Click here to download all references as Bib-File.•
2021-07-07
⋅
Twitter (@resecurity_com)
⋅
Tweet REvil attack chain used against Kaseya REvil |
2021-07-07
⋅
Twitter (@C0rk1_H)
⋅
Tweet on purplefox exploiting PrintNightmare (CVE-2021-34527) vulnerability in cryptocurrency mining campaign PurpleFox |
2021-07-06
⋅
Twitter (@_alex_il_)
⋅
Tweet on REvil ransomware actor using vulnerable defender executable in its infection flow in early may before Kaseya attack REvil |
2021-07-06
⋅
Twitter (@MBThreatIntel)
⋅
Tweet on a malspam campaign that is taking advantage of Kaseya VSA ransomware attack to drop CobaltStrike Cobalt Strike |
2021-07-05
⋅
Twitter (@R3MRUM)
⋅
Twitter thread with additional context on C2 domains found in REvil configuration REvil |
2021-07-05
⋅
Twitter (@SophosLabs)
⋅
Tweet with a REvil ransomware execution demo REvil |
2021-07-04
⋅
Twitter (@svch0st)
⋅
Tweet on #Kaseya detection tool for detecting REvil REvil |
2021-07-04
⋅
Twitter (@PolarToffee)
⋅
Tweet on AvosLocker, ransomware advertising for affiliates through Dread |
2021-07-03
⋅
Twitter (@fwosar)
⋅
Twitter thread on REvil's cryptographic scheme REvil |
2021-07-03
⋅
Twitter (@LloydLabs)
⋅
Twitter Thread on Revil sideloading DLL used in Kaseya attack REvil |
2021-07-02
⋅
Twitter (@VK_intel)
⋅
Tweet on Revil ransomware analysis used in Kaseya attack REvil |
2021-07-02
⋅
Twitter (@SyscallE)
⋅
Tweet on Revil dropper used in Kaseya attack REvil |
2021-06-29
⋅
Twitter (@IntezerLabs)
⋅
Tweet on unknown elf backdoor based on an open source remote shell named "amcsh" BioSet |
2021-06-29
⋅
Twitter (@sisoma2)
⋅
Tweet on vidar stealer using Tumblr to obtain dynamic config Vidar |
2021-06-29
⋅
Twitter (@VK_intel)
⋅
Tweet on Linux version of REvil ransomware REvil |
2021-06-28
⋅
Twitter (@AdamTheAnalyst)
⋅
Tweet on suspected REvil exfiltration (over RClone FTP) server REvil REvil |
2021-06-28
⋅
Twitter (@VK_intel)
⋅
Tweet on ELF version of REvil REvil |
2021-06-27
⋅
Twitter (@GossiTheDog)
⋅
Tweet on babuk ransomware builder Babuk |
2021-06-23
⋅
Twitter (@IntezerLabs)
⋅
Tweet on linux version of Derusbi Derusbi |
2021-06-22
⋅
Twitter (@Cryptolaemus1)
⋅
Tweet on TA575, a Dridex affiliate delivering cobaltstrike (packed withe Cryptone) directly via the macro docs Cobalt Strike Dridex |