Click here to download all references as Bib-File.•
| 2026-08-15
⋅
neso.re
⋅
Borrowed Machinery: SnappyClient, HijackLoader, and a Shared Codebase? HijackLoader SnappyClient |
| 2026-08-14
⋅
QUIRSO GmbH
⋅
Global Exploitation of CVE-2026–59310 by Suspected Chinese-Nexus APT & Related CVE-2026–59309 Activity |
| 2026-08-14
⋅
⋅
Ministere de l'Economie et des Finances
⋅
Illegitimate access to the information system of the Directorate General of Public Finances ZeroBytes |
| 2026-08-11
⋅
Aryaka Network
⋅
Beyond the Batch File Analysis of a Multi-Stage DonutLoader Infection Chain donut_injector |
| 2026-08-11
⋅
abuse.ch
⋅
MalwareBazaar | SHA256 29e97b2ae2e4c12dddaa69995462ffce950409f222242725f3aab323949ed8ee (HypeAgent) HypeAgent |
| 2026-08-10
⋅
AhnLab
⋅
Attack Cases for Domestic Web Servers Running SoftEther VPN in Korea Larva-26010 |
| 2026-08-10
⋅
LevelBlue
⋅
CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain Babadeda |
| 2026-08-10
⋅
sonatype
⋅
Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads JADESNOW |
| 2026-08-07
⋅
⋅
Kaspersky
⋅
The APT group Head Mare exploits vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph malware to video conferencing participants PhantomCore PhantomGraph |
| 2026-08-05
⋅
SOC Prime
⋅
SmartApeSG Pushes an Unknown RAT Through ClickFix Lures SmartApeSG |
| 2026-08-03
⋅
AhnLab
⋅
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005) CRAT DRATzarus Larva-26005 |
| 2026-08-02
⋅
AhnLab
⋅
Analysis of a Phishing Email Attack Case by the Larva-24009 Threat Actor Quasar RAT Larva-24009 |
| 2026-07-31
⋅
StealthMole
⋅
The Many Faces of ModernStealer: Tracing an Underground Military Data Network ModernStealer |
| 2026-07-31
⋅
Medium @prtheus
⋅
1337_GTWK Linux Malware Analysis 1337_GTWK |
| 2026-07-31
⋅
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft ChocoShell CornFlake Storm-2945 |
| 2026-07-30
⋅
AhnLab
⋅
[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group) Gunra |
| 2026-07-30
⋅
Linux Malware 1337_GWTK Server Analysis 1337_GTWK |
| 2026-07-29
⋅
Proofpoint
⋅
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit ZimReaper Void Blizzard |
| 2026-07-29
⋅
SafeDep
⋅
Joyfill npm Packages Compromised with Blockchain C2 Loader JADESNOW |
| 2026-07-28
⋅
SOCRadar
⋅
Dark Web Profile: ExfilSquad ExfilSquad |