Click here to download all references as Bib-File.•
| 2025-11-25
⋅
Arctic Wolf
⋅
Russian RomCom Utilizing SocGholish to Deliver Mythic Agent to U.S. Companies Supporting Ukraine FAKEUPDATES |
| 2025-10-22
⋅
SentinelOne
⋅
PhantomCaptcha | Multi-Stage WebSocket RAT Targets Ukraine in Single-Day Spearphishing Operation Princess |
| 2025-09-30
⋅
Google
⋅
Cybercrime Observations from the Frontlines: UNC6040 Proactive Hardening Recommendations |
| 2025-09-30
⋅
Elastic
⋅
WARMCOOKIE One Year Later: New Features and Fresh Insights WarmCookie |
| 2025-09-25
⋅
Koi Security
⋅
First Malicious MCP in the Wild: The Postmark Backdoor That's Stealing Your Emails |
| 2025-09-16
⋅
Wiz.io
⋅
Shai-Hulud: Ongoing Package Supply Chain Worm Delivering Data-Stealing Malware Shai-Hulud |
| 2025-09-02
⋅
At-Bay
⋅
Rhysida: Evading Detection, One Service at a Time Rhysida |
| 2025-08-26
⋅
Google
⋅
Widespread Data Theft Targets Salesforce Instances via Salesloft Drift UNC6395 |
| 2025-08-19
⋅
The Wall Street Journal
⋅
Oregon Man Accused of Operating One of Most Powerful Attack ‘Botnets’ Ever Seen RapperBot |
| 2025-08-11
⋅
ESET Research
⋅
Update WinRAR tools now: RomCom and others exploiting zero-day vulnerability dynamichttp |
| 2025-07-20
⋅
rmceoin.github.io
⋅
Perl based macOS/linux Stealer Pearl Stealer |
| 2025-06-30
⋅
Proofpoint
⋅
10 Things I Hate About Attribution: RomCom vs. TransferLoader MeltingClaw RustyClaw ShadyHammock SlipScreen TransferLoader |
| 2025-06-02
⋅
Aryaka Networks
⋅
Remcos on the Wire: Analyzing Network Artifacts and C2 Command Structures Remcos |
| 2025-04-25
⋅
Twitter (@teamcymru_S2)
⋅
Tweet on North Korean Cyber Ops Leveraging Russian Infrastructure |
| 2025-03-28
⋅
Cisco Talos
⋅
Gamaredon campaign abuses LNK files to distribute Remcos backdoor Remcos |
| 2025-02-21
⋅
SonicWall
⋅
Remcos RAT Targets Europe: New AMSI and ETW Evasion Tactics Uncovered Remcos |
| 2025-01-30
⋅
Bitdefender
⋅
UAC-0063: Cyber Espionage Operation Expanding from Central Asia HATVIBE |
| 2025-01-20
⋅
Medium walmartglobaltech
⋅
Qbot is Back.Connect ReedBed UNC4393 |
| 2024-12-10
⋅
cyble
⋅
Head Mare Group Intensifies Attacks on Russia with PhantomCore Backdoor PhantomCore Head Mare |
| 2024-12-04
⋅
Rapid7
⋅
Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware Black Basta Cobalt Strike DarkGate SystemBC Zloader |