Click here to download all references as Bib-File.•
2024-05-23
⋅
Twitter (@embee_research)
⋅
Tracking APT SideWinder With DNS Records SideWinder |
2024-05-23
⋅
Palo Alto Networks Unit 42
⋅
Operation Diplomatic Specter: An Active Chinese Cyberespionage Campaign Leverages Rare Tool Set to Target Governmental Entities in the Middle East, Africa and Asia Agent Racoon CHINACHOPPER Ghost RAT JuicyPotato MimiKatz Ntospy PlugX SweetSpecter TunnelSpecter CL-STA-0043 |
2024-05-22
⋅
Bleeping Computer
⋅
Chinese hackers hide on military and govt networks for 6 years SilentGh0st Unfading Sea Haze |
2024-05-22
⋅
Mandiant
⋅
IOC Extinction? China-Nexus Cyber Espionage Actors Use ORB Networks to Raise Cost on Defenders |
2024-05-22
⋅
Deep Dive Into Unfading Sea Haze: A New Threat Actor in the South China Sea SilentGh0st |
2024-05-21
⋅
Yoroi
⋅
Uncovering an undetected KeyPlug implant attacking industries in Italy KEYPLUG |
2024-05-20
⋅
Checkpoint
⋅
Bad Karma, No Justice: Void Manticore Destructive Activities in Israel Void Manticore |
2024-05-20
⋅
cyble
⋅
Tiny BackDoor Goes Undetected – Suspected Turla leveraging MSBuild to Evade detection |
2024-05-16
⋅
⋅
AhnLab
⋅
Analysis of APT attack cases targeting domestic companies using Dora RAT (Andariel Group) |
2024-05-16
⋅
Elastic
⋅
Spring Cleaning with LATRODECTUS: A Potential Replacement for ICEDID IcedID Latrodectus |
2024-05-16
⋅
Symantec
⋅
Springtail: New Linux Backdoor Added to Toolkit Gomir Kimsuky |
2024-05-15
⋅
Microsoft
⋅
Threat actors misusing Quick Assist in social engineering attacks leading to ransomware Black Basta Cobalt Strike QakBot SystemBC |
2024-05-15
⋅
ESET Research
⋅
To the Moon and back(doors): Lunar landing in diplomatic missions LunarMail |
2024-05-15
⋅
Stairwell
⋅
Stairwell threat report: Black Basta overview and detection rules Black Basta Black Basta |
2024-05-15
⋅
Microsoft
⋅
Threat actors misusing Quick Assist in social engineering attacks leading to ransomware Black Basta Cobalt Strike QakBot UNC4393 |
2024-05-14
⋅
Kaspersky
⋅
QakBot attacks with Windows zero-day (CVE-2024-30051) Cobalt Strike QakBot |
2024-05-13
⋅
Emerging Threats
⋅
SIGS: W32/Badspace.Backdoor WarmCookie |
2024-05-11
⋅
Russian APT deploys new 'Kapeka' backdoor in Eastern European attacks Kapeka |
2024-05-10
⋅
⋅
Qianxin Threat Intelligence Center
⋅
Recruitment trap for blockchain practitioners: Analysis of suspected Lazarus (APT-Q-1) stealing operations BeaverTail |
2024-05-10
⋅
Rapid7 Labs
⋅
Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators Black Basta Black Basta Cobalt Strike NetSupportManager RAT |