Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2022-11-01 ⋅ NCSC UK ⋅ NCSC UK
NCSC Annual Review 2022
2022-10-31 ⋅ Kaspersky Labs ⋅ Suguru Ishimaru
APT10: Tracking down LODEINFO 2022, part II
LODEINFO
2022-10-31 ⋅ Kaspersky Labs ⋅ Suguru Ishimaru
APT10: Tracking down LODEINFO 2022, part I
LODEINFO
2022-10-31 ⋅ Twitter (@CryptoInsane) ⋅ CryptoInsane
Tweet about Yanluowang Leaks
Yanluowang
2022-10-31 ⋅ Cynet ⋅ Max Malyutin
Orion Threat Alert: Qakbot TTPs Arsenal and the Black Basta Ransomware
Black Basta Cobalt Strike QakBot
2022-10-31 ⋅ The Record ⋅ Alexander Martin
Mondelez and Zurich reach settlement in NotPetya cyberattack insurance suit
EternalPetya
2022-10-31 ⋅ Elastic ⋅ Andrew Pease, Daniel Stepanic, Derek Ditch, Seth Goodwin
ICEDIDs network infrastructure is alive and well
IcedID
2022-10-31 ⋅ Cyber Geeks ⋅ Vlad Pasca
A Technical Analysis of Pegasus for Android - Part 3
Chrysaor
2022-10-31 ⋅ Security homework ⋅ Christophe Rieunier
QakBot CCs prioritization and new record types
QakBot
2022-10-31 ⋅ paloalto Netoworks: Unit42 ⋅ Or Chechik
Banking Trojan Techniques: How Financially Motivated Malware Became Infrastructure
Dridex Kronos TrickBot Zeus
2022-10-28 ⋅ velociraptor ⋅ Matt Green
Windows.Carving.SystemBC - SystemBC RAT configuration Purser for Velociraptor
SystemBC
2022-10-28 ⋅ cocomelonc ⋅ cocomelonc
APT techniques: Token theft via UpdateProcThreadAttribute. Simple C++ example.
2022-10-28 ⋅ ThreatFabric ⋅ ThreatFabric
Malware wars: the attack of the droppers
Brunhilda SharkBot Vultur
2022-10-28 ⋅ Elastic ⋅ @rsprooten, Elastic Security Intelligence & Analytics Team
EMOTET dynamic config extraction
Emotet
2022-10-27 ⋅ vmware ⋅ Takahiro Haruyama
Threat Analysis: Active C2 Discovery Using Protocol Emulation Part3 (ShadowPad)
ShadowPad
2022-10-27 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
Raspberry Robin worm part of larger ecosystem facilitating pre-ransomware activity
FAKEUPDATES BumbleBee Clop Fauppod Raspberry Robin Roshtyak Silence DEV-0950 Mustard Tempest
2022-10-27 ⋅ Microsoft ⋅ Microsoft Security Threat Intelligence
Raspberry Robin worm part of larger ecosystem facilitating pre-ransomware activity
FAKEUPDATES BumbleBee Fauppod PhotoLoader Raspberry Robin Roshtyak
2022-10-27 ⋅ Bleeping Computer ⋅ Sergiu Gatlan
Microsoft links Raspberry Robin worm to Clop ransomware attacks
Clop Raspberry Robin
2022-10-27 ⋅ ANY.RUN ⋅ ANY.RUN
STRRAT: Malware Analysis of a JAR archive
STRRAT
2022-10-27 ⋅ Bleeping Computer ⋅ Bill Toulas
Fodcha DDoS botnet reaches 1Tbps in power, injects ransoms in packets
Fodcha