Click here to download all references as Bib-File.•
2020-06-23
⋅
Symantec
⋅
Sodinokibi: Ransomware Attackers also Scanning for PoS Software, Leveraging Cobalt Strike Cobalt Strike REvil |
2020-06-22
⋅
MalwareLab.pl
⋅
VenomRAT - new, hackforums grade, reincarnation of QuassarRAT Quasar RAT Venom RAT |
2020-06-22
⋅
zero2auto
⋅
Unpacking Visual Basic Packers – IcedID IcedID |
2020-06-22
⋅
wietzebeukema.nl
⋅
Hijacking DLLs in Windows |
2020-06-22
⋅
⋅
CERT-FR
⋅
Évolution De Lactivité du Groupe Cybercriminel TA505 Amadey AndroMut Bart Clop Dridex FlawedGrace Gandcrab Get2 GlobeImposter Jaff Locky Marap Philadephia Ransom QuantLoader Scarab Ransomware SDBbot ServHelper Silence tRat TrickBot |
2020-06-22
⋅
Sentinel LABS
⋅
Inside a TrickBot Cobalt Strike Attack Server Cobalt Strike TrickBot |
2020-06-22
⋅
FindingBad Blogspot
⋅
Dynamic Correlation, ML and Hunting |
2020-06-19
⋅
ACSC
⋅
Copy-paste compromises Copy-Paste |
2020-06-19
⋅
Australian Signals Directorate
⋅
Advisory 2020-008: Copy-paste compromises - tactics, techniques and procedures used to target multiple Australian networks Copy-Paste |
2020-06-19
⋅
Youtube (Raphael Mudge)
⋅
Beacon Object Files - Luser Demo Cobalt Strike |
2020-06-19
⋅
Zscaler
⋅
Targeted Attack Leverages India-China Border Dispute to Lure Victims Cobalt Strike |
2020-06-19
⋅
Positive Technologies
⋅
The eagle eye is back: old and new backdoors from APT30 backspace NETEAGLE RCtrl RHttpCtrl APT30 |
2020-06-18
⋅
Microsoft
⋅
Inside Microsoft Threat Protection: Mapping attack chains from cloud to endpoint (APT33/HOLMIUM) POWERTON |
2020-06-18
⋅
Australian Cyber Security Centre
⋅
Advisory 2020-008: Copy-Paste Compromises –tactics, techniques and procedures used to target multiple Australian networks TwoFace Cobalt Strike Empire Downloader |
2020-06-17
⋅
Malwarebytes
⋅
Multi-stage APT attack drops Cobalt Strike using Malleable C2 feature Cobalt Strike |
2020-06-17
⋅
SentinelOne
⋅
A Click from the Backyard | Analysis of CVE-2020-9332, a Vulnerable USB Redirection Software |
2020-06-17
⋅
Kaspersky Labs
⋅
Targeted attacks on industrial companies using Snake ransomware Snake |
2020-06-17
⋅
Cognizant
⋅
Notice of Data Breach Maze |
2020-06-17
⋅
Twitter (@MsftSecIntel)
⋅
A tweet thread on TA505 using CAPTCHA to avoid detection and infecting victims with FlawedGrace FlawedGrace |
2020-06-17
⋅
Github (f0wl)
⋅
deICEr: A Go tool for extracting config from IcedID second stage Loaders IcedID |