Click here to download all references as Bib-File.•
2022-06-06
⋅
NCC Group
⋅
Shining the Light on Black Basta Black Basta |
2022-05-20
⋅
nccgroup
⋅
Metastealer – filling the Racoon void MetaStealer |
2022-04-12
⋅
Sophos
⋅
Attackers linger on government agency computers before deploying Lockbit ransomware LockBit |
2021-12-22
⋅
Sophos
⋅
Avos Locker remotely accesses boxes, even running in Safe Mode AvosLocker |
2021-12-20
⋅
IronNet
⋅
Detecting anomalous network traffic resulting from a successful Log4j attack |
2021-12-16
⋅
TEAMT5
⋅
Winnti is Coming - Evolution after Prosecution Cobalt Strike FishMaster FunnySwitch HIGHNOON ShadowPad Spyder |
2021-12-02
⋅
Palo Alto Networks Unit 42
⋅
APT Expands Attack on ManageEngine With Active Campaign Against ServiceDesk Plus Godzilla Webshell |
2021-11-29
⋅
Certitude
⋅
Unpatched Exchange Servers distribute Phishing Links (SquirrelWaffle) Squirrelwaffle |
2021-11-16
⋅
IronNet
⋅
How IronNet's Behavioral Analytics Detect REvil and Conti Ransomware Cobalt Strike Conti IcedID REvil |
2021-11-07
⋅
Palo Alto Networks Unit 42
⋅
Targeted Attack Campaign Against ManageEngine ADSelfService Plus Delivers Godzilla Webshells, NGLite Trojan and KdcSponge Stealer Godzilla Webshell NGLite |
2021-10-12
⋅
IronNet
⋅
Continued Exploitation of CVE-2021-26084 |
2021-10-07
⋅
Evolution after prosecution : Psychedelic APT41 Dizzyvoid |
2021-10-07
⋅
Palo Alto Networks Unit 42
⋅
SilverTerrier – Nigerian Business Email Compromise |
2021-09-29
⋅
Trend Micro
⋅
FormBook Adds Latest Office 365 0-Day Vulnerability (CVE-2021-40444) to Its Arsenal Formbook |
2021-09-03
⋅
Sophos
⋅
Conti affiliates use ProxyShell Exchange exploit in ransomware attacks Cobalt Strike Conti |
2021-08-05
⋅
Twitter (@AltShiftPrtScn)
⋅
Tweet on Conti ransomware affiliates using AnyDesk, Atera, Splashtop, Remote Utilities and ScreenConnect to maintain network access Conti |
2021-08-05
⋅
Twitter (@AltShiftPrtScn)
⋅
Tweet on Lorenz ransomware tricking user into allowing OAuth permissions to "Thunderbird with ExQuilla" for O365 Lorenz |
2021-07-21
⋅
⋅
TEAMT5
⋅
"Le" is not tired of this, IE is really naughty Magniber |
2021-07-21
⋅
Twitter (@AltShiftPrtScn)
⋅
Tweet on Conti ransomware actor installing AnyDesk for remote access in victim environment Conti |
2021-07-19
⋅
Minister for Foreign Affairs of Australia
⋅
Australia joins international partners in attribution of malicious cyber activity to China APT31 APT40 HAFNIUM |