Click here to download all references as Bib-File.•
| 2021-01-11
⋅
Kaspersky Labs
⋅
Sunburst backdoor – code overlaps with Kazuar Kazuar SUNBURST |
| 2021-01-09
⋅
Connor McGarr's Blog
⋅
Malware Development: Leveraging Beacon Object Files for Remote Process Injection via Thread Hijacking Cobalt Strike |
| 2021-01-09
⋅
Github (f0wl)
⋅
ezuri_unpack |
| 2021-01-08
⋅
Zscaler
⋅
Ransomware Delivered Using RDP Brute-Force Attack Dharma |
| 2021-01-08
⋅
Reaqta
⋅
Leonardo S.p.A. Data Breach Analysis |
| 2021-01-08
⋅
US-CERT
⋅
Alert (AA21-008A): Detecting Post-Compromise Threat Activity in Microsoft Cloud Environments SUNBURST SUPERNOVA |
| 2021-01-07
⋅
TRUESEC
⋅
Avoiding supply-chain attacks similar to SolarWinds Orion’s (SUNBURST) SUNBURST |
| 2021-01-07
⋅
Symantec
⋅
SolarWinds: How a Rare DGA Helped Attacker Communications Fly Under the Radar SUNBURST |
| 2021-01-07
⋅
Palo Alto Networks Unit 42
⋅
TA551: Email Attack Campaign Switches from Valak to IcedID IcedID |
| 2021-01-07
⋅
Twitter (@campuscodi)
⋅
Tweet on London's Hackney Council attacked by Pysa/Mespinoza ransomware Mespinoza |
| 2021-01-06
⋅
Bleeping Computer
⋅
Hackers start exploiting the new backdoor in Zyxel devices |
| 2021-01-06
⋅
Trend Micro
⋅
Expanding Range and Improving Speed: A RansomExx Approach RansomEXX |
| 2021-01-06
⋅
DomainTools
⋅
Holiday Bazar: Tracking a TrickBot-Related Ransomware Incident BazarBackdoor TrickBot |
| 2021-01-06
⋅
QuoIntelligence
⋅
ReconHellcat Uses NIST Theme as Lure To Deliver New BlackSoul Malware BlackSoul |
| 2021-01-05
⋅
AhnLab
⋅
[Threat Analysis] CLOP Ransomware that Attacked Korean Distribution Giant Clop |
| 2021-01-05
⋅
Lacework Labs
⋅
TeamTNT Builds Botnet from Chinese Cloud Servers TeamTNT TNTbotinger TeamTNT |
| 2021-01-05
⋅
Intezer
⋅
Operation ElectroRAT: Attacker Creates Fake Companies to Drain Your Crypto Wallets ElectroRAT |
| 2021-01-05
⋅
⋅
Sangfor
⋅
Red team's perspective on the TTPs in Sunburst's backdoor SUNBURST |
| 2021-01-05
⋅
⋅
Sangfor
⋅
Attack from Mustang Panda? My rabbit is back! NjRAT |
| 2021-01-05
⋅
Trend Micro
⋅
Earth Wendigo Injects JavaScript Backdoor to Service Worker for Mailbox Exfiltration Cobalt Strike Earth Wendigo |