Click here to download all references as Bib-File.•
| 2026-03-23
⋅
Sophos
⋅
NICKEL ALLEY strategy: Fake it ‘til you make it PylangGhost GolangGhost Nickel Alley |
| 2026-03-11
⋅
Microsoft
⋅
Contagious Interview: Malware delivered through fake developer job interviews BeaverTail OtterCookie StoatWaffle InvisibleFerret PylangGhost GolangGhost Contagious Interview |
| 2026-03-09
⋅
Abstract Security
⋅
Contagious Interview: Evolution of VS Code and Cursor Tasks Infection Chains Part 2 GolangGhost PylangGhost GolangGhost |
| 2026-03-03
⋅
Sophos
⋅
Hacktivist campaigns increase as United States, Iran, and Israel conflict intensifies APTIran |
| 2026-03-02
⋅
Microsoft
⋅
OAuth redirection abuse enables phishing and malware delivery |
| 2026-02-25
⋅
Abstract Security
⋅
Contagious Interview: Evolution of VS Code and Cursor Tasks Infection Chains - Part 1 BeaverTail PylangGhost GolangGhost |
| 2026-01-28
⋅
Proofpoint
⋅
Can’t stop, won’t stop: TA584 innovates initial access XWorm TA584 |
| 2026-01-22
⋅
Red Asgard
⋅
Hunting Lazarus Part II: When the Dead Drop Moved to the Blockchain StoatWaffle |
| 2026-01-20
⋅
Abstract Security
⋅
Contagious Interview: Tracking the VS Code Tasks Infection Vector BeaverTail InvisibleFerret |
| 2026-01-16
⋅
sysdig
⋅
VoidLink threat analysis: Sysdig discovers C2-compiled kernel rootkits VoidLink |
| 2025-12-18
⋅
Proofpoint
⋅
Access granted: phishing with device code authorization for account takeover TA2723 UNK_AcademicFlare |
| 2025-12-16
⋅
sysdig
⋅
EtherRAT dissected: How a React2Shell implant delivers 5 payloads through blockchain C2 EtherRAT |
| 2025-12-10
⋅
SpyCloud
⋅
Analyzing the Impact of the Operation Endgame Takedown on Rhadamanthys & the MaaS Ecosystem Rhadamanthys |
| 2025-12-08
⋅
sysdig
⋅
EtherRAT: DPRK uses novel Ethereum implant in React2Shell attacks EtherRAT |
| 2025-11-04
⋅
Twitter (@nextronresearch)
⋅
Tweet about BQT ransomware on Linux BQTlock |
| 2025-10-14
⋅
Reliaquest
⋅
SOE-phisticated Persistence: Inside Flax Typhoon's ArcGIS Compromise |
| 2025-10-13
⋅
SpyCloud
⋅
More Than Meets the YY: Analyzing the YYlaiyu PhaaS Panel |
| 2025-10-13
⋅
Proofpoint
⋅
When the monster bytes: tracking TA585 and its arsenal MonsterV2 |
| 2025-09-16
⋅
Proofpoint
⋅
Going Underground: China-aligned TA415 Conducts U.S.-China Economic Relations Targeting Using VS Code Remote Tunnels |
| 2025-09-15
⋅
Zscalar
⋅
SmokeLoader Rises From the Ashes SmokeLoader |