Click here to download all references as Bib-File.•
| 2021-03-11
⋅
Fortinet
⋅
Whitelist Me, Maybe? “Netbounce” Threat Actor Tries A Bold Approach To Evade Detection |
| 2021-03-11
⋅
Bleeping Computer
⋅
Ransomware now attacks Microsoft Exchange servers with ProxyLogon exploits |
| 2021-03-11
⋅
Palo Alto Networks Unit 42
⋅
Microsoft Exchange Server Attack Timeline CHINACHOPPER |
| 2021-03-11
⋅
Flashpoint
⋅
CL0P and REvil Escalate Their Ransomware Tactics Clop REvil |
| 2021-03-11
⋅
YouTube ( Malware_Analyzing_&_RE_Tips_Tricks)
⋅
Formbook Reversing - Part1 [Formbook .NET loader/injector analyzing, decrypting, unpacking, patching] Formbook |
| 2021-03-11
⋅
Elastic
⋅
Update - Detection and Response for HAFNIUM Activity |
| 2021-03-10
⋅
Center for Security Studies (CSS)
⋅
Publicly attributing cyber attacks: a framework |
| 2021-03-10
⋅
PICUS Security
⋅
Tactics, Techniques, and Procedures (TTPs) Used by HAFNIUM to Target Microsoft Exchange Servers CHINACHOPPER |
| 2021-03-10
⋅
Proofpoint
⋅
NimzaLoader: TA800’s New Initial Access Malware BazarNimrod Cobalt Strike |
| 2021-03-10
⋅
US-CERT
⋅
Remediating Networks Affected by the SolarWinds and Active Directory/M365 Compromise SUNBURST |
| 2021-03-10
⋅
Bleeping Computer
⋅
Norway parliament data stolen in Microsoft Exchange attack |
| 2021-03-10
⋅
Lemon's InfoSec Ramblings
⋅
Microsoft Exchange & the HAFNIUM Threat Actor CHINACHOPPER |
| 2021-03-10
⋅
Intezer
⋅
New Linux Backdoor RedXOR Likely Operated by Chinese Nation-State Actor RedXOR XOR DDoS |
| 2021-03-09
⋅
Youtube (SANS Digital Forensics and Incident Response)
⋅
Jackpotting ESXi Servers For Maximum Encryption | Eric Loui & Sergei Frankoff | SANS CTI Summit 2021 DarkSide RansomEXX DarkSide RansomEXX GOLD DUPONT |
| 2021-03-09
⋅
Malwarebytes
⋅
Microsoft Exchange attacks cause panic as criminals go shell collecting |
| 2021-03-09
⋅
CyberArk
⋅
Kinsing: The Malware with Two Faces Kinsing |
| 2021-03-09
⋅
Attivo NETWORKS
⋅
Hafnium – Active Exploitation of Microsoft Exchange and Lateral Movement |
| 2021-03-08
⋅
Symantec
⋅
How Symantec Stops Microsoft Exchange Server Attacks CHINACHOPPER MimiKatz |
| 2021-03-08
⋅
Palo Alto Networks Unit 42
⋅
Attack Chain Overview: Emotet in December 2020 and January 2021 Emotet |
| 2021-03-08
⋅
DeepEnd REsearch
⋅
Renewed SideWinder Activity in South Asia |