Click here to download all references as Bib-File.

Enter keywords to filter the library entries below or Propose new Entry
2025-10-16TrendmicroJunestherry Dela Cruz
Shifts in the Underground: The Impact of Water Kurita’s (Lumma Stealer) Doxxing
Lumma Stealer Water Kurita
2025-09-26Arctic WolfArctic Wolf
Smash and Grab: Aggressive Akira Campaign Targets SonicWall VPNs, Deploys Ransomware in an Hour or Less
Akira Akira
2025-09-24TEAMT5Still Hsu, Tim Chen
Google Calendar As C2 Infrastructure: A China-Nexus Campaign With Stealthy Tactics
TOUGHPROGRESS
2025-09-19BlackPointCaden Toellner, Nevan Beal, Sam Decker
KeyZero: A Custom PowerShell RAT
2025-09-19ESET ResearchMatthieu Faou, Zoltán Rusnák
Gamaredon X Turla collab
PteroGraphin
2025-09-11IBM X-ForceGolo Mühr, Joshua Chung
Hive0154, aka Mustang Panda, drops updated Toneshell backdoor and novel SnakeDisk USB worm
PUBLOAD SnakeDisk TONESHELL Yokai
2025-09-09Trend MicroDon Ovid Ladores, Jacob Santos, Junestherry Dela Cruz, Maristel Policarpio
Unmasking The Gentlemen Ransomware: Tactics, Techniques, and Procedures Revealed
Gentlemen The Gentlemen
2025-08-27eSentireeSentire Threat Response Unit (TRU)
Threat Actors Deploy Sinobi Ransomware via Compromised SonicWall SSL VPN Credentials
Lynx Sinobi
2025-08-27Group-IBNikita Rostovcev, Sergei Turner
ShadowSilk: A Cross-Border Binary Union for Data Exfiltration
Cobalt Strike YoroTrooper
2025-08-27PlainBitHeejae Hwang
PureHVNC malware disguised as a copyright infringement notice email
ClipBanker PureRAT
2025-08-18TrellixRyan Weil
A Comprehensive Analysis of HijackLoader and Its Infection Chain
HijackLoader
2025-08-12bluecyberKhắc Minh
Analysis of a ClickFix malware attack
Vidar
2025-08-11cocomelonccocomelonc
Malware development trick 49: abusing Azure DevOps REST API for covert data channels. Simple C examples.
AllaKore
2025-07-31Reverse The MalwareDiyar Saadi
Threat Intelligence visa ccTLD ( country code top-level domain )
2025-07-29ForesietForesiet
AURA Stealer: A Crude Clone of LummaC2 – Technical Analysis and Threat Breakdown
Aura Stealer
2025-07-22Cryptika cybersecurityCryptika cybersecurity
DeerStealer Malware Delivered Via Weaponized .LNK Using LOLBin Tools
DeerStealer
2025-07-07Github (VenzoV)VenzoV
Golang garbled executable from Amatera config
Amatera
2025-06-24TrellixNico Paulo Yturriaga, Pham Duy Phuc
OneClik: A ClickOnce-Based APT Campaign Targeting Energy, Oil and Gas Infrastructure
2025-06-19Government of CanadaGovernment of Canada
Cyber threat bulletin: People's Republic of China cyber threat activity: PRC cyber actors target telecommunications companies as part of a global cyberespionage campaign
2025-06-04GoogleGoogle Threat Intelligence Group
The Cost of a Call: From Voice Phishing to Data Extortion
UNC6040