Click here to download all references as Bib-File.•
2025-04-09
⋅
NCSC UK
⋅
Advisory: BADBAZAAR and MOONSHINE: Spyware targeting Uyghur, Taiwanese and Tibetan groups and civil society actors badbazaar |
2025-04-08
⋅
Microsoft
⋅
Exploitation of CLFS zero-day leads to ransomware activity RansomEXX Storm-2460 |
2025-04-08
⋅
Trustwave
⋅
A deep Dive into the Leaked Black Basta Chat Logs Black Basta Black Basta |
2025-04-08
⋅
Seqrite
⋅
Goodbye HTA, Hello MSI: New TTPs and Clusters of an APT driven by Multi-Platform Attacks CurlBack RAT XenoRAT |
2025-04-08
⋅
Hunt.io
⋅
State-Sponsored Tactics: How Gamaredon and ShadowPad Operate and Rotate Their Infrastructure ShadowPad |
2025-04-07
⋅
SOC Prime
⋅
UAC-0226 Attack Detection: New Cyber-Espionage Campaign Targeting Ukrainian Innovation Hubs and Government Entities with GIFTEDCROOK Stealer GIFTEDCROOK UAC-0219 UAC-0226 |
2025-04-06
⋅
⋅
Cert-UA
⋅
Target espionage activity UAC-0226 in relation to the centers of innovation, state and law enforcement services using the GIFTEDCROOK (CERT-UA#14303) GIFTEDCROOK UAC-0226 |
2025-04-05
⋅
The Record
⋅
Maryland pharmacist used keyloggers to spy on coworkers for a decade, victim alleges |
2025-04-04
⋅
The Hacker News
⋅
OPSEC Failure Exposes Coquettte's Malware Campaigns on Bulletproof Hosting Servers Rugmi |
2025-04-04
⋅
Socket
⋅
Lazarus Expands Malicious npm Campaign: 11 New Packages Add Malware Loaders and Bitbucket Payloads BeaverTail InvisibleFerret |
2025-04-03
⋅
SOC Prime
⋅
UAC-0219 Attack Detection: A New Cyber-Espionage Campaign Using a PowerShell Stealer WRECKSTEEL WRECKSTEEL UAC-0219 |
2025-04-03
⋅
Microsoft
⋅
Threat actors leverage tax season to deploy tax-themed phishing campaigns Brute Ratel C4 CloudEyE Latrodectus Remcos Storm-0249 |
2025-04-03
⋅
Mandiant
⋅
Suspected China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457) SPAWNSNARE |
2025-04-03
⋅
ThreatMon
⋅
Ransomhub Group & New Betruger Backdoor Technical Malware Analysis Report |
2025-04-02
⋅
ANALYST1
⋅
Inside BlackBasta: Actor Profiles, Extortion Tactics & Finances Black Basta Black Basta |
2025-04-02
⋅
BushidoToken
⋅
Tracking Adversaries: EvilCorp, the RansomHub affiliate RansomHub |
2025-04-02
⋅
Intel 471
⋅
An in-depth look at Black Basta's TTPs Black Basta Black Basta |
2025-04-01
⋅
Hunt.io
⋅
Same Russian-Speaking Threat Actor, New Tactics: Abuse of Cloudflare Services for Phishing and Telegram to Filter Victim IPs Pyramid |
2025-04-01
⋅
⋅
Cert-UA
⋅
UAC-0219: Cyber espionage using PowerShell stealer WRECKSTEEL (CERT-UA#14283) WRECKSTEEL UAC-0219 UAC-0226 |
2025-04-01
⋅
ZW01f
⋅
Auto-color - Linux backdoor Auto-Color |