Click here to download all references as Bib-File.

Enter keywords to filter the library entries below or Propose new Entry
2021-03-08Palo Alto Networks Unit 42Jeff White
Analyzing Attacks Against Microsoft Exchange Server With China Chopper Webshells
CHINACHOPPER
2021-03-08Sentinel LABSJim Walter
HelloKitty Ransomware Lacks Stealth, But Still Strikes Home
HelloKitty
2021-03-07TRUESECRasmus Grönlund
Tracking Microsoft Exchange Zero-Day ProxyLogon and HAFNIUM
CHINACHOPPER
2021-03-07InfoSec Handlers Diary BlogDidier Stevens
PCAPs and Beacons
Cobalt Strike
2021-03-07The Wall Street JournalDustin Volz, Michael R. Gordon
Russian Disinformation Campaign Aims to Undermine Confidence in Pfizer, Other Covid-19 Vaccines, U.S. Officials Say
2021-03-06de VolkskrantHuib Modderkolk
Russian and Chinese hackers gained access to EMA
2021-03-05MalwarebytesHossein Jazi
New steganography attack targets Azerbaijan
2021-03-05SophosSOPHOS MTR
HAFNIUM: Advice about the new nation-state attack
2021-03-05Medium walmartglobaltechJason Reaves
A look at an Android bot from unpacking to DGA
FluBot
2021-03-05BlackberryCodi Starks, Kevin Finnigin
ZeroLogon to Ransomware
Mailto
2021-03-05MicrosoftLouie Mayor
Exchange Server IIS dropping web shells and other artifacts
HAFNIUM
2021-03-05WiredAndy Greenberg
Chinese Hacking Spree Hit an ‘Astronomical’ Number of Victims
CHINACHOPPER
2021-03-04ElasticDevon Kerr
Detection and Response for HAFNIUM Activity
HAFNIUM
2021-03-04FireEyeAndrew Thompson, Chris DiGiamo, Matt Bromiley, Robert Wallace
Detection and Response to Exploitation of Microsoft Exchange Zero-Day Vulnerabilities
CHINACHOPPER HAFNIUM
2021-03-04FireEyeBen Read, Jonathan Leathery, Lindsay Smith
New SUNSHUTTLE Second-Stage Backdoor Uncovered Targeting U.S.-Based Entity; Possible Connection to UNC2452
UNC2452
2021-03-04WMC GlobalWMC Global Threat Intelligence Team
The Compact Campaign
2021-03-04FlashpointFlashpoint
Breaking: Elite Cybercrime Forum “Maza” Breached by Unknown Attacker
2021-03-03Cert-UACert-UA
Renewal of cyber attacks using the Pterodo hacker group Armageddon/Gamaredon
Pteranodon
2021-03-03GTSCGTSC
'Mild' update on Microsoft Exchange 0day security vulnerability being used to attack organizations in Vietnam
ToddyCat
2021-03-03splunkRyan Kovar
Detecting HAFNIUM Exchange Server Zero-Day Activity in Splunk
HAFNIUM