Click here to download all references as Bib-File.•
2024-08-29
⋅
Hunt.io
⋅
Latrodectus Malware Masquerades as AhnLab Security Software to Infect Victims Latrodectus |
2024-08-28
⋅
Bleeping Computer
⋅
PoorTry Windows driver evolves into a full-featured EDR wiper POORTRY |
2024-08-28
⋅
ESET Research
⋅
Analysis of two arbitrary code execution vulnerabilities affecting WPS Office SpyGrace |
2024-08-28
⋅
ESET Research
⋅
ESET Research: Spy group exploits WPS Office zero day; analysis uncovers a second vulnerability SpyGrace |
2024-08-28
⋅
Help Net Security
⋅
APT group exploits WPS Office for Windows RCE vulnerability (CVE-2024-7262) |
2024-08-28
⋅
Talos Intelligence
⋅
BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks BlackByte |
2024-08-27
⋅
DailyDarkWeb
⋅
Threat Actor Claimed to Breach Database of DimeCuba SILKFIN AGENCY |
2024-08-27
⋅
Lumen
⋅
Taking the Crossroads: The Versa Director Zero-Day Exploitation VersaMem |
2024-08-27
⋅
SonicWall
⋅
AutoIT Bot Targets Gmail Accounts First |
2024-08-26
⋅
Netskope
⋅
Static Unpacker for Latrodectus Latrodectus |
2024-08-26
⋅
The DFIR Report
⋅
BlackSuit Ransomware BlackSuit Cobalt Strike SystemBC |
2024-08-24
⋅
YouTube (Black Hat)
⋅
Chinese APT: A Master of Exploiting Edge Devices (Video) SEASPY UNC4841 |
2024-08-23
⋅
ITOCHU
⋅
Pirates of The Nang Hai: Follow the Artifacts No One Know Cobalt Strike Xiangoop |
2024-08-23
⋅
TEAMT5
⋅
Sailing the Seven SEAs: Deep Dive into Polaris' Arsenal and Intelligence Insights Cobalt Strike Hodur PlugX TONESHELL |
2024-08-23
⋅
DailyDarkWeb
⋅
A Threat Actor Alleged Breach of Sri Lankan Farmers Community Database SILKFIN AGENCY |
2024-08-22
⋅
Mandiant
⋅
PEAKLIGHT: Decoding the Stealthy Memory-Only Malware CryptBot Emmenhtal HijackLoader Lumma Stealer |
2024-08-22
⋅
DFIR.ch
⋅
Botnet Fenix Fenix |
2024-08-22
⋅
Github (X-ZIGZAG)
⋅
Github Repository for X-ZIGZAG X-ZIGZAG |
2024-08-22
⋅
⋅
NTT
⋅
AppDomainManager Injectionを悪用したマルウェアによる攻撃について Cobalt Strike Earth Baxia |
2024-08-22
⋅
NTT Security
⋅
Attacks by malware abusing AppDomainManager Injection |