Click here to download all references as Bib-File.

Enter keywords to filter the library entries below or Propose new Entry
2026-08-26MicrosoftParasharan Raghavan, Sagar Patil, Suriyaraj Natarajan
TerminalFix campaign deploys a reverse tunnel through multistage intrusion
Lorem Ipsum
2026-07-31Microsoft Threat Intelligence
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
ChocoShell CornFlake Storm-2945
2026-07-16Microsoft SecurityBalaji Venkatesh S, Microsoft Security Research
ACR Stealer: Two observed intrusion chains amid increased threat activity
ACR Stealer
2026-06-25Microsoft SecurityMicrosoft Defender Experts, Microsoft Defender Security Research Team, Parth Jomadkar
Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access
TonRAT
2026-06-17MicrosoftMicrosoft Defender Research Team
From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet
2026-06-03MicrosoftMicrosoft
How Microsoft names threat actors
Wisteria Tsunami
2026-05-28eSentireeSentire
Nimbus RAT: How Threat Actors Are Abusing Microsoft Teams and Google Drive to Deploy a Java RAT
2026-05-20K7 SecuritySrinivasan E
Fake Microsoft Teams download sites are being used to deliver ValleyRAT via DLL sideloading
ValleyRAT
2026-05-19MicrosoftMicrosoft Threat Intelligence
Exposing Fox Tempest: A malware-signing service operation (Podcast)
Akira Rhysida Akira BlackByte BlueSky Broomstick Lumma Stealer Rhysida Spyder Vidar Fox Tempest
2026-05-19MicrosoftSteven Masada
Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomware
Akira INC Qilin Rhysida AgendaCrypt Akira Broomstick INC Lumma Stealer Rhysida Vidar Fox Tempest
2026-05-19The RecordJonathan Greig
Microsoft disrupts Fox Tempest malware-signing-as-a-service platform tied to ransomware gangs
Akira INC Qilin Rhysida AgendaCrypt Akira Broomstick INC Lumma Stealer Rhysida Vidar Fox Tempest
2026-05-19Github (microsoft)Microsoft
MSTIC actor name mapping in JSON format
Amethyst Rain Houndstooth Typhoon Pinstripe Lightning Storm-0252 Wisteria Tsunami
2026-05-18MicrosoftMicrosoft Defender Security Research Team
How Storm-2949 turned a compromised identity into a cloud-wide breach
Storm-2949
2026-05-14MicrosoftMicrosoft Threat Intelligence
Kazuar: Anatomy of a nation-state botnet
Kazuar
2026-04-07MicrosoftMicrosoft Threat Intelligence
SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks
2026-03-12MicrosoftMicrosoft Threat Intelligence
Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft
Storm-2561
2026-03-11MicrosoftMicrosoft Defender Experts, Microsoft Defender Security Research Team
Contagious Interview: Malware delivered through fake developer job interviews
BeaverTail OtterCookie StoatWaffle InvisibleFerret PylangGhost GolangGhost Contagious Interview
2026-03-06MicrosoftMicrosoft Threat Intelligence
AI as tradecraft: How threat actors operationalize AI
OtterCookie
2026-03-03MicrosoftMicrosoft
Signed malware impersonating workplace apps deploys RMM backdoors
TrustConnect RAT
2026-03-02MicrosoftMicrosoft Defender Security Research Team
OAuth redirection abuse enables phishing and malware delivery