Click here to download all references as Bib-File.•
| 2023-11-21
            
            ⋅
            
            Censys
            ⋅ Tracking Vidar Infrastructure with Censys Vidar | 
| 2023-11-21
            
            ⋅
            
            Reliaquest
            ⋅ Scattered Spider Attack Analysis | 
| 2023-11-21
            
            ⋅
            
            IBM
            ⋅ Stealthy WailingCrab Malware misuses MQTT Messaging Protocol Gozi WikiLoader | 
| 2023-11-21
            
            ⋅
            
            Trellix
            ⋅ The Continued Evolution of the DarkGate Malware-as-a-Service DarkGate | 
| 2023-11-21
            
            ⋅
            
            Palo Alto Networks Unit 42
            ⋅ Hacking Employers and Seeking Employment: Two Job-Related Campaigns Bear Hallmarks of North Korean Threat Actors BeaverTail InvisibleFerret WageMole | 
| 2023-11-21
            
            ⋅
            
            Medium infoSec Write-ups
            ⋅ Unmasking NJRat: A Deep Dive into a Notorious Remote Access Trojan Part1 NjRAT | 
| 2023-11-21
            
            ⋅
            
            adlumin
            ⋅ PlayCrypt Ransomware-as-a-Service Expands Threat from Script Kiddies and Sophisticated Attackers PLAY | 
| 2023-11-21
            
            ⋅
            
            ANY.RUN
            ⋅ XWorm Malware: Exploring C&C Communication XWorm | 
| 2023-11-20
            
            ⋅
            
            Cofense
            ⋅ Are DarkGate and PikaBot the new QakBot? DarkGate Pikabot QakBot | 
| 2023-11-20
            
            ⋅
            
            Russian Panda Research Blog
            ⋅ MetaStealer - Redline's Doppelgänger MetaStealer RedLine Stealer | 
| 2023-11-20
            
            ⋅
            
            PWC
            ⋅ King of Thieves: Black Alicanto and the Ecosystem of North Korea-Based Cyber Operations RustBucket CageyChameleon RustBucket | 
| 2023-11-20
            
            ⋅
            
            Trend Micro
            ⋅ CVE-2023-46604 (Apache ActiveMQ) Exploited to Infect Systems With Cryptominers and Rootkits | 
| 2023-11-20
            
            ⋅
            
            vmware
            ⋅ NetSupport RAT: The RAT King Returns NetSupportManager RAT | 
| 2023-11-20
            
            ⋅
            
            Outpost24
            ⋅ Unveiling LummaC2 stealer’s novel Anti-Sandbox technique: Leveraging trigonometry for human behavior detection Lumma Stealer | 
| 2023-11-20
            
            ⋅
            
            Sekoia
            ⋅ DarkGate Internals DarkGate | 
| 2023-11-19
            
            ⋅
            
            OALabs
            ⋅ PikaBot Is Back With a Vengeance - Part 2 Pikabot | 
| 2023-11-19
            
            ⋅
            
            MalDbg
            ⋅ A Look at IPStorm - Cross-Platform Malware Written in Go IPStorm IPStorm | 
| 2023-11-19
            
            ⋅
            
            Twitter (@embee_research)
            ⋅ Combining Pivot Points to Identify Malware Infrastructure - Redline, Smokeloader and Cobalt Strike Amadey Cobalt Strike RedLine Stealer SmokeLoader | 
| 2023-11-17
            
            ⋅
            
            Check Point Software Technologies Ltd
            ⋅ Malware Spotlight – Into the Trash: Analyzing LitterDrifter LitterDrifter | 
| 2023-11-17
            
            ⋅
            
            Cisco Talos
            ⋅ A deep dive into Phobos ransomware, recently deployed by 8Base group 8Base Phobos |