Click here to download all references as Bib-File.•
| 2025-09-30
            
            ⋅
            
            Palo Alto Networks Unit 42
            ⋅ Phantom Taurus: A New Chinese Nexus APT and the Discovery of the NET-STAR Malware Suite NET-STAR | 
| 2025-09-10
            
            ⋅
            
            Palo Alto Networks Unit 42
            ⋅ AdaptixC2: A New Open-Source Framework Leveraged in Real-World Attacks AdaptixC2 | 
| 2025-06-17
            
            ⋅
            
            Palo Alto Networks Unit 42
            ⋅ Exploring a New KimJongRAT Stealer Variant and Its PowerShell Implementation KimJongRat | 
| 2025-06-13
            
            ⋅
            
            Twitter (@Unit42_Intel)
            ⋅ Tweet about APT27 SysUpdate activity HyperSSL HyperSSL | 
| 2025-05-07
            
            ⋅
            
            Palo Alto Networks Unit 42
            ⋅ Iranian Cyber Actors Impersonate Model Agency in Suspected Espionage Operation APT35 | 
| 2025-04-14
            
            ⋅
            
            Palo Alto Networks Unit 42
            ⋅ Slow Pisces Targets Developers With Coding Challenges and Introduces New Customized Python Malware RN Stealer | 
| 2025-03-06
            
            ⋅
            
            Palo Alto Networks Unit 42
            ⋅ The Next Level: Typo DGAs Used in Malicious Redirection Chains | 
| 2025-02-28
            
            ⋅
            
            Palo Alto Networks Unit 42
            ⋅ JavaGhost’s Persistent Phishing Attacks From the Cloud JavaGhost | 
| 2025-02-27
            
            ⋅
            
            Palo Alto Networks Unit 42
            ⋅ Squidoor: Suspected Chinese Threat Actor’s Backdoor Targets Global Organizations FINALDRAFT FINALDRAFT REF7707 | 
| 2025-02-24
            
            ⋅
            
            Palo Alto Networks Unit 42
            ⋅ Auto-Color: An Emerging and Evasive Linux Backdoor | 
| 2025-01-17
            
            ⋅
            
            Twitter (@Unit42_Intel)
            ⋅ Tweet about affiliates of DarkScorpius using Social Engineering via MS Teams UNC4393 | 
| 2024-11-19
            
            ⋅
            
            Palo Alto Networks Unit 42
            ⋅ FrostyGoop’s Zoom-In: A Closer Look into the Malware Artifacts, Behaviors and Network Communications FrostyGoop | 
| 2024-11-14
            
            ⋅
            
            Palo Alto
            ⋅ Fake North Korean IT Worker Linked to BeaverTail Video Conference App Phishing Attack BeaverTail InvisibleFerret WageMole | 
| 2024-10-30
            
            ⋅
            
            Palo Alto Networks Unit 42
            ⋅ Jumpy Pisces Engages in Play Ransomware Dtrack MimiKatz PLAY Sliver | 
| 2024-10-09
            
            ⋅
            
            Palo Alto
            ⋅ Contagious Interview: DPRK Threat Actors Lure Tech Industry Job Seekers to Install New Variants of BeaverTail and InvisibleFerret Malware BeaverTail Beavertail | 
| 2024-09-26
            
            ⋅
            
            Palo Alto Networks Unit 42
            ⋅ Unraveling Sparkling Pisces’s Tool Set: KLogEXE and FPSpy FPSpy KLogEXE Kimsuky | 
| 2024-09-23
            
            ⋅
            
            Palo Alto Networks Unit 42
            ⋅ Inside SnipBot: The Latest RomCom Malware Variant ROMCOM RAT | 
| 2024-09-19
            
            ⋅
            
            Palo Alto Networks Unit 42
            ⋅ Discovering Splinter: A First Look at a New Post-Exploitation Red Team Tool Splinter | 
| 2024-09-10
            
            ⋅
            
            Palo Alto Networks Unit 42
            ⋅ Threat Assessment: Repellent Scorpius, Distributors of Cicada3301 Ransomware Cicada3301 | 
| 2024-08-09
            
            ⋅
            
            Palo Alto Networks Unit 42
            ⋅ Ransomware Review: First Half of 2024 Ukrainian Cyber Alliance |