Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2021-09-17 ⋅ Avast ⋅ Martin Chlumecký
DirtyMoe: Code Signing Certificate
DirtyMoe
2021-09-17 ⋅ Medium inteloperator ⋅ Intel Operator
The default: 63 6f 62 61 6c 74 strike
Cobalt Strike
2021-09-16 ⋅ PCrisk ⋅ Tomas Meskauskas
.harma (Ouroboros) ransomware from the operating system
Zeropadypt
2021-09-16 ⋅ Department Of Health And Social Services (DHSS) ⋅ Department Of Health And Social Services (DHSS)
Department of Health and Social Services 2021 Cyberattack: Frequently Asked Questions Updated Sept. 16, 2021
2021-09-16 ⋅ Group-IB ⋅ Ivan Lebedev, Reza Rafati
RUNLIR - phishing campaign targeting Netherlands
2021-09-16 ⋅ Twitter (@GossiTheDog) ⋅ Kevin Beaumont
Tweet on some unknown threat actor dropping Mgbot, custom IIS modular backdoor and cobalstrike using exploiting ProxyShell
Cobalt Strike MgBot
2021-09-16 ⋅ Kaspersky ⋅ AMR
Exploitation of the CVE-2021-40444 vulnerability in MSHTML
2021-09-16 ⋅ Cisco ⋅ Tiago Pereira, Vitor Ventura
Operation Layover: How we tracked an attack on the aviation industry to five years of compromise
AsyncRAT Houdini NjRAT
2021-09-16 ⋅ Blackberry ⋅ The BlackBerry Research & Intelligence Team
Threat Thursday: NetWire RAT is Coming Down the Line
NetWire RC
2021-09-15 ⋅ Microsoft ⋅ Microsoft 365 Defender Threat Intelligence Team, Microsoft Threat Intelligence Center (MSTIC)
Analyzing attacks that exploit the CVE-2021-40444 MSHTML vulnerability
EXOTIC LILY
2021-09-15 ⋅ CrowdStrike ⋅ Falcon OverWatch Team
Shining a Light on DarkOxide
2021-09-15 ⋅ Microsoft ⋅ Microsoft 365 Defender Threat Intelligence Team, Microsoft Threat Intelligence Center (MSTIC)
Analyzing attacks that exploit the CVE-2021-40444 MSHTML vulnerability
Cobalt Strike
2021-09-14 ⋅ Twitter (@siri_urz) ⋅ S!Ri
Tweet on ATOMSILO ransomware
ATOMSILO
2021-09-14 ⋅ NK News ⋅ Ethan Jewell, Jeongmin Kim
North Korea-linked account poses as KBS scriptwriter to dupe DPRK watchers
2021-09-14 ⋅ CrowdStrike ⋅ CrowdStrike Intelligence Team
Big Game Hunting TTPs Continue to Shift After DarkSide Pipeline Attack
BlackMatter DarkSide REvil Avaddon BlackMatter Clop Conti CryptoLocker DarkSide DoppelPaymer Hades REvil
2021-09-14 ⋅ Fortinet ⋅ John Simmons
More ProxyShell? Web Shells Lead to ZeroLogon and Application Impersonation Attacks
2021-09-14 ⋅ ZecOps ⋅ ZecOps Research Team
The Recent iOS 0-Click, CVE-2021-30860, Sounds Familiar. An Unreleased Write-up: One Year Later
Chrysaor
2021-09-14 ⋅ McAfee ⋅ Christiaan Beek
Operation ‘Harvest’: A Deep Dive into a Long-term Campaign
MimiKatz PlugX Winnti
2021-09-14 ⋅ Objective-See ⋅ Patrick Wardle
OSX.ZuRu: trojanized apps spread malware, via sponsored search results
ZuRu
2021-09-13 ⋅ Trend Micro ⋅ Daniel Lunghi, Jaromír Hořejší
APT-C-36 Updates Its Spam Campaign Against South American Entities With Commodity RATs
APT-C-36