Click here to download all references as Bib-File.•
2024-10-17
⋅
Cisco Talos
⋅
UAT-5647 targets Ukrainian and Polish entities with RomCom malware variants MeltingClaw ROMCOM RAT ShadyHammock RomCom |
2024-08-21
⋅
Cisco Talos
⋅
MoonPeak malware from North Korean actors unveils new details on attacker infrastructure MoonPeak XenoRAT UAT-5394 |
2024-06-13
⋅
Cisco Talos
⋅
Operation Celestial Force employs mobile and desktop malware to target Indian entities Gravity RAT Gravity RAT |
2024-02-15
⋅
Cisco Talos
⋅
TinyTurla Next Generation - Turla APT spies on Polish NGOs TinyTurlaNG |
2023-12-11
⋅
Cisco Talos
⋅
Operation Blacksmith: Lazarus targets organizations worldwide using novel Telegram-based malware written in DLang BottomLoader DLRAT HazyLoad NineRAT |
2023-10-25
⋅
Cisco Talos
⋅
Kazakhstan-associated YoroTrooper disguises origin of attacks as Azerbaijan Ave Maria Loda YoroTrooper |
2023-09-19
⋅
Cisco Talos
⋅
New ShroudedSnooper actor targets telecommunications firms in the Middle East with novel Implants HTTPSnoop PipeSnoop LightBasin ShroudedSnooper |
2023-08-24
⋅
Cisco Talos
⋅
Lazarus Group's infrastructure reuse leads to discovery of new malware Collection RAT |
2023-08-24
⋅
Cisco Talos
⋅
Lazarus Group exploits ManageEngine vulnerability to deploy QuiteRAT QuiteRAT |
2023-03-14
⋅
Cisco Talos
⋅
Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agency Poet RAT Loda Kasablanka YoroTrooper |
2022-09-08
⋅
Cisco Talos
⋅
Lazarus and the tale of three RATs MagicRAT MimiKatz VSingle YamaBot |
2022-09-07
⋅
Cisco Talos
⋅
MagicRAT: Lazarus’ latest gateway into victim networks MagicRAT Tiger RAT |
2022-08-02
⋅
Cisco Talos
⋅
Manjusaka: A Chinese sibling of Sliver and Cobalt Strike Manjusaka Cobalt Strike Manjusaka |
2022-03-10
⋅
Talos
⋅
Iranian linked conglomerate MuddyWater comprised of regionally focused subgroups STARWHALE |
2022-02-09
⋅
Cisco
⋅
What’s with the shared VBA code between Transparent Tribe and other threat actors? |
2022-02-02
⋅
Cisco
⋅
Arid Viper APT targets Palestine with new wave of politically themed phishing attacks, malware Micropsia |
2022-01-31
⋅
Cisco
⋅
Iranian APT MuddyWater targets Turkish users via malicious PDFs, executables |
2021-09-30
⋅
Cisco
⋅
A wolf in sheep's clothing: Actors spread malware by leveraging trust in Amnesty International and fear of Pegasus |
2021-09-16
⋅
Cisco
⋅
Operation Layover: How we tracked an attack on the aviation industry to five years of compromise AsyncRAT Houdini NjRAT |
2021-08-31
⋅
Cisco Talos
⋅
Attracting flies with Honey(gain): Adversarial abuse of proxyware |