Click here to download all references as Bib-File.•
| 2022-03-24
⋅
Twitter (@ESETresearch)
⋅
Tweet on PipeMon variants by Winnti Group PipeMon |
| 2022-03-24
⋅
Twitter (@struppigel)
⋅
Tweet on Ginzo Stealer Ginzo Stealer |
| 2022-03-15
⋅
Twitter (@HackNPatch)
⋅
Tweet on Exploring CaddyWiper API resolution CaddyWiper |
| 2022-03-14
⋅
Twitter (@ESETresearch)
⋅
Tweet on CaddyWiper as 3rd destructive wiper found deployed against Ukraine CaddyWiper Sunglow Blizzard |
| 2022-03-12
⋅
Twitter (@ET_Labs)
⋅
A quick thread examining the network artifacts of the HermeticWizard spreading HermeticWizard |
| 2022-03-10
⋅
Twitter (@Katechondic)
⋅
Tweet on additional computer names "desktop-g1i8n3f" & "desktop-j6llo2k", seen with Crimson RAT C2 infrastructure used by APT36 Crimson RAT |
| 2022-03-10
⋅
Twitter (@teamcymru_S2)
⋅
Tweet on Crimson RAT infrastructure used by APT36 Crimson RAT |
| 2022-03-09
⋅
Twitter (@struppigel)
⋅
Tweets detailing NominatusToxicBattery NominatusToxicBattery |
| 2022-03-09
⋅
Twitter (@silascutler)
⋅
Tweet on HermeticWizard's self-spreading mechanism HermeticWizard |
| 2022-03-08
⋅
Twitter (@CyberJack42)
⋅
Tweet on ELFSHELF alias for KEYPLUG KEYPLUG |
| 2022-03-08
⋅
Twitter (@ShaneHuntley)
⋅
Tweet on APT31 phishing campaign targeting high profile Gmail users affiliated with the U.S. government in February |
| 2022-03-08
⋅
Twitter (@struppigel)
⋅
Tweet on KazyLoader KazyLoader |
| 2022-03-01
⋅
Twitter (@TheDFIRReport)
⋅
Twitter thread with highlights from conti leaks Conti |
| 2022-03-01
⋅
Twitter (@ContiLeaks)
⋅
Tweet on Emotet final server scheme Emotet |
| 2022-02-28
⋅
Twitter (@struppigel)
⋅
Tweet on Gofing discovery Gofing |
| 2022-02-28
⋅
Twitter (@M_haggis)
⋅
Tweet on parsing Daxin driver metadata using powershell Daxin |
| 2022-02-25
⋅
Twitter (@fr0gger)
⋅
Tweets with an overview of HermeticWiper HermeticWiper |
| 2022-02-23
⋅
Twitter (@threatintel)
⋅
Tweet on new wiper malware being used in attacks on Ukraine HermeticWiper |
| 2022-02-17
⋅
Twitter (@Honeymoon_IoC)
⋅
Tweets on win.prometei caught via Cowrie Prometei |
| 2022-02-03
⋅
Gdata
⋅
QR codes on Twitter deliver malicious Chrome extension Choziosi |