Click here to download all references as Bib-File.•
| 2025-08-26
⋅
Google
⋅
Widespread Data Theft Targets Salesforce Instances via Salesloft Drift UNC6395 |
| 2025-08-25
⋅
circleid
⋅
RomCom and TransferLoader IoCs in the Spotlight ROMCOM RAT TransferLoader |
| 2025-08-19
⋅
The Wall Street Journal
⋅
Oregon Man Accused of Operating One of Most Powerful Attack ‘Botnets’ Ever Seen RapperBot |
| 2025-08-11
⋅
ESET Research
⋅
Update WinRAR tools now: RomCom and others exploiting zero-day vulnerability dynamichttp |
| 2025-07-20
⋅
rmceoin.github.io
⋅
Perl based macOS/linux Stealer Pearl Stealer |
| 2025-06-30
⋅
Proofpoint
⋅
10 Things I Hate About Attribution: RomCom vs. TransferLoader DustyHammock MeltingClaw RustyClaw ShadyHammock SlipScreen TransferLoader TA829 |
| 2025-06-02
⋅
Aryaka Networks
⋅
Remcos on the Wire: Analyzing Network Artifacts and C2 Command Structures Remcos |
| 2025-04-25
⋅
Twitter (@teamcymru_S2)
⋅
Tweet on North Korean Cyber Ops Leveraging Russian Infrastructure |
| 2025-03-28
⋅
Cisco Talos
⋅
Gamaredon campaign abuses LNK files to distribute Remcos backdoor Remcos |
| 2025-02-21
⋅
SonicWall
⋅
Remcos RAT Targets Europe: New AMSI and ETW Evasion Tactics Uncovered Remcos |
| 2025-01-30
⋅
Bitdefender
⋅
UAC-0063: Cyber Espionage Operation Expanding from Central Asia HATVIBE |
| 2025-01-20
⋅
Medium walmartglobaltech
⋅
Qbot is Back.Connect ReedBed UNC4393 |
| 2024-12-10
⋅
cyble
⋅
Head Mare Group Intensifies Attacks on Russia with PhantomCore Backdoor PhantomCore Head Mare |
| 2024-12-04
⋅
Rapid7
⋅
Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware Black Basta Cobalt Strike DarkGate SystemBC Zloader |
| 2024-11-08
⋅
Fortinet
⋅
New Campaign Uses Remcos RAT to Exploit Victims Remcos |
| 2024-10-31
⋅
Sophos X-Ops
⋅
Pacific Rim: Inside the Counter-Offensive—The TTPs Used to Neutralize China-Based Threats Asnarök |
| 2024-10-31
⋅
Sophos X-Ops
⋅
Pacific Rim timeline: Information for defenders from a braid of interlocking attack campaigns Asnarök Tstark |
| 2024-10-23
⋅
Cisco Talos
⋅
Threat Spotlight: WarmCookie/BadSpace Cobalt Strike csharp-streamer RAT WarmCookie |
| 2024-10-17
⋅
Cisco Talos
⋅
UAT-5647 targets Ukrainian and Polish entities with RomCom malware variants MeltingClaw ROMCOM RAT RustyClaw ShadyHammock RomCom |
| 2024-10-17
⋅
Hunt.io
⋅
From Warm to Burned: Shedding Light on Updated WarmCookie Infrastructure WarmCookie |