Click here to download all references as Bib-File.
2021-03-24 ⋅ Twitter (@VK_intel) ⋅ Tweet on REvil ransomware REvil |
2021-01-29 ⋅ Twitter (@VK_intel) ⋅ Tweet on analysis of Vovalex ransomware written in DLang Vovalex |
2021-01-07 ⋅ Advanced Intelligence ⋅ Crime Laundering Primer: Inside Ryuk Crime (Crypto) Ledger & Risky Asian Crypto Traders Ryuk |
2020-11-19 ⋅ Twitter (@VK_intel) ⋅ Tweet on Trickbot Group pushing LIGHTBOT powershell script to gather information about AD Server LightBot |
2020-11-17 ⋅ Twitter (@VK_intel) ⋅ Tweet on a new fileless TrickBot loading method using code from MemoryModule TrickBot |
2020-11-06 ⋅ Advanced Intelligence ⋅ Anatomy of Attack: Inside BazarBackdoor to Ryuk Ransomware "one" Group via Cobalt Strike BazarBackdoor Cobalt Strike Ryuk |
2020-10-12 ⋅ Advanced Intelligence ⋅ "Front Door" into BazarBackdoor: Stealthy Cybercrime Weapon BazarBackdoor Cobalt Strike Ryuk |
2020-08-14 ⋅ Twitter (@VK_intel) ⋅ Tweet on Zloader infection leading to Cobaltstrike Installation Cobalt Strike Zloader |
2020-07-11 ⋅ Advanced Intelligence ⋅ TrickBot Group Launches Test Module Alerting on Fraud Activity TrickBot |
2020-07-10 ⋅ ReversingLabs ⋅ YARA Rules talks and presentation of REVERSING 2020 |
2020-06-17 ⋅ Twitter (@VK_intel) ⋅ Tweet on signed Tinymet payload (V.02) used by TA505 TinyMet |
2020-05-19 ⋅ zero2auto ⋅ Netwalker Ransomware - From Static Reverse Engineering to Automatic Extraction Mailto |
2020-05-04 ⋅ Twitter (@VK_intel) ⋅ GuLoader API Loader Algorithm CloudEyE |
2020-04-29 ⋅ Twitter (@VK_intel) ⋅ Some Insight into GuLoader family CloudEyE |
2020-04-24 ⋅ TrickBot "BazarBackdoor" Process Hollowing Injection Primer BazarBackdoor |
2020-04-21 ⋅ Twitter (@VK_intel) ⋅ Tweet on Signed GuLoader CloudEyE |
2020-02-27 ⋅ Let’s Learn: Inside Parallax RAT Malware: Process Hollowing Injection & Process Doppelgänging API Mix: Part I Parallax RAT |
2020-02-05 ⋅ SentinelOne ⋅ Pro-Russian CyberSpy Gamaredon Intensifies Ukrainian Security Targeting Pteranodon |
2020-01-25 ⋅ Github (k-vitali) ⋅ Extracted Config for Ragnarok Ransomware Ragnarok |
2020-01-09 ⋅ SentinelOne ⋅ Top-Tier Russian Organized Cybercrime Group Unveils Fileless Stealthy “PowerTrick” Backdoor for High-Value Targets TrickBot WIZARD SPIDER |