Click here to download all references as Bib-File.•
2021-05-28
⋅
Microsoft
⋅
Breaking down NOBELIUM’s latest early-stage toolset BOOMBOX Cobalt Strike |
2021-05-27
⋅
Microsoft
⋅
Another Nobelium Cyberattack |
2021-05-21
⋅
⋅
LAC
⋅
Targeted attack by 'Cobalt Strike loader' that exploits Microsoft's digital signature-Attacker group APT41 Cobalt Strike DUSTPAN |
2021-05-21
⋅
blackarrow
⋅
Leveraging Microsoft Teams to persist and cover up Cobalt Strike traffic Cobalt Strike |
2021-05-20
⋅
Microsoft
⋅
Phorpiex morphs: How a longstanding botnet persists and thrives in the current threat environment Phorpiex |
2021-05-20
⋅
Github (microsoft)
⋅
Microsoft 365 Defender Hunting Queries for hunting multiple threat actors' TTPs and malwares STRRAT OceanLotus BabyShark Elise Revenge RAT WastedLocker Zebrocy |
2021-05-20
⋅
Twitter (@MsftSecIntel)
⋅
Tweet on Java-based STRRAT malware campaign distributed via email STRRAT |
2021-05-12
⋅
Microsoft
⋅
Incident response playbooks |
2021-05-11
⋅
Twitter (@MsftSecIntel)
⋅
Tweet on Snip3 crypter delivering AsyncRAT or AgentTesla Agent Tesla AsyncRAT |
2021-05-07
⋅
Cisco Talos
⋅
Lemon Duck spreads its wings: Actors target Microsoft Exchange servers, incorporate new TTPs CHINACHOPPER Cobalt Strike Lemon Duck |
2021-05-07
⋅
SophosLabs Uncut
⋅
New Lemon Duck variants exploiting Microsoft Exchange Server CHINACHOPPER Cobalt Strike Lemon Duck |
2021-05-07
⋅
Microsoft
⋅
Human operated ransomware |
2021-04-26
⋅
⋅
Medium testbnull
⋅
Microsoft Exchange From Deserialization to Post-Auth RCE (CVE-2021–28482) |
2021-04-22
⋅
Cybereason
⋅
Prometei Botnet Exploiting Microsoft Exchange Vulnerabilities Prometei Prometei |
2021-04-20
⋅
Bleeping Computer
⋅
Fake Microsoft Store, Spotify sites spread info-stealing malware Ficker Stealer |
2021-04-19
⋅
CERT NZ
⋅
Microsoft 365 phishing using fake voicemail messages |
2021-04-16
⋅
Trend Micro
⋅
Could the Microsoft Exchange breach be stopped? CHINACHOPPER |
2021-04-16
⋅
Associated Press
⋅
Sanctioned Russian IT firm was partner with Microsoft, IBM |
2021-04-16
⋅
Zero Day
⋅
Sanctioned Firm Accused of Helping Russian Intelligence Was Part of Microsoft’s Early Vuln Access Program — MAPP |
2021-04-15
⋅
Palo Alto Networks Unit 42
⋅
Actor Exploits Microsoft Exchange Server Vulnerabilities, Cortex XDR Blocks Harvesting of Credentials CHINACHOPPER |