Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2026-05-21 ⋅ Lumen ⋅ Danny Adamitis, Ryan English, Steve Rudd
Introducing Showboat: A new malware family taunts defenses and targets international telecom firms
Showboat
2026-05-21 ⋅ PWC ⋅ PwC Threat Intelligence
Inside Red Lamassu’s JFMBackdoor
JFMBackdoor Calypso
2026-05-20 ⋅ Nokia ⋅ Nokia Deepfield ERT
Potassium: it was never about the taste
Potassium
2026-05-20 ⋅ Seqrite Labs ⋅ Dixit Panchal, Kartik Jivani, Vaibhav Krushna Billade
Operation Dragon Whistle: UNG0002 Targets Chinese Academia via Weaponized Institutional Lure
Cobalt Strike
2026-05-20 ⋅ Hackernoon ⋅ Mrwriteup
ZeffSec Resurfaces on Telegram, Claims Breach of Gozine2.ir
ZeffSec
2026-05-20 ⋅ K7 Security ⋅ Srinivasan E
Fake Microsoft Teams download sites are being used to deliver ValleyRAT via DLL sideloading
ValleyRAT
2026-05-19 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
Exposing Fox Tempest: A malware-signing service operation (Podcast)
Akira Rhysida Akira BlackByte BlueSky Broomstick Lumma Stealer Rhysida Spyder Vidar Fox Tempest
2026-05-19 ⋅ Microsoft ⋅ Steven Masada
Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomware
Akira INC Qilin Rhysida AgendaCrypt Akira Broomstick INC Lumma Stealer Rhysida Vidar Fox Tempest
2026-05-19 ⋅ The Record ⋅ Jonathan Greig
Microsoft disrupts Fox Tempest malware-signing-as-a-service platform tied to ransomware gangs
Akira INC Qilin Rhysida AgendaCrypt Akira Broomstick INC Lumma Stealer Rhysida Vidar Fox Tempest
2026-05-19 ⋅ Github (microsoft) ⋅ Microsoft
MSTIC actor name mapping in JSON format
Amethyst Rain Houndstooth Typhoon Pinstripe Lightning Storm-0252 Wisteria Tsunami
2026-05-19 ⋅ Trend Micro ⋅ Aldrin Ceriola, Gabriel Nicoleta, Jovit Samaniego, Mohamed Fahmy
Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud
Banana RAT SHADOW-WATER-063
2026-05-18 ⋅ Microsoft ⋅ Microsoft Defender Security Research Team
How Storm-2949 turned a compromised identity into a cloud-wide breach
Storm-2949
2026-05-18 ⋅ Zynap ⋅ Oscar Gallego
Zynap’s Next-Gen Sandbox Redefines Automatic Malware Analysis
Black Basta HijackLoader
2026-05-18 ⋅ Gen Threat Labs ⋅ Gen Threat Labs
X.com - Gen Threat Labs - AuraStealer (version 1.8.0)
Aura Stealer
2026-05-17 ⋅ neso.re ⋅ neso
ClickFix x HijackLoader: Dissecting a Live Stealer Campaign
HijackLoader
2026-05-17 ⋅ Github (zanez) ⋅ Irvin Martínez González
Analysis on Malware that attacks Israel's Water treatment facilities
ZionSiphon
2026-05-16 ⋅ Symantec ⋅ Threat Hunter Team
Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations
fast16
2026-05-16 ⋅ Derp ⋅ Matt Kirkland
Vidar v1.5 in Go: same family, new language, heavy sandbox checks
Vidar
2026-05-14 ⋅ eSentire ⋅ eSentire Threat Response Unit (TRU)
Amatera Stealer 4.0.2 Beta: What's New in This Variant
Amatera
2026-05-14 ⋅ ESET Research ⋅ ESET Research
FrostyNeighbor: Fresh mischief and digital shenanigans
Cobalt Strike PicassoLoader