Click here to download all references as Bib-File.•
| 2026-07-21
⋅
DTEX
⋅
From Payroll to Pyongyang: The DPRK IT Worker Money Trail |
| 2026-07-21
⋅
ANY.RUN
⋅
SnappyClient Analysis SnappyClient |
| 2026-07-20
⋅
Medium Ireneusz Tarnowski
⋅
INC Ransom: Infrastructure Analysis, Operational Tradecraft, and Detection Opportunities INC INC |
| 2026-07-18
⋅
Github (muhammadzidane632)
⋅
Hopeless Hopeless |
| 2026-07-17
⋅
OpenSourceMalware
⋅
ChainVeil and ViteVenom are DPRK’s PolinRider Campaign JADESNOW |
| 2026-07-17
⋅
Elastic
⋅
New North Korean campaign uses fake coding interviews to steal developer credentials OtterCookie |
| 2026-07-15
⋅
Zscaler
⋅
ClaudeFix: Shared Claude Chats Meet ClickFix MacSync |
| 2026-07-15
⋅
OpenSourceMalware
⋅
PolinRider Confirmed Footprint Grows 6.5x Since March JADESNOW |
| 2026-07-15
⋅
Expel
⋅
Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident Ghost RAT |
| 2026-07-15
⋅
Symantec
⋅
Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor Daxin |
| 2026-07-14
⋅
Checkmarx
⋅
Sequel to ChainVeil npm Malware Targets Vite Ecosystem JADESNOW |
| 2026-07-14
⋅
Ctrl-Alt-Intel
⋅
Burnt by Burgers: Highlighting Void Blizzard’s Russian State Links |
| 2026-07-14
⋅
PICUS Security
⋅
FSB Center 16: How Russian hackers exploit routers via SNMP and Cisco Smart Install |
| 2026-07-13
⋅
Github (VenzoV)
⋅
Lockbit 5.0 loader technical analysis LockBit |
| 2026-07-13
⋅
abuse.ch
⋅
MalwareBazaar | SHA256 13543ef85a0988a09ef430a1f114f920a670a82f9e360ff9e6872252062d4768 (RevStealer) RevStealer |
| 2026-07-13
⋅
kienmanowar Blog
⋅
[QuickNote] SolidPDFCreator – Mustang Panda Stage-1 Backdoor (Target India) |
| 2026-07-12
⋅
OX Security
⋅
Malware-Slop: Crypto Stealer Impersonating Polymarket Exposes Its Own Credentials OtterCandy |
| 2026-07-07
⋅
Proofpoint
⋅
One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation IceCube |
| 2026-07-07
⋅
Cisco Talos
⋅
UAT-7810 continues building ORB networks using new malware DOGLEASH LONGLEASH JARLEASH UAT-7810 |
| 2026-07-02
⋅
Mrtiepolo
⋅
Operation Turb00 — Part 3: Unmasking the SnappyClient RAT HijackLoader SnappyClient |