Click here to download all references as Bib-File.•
2023-01-01
⋅
ThreatMon
⋅
Reverse Engineering RokRAT: A Closer Look at APT37’s Onedrive-Based Attack Vector RokRAT |
2022-12-09
⋅
Secureworks
⋅
Drokbk Malware Uses GitHub as Dead Drop Resolver Drokbk |
2022-12-09
⋅
Positive Technologies
⋅
APT Cloud Atlas: Unbroken Threat |
2022-11-04
⋅
DataBreaches.net
⋅
Malaysian online stock brokerage firm victim of cyberattack Desorden Group |
2022-09-28
⋅
Twitter (@ESETresearch)
⋅
Twitter Thread linking CloudMensis to RokRAT / ScarCruft CloudMensis RokRAT |
2022-09-07
⋅
Google
⋅
Initial access broker repurposing techniques in targeted attacks against Ukraine AnchorMail Cobalt Strike IcedID |
2022-09-06
⋅
ESET Research
⋅
Worok: The big picture MimiKatz PNGLoad reGeorg ShadowPad Worok |
2022-08-17
⋅
Group-IB
⋅
Switching side jobs Links between ATMZOW JS-sniffer and Hancitor Hancitor |
2022-08-02
⋅
Recorded Future
⋅
Initial Access Brokers Are Key to Rise in Ransomware Attacks Azorult BlackMatter Conti Mars Stealer Raccoon RedLine Stealer Taurus Stealer Vidar |
2022-07-14
⋅
Sophos
⋅
Rapid Response: The Ngrok Incident Guide |
2022-06-13
⋅
Sekoia
⋅
BumbleBee: a new trendy loader for Initial Access Brokers BumbleBee |
2022-05-23
⋅
Trend Micro
⋅
Operation Earth Berberoka reptile oRAT Ghost RAT PlugX pupy Earth Berberoka |
2022-05-19
⋅
Trend Micro
⋅
Bruised but Not Broken: The Resurgence of the Emotet Botnet Malware Emotet QakBot |
2022-04-27
⋅
Trend Micro
⋅
New APT Group Earth Berberoka Targets Gambling Websites With Old and New Malware HelloBot AsyncRAT Ghost RAT HelloBot PlugX Quasar RAT Earth Berberoka |
2022-04-27
⋅
Trendmicro
⋅
IOCs for Earth Berberoka - Windows AsyncRAT Cobalt Strike PlugX Quasar RAT Earth Berberoka |
2022-04-27
⋅
Trendmicro
⋅
IOCs for Earth Berberoka - Linux Rekoobe pupy Earth Berberoka |
2022-04-27
⋅
Trendmicro
⋅
IOCs for Earth Berberoka - MacOS oRAT Earth Berberoka |
2022-04-27
⋅
Trendmicro
⋅
IOCs for Earth Berberoka Earth Berberoka |
2022-03-17
⋅
Google
⋅
Exposing initial access broker with ties to Conti BazarBackdoor BumbleBee Conti EXOTIC LILY |
2022-03-17
⋅
Google
⋅
Exposing initial access broker with ties to Conti BazarBackdoor BumbleBee Cobalt Strike Conti |