Click here to download all references as Bib-File.•
| 2021-03-24
            
            ⋅
            
            Twitter (@VK_intel)
            ⋅ Tweet on REvil ransomware REvil | 
| 2021-01-29
            
            ⋅
            
            Twitter (@VK_intel)
            ⋅ Tweet on analysis of Vovalex ransomware written in DLang Vovalex | 
| 2021-01-07
            
            ⋅
            
            Advanced Intelligence
            ⋅ Crime Laundering Primer: Inside Ryuk Crime (Crypto) Ledger & Risky Asian Crypto Traders Ryuk | 
| 2020-11-19
            
            ⋅
            
            Twitter (@VK_intel)
            ⋅ Tweet on Trickbot Group pushing LIGHTBOT powershell script to gather information about AD Server LightBot | 
| 2020-11-17
            
            ⋅
            
            Twitter (@VK_intel)
            ⋅ Tweet on a new fileless TrickBot loading method using code from MemoryModule TrickBot | 
| 2020-11-06
            
            ⋅
            
            Advanced Intelligence
            ⋅ Anatomy of Attack: Inside BazarBackdoor to Ryuk Ransomware "one" Group via Cobalt Strike BazarBackdoor Cobalt Strike Ryuk | 
| 2020-10-12
            
            ⋅
            
            Advanced Intelligence
            ⋅ "Front Door" into BazarBackdoor: Stealthy Cybercrime Weapon BazarBackdoor Cobalt Strike Ryuk | 
| 2020-08-14
            
            ⋅
            
            Twitter (@VK_intel)
            ⋅ Tweet on Zloader infection leading to Cobaltstrike Installation Cobalt Strike Zloader | 
| 2020-07-11
            
            ⋅
            
            Advanced Intelligence
            ⋅ TrickBot Group Launches Test Module Alerting on Fraud Activity TrickBot | 
| 2020-07-10
            
            ⋅
            
            ReversingLabs
            ⋅ YARA Rules talks and presentation of REVERSING 2020 | 
| 2020-06-17
            
            ⋅
            
            Twitter (@VK_intel)
            ⋅ Tweet on signed Tinymet payload (V.02) used by TA505 TinyMet | 
| 2020-05-19
            
            ⋅
            
            zero2auto
            ⋅ Netwalker Ransomware - From Static Reverse Engineering to Automatic Extraction Mailto | 
| 2020-05-04
            
            ⋅
            
            Twitter (@VK_intel)
            ⋅ GuLoader API Loader Algorithm CloudEyE | 
| 2020-04-29
            
            ⋅
            
            Twitter (@VK_intel)
            ⋅ Some Insight into GuLoader family CloudEyE | 
| 2020-04-24
            
            ⋅ TrickBot "BazarBackdoor" Process Hollowing Injection Primer BazarBackdoor | 
| 2020-04-21
            
            ⋅
            
            Twitter (@VK_intel)
            ⋅ Tweet on Signed GuLoader CloudEyE | 
| 2020-02-27
            
            ⋅ Let’s Learn: Inside Parallax RAT Malware: Process Hollowing Injection & Process Doppelgänging API Mix: Part I Parallax RAT | 
| 2020-02-05
            
            ⋅
            
            SentinelOne
            ⋅ Pro-Russian CyberSpy Gamaredon Intensifies Ukrainian Security Targeting Pteranodon | 
| 2020-01-25
            
            ⋅
            
            Github (k-vitali)
            ⋅ Extracted Config for Ragnarok Ransomware Ragnarok | 
| 2020-01-09
            
            ⋅
            
            SentinelOne
            ⋅ Top-Tier Russian Organized Cybercrime Group Unveils Fileless Stealthy “PowerTrick” Backdoor for High-Value Targets TrickBot WIZARD SPIDER |