Click here to download all references as Bib-File.•
| 2022-05-06
⋅
Twitter (@MsftSecIntel)
⋅
Twitter Thread on initial infeciton of SocGholish/ FAKEUPDATES campaigns lead to BLISTER Loader, CobaltStrike, Lockbit and followed by Hands On Keyboard activity FAKEUPDATES Blister Cobalt Strike LockBit |
| 2022-05-05
⋅
Suspicious Actor
⋅
Studying “Next Generation Malware” - NightHawk’s Attempt At Obfuscate and Sleep Nighthawk |
| 2022-05-05
⋅
Malwarebytes Labs
⋅
Nigerian Tesla: 419 scammer gone malware distributor unmasked Agent Tesla |
| 2022-05-05
⋅
Blackberry
⋅
Threat Thursday: ZingoStealer – The Cost of “Free” ZingoStealer |
| 2022-05-03
⋅
Talos Intelligence
⋅
Conti and Hive ransomware operations: What we learned from these groups' victim chats Conti Hive |
| 2022-04-28
⋅
Blackberry
⋅
Threat Thursday: BoratRAT Borat RAT |
| 2022-04-27
⋅
eSentire
⋅
eSentire Threat Intelligence Malware Analysis: SolarMarker solarmarker |
| 2022-04-21
⋅
Blackberry
⋅
Threat Thursday: BlackGuard Infostealer Rises from Russian Underground Markets BlackGuard |
| 2022-04-20
⋅
CISA
⋅
AA22-110A Joint CSA: Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure VPNFilter BlackEnergy DanaBot DoppelDridex Emotet EternalPetya GoldMax Industroyer Sality SmokeLoader TrickBot Triton Zloader |
| 2022-04-19
⋅
360
⋅
Public Cloud Cybersecurity Threat Intelligence (202203) Bashlite Tsunami Mirai |
| 2022-04-18
⋅
National Intelligence University
⋅
Russian Intelligence: A Case-based Study of Russian Services and Missions Past and Present |
| 2022-04-14
⋅
Blackberry
⋅
Threat Thursday: HeaderTip Backdoor Shows Attackers from China Preying on Ukraine HeaderTip |
| 2022-04-14
⋅
PRODAFT Threat Intelligence
⋅
PYSA (Mespinoza) In-Depth Analysis Mespinoza |
| 2022-04-13
⋅
PRODAFT Threat Intelligence
⋅
[PYSA] Ransomware Group In-Depth Analysis Mespinoza |
| 2022-04-13
⋅
Microsoft
⋅
Dismantling ZLoader: How malicious ads led to disabled security tools and ransomware BlackMatter Cobalt Strike DarkSide Ryuk Zloader |
| 2022-04-12
⋅
⋅
360 Threat Intelligence Center
⋅
Recent attacks by Bahamut group revealed Bahamut |
| 2022-04-12
⋅
Sophos
⋅
Attackers linger on government agency computers before deploying Lockbit ransomware LockBit |
| 2022-04-11
⋅
⋅
Qianxin Threat Intelligence Center
⋅
Snow Abuse: Analysis of the Suspected Lazarus Attack Activities against South Korean Companies |
| 2022-04-11
⋅
Cluster25
⋅
DPRK-Nexus Adversary Targets South-Korean Individuals In A New Chapter of Kitty Phishing Operation |
| 2022-04-07
⋅
ANALYST1
⋅
North Korea: Intelligence Assessment 2022 |