Click here to download all references as Bib-File.•
2022-05-04
⋅
Cybereason
⋅
Operation CuckooBees: Deep-Dive into Stealthy Winnti Techniques PRIVATELOG Spyder STASHLOG Winnti |
2022-05-04
⋅
Twitter (@felixw3000)
⋅
Twitter Thread with info on infection chain with IcedId, Cobalt Strike, and Hidden VNC. Cobalt Strike IcedID PhotoLoader |
2022-05-04
⋅
F-Secure
⋅
Scheduled Task Tampering |
2022-05-04
⋅
HP
⋅
Tips for Automating IOC Extraction from GootLoader, a Changing JavaScript Malware GootLoader |
2022-05-04
⋅
Cybereason
⋅
Operation CuckooBees: A Winnti Malware Arsenal Deep-Dive PRIVATELOG Spyder STASHLOG Winnti |
2022-05-04
⋅
CrowdStrike
⋅
Compromised Docker Honeypots Used for Pro-Ukrainian DoS Attack |
2022-05-04
⋅
Mandiant
⋅
Old Services, New Tricks: Cloud Metadata Abuse by UNC2903 WSO |
2022-05-04
⋅
Twitter (@ESETresearch)
⋅
Twitter thread on code similarity analysis, focussing on IsaacWiper and recent Cluster25 publication IsaacWiper |
2022-05-04
⋅
Inky
⋅
Fresh Phish: Britain’s National Health Service Infected by Massive Phishing Campaign |
2022-05-04
⋅
Sophos
⋅
Attacking Emotet’s Control Flow Flattening Emotet |
2022-05-03
⋅
Google
⋅
Update on cyber activity in Eastern Europe Callisto |
2022-05-03
⋅
Silent Push
⋅
Subdomain Takeovers and 1.1 million “dangling” risks |
2022-05-03
⋅
Fortinet
⋅
Unpacking Python Executables on Windows and Linux |
2022-05-03
⋅
Recorded Future
⋅
SOLARDEFLECTION C2 Infrastructure Used by NOBELIUM in Company Brand Misuse Cobalt Strike |
2022-05-03
⋅
⋅
AhnLab
⋅
Backdoors disguised as document editing and messenger programs (*.chm) |
2022-05-03
⋅
Minerva Labs
⋅
A new BluStealer Loader Uses Direct Syscalls to Evade EDRs BluStealer |
2022-05-03
⋅
Google
⋅
Update on cyber activity in Eastern Europe Curious Gorge |
2022-05-03
⋅
Recorded Future
⋅
SOLARDEFLECTION C2 Infrastructure Used by NOBELIUM in Company Brand Misuse Cobalt Strike EnvyScout |
2022-05-03
⋅
Trellix
⋅
The Hermit Kingdom’s Ransomware play VHD Ransomware |
2022-05-03
⋅
Talos Intelligence
⋅
Conti and Hive ransomware operations: What we learned from these groups' victim chats Conti Hive |