Click here to download all references as Bib-File.•
2021-12-09
⋅
HP
⋅
Emotet’s Return: What’s Different? Emotet |
2021-11-23
⋅
HP
⋅
RATDispenser: Stealthy JavaScript Loader Dispensing RATs into the Wild AdWind Ratty STRRAT CloudEyE Formbook Houdini Panda Stealer Remcos |
2021-11-16
⋅
Flashpoint
⋅
RAMP Ransomware’s Apparent Overture to Chinese Threat Actors |
2021-10-18
⋅
Flashpoint
⋅
REvil Disappears Again: ‘Something Is Rotten in the State of Ransomware’ REvil REvil |
2021-10-01
⋅
HP
⋅
Threat Insights Report Q3 - 2021 STRRAT CloudEyE NetWire RC Remcos TrickBot Vjw0rm |
2021-09-29
⋅
Flashpoint
⋅
Russian hacker Q&A: An Interview With REvil-Affiliated Ransomware Contractor REvil REvil |
2021-09-28
⋅
Flashpoint
⋅
REvil’s “Cryptobackdoor” Con: Ransomware Group’s Tactics Roil Affiliates, Sparking a Fallout REvil |
2021-09-19
⋅
HP
⋅
MirrorBlast and TA505: Examining Similarities in Tactics, Techniques and Procedures MirrorBlast |
2021-08-10
⋅
Flashpoint
⋅
REvil Master Key for Kaseya Attack Posted to XSS REvil |
2021-07-30
⋅
HP
⋅
Detecting TA551 domains Valak Dridex IcedID ISFB QakBot |
2021-07-27
⋅
Flashpoint
⋅
Chatter Indicates BlackMatter as REvil Successor REvil |
2021-07-09
⋅
Seqrite
⋅
Seqrite uncovers second wave of Operation SideCopy targeting Indian critical infrastructure PSUs NjRAT ReverseRAT |
2021-06-28
⋅
HP
⋅
Snake Keylogger’s Many Skins: Analysing Code Reuse Among Infostealers 404 Keylogger Phoenix Keylogger |
2021-06-15
⋅
Nextron Systems
⋅
Use YARA math Module Extension in THOR TechPreview and THOR Lite |
2021-06-04
⋅
JPCERT/CC
⋅
PHP Malware Used in Lucky Visitor Scam |
2021-05-25
⋅
Hydra: Where The Crypto Money Laundering Trail Goes Dark |
2021-05-21
⋅
Twitter (@alberto__segura)
⋅
Tweet on Flubot version 4.2 (p.php variant) with new AES strings encryption FluBot |
2021-05-13
⋅
Malwarebytes
⋅
Newly observed PHP-based skimmer shows ongoing Magecart Group 12 activity magecart |
2021-05-11
⋅
Flashpoint
⋅
DarkSide Ransomware Links to REvil Group Difficult to Dismiss DarkSide REvil |
2021-04-30
⋅
MADRID Labs
⋅
Qbot: Analyzing PHP Proxy Scripts from Compromised Web Server QakBot |