Click here to download all references as Bib-File.•
| 2026-05-28
⋅
eSentire
⋅
Nimbus RAT: How Threat Actors Are Abusing Microsoft Teams and Google Drive to Deploy a Java RAT |
| 2026-05-28
⋅
ESET Research
⋅
ESET APT Activity Report Q4 2025–Q1 2026 WAVESHAPER BirdCall BLINDINGCAN RokRAT Rook Tiger RAT |
| 2026-05-28
⋅
GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations LegionRelay PhantomRelay |
| 2026-05-28
⋅
WithSecure
⋅
GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations GreyVibe |
| 2026-05-28
⋅
LevelBlue
⋅
Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign |
| 2026-05-27
⋅
Wiz.io
⋅
Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure JINX-0164 |
| 2026-05-26
⋅
Intrinsec
⋅
Pivoting on a malspam infrastructure delivering JS malware backed by bulletproof networks |
| 2026-05-21
⋅
PWC
⋅
Inside Red Lamassu’s JFMBackdoor JFMBackdoor Calypso |
| 2026-05-20
⋅
Seqrite Labs
⋅
Operation Dragon Whistle: UNG0002 Targets Chinese Academia via Weaponized Institutional Lure Cobalt Strike |
| 2026-05-20
⋅
Hackernoon
⋅
ZeffSec Resurfaces on Telegram, Claims Breach of Gozine2.ir ZeffSec |
| 2026-05-19
⋅
Github (microsoft)
⋅
MSTIC actor name mapping in JSON format Amethyst Rain Houndstooth Typhoon Pinstripe Lightning Storm-0252 Wisteria Tsunami |
| 2026-05-18
⋅
Microsoft
⋅
How Storm-2949 turned a compromised identity into a cloud-wide breach Storm-2949 |
| 2026-05-17
⋅
neso.re
⋅
ClickFix x HijackLoader: Dissecting a Live Stealer Campaign HijackLoader |
| 2026-05-17
⋅
Github (zanez)
⋅
Analysis on Malware that attacks Israel's Water treatment facilities ZionSiphon |
| 2026-05-13
⋅
0x3oBAD
⋅
MustangPanda New Backdoor LotusLite LOTUSLITE |
| 2026-05-11
⋅
Qianxin
⋅
Threat Actor Mr_Rot13 Actively Exploits CVE-2026-41940 for Backdoor Deployment Mr_Rot13 |
| 2026-05-07
⋅
Sophos
⋅
Donuts and Beagles: Fake Claude site spreads backdoor TriBack Loader |
| 2026-05-05
⋅
ESET Research
⋅
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack BirdCall |
| 2026-05-04
⋅
BlueVoyant
⋅
Lorem Ipsum Malware: Trojanized MS Teams Installers Deliver Multi-Stage Loader and Backdoor Lorem Ipsum |
| 2026-05-04
⋅
Trend Micro
⋅
Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities QLNX |