Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2026-05-07 ⋅ Sophos ⋅ Chaitanya Ghorpade, Gabor Szappanos, Matt Wixey, Rahil Shah, Rahul Dugar
Donuts and Beagles: Fake Claude site spreads backdoor
TriBack Loader
2026-03-23 ⋅ Sophos ⋅ Sophos Counter Threat Unit Research Team
NICKEL ALLEY strategy: Fake it ‘til you make it
PylangGhost GolangGhost Nickel Alley
2026-03-19 ⋅ Sophos ⋅ Sophos Counter Threat Unit Research Team
Android devices ship with firmware-level malware
Keenadu
2026-03-03 ⋅ Sophos ⋅ Sophos Counter Threat Unit Research Team
Hacktivist campaigns increase as United States, Iran, and Israel conflict intensifies
APTIran
2025-12-05 ⋅ Sophos ⋅ Morgan Demboski
Sharpening the knife: GOLD BLADE’s strategic evolution
Earth Kapre
2025-08-26 ⋅ Sophos ⋅ Sophos Counter Threat Unit Research Team
Velociraptor incident response tool abused for remote access
2025-05-09 ⋅ Sophos X-Ops ⋅ Andrew Petrus, Ben Goldberg, Haigh Minassian, Imane Ismail, Sushmita Shetty
Lumma Stealer, coming and going
Lumma Stealer
2025-01-25 ⋅ Sophos ⋅ Anthony Bradshaw, Colin Cowie, Daniel Souter, Hunter Neal, Mark Parsons, Sean Baird, Sean Gallagher
Sophos MDR tracks two ransomware campaigns using “email bombing,” Microsoft Teams “vishing”
ReedBed STAC5143 UNC4393
2024-12-19 ⋅ Sophos ⋅ Colin Cowie, Jordon Olness, Joshua Rawles, Mark Parsons, Sean Gallagher
Phishing platform Rockstar 2FA trips, and “FlowerStorm” picks up the pieces
FlowerStorm
2024-11-06 ⋅ Sophos ⋅ Asha Castle, Hikaru Koike, Sean Gallagher, Trang Tang
Bengal cat lovers in Australia get psspsspss’d in Google-driven Gootloader campaign
GootLoader
2024-10-31 ⋅ Sophos X-Ops ⋅ Ross McKerchar
Pacific Rim: Inside the Counter-Offensive—The TTPs Used to Neutralize China-Based Threats
Asnarök
2024-10-31 ⋅ Sophos X-Ops ⋅ Andrew Brandt, Ross McKerchar
Pacific Rim timeline: Information for defenders from a braid of interlocking attack campaigns
Asnarök Tstark
2023-12-20 ⋅ Sophos X-Ops ⋅ Mark Loman, Matt Wixey
CryptoGuard: An asymmetric approach to the ransomware battle
Akira LockBit Storm-1567
2023-09-22 ⋅ Sophos X-Ops ⋅ Sophos X-Ops
Mastodon Thread on observed activity involving TinyTurla
TinyTurla
2023-07-26 ⋅ Sophos
Into the tank with Nitrogen
Nitrogen Loader
2023-06-12 ⋅ Sophos ⋅ Karl Ackerman
Deep dive into the Pikabot cyber threat
Pikabot
2023-05-09 ⋅ Sophos ⋅ Paul Jaramillo
Akira Ransomware is “bringin’ 1988 back”
Akira
2023-05-03 ⋅ Sophos ⋅ Andrew Brandt, Gabor Szappanos, Xinran Wu
A doubled “Dragon Breath” adds new air to DLL sideloading attacks
Ghost RAT DragonBreath
2023-04-21 ⋅ Sophos ⋅ Colin Cowie, Paul Jaramillo
IcedID: Defrosting a Recent Campaign Illustrating evolving tactics and shared infrastructure
IcedID PhotoLoader
2023-04-19 ⋅ Sophos ⋅ Andreas Klopsch
‘AuKill’ EDR killer malware abuses Process Explorer driver
AuKill