Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2026-09-25 ⋅ Microsoft ⋅ Microsoft Security Research, Tushar Mudi, Yossi Weizman
Storm-3168: Agentic-driven cloud attacks using compromised service principals
JadePuffer
2026-09-22 ⋅ Microsoft ⋅ Microsoft Defender Experts, Microsoft Security Research, Microsoft Threat Intelligence
Unmasking EvilTokens: Getting to the root of device code phishing
Storm-2992
2026-08-03 ⋅ SOCRadar ⋅ SOCRadar
Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs
CountLoader
2026-06-24 ⋅ BitSight ⋅ Bitsight TRACE
Amadey and StealC: Malware-as-a-Service Unavailable
Amadey Stealc
2026-06-02 ⋅ Qualys ⋅ Aniket Harne
The HazyBeacon Protocol – How Malware Weaponizes Amazon Web Services (AWS) Lambda Function URLs
CL-STA-1020
2026-06-02 ⋅ The Register ⋅ Carly Page
Russian spy agency says foreign spies turned officials' smartphones into surveillance devices
2026-05-19 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
Exposing Fox Tempest: A malware-signing service operation (Podcast)
Akira Rhysida Akira BlackByte BlueSky Broomstick Lumma Stealer Rhysida Spyder Vidar Fox Tempest
2026-05-19 ⋅ Microsoft ⋅ Steven Masada
Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomware
Akira INC Qilin Rhysida AgendaCrypt Akira Broomstick INC Lumma Stealer Rhysida Vidar Fox Tempest
2026-05-19 ⋅ The Record ⋅ Jonathan Greig
Microsoft disrupts Fox Tempest malware-signing-as-a-service platform tied to ransomware gangs
Akira INC Qilin Rhysida AgendaCrypt Akira Broomstick INC Lumma Stealer Rhysida Vidar Fox Tempest
2026-05-11 ⋅ ThreatFabric ⋅ ThreatFabric
New TrickMo Variant: Device Take Over malware targeting Banking, Fintech, Wallet & Auth apps
TrickMo
2026-04-15 ⋅ Cyberdaily.au ⋅ David Hollingworth
Exclusive: Krybit hackers claim breach of New Zealand IT services provider
Krybit
2026-04-13 ⋅ Cleafy ⋅ Cleafy
Mirax: a new Android RAT turning infected devices into potential residential proxy nodes
Mirax
2026-04-10 ⋅ Infoblox ⋅ Chong Lua Dao, Infoblox Threat Intel
Scams, Slaves and (Malware-as-a) Service: Tracking a Trojan to Cambodia’s Scam Centers
2026-03-20 ⋅ IC3 ⋅ FBI, IC3
I-032026-PSA: Russian Intelligence Services Target Commercial Messaging Application Accounts
2026-03-19 ⋅ Sophos ⋅ Sophos Counter Threat Unit Research Team
Android devices ship with firmware-level malware
Keenadu
2026-02-26 ⋅ Group-IB ⋅ Hans Figueroa, Vlada Govorova
GTFire Phishing Scheme: Avoiding Detection Using Google Services
GTFire
2026-02-17 ⋅ Kaspersky ⋅ Kaspersky
Kaspersky discovers Keenadu – a multifaceted Android malware that can come preinstalled on new devices
Keenadu
2026-02-01 ⋅ Midnight Blue Labs ⋅ Midnight Blue
Have you tried turning it off and on again? On bricking OT devices (part 2)
2026-02-01 ⋅ Midnight Blue Labs ⋅ Midnight Blue
Have you tried turning it off and on again? On bricking OT devices (part 1)
2025-12-18 ⋅ Proofpoint ⋅ Proofpoint Threat Research Team
Access granted: phishing with device code authorization for account takeover
TA2723 UNK_AcademicFlare