Click here to download all references as Bib-File.•
| 2020-06-25
⋅
Elastic
⋅
A close look at the advanced techniques used in a Malaysian-focused APT campaign DADSTACHE APT40 |
| 2020-06-18
⋅
ESET Research
⋅
Digging up InvisiMole’s hidden arsenal RC2FM Gamaredon Group |
| 2020-06-18
⋅
ESET Research
⋅
Digging up InvisiMole’s hidden arsenal InvisiMole Gamaredon Group InvisiMole |
| 2020-06-09
⋅
Github (Sentinel-One)
⋅
CobaltStrikeParser Cobalt Strike |
| 2020-06-08
⋅
ESET Research
⋅
InvisiMole: The Hidden Part of the Story - Unearthing InvisiMole's Espionage Toolset and Strategic Cooperations InvisiMole RC2FM |
| 2020-05-30
⋅
Youtube (OALabs)
⋅
IRC Botnet Reverse Engineering Part 1 - Preparing Binary for Analysis in IDA PRO Hamweq |
| 2020-02-13
⋅
Elastic
⋅
Playing defense against Gamaredon Group Pteranodon |
| 2020-01-16
⋅
Intrusiontruth
⋅
APT40 is run by the Hainan department of the Chinese Ministry of State Security |
| 2019-12-05
⋅
U.S. Department of the Treasury
⋅
Treasury Sanctions Evil Corp, the Russia-Based Cybercriminal Group Behind Dridex Malware Dridex |
| 2019-10-22
⋅
Contextis
⋅
AVIVORE - An overview of Tools, Techniques and Procedures (Whitepaper) PlugX Avivore |
| 2019-05-16
⋅
Department of Justice
⋅
GozNym Cyber-Criminal Network Operating out of Europe Targeting American Entities Dismantled in International Operation Nymaim |
| 2019-05-14
⋅
ESET Research
⋅
Plead malware distributed via MitM attacks at router level, misusing ASUS WebStorage PLEAD BlackTech |
| 2019-04-11
⋅
Department of Justice
⋅
Two Romanian Cybercriminals Convicted of All 21 Counts Relating to Infecting Over 400,000 Victim Computers with Malware and Stealing Millions of Dollars SuppoBox |
| 2019-03-28
⋅
Carbon Black
⋅
CryptoMix Clop Ransomware Disables Startup Repair, Removes & Edits Shadow Volume Copies Clop |
| 2019-03-26
⋅
FireEye
⋅
WinRAR Zero-day Abused in Multiple Campaigns SappyCache |
| 2019-03-20
⋅
Github (649)
⋅
APT38 DYEPACK FRAMEWORK DYEPACK |
| 2019-02-13
⋅
Department of Justice
⋅
Former U.S. Counterintelligence Agent Charged With Espionage on Behalf of Iran; Four Iranians Charged With a Cyber Campaign Targeting Her Former Colleagues Charming Kitten |
| 2018-12-12
⋅
US Department of Justice
⋅
Indictment against Andrey Turchin aka fxmsp |
| 2018-11-28
⋅
Department of Justice
⋅
Two Iranian Men Indicted for Deploying Ransomware to Extort Hospitals, Municipalities, and Public Institutions, Causing Over $30 Million in Losses SamSam |
| 2018-10-18
⋅
ESET Research
⋅
GREYENERGY: A successor to BlackEnergy Felixroot GreyEnergy |