Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2026-08-26 ⋅ Microsoft ⋅ Parasharan Raghavan, Sagar Patil, Suriyaraj Natarajan
TerminalFix campaign deploys a reverse tunnel through multistage intrusion
Lorem Ipsum
2026-08-07 ⋅ ⋅ CERT.PL ⋅ CERT.PL
Active phishing campaign targeting Microsoft Exchange servers
2026-07-31 ⋅ Microsoft Threat Intelligence
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
ChocoShell CornFlake Storm-2945
2026-07-16 ⋅ Microsoft Security ⋅ Balaji Venkatesh S, Microsoft Security Research
ACR Stealer: Two observed intrusion chains amid increased threat activity
ACR Stealer
2026-06-25 ⋅ Microsoft Security ⋅ Microsoft Defender Experts, Microsoft Defender Security Research Team, Parth Jomadkar
Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access
TonRAT
2026-06-17 ⋅ Microsoft ⋅ Microsoft Defender Research Team
From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet
2026-06-03 ⋅ Microsoft ⋅ Microsoft
How Microsoft names threat actors
Wisteria Tsunami
2026-05-28 ⋅ eSentire ⋅ eSentire
Nimbus RAT: How Threat Actors Are Abusing Microsoft Teams and Google Drive to Deploy a Java RAT
2026-05-20 ⋅ K7 Security ⋅ Srinivasan E
Fake Microsoft Teams download sites are being used to deliver ValleyRAT via DLL sideloading
ValleyRAT
2026-05-19 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
Exposing Fox Tempest: A malware-signing service operation (Podcast)
Akira Rhysida Akira BlackByte BlueSky Broomstick Lumma Stealer Rhysida Spyder Vidar Fox Tempest
2026-05-19 ⋅ Microsoft ⋅ Steven Masada
Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomware
Akira INC Qilin Rhysida AgendaCrypt Akira Broomstick INC Lumma Stealer Rhysida Vidar Fox Tempest
2026-05-19 ⋅ The Record ⋅ Jonathan Greig
Microsoft disrupts Fox Tempest malware-signing-as-a-service platform tied to ransomware gangs
Akira INC Qilin Rhysida AgendaCrypt Akira Broomstick INC Lumma Stealer Rhysida Vidar Fox Tempest
2026-05-19 ⋅ Github (microsoft) ⋅ Microsoft
MSTIC actor name mapping in JSON format
Amethyst Rain Houndstooth Typhoon Pinstripe Lightning Storm-0252 Wisteria Tsunami
2026-05-18 ⋅ Microsoft ⋅ Microsoft Defender Security Research Team
How Storm-2949 turned a compromised identity into a cloud-wide breach
Storm-2949
2026-05-14 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
Kazuar: Anatomy of a nation-state botnet
Kazuar
2026-04-07 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks
2026-03-12 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft
Storm-2561
2026-03-11 ⋅ Microsoft ⋅ Microsoft Defender Experts, Microsoft Defender Security Research Team
Contagious Interview: Malware delivered through fake developer job interviews
BeaverTail OtterCookie StoatWaffle InvisibleFerret PylangGhost GolangGhost Contagious Interview
2026-03-06 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
AI as tradecraft: How threat actors operationalize AI
OtterCookie
2026-03-03 ⋅ Microsoft ⋅ Microsoft
Signed malware impersonating workplace apps deploys RMM backdoors
TrustConnect RAT