Click here to download all references as Bib-File.

Enter keywords to filter the library entries below or Propose new Entry
2026-05-28eSentireeSentire
Nimbus RAT: How Threat Actors Are Abusing Microsoft Teams and Google Drive to Deploy a Java RAT
2026-05-28ESET ResearchESET Research
ESET APT Activity Report Q4 2025–Q1 2026
WAVESHAPER BirdCall BLINDINGCAN RokRAT Rook Tiger RAT
2026-05-28Mohammad Kazem Hassan Nejad
GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations
LegionRelay PhantomRelay
2026-05-28WithSecureMohammad Kazem Hassan Nejad
GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations
GreyVibe
2026-05-28LevelBlueMaor Gabay
Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign
2026-05-27Wiz.ioAndre Maccarone, Benjamin Read, Eden Abergil, Shira Ayal, Yuval Dan
Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure
JINX-0164
2026-05-26IntrinsecCTI Intrinsec, David Sardinha
Pivoting on a malspam infrastructure delivering JS malware backed by bulletproof networks
2026-05-21PWCPwC Threat Intelligence
Inside Red Lamassu’s JFMBackdoor
JFMBackdoor Calypso
2026-05-20Seqrite LabsDixit Panchal, Kartik Jivani, Vaibhav Krushna Billade
Operation Dragon Whistle: UNG0002 Targets Chinese Academia via Weaponized Institutional Lure
Cobalt Strike
2026-05-20HackernoonMrwriteup
ZeffSec Resurfaces on Telegram, Claims Breach of Gozine2.ir
ZeffSec
2026-05-19Github (microsoft)Microsoft
MSTIC actor name mapping in JSON format
Amethyst Rain Houndstooth Typhoon Pinstripe Lightning Storm-0252 Wisteria Tsunami
2026-05-18MicrosoftMicrosoft Defender Security Research Team
How Storm-2949 turned a compromised identity into a cloud-wide breach
Storm-2949
2026-05-17neso.reneso
ClickFix x HijackLoader: Dissecting a Live Stealer Campaign
HijackLoader
2026-05-17Github (zanez)Irvin Martínez González
Analysis on Malware that attacks Israel's Water treatment facilities
ZionSiphon
2026-05-130x3oBADAbdullah Islam
MustangPanda New Backdoor LotusLite
LOTUSLITE
2026-05-11QianxinQiAnXin XLab Team
Threat Actor Mr_Rot13 Actively Exploits CVE-2026-41940 for Backdoor Deployment
Mr_Rot13
2026-05-07SophosChaitanya Ghorpade, Gabor Szappanos, Matt Wixey, Rahil Shah, Rahul Dugar
Donuts and Beagles: Fake Claude site spreads backdoor
TriBack Loader
2026-05-05ESET ResearchFilip Jurčacko
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
BirdCall
2026-05-04BlueVoyantJoshua Green, Thomas Elkins
Lorem Ipsum Malware: Trojanized MS Teams Installers Deliver Multi-Stage Loader and Backdoor
Lorem Ipsum
2026-05-04Trend MicroAhmed Mohamed Ibrahim, Aliakbar Zahravi
Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities
QLNX