Click here to download all references as Bib-File.•
2023-12-07
⋅
Microsoft
⋅
Star Blizzard increases sophistication and evasion in ongoing attacks Callisto |
2023-12-06
⋅
splunk
⋅
Unmasking the Enigma: A Historical Dive into the World of PlugX Malware PlugX |
2023-12-05
⋅
PWC
⋅
The Tortoise and The Malwahare SnappyTCP |
2023-12-05
⋅
Proofpoint
⋅
TA422’s Dedicated Exploitation Loop—the Same Week After Week |
2023-12-02
⋅
openhunting.io
⋅
Threat Hunting Malware Infrastructure VBREVSHELL AsyncRAT |
2023-12-01
⋅
Twitter (@MsftSecIntel)
⋅
Tweet about Storm-1044 and Storm-0216, Danabot leading to Cactus ransomware Cactus DanaBot TA2101 |
2023-12-01
⋅
Twitter (@MsftSecIntel)
⋅
Tweet on Danabot leading to cactus ransomware Cactus DanaBot Storm-1044 |
2023-11-30
⋅
Twitter (@embee_research)
⋅
Advanced Threat Intel Queries - Catching 83 Qakbot Servers with Regex, Censys and TLS Certificates QakBot |
2023-11-27
⋅
Twitter (@embee_research)
⋅
Building Threat Intel Queries Utilising Regex and TLS Certificates - (BianLian) BianLian |
2023-11-22
⋅
Microsoft
⋅
Diamond Sleet supply chain compromise distributes a modified CyberLink installer LambLoad |
2023-11-21
⋅
Palo Alto Networks Unit 42
⋅
Hacking Employers and Seeking Employment: Two Job-Related Campaigns Bear Hallmarks of North Korean Threat Actors BeaverTail InvisibleFerret WageMole |
2023-11-21
⋅
adlumin
⋅
PlayCrypt Ransomware-as-a-Service Expands Threat from Script Kiddies and Sophisticated Attackers PLAY |
2023-11-16
⋅
YouTube (Swiss Cyber Storm)
⋅
Resilience Rising: Countering the Threat Actors Behind Black Basta Ransomware Black Basta |
2023-11-09
⋅
Microsoft
⋅
Microsoft shares threat intelligence at CYBERWARCON 2023 Blue Tsunami |
2023-11-08
⋅
Deep instinct
⋅
MuddyC2Go – Latest C2 Framework Used by Iranian APT MuddyWater Spotted in Israel PhonyC2 MuddyC2Go |
2023-11-03
⋅
Uptycs
⋅
GhostSec: From Fighting ISIS to Possibly Targeting Israel with RaaS GhostLocker GhostSec |
2023-11-02
⋅
eSentire
⋅
From DarkGate to DanaBot DanaBot DarkGate |
2023-11-02
⋅
DataBreaches.net
⋅
Jeffco Public Schools hit by the same threat actors that hit Clark County School District — and via the same way SingularityMD |
2023-11-01
⋅
Deep instinct
⋅
MuddyWater eN-Able spear-phishing with new TTPs PhonyC2 |
2023-10-31
⋅
Infoblox
⋅
Prolific Puma: Shadowy Link Shortening Service Enables Cybercrime Prolific Puma |