Click here to download all references as Bib-File.

Enter keywords to filter the library entries below or Propose new Entry
2021-08-03Bleeping ComputerLawrence Abrams
Ransomware attack hits Italy's Lazio region, affects COVID-19 site
LockBit RansomEXX
2021-08-03Twitter (@sysopfb)Jason Reaves
Tweet on python script to decode the blob from Blackmatter ransomware
DarkSide
2021-08-03Twitter (@ValthekOn)Valthek
Tweet on blacklisted extensions & names of BlackMatter ransomware making the check against custom hashes values
DarkSide
2021-08-03Twitter (@sisoma2)sisoma2
Python script for recovering the hashes hardcoded in different samples of the BlackMatter ransomware
DarkSide
2021-08-03Group-IBAnastasia Tikhonova, Dmitry Kupin
The Art of Cyberwarfare Chinese APTs attack Russia
Albaniiutas Mail-O SManager TA428
2021-08-02Youtube (Forschungsinstitut Cyber Defense)Alexander Rausch, Konstantin Klinger
The CODE 2021: Workshop presentation and demonstration about CobaltStrike
Cobalt Strike
2021-08-02The RecordDmitry Smilyanets
An interview with BlackMatter: A new ransomware group that’s learning from the mistakes of DarkSide and REvil
DarkSide LockBit REvil
2021-08-02360 Threat Intelligence CenterAdvanced Threat Institute
Operation Hunting - The latest attack by the CNC (APT-C-48) has been revealed
2021-08-02AT&TJavier Ruiz, Ofer Caspi
New sophisticated RAT in town: FatalRat analysis
FatalRat
2021-08-01The RecordCatalin Cimpanu
Decryptor released for Prometheus ransomware victims
Prometheus
2021-08-01ID RansomwareAndrew Ivanov
BlackMatter Ransomware
DarkSide
2021-07-31Bleeping ComputerLawrence Abrams
DarkSide ransomware gang returns as new BlackMatter operation
DarkSide
2021-07-31Bleeping ComputerLawrence Abrams
BlackMatter ransomware gang rises from the ashes of DarkSide, REvil
DarkSide REvil
2021-07-30ThreatpostElizabeth Montalbano
Novel Meteor Wiper Used in Attack that Crippled Iranian Train System
Meteor
2021-07-30HPPatrick Schläpfer
Detecting TA551 domains
Valak Dridex IcedID ISFB QakBot
2021-07-30Bleeping ComputerSergiu Gatlan
DOJ: SolarWinds hackers breached emails from 27 US Attorneys’ offices
2021-07-30RiskIQTeam Atlas
Bear Tracks: Infrastructure Patterns Lead to More Than 30 Active APT29 C2 Servers
elf.wellmess WellMess
2021-07-29MicrosoftMicrosoft Defender Threat Intelligence
BazaCall: Phony call centers lead to exfiltration and ransomware
BazarBackdoor BazarCall
2021-07-29MicrosoftMicrosoft 365 Defender Threat Intelligence Team
When coin miners evolve, Part 2: Hunting down LemonDuck and LemonCat attacks
Lemon Duck
2021-07-29360 Total Securitykate
“Netfilter Rootkit II ” Continues to Hold WHQL Signatures
NetfilterRootkit