Click here to download all references as Bib-File.•
| 2024-11-09
⋅
Microsoft
⋅
BlueHat 2024: S17: MSTIC - A Threat Intelligence Year in Review Storm-0826 |
| 2024-11-06
⋅
Cloudsek
⋅
Mozi Resurfaces as Androxgh0st Botnet: Unraveling The Latest Exploitation Wave Mozi |
| 2024-10-03
⋅
GitHub (dstepanic)
⋅
Getting Cozy with Milk and WARMCOOKIES WarmCookie |
| 2024-09-20
⋅
Trend Micro
⋅
How Ransomhub Ransomware Uses EDRKillShifter to Disable EDR and Antivirus Protections RansomHub Water Bakunawa |
| 2024-08-19
⋅
Aon
⋅
Unveiling "sedexp": A Stealthy Linux Malware Exploiting udev Rules sedexp |
| 2024-08-13
⋅
Google
⋅
Finding Malware: Unveiling NUMOZYLOD with Google Security Operations EugenLoader UNC4536 |
| 2024-05-01
⋅
Mandiant
⋅
Uncharmed: Untangling Iran's APT42 Operations TAMECAT |
| 2024-04-24
⋅
Securonix
⋅
Analysis of Ongoing FROZEN#SHADOW Attack Campaign Leveraging SSLoad Malware and RMM Software for Domain Takeover Cobalt Strike Latrodectus |
| 2024-04-15
⋅
UC Santa Cruz
⋅
A Tale of Two Industroyers: It was the Season of Darkness Industroyer INDUSTROYER2 |
| 2024-04-10
⋅
2024-04-10
⋅
XZ Utils Backdoor | Threat Actor Planned to Inject Further Vulnerabilities xzbot |
| 2024-03-07
⋅
ESET Research
⋅
Evasive Panda leverages Monlam Festival to target Tibetans MgBot Nightdoor |
| 2024-02-27
⋅
Mandiant
⋅
When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors LIGHTRAIL MINIBIKE MINIBUS UNC1549 |
| 2024-02-27
⋅
Twitter (@greglesnewich)
⋅
Tweet with context on TA421 / APT29 / Midnight Blizzard / BlueBravo / Cozy Bear WINELOADER |
| 2024-02-13
⋅
Palo Alto Networks Unit 42
⋅
A Deep Dive Into Malicious Direct Syscall Detection Lumma Stealer |
| 2024-01-26
⋅
Ars Technica
⋅
The life and times of Cozy Bear, the Russian hackers who just hit Microsoft and HPE |
| 2024-01-25
⋅
JSAC 2024
⋅
NSPX30: A sophisticated AitM-enabled implant evolving since 2005 NSPX30 ProjectWood |
| 2024-01-25
⋅
ESET Research
⋅
NSPX30: A sophisticated AitM-enabled implant evolving since 2005 NSPX30 ProjectWood Blackwood TheWizards |
| 2024-01-16
⋅
NOZOMI Network Labs
⋅
P2PInfect Worm Evolves to Target a New Platform P2Pinfect |
| 2023-09-28
⋅
Confiant
⋅
Exploring ScamClub Payloads via Deobfuscation Using Abstract Syntax Trees ScamClub |
| 2023-06-15
⋅
Google
⋅
Barracuda ESG Zero-Day Vulnerability (CVE-2023-2868) Exploited Globally by Aggressive and Skilled Actor, Suspected Links to China SALTWATER SEASPY WHIRLPOOL UNC4841 |