Click here to download all references as Bib-File.•
| 2025-01-14
⋅
Infoblox
⋅
One Mikro Typo: How a simple DNS misconfiguration enables malware delivery by a Russian botnet |
| 2025-01-07
⋅
SANS ISC
⋅
PacketCrypt Classic Cryptocurrency Miner on PHP Servers |
| 2025-01-03
⋅
SANS ISC
⋅
SwaetRAT Delivery Through Python SwaetRAT |
| 2024-12-11
⋅
Lookout
⋅
Lookout Discovers Two Russian Android Spyware Families from Gamaredon APT BoneSpy DroidWatcher PlainGnome |
| 2024-12-11
⋅
Lookout
⋅
Lookout Discovers New Chinese Surveillance Tool Used by Public Security Bureaus EagleMsgSpy |
| 2024-11-14
⋅
Cisco Talos
⋅
New PXA Stealer targets government and education sectors for sensitive information PXA Stealer |
| 2024-11-07
⋅
Cisco Talos
⋅
Unwrapping the emerging Interlock ransomware attack Interlock Rhysida |
| 2024-10-31
⋅
Twitter (@nextronresearch)
⋅
Tweet about discovery of HellDown ransomware HellDown |
| 2024-10-30
⋅
Palo Alto Networks Unit 42
⋅
Jumpy Pisces Engages in Play Ransomware Dtrack MimiKatz PLAY Sliver |
| 2024-10-24
⋅
Cisco Talos
⋅
Writing a BugSleep C2 server and detecting its traffic with Snort bugsleep |
| 2024-10-24
⋅
Hunt.io
⋅
Rekoobe Backdoor Discovered in Open Directory, Possibly Targeting TradingView Users Rekoobe |
| 2024-10-23
⋅
Cisco Talos
⋅
Highlighting TA866/Asylum Ambuscade Activity Since 2021 WasabiSeed Cobalt Strike csharp-streamer RAT Resident Rhadamanthys WarmCookie |
| 2024-10-23
⋅
Cisco Talos
⋅
Threat Spotlight: WarmCookie/BadSpace Cobalt Strike csharp-streamer RAT WarmCookie |
| 2024-10-22
⋅
Cisco Talos
⋅
Threat actor abuses Gophish to deliver new PowerRAT and DCRAT PowerRAT |
| 2024-10-17
⋅
Cisco Talos
⋅
UAT-5647 targets Ukrainian and Polish entities with RomCom malware variants MeltingClaw ROMCOM RAT RustyClaw ShadyHammock RomCom |
| 2024-10-16
⋅
⋅
ASEC
⋅
An Lab and the National Cyber Security Center (NCSC), joint report distribution and Microsoft browser 0-DAY discovery (CVE-2024-38178) |
| 2024-09-26
⋅
Palo Alto Networks Unit 42
⋅
Unraveling Sparkling Pisces’s Tool Set: KLogEXE and FPSpy FPSpy KLogEXE Kimsuky |
| 2024-09-19
⋅
Palo Alto Networks Unit 42
⋅
Discovering Splinter: A First Look at a New Post-Exploitation Red Team Tool Splinter |
| 2024-08-28
⋅
Talos Intelligence
⋅
BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks BlackByte |
| 2024-08-21
⋅
Cisco Talos
⋅
MoonPeak malware from North Korean actors unveils new details on attacker infrastructure MoonPeak XenoRAT UAT-5394 |