Click here to download all references as Bib-File.•
| 2026-08-03
⋅
AhnLab
⋅
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005) CRAT DRATzarus Larva-26005 |
| 2026-07-31
⋅
Medium @prtheus
⋅
1337_GTWK Linux Malware Analysis 1337_GTWK |
| 2026-07-30
⋅
Linux Malware 1337_GWTK Server Analysis 1337_GTWK |
| 2026-07-29
⋅
SafeDep
⋅
Joyfill npm Packages Compromised with Blockchain C2 Loader JADESNOW |
| 2026-07-28
⋅
StepSecurity
⋅
Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan JADESNOW |
| 2026-07-28
⋅
Socket
⋅
Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan JADESNOW |
| 2026-07-28
⋅
Hunt.io
⋅
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon |
| 2026-07-27
⋅
Intezer
⋅
Two Trojan Families Trotting in Through Google Search Ads |
| 2026-07-27
⋅
Intrusiontruth
⋅
Dear Diary, Today I found a Ghost in the Network |
| 2026-07-27
⋅
Medium (@billmarczak)
⋅
An Angry Spark, or a Triangle in Disguise? TriangleDB |
| 2026-07-27
⋅
Netresec
⋅
PureLogs, PureRAT and misleading zgRAT PureLogs Stealer PureRAT zgRAT |
| 2026-07-24
⋅
JUMPSEC LABS
⋅
Inside a DPRK BlueNoroff ClickFix Kit |
| 2026-07-24
⋅
Daily NK
⋅
North Korea busts elite hacking ring inside its own banks |
| 2026-07-24
⋅
Nokia
⋅
Jackskid's residential proxy, brought to you by UPnP Jackskid |
| 2026-07-23
⋅
Proofpoint
⋅
Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458 SpyPress |
| 2026-07-23
⋅
Proofpoint
⋅
TA488 Targets Zimbra Mailservers with Half-Click Exploits ZimReaper |
| 2026-07-23
⋅
Group-IB
⋅
JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake AdaptixC2 reGeorg |
| 2026-07-22
⋅
Prophet Security
⋅
EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain |
| 2026-07-22
⋅
Huntress Labs
⋅
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT SectopRAT |
| 2026-07-22
⋅
bluecyber
⋅
Beyond the Archive: CVE-2025-8088 Stealer Targeting Ukraine GIFTEDCROOK |