Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2026-07-20 ⋅ sysdig ⋅ Michael Clark
JADEPUFFER evolves: The agentic threat actor deploys ransomware built to destroy AI models
JadePuffer
2026-07-01 ⋅ sysdig ⋅ Michael Clark
JADEPUFFER: Agentic ransomware for automated database extortion
JadePuffer
2026-01-16 ⋅ sysdig ⋅ Sysdig Threat Research Team
VoidLink threat analysis: Sysdig discovers C2-compiled kernel rootkits
VoidLink
2025-12-16 ⋅ sysdig ⋅ Sysdig Threat Research Team
EtherRAT dissected: How a React2Shell implant delivers 5 payloads through blockchain C2
EtherRAT
2025-12-08 ⋅ sysdig ⋅ Sysdig Threat Research Team
EtherRAT: DPRK uses novel Ethereum implant in React2Shell attacks
EtherRAT
2025-09-09 ⋅ sysdig ⋅ Alessandra Rizzo
ZynorRAT technical analysis: Reverse engineering a novel, Turkish Go-based RAT
ZynorRAT
2025-04-15 ⋅ sysdig ⋅ Alessandra Rizzo
UNC5174’s evolution in China’s ongoing cyber warfare: From SNOWLIGHT to VShell
SNOWLIGHT Sliver VShell
2024-07-11 ⋅ sysdig ⋅ Miguel Hernández
CRYSTALRAY: Inside the Operations of a Rising Threat Actor Exploiting OSS Tools
CRYSTALRAY
2024-04-09 ⋅ sysdig ⋅ Sysdig Threat Research Team
RUBYCARP: A Detailed Analysis of a Sophisticated Decade-Old Botnet Group
PerlBot RUBYCARP
2023-07-11 ⋅ sysdig ⋅ Alessandro Brucato
SCARLETEEL 2.0: Fargate, Kubernetes, and Crypto
SCARLETEEL
2023-02-28 ⋅ sysdig ⋅ Alberto Pellitteri
SCARLETEEL: Operation leveraging Terraform, Kubernetes, and AWS for data theft
SCARLETEEL
2021-12-07 ⋅ sysdig ⋅ Alberto Pellitteri
Threat news: TeamTNT stealing credentials using EC2 Instance Metadata
TeamTNT
2021-11-16 ⋅ sysdig ⋅ Stefano Chierici
Hands-On Muhstik Botnet: crypto-mining attacks targeting Kubernetes
Tsunami
2021-11-02 ⋅ sysdig ⋅ Alberto Pellitteri
Malware analysis: Hands-On Shellbot malware
PerlBot
2020-11-23 ⋅ sysdig ⋅ Kaizhe Huang
Zoom into Kinsing
Kinsing Kinsing