Click here to download all references as Bib-File.•
2022-11-03
⋅
Zscaler
⋅
APT-36 Uses New TTPs and New Tools to Target Indian Governmental Organizations LimePad |
2022-11-03
⋅
paloalto Netoworks: Unit42
⋅
Cobalt Strike Analysis and Tutorial: Identifying Beacon Team Servers in the Wild Cobalt Strike |
2022-11-03
⋅
SentinelOne
⋅
Black Basta Ransomware | Attacks deploy Custom EDR Evasion Tools tied to FIN7 Threat Actor Black Basta QakBot SocksBot |
2022-11-02
⋅
Sekoia
⋅
BlueFox Stealer: a newcomer designed for traffers teams Aurora Stealer BlueFox |
2022-11-02
⋅
Blackberry
⋅
RomCom Threat Actor Abuses KeePass and SolarWinds to Target Ukraine and Potentially the United Kingdom ROMCOM RAT RomCom |
2022-11-02
⋅
ASEC
⋅
Appleseed Being Distributed to Nuclear Power Plant-Related Companies Appleseed |
2022-11-02
⋅
NOZOMI Network Labs
⋅
Could Threat Actors Be Downgrading Their Malware to Evade Detection? Bashlite |
2022-11-01
⋅
BlackPoint
⋅
Ratting Out Arechclient2 SectopRAT |
2022-10-31
⋅
Cynet
⋅
Orion Threat Alert: Qakbot TTPs Arsenal and the Black Basta Ransomware Black Basta Cobalt Strike QakBot |
2022-10-31
⋅
The Record
⋅
Mondelez and Zurich reach settlement in NotPetya cyberattack insurance suit EternalPetya |
2022-10-31
⋅
Security homework
⋅
QakBot CCs prioritization and new record types QakBot |
2022-10-31
⋅
paloalto Netoworks: Unit42
⋅
Banking Trojan Techniques: How Financially Motivated Malware Became Infrastructure Dridex Kronos TrickBot Zeus |
2022-10-28
⋅
velociraptor
⋅
Windows.Carving.SystemBC - SystemBC RAT configuration Purser for Velociraptor SystemBC |
2022-10-28
⋅
cocomelonc
⋅
APT techniques: Token theft via UpdateProcThreadAttribute. Simple C++ example. |
2022-10-28
⋅
ThreatFabric
⋅
Malware wars: the attack of the droppers Brunhilda SharkBot Vultur |
2022-10-27
⋅
vmware
⋅
Threat Analysis: Active C2 Discovery Using Protocol Emulation Part3 (ShadowPad) ShadowPad |
2022-10-27
⋅
Microsoft
⋅
Raspberry Robin worm part of larger ecosystem facilitating pre-ransomware activity FAKEUPDATES BumbleBee Clop Fauppod Raspberry Robin Roshtyak Silence DEV-0950 Mustard Tempest |
2022-10-27
⋅
Microsoft
⋅
Raspberry Robin worm part of larger ecosystem facilitating pre-ransomware activity FAKEUPDATES BumbleBee Fauppod PhotoLoader Raspberry Robin Roshtyak |
2022-10-27
⋅
Bleeping Computer
⋅
Microsoft links Raspberry Robin worm to Clop ransomware attacks Clop Raspberry Robin |
2022-10-27
⋅
ANY.RUN
⋅
STRRAT: Malware Analysis of a JAR archive STRRAT |