Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2020-10-29 ⋅ Twitter (@SophosLabs) ⋅ SophosLabs
Tweet on similarities between BUER in-memory loader & RYUK in-memory loader
Buer Ryuk
2020-10-28 ⋅ SophosLabs Uncut ⋅ Anand Ajjan, Bill Kearny, Brett Cove, Elida Leite, Gabor Szappanos, Peter Mackenzie, Sean Gallagher, Syed Shahram
Hacks for sale: inside the Buer Loader malware-as-a-service
Buer Ryuk Zloader
2020-10-21 ⋅ SophosLabs Uncut ⋅ Sean Gallagher
LockBit uses automated attack tools to identify tasty targets
LockBit
2020-09-24 ⋅ SophosLabs ⋅ SophosLabs
Email-delivered MoDi RAT attack pastes PowerShell commands
MoDi RAT
2020-09-24 ⋅ SophosLabs Uncut ⋅ Andrew Brandt, Andrew O'Donnell, Fraser Howard
Email-delivered MoDi RAT attack pastes PowerShell commands
DBatLoader
2020-09-17 ⋅ SophosLabs Uncut ⋅ Andrew Brandt, Peter Mackenzie
Maze attackers adopt Ragnar Locker virtual machine technique
Maze
2020-08-12 ⋅ SophosLabs Uncut ⋅ Sean Gallagher
Color by numbers: inside a Dharma ransomware-as-a-service attack
Dharma
2020-08-04 ⋅ SophosLabs Uncut ⋅ Anand Ajjan, Mark Loman
WastedLocker’s techniques point to a familiar heritage
WastedLocker
2020-07-14 ⋅ SophosLabs Uncut ⋅ Markel Picado, Sean Gallagher
RATicate upgrades “RATs as a Service” attacks with commercial “crypter”
LokiBot BetaBot CloudEyE NetWire RC
2020-05-27 ⋅ SophosLabs ⋅ Andrew Brandt, Gabor Szappanos
Netwalker ransomware tools give insight into threat actor
Mailto
2020-05-21 ⋅ Sophos ⋅ SophosLabs Uncut
Asnarök attackers twice modified attack midstream
NOTROBIN Ragnarok
2020-05-21 ⋅ Sophos ⋅ SophosLabs Uncut
Ragnar Locker ransomware deploys virtual machine to dodge security
RagnarLocker
2020-05-14 ⋅ SophosLabs ⋅ Markel Picado
RATicate: an attacker’s waves of information-stealing malware
Agent Tesla BetaBot BlackRemote Formbook Loki Password Stealer (PWS) NetWire RC NjRAT Remcos
2020-05-12 ⋅ SophosLabs Uncut ⋅ Sophos
Maze ransomware: extorting victims for 1 year and counting
Maze
2020-03-05 ⋅ SophosLabs ⋅ Sergei Shevchenko
Cloud Snooper Attack Bypasses AWS Security Measures
Cloud Snooper Ghost RAT
2019-12-24 ⋅ Sophos ⋅ SophosLabs Threat Research
Gozi V3: tracked by their own stealth
ISFB
2019-12-09 ⋅ SophosLabs Uncut ⋅ Andrew Brandt
Snatch ransomware reboots PCs into Safe Mode to bypass protection
Snatch
2019-09-18 ⋅ SophosLabs Uncut ⋅ Peter Mackenzie
The WannaCry hangover
WannaCryptor
2019-09-17 ⋅ SophosLabs ⋅ Peter Mackenzie
WannaCry Aftershock
WannaCryptor
2019-08-05 ⋅ SophosLabs ⋅ Albert Zsigovits
Baldr vs The World: A credential thief's burst of creative energy delivers a dangerous new threat
Baldr