Click here to download all references as Bib-File.•
2021-09-16
⋅
PCrisk
⋅
.harma (Ouroboros) ransomware from the operating system Zeropadypt |
2021-09-16
⋅
Twitter (@GossiTheDog)
⋅
Tweet on some unknown threat actor dropping Mgbot, custom IIS modular backdoor and cobalstrike using exploiting ProxyShell Cobalt Strike MgBot |
2021-09-16
⋅
Objective-See
⋅
Analysis of CVE-2021-30860 the flaw and fix of a zero-click vulnerability, exploited in the wild Chrysaor |
2021-09-14
⋅
Twitter (@siri_urz)
⋅
Tweet on ATOMSILO ransomware ATOMSILO |
2021-09-02
⋅
nviso
⋅
Anatomy and Disruption of Metasploit Shellcode |
2021-09-01
⋅
Intezer
⋅
TeamTNT: Cryptomining Explosion TeamTNT Tsunami |
2021-08-16
⋅
Trend Micro
⋅
LockBit Resurfaces With Version 2.0 Ransomware Detections in Chile, Italy, Taiwan, UK LockBit |
2021-08-11
⋅
GEMINI
⋅
Amid Boom in Phishing, Fraudsters Target Customers of Small and Mid-sized Banks |
2021-08-10
⋅
PCrisk
⋅
PCRisk description for Shurk Steal Shurk Steal |
2021-08-10
⋅
Bleeping Computer
⋅
Crytek confirms Egregor ransomware attack, customer data theft Egregor Maze |
2021-08-06
⋅
ESET Research
⋅
Anatomy of native IIS malware IISniff RGDoor |
2021-08-05
⋅
Uptycs
⋅
Cryptominer ELFs Using MSR to Boost Mining Process |
2021-08-04
⋅
ESET Research
⋅
Anatomy of Native IIS Malware (white papaer) IISniff RGDoor |
2021-08-04
⋅
ESET Research
⋅
Anatomy of Native IIS Malware (slides) IISniff RGDoor |
2021-08-03
⋅
Cybereason
⋅
DeadRinger: Exposing Chinese Threat Actors Targeting Major Telcos CHINACHOPPER Cobalt Strike MimiKatz Nebulae |
2021-08-03
⋅
Twitter (@ValthekOn)
⋅
Tweet on blacklisted extensions & names of BlackMatter ransomware making the check against custom hashes values DarkSide |
2021-07-26
⋅
vmware
⋅
Hunting IcedID and unpacking automation with Qiling IcedID |
2021-07-21
⋅
⋅
TEAMT5
⋅
"Le" is not tired of this, IE is really naughty Magniber |
2021-07-19
⋅
Ministry of Foreign Affairs of Japan
⋅
Cases of cyberattacks including those by a group known as APT40 which the Chinese government is behind (Statement by Press Secretary YOSHIDA Tomoyuki) APT40 |
2021-07-15
⋅
Microsoft
⋅
Protecting customers from a private-sector offensive actor using 0-day exploits and DevilsTongue malware Caramel Tsunami |