Click here to download all references as Bib-File.•
2021-04-29
⋅
FireEye
⋅
UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat Cobalt Strike FiveHands HelloKitty |
2021-04-18
⋅
Bleeping Computer
⋅
Discord Nitro gift codes now demanded as ransomware payments Nitro |
2021-04-16
⋅
Team Cymru
⋅
Transparent Tribe APT Infrastructure Mapping Part 1: A High-Level Study of CrimsonRAT Infrastructure October 2020 – March 2021 Crimson RAT |
2021-04-07
⋅
Medium walmartglobaltech
⋅
Not your same old adware anymore, PBOT updates |
2021-03-26
⋅
Bleeping Computer
⋅
Ransomware gang urges victims’ customers to demand a ransom payment Clop |
2021-03-15
⋅
Modern War Institute
⋅
Incorporating the Cyberspace Domain: How Russia and China Exploit Asymmetric Advantages in Great Power Competition |
2021-03-15
⋅
Team Cymru
⋅
FIN8: BADHATCH Threat Indicator Enrichmen BADHATCH |
2021-03-10
⋅
PICUS Security
⋅
Tactics, Techniques, and Procedures (TTPs) Used by HAFNIUM to Target Microsoft Exchange Servers CHINACHOPPER |
2021-03-08
⋅
Symantec
⋅
How Symantec Stops Microsoft Exchange Server Attacks CHINACHOPPER MimiKatz |
2021-03-08
⋅
Secureworks
⋅
SUPERNOVA Web Shell Deployment Linked to SPIRAL Threat Group SUPERNOVA BRONZE SPIRAL |
2021-02-18
⋅
Symantec
⋅
Lazarus: Three North Koreans Charged for Financially Motivated Attacks AppleJeus POOLRAT Unidentified macOS 001 (UnionCryptoTrader) AppleJeus Unidentified 077 (Lazarus Downloader) |
2021-02-05
⋅
Team Cymru
⋅
Kobalos Malware Mapping Potentially Impacted Networks and IP Address Mapping Kobalos |
2021-01-27
⋅
Team Cymru
⋅
Taking Down Emotet How Team Cymru Leveraged Visibility and Relationships to Coordinate Community Efforts Emotet |
2021-01-26
⋅
Team Cymru
⋅
GhostDNSbusters (Part 3) Illuminating GhostDNS Infrastructure |
2021-01-22
⋅
Symantec
⋅
SolarWinds: How Sunburst Sends Data Back to the Attackers SUNBURST |
2021-01-20
⋅
Team Cymru
⋅
MoqHao Part 1: Identifying Phishing Infrastructure MoqHao |
2021-01-18
⋅
Symantec
⋅
Raindrop: New Malware Discovered in SolarWinds Investigation Cobalt Strike Raindrop SUNBURST TEARDROP |
2021-01-18
⋅
Twitter (@teamcymru)
⋅
Tweet on APT36 CrimsonRAT C2 Crimson RAT |
2021-01-15
⋅
Symantec
⋅
SolarWinds: Insights into Attacker Command and Control Process SUNBURST |
2021-01-07
⋅
Symantec
⋅
SolarWinds: How a Rare DGA Helped Attacker Communications Fly Under the Radar SUNBURST |