Click here to download all references as Bib-File.•
| 2020-02-02
⋅
uf0 Blog
⋅
Uncovering Mimikatz ‘msv’ and collecting credentials through PyKD MimiKatz |
| 2020-01-26
⋅
Dark Matter: Uncovering the DarkComet RAT Ecosystem DarkComet |
| 2020-01-14
⋅
FireEye
⋅
Rough Patch: I Promise It'll Be 200 OK (Citrix ADC CVE-2019-19781) NOTROBIN |
| 2019-12-11
⋅
Cybereason
⋅
Dropping Anchor: From a TrickBot Infection to the Discovery of the Anchor Malware Anchor WIZARD SPIDER |
| 2019-10-17
⋅
ESET Research
⋅
OPERATION GHOST The Dukes aren’t back — they never left FatDuke |
| 2019-10-16
⋅
Proofpoint
⋅
TA505 Distributes New SDBbot Remote Access Trojan with Get2 Downloader Get2 SDBbot TA505 |
| 2019-10-02
⋅
Certego
⋅
Malware Tales: FTCODE FTCODE |
| 2019-09-02
⋅
Volexity
⋅
Digital Crackdown: Large-Scale Surveillance and Exploitation of Uyghurs scanbox POISON CARP |
| 2019-08-19
⋅
FireEye
⋅
GAME OVER: Detecting and Stopping an APT41 Operation ACEHASH CHINACHOPPER HIGHNOON |
| 2019-07-18
⋅
FireEye
⋅
Hard Pass: Declining APT34’s Invite to Join Their Professional Network LONGWATCH PICKPOCKET TONEDEAF VALUEVAULT |
| 2019-07-02
⋅
Proofpoint
⋅
TA505 begins summer campaigns with a new pet malware downloader, AndroMut, in the UAE, South Korea, Singapore, and the United States AndroMut FlawedAmmyy |
| 2019-06-14
⋅
Certego
⋅
Malware Tales: Sodinokibi REvil |
| 2019-05-29
⋅
ESET Research
⋅
A dive into Turla PowerShell usage PowerShellRunner TurlaRPC |
| 2019-05-07
⋅
ESET Research
⋅
Turla LightNeuron: An email too far LightNeuron |
| 2019-05-01
⋅
ESET Research
⋅
TURLA LIGHTNEURON: One email away from remote code execution LightNeuron |
| 2019-04-30
⋅
Cisco Talos
⋅
Sodinokibi ransomware exploits WebLogic Server vulnerability REvil |
| 2019-04-17
⋅
Cisco Talos
⋅
DNS Hijacking Abuses Trust In Core Internet Service Sea Turtle |
| 2019-02-20
⋅
Cisco Talos
⋅
Combing Through Brushaloader Amid Massive Detection Uptick BrushaLoader |
| 2019-02-14
⋅
Certego
⋅
Malware Tales: Gootkit GootKit |
| 2019-01-25
⋅
CrowdStrike
⋅
Widespread DNS Hijacking Activity Targets Multiple Sectors DNSpionage |