivering Amatera via ClearFake Campaigns
ACR Stealer Amatera
2026-08-17ZscalerZscaler ThreatLabz
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
C2Looper
2026-08-15neso.reneso
Borrowed Machinery: SnappyClient, HijackLoader, and a Shared Codebase?
HijackLoader SnappyClient
2026-08-14QUIRSO GmbHÇağatay Yürekli, Denis Szadkowski, Maike Orlikowski
Global Exploitation of CVE-2026–59310 by Suspected Chinese-Nexus APT & Related CVE-2026–59309 Activity
2026-08-11Aryaka NetworkAditya K Sood, bikash dash
Beyond the Batch File Analysis of a Multi-Stage DonutLoader Infection Chain
donut_injector
2026-08-10AhnLabASEC
Attack Cases for Domestic Web Servers Running SoftEther VPN in Korea
Larva-26010
2026-08-10sonatypeSonatype Research Team
Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads
JADESNOW
2026-08-07KasperskyKaspersky
The APT group Head Mare exploits vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph malware to video conferencing participants
PhantomCore PhantomGraph
2026-08-05SOC PrimeSOC Prime
SmartApeSG Pushes an Unknown RAT Through ClickFix Lures
SmartApeSG