Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2025-09-09 ⋅ Huntress Labs ⋅ Jamie Levy, Lindsey O'Donnell-Welch, Michael Tigges
How an Attacker’s Blunder Gave Us a Rare Look Inside Their Day-to-Day Operations
2025-09-08 ⋅ Jamf Blog ⋅ Ferdous Saljooki, Maggie Zirnhelt
ChillyHell: A Deep Dive into a Modular macOS Backdoor
UNC4487
2025-09-08 ⋅ Fortinet ⋅ Yurren Wan
MostereRAT Deployed AnyDesk/TightVNC for Covert Full Access
MostereRAT
2025-09-08 ⋅ Zscaler ⋅ Seongsu Park
APT37 Targets Windows with Rust Backdoor and Python Loader
Rustonotto
2025-09-07 ⋅ ⋅ 360 ⋅ 360
APT-C-53 (Gamaredon) Attacks on Ukrainian Government Functions
Pteranodon
2025-09-07 ⋅ Hexastrike Cybersecurity ⋅ Maurice Fielenbach
ValleyRAT Exploiting BYOVD to Kill Endpoint Security
ValleyRAT
2025-09-05 ⋅ Arctic Wolf ⋅ Dmitry Kupin, Dmitry Melikov, Jacob Faires, Jon Grimm, Pavel Usatenko
GPUGate Malware: Malicious GitHub Desktop Implants Use Hardware-Specific Decryption, Abuse Google Ads to Target Western Europe
2025-09-05 ⋅ Kroll ⋅ Dave Truman, Marc Messer
FANCY BEAR GONEPOSTAL – Espionage Tool Provides Backdoor Access to Microsoft Outlook
GONEPOSTAL
2025-09-04 ⋅ ESET Research ⋅ Fernando Tavella
GhostRedirector poisons Windows servers: Backdoors with a side of Potatoes
GoToHTTP GhostRedirector
2025-09-04 ⋅ SentinelOne ⋅ Aleksandar Milenkoski, Kenneth Kinion, Sreekar Madabushi
Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms
ContagiousDrop Contagious Interview
2025-09-04 ⋅ The Register ⋅ Iain Thomson
US puts $10M bounty on three Russians accused of attacking critical infrastructure
2025-09-03 ⋅ Proofpoint ⋅ Kyle Cucci, Proofpoint Threat Research Team, Rob Kinner
Not Safe for Work: Tracking and Investigating Stealerium and Phantom Infostealers
Phantom Stealer Stealerium
2025-09-02 ⋅ At-Bay ⋅ Aaron Smith, Laurie Iacono, MC, Ricardo Vazquez, Rohit Pappali, Will Botto, Yiwei Guo
Rhysida: Evading Detection, One Service at a Time
Rhysida
2025-09-01 ⋅ cocomelonc ⋅ cocomelonc
MacOS hacking part 11: bind shell for ARM (M1). Simple Assembly (M1) and C (run shellcode) examples
2025-08-28 ⋅ Gdata ⋅ Karsten Hahn, Louis Sorita
AppSuite PDF Editor Backdoor: A Detailed Technical Analysis
TamperedChef
2025-08-28 ⋅ Aryaka Networks ⋅ bikash dash, varadharajan krishnasamy
Vidar Infostealer in Action From API Hooking to Covert Data Exfiltration
Vidar
2025-08-28 ⋅ Intrinsec ⋅ David Sardinha
VAIZ, FDN3, TK-NET: A nebula of Ukrainian networks engaged in brute force and password spraying attacks
Amadey
2025-08-27 ⋅ eSentire ⋅ eSentire Threat Response Unit (TRU)
Threat Actors Deploy Sinobi Ransomware via Compromised SonicWall SSL VPN Credentials
Lynx Sinobi
2025-08-27 ⋅ StepSecurity ⋅ Anish Kurmi
Supply Chain Security Alert: Popular Nx Build System Package Compromised with Data-Stealing Malware
s1ngularity Stealer
2025-08-27 ⋅ US Department of Defense ⋅ CISA
Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System