Click here to download all references as Bib-File.•
2025-01-16
⋅
Validin
⋅
Lazarus APT: Techniques for Hunting Contagious Interview |
2025-01-07
⋅
Hunt.io
⋅
Golang Beacons and VS Code Tunnels: Tracking a Cobalt Strike Server Leveraging Trusted Infrastructure Cobalt Strike |
2024-12-30
⋅
Intrinsec
⋅
CryptBot: Hunting for initial access vectors CryptBot Lumma Stealer PrivateLoader |
2024-12-12
⋅
Hunt.io
⋅
Oyster’s Trail: Resurgence of Infrastructure Linked to Ransomware and Cybercrime Actors Broomstick |
2024-12-10
⋅
Hunt.io
⋅
“Million OK !!!!” and the Naver Facade: Tracking Recent Suspected Kimsuky Infrastructure Kimsuky |
2024-12-03
⋅
Hunt.io
⋅
Rare Watermark Links Cobalt Strike 4.10 Team Servers to Ongoing Suspicious Activity Cobalt Strike |
2024-11-28
⋅
Hunt.io
⋅
Uncovering Threat Actor Tactics: How Open Directories Provide Insight into XWorm Delivery Strategies XWorm |
2024-11-21
⋅
Hunt.io
⋅
DarkPeony’s Trail: Certificate Patterns Point to Sustained Campaign Infrastructure DOPLUGS |
2024-11-19
⋅
Hunt.io
⋅
XenoRAT Adopts Excel XLL Files and ConfuserEx as Access Method XenoRAT |
2024-11-14
⋅
Huntress Labs
⋅
It’s Not Safe to Pay SafePay SafePay |
2024-11-12
⋅
Hunt.io
⋅
Targeting Innovation: Sliver C2 and Ligolo-ng Used in Operation Aimed at Y Combinator Sliver |
2024-11-05
⋅
Hunt.io
⋅
RunningRAT’s Next Move: From Remote Access to Crypto Mining for Profit Running RAT |
2024-10-31
⋅
Hunt.io
⋅
Tricks, Treats, and Threats: Cobalt Strike & the Goblin Lurking in Plain Sight Cobalt Strike |
2024-10-24
⋅
Hunt.io
⋅
Rekoobe Backdoor Discovered in Open Directory, Possibly Targeting TradingView Users Rekoobe |
2024-10-17
⋅
Hunt.io
⋅
From Warm to Burned: Shedding Light on Updated WarmCookie Infrastructure WarmCookie |
2024-10-15
⋅
Microsoft
⋅
Phish, Click, Breach: Hunting for a Sophisticated Cyber Attack UNC4393 |
2024-10-10
⋅
Hunt.io
⋅
Unmasking Adversary Infrastructure: How Certificates and Redirects Exposed Earth Baxia and PlugX Activity Cobalt Strike PlugX |
2024-10-08
⋅
Hunt.io
⋅
Inside a Cybercriminal’s Server: DDoS Tools, Spyware APKs, and Phishing Pages SpyNote |
2024-09-03
⋅
Hunt.io
⋅
ToneShell Backdoor Used to Target Attendees of the IISS Defence Summit TONESHELL |
2024-09-01
⋅
Hunt.io
⋅
Echoes of Stargazer Goblin: Analyzing Shared TTPs from an Open Directory Sliver |