Click here to download all references as Bib-File.•
2023-06-15
⋅
Google
⋅
Barracuda ESG Zero-Day Vulnerability (CVE-2023-2868) Exploited Globally by Aggressive and Skilled Actor, Suspected Links to China SALTWATER SEASPY WHIRLPOOL UNC4841 |
2023-06-06
⋅
Security Intelligence
⋅
ITG10 Likely Targeting South Korean Entities of Interest to the Democratic People’s Republic of Korea (DPRK) RokRAT |
2023-06-02
⋅
Mandiant
⋅
Zero-Day Vulnerability in MOVEit Transfer Exploited for Data Theft |
2023-05-17
⋅
Group-IB
⋅
The distinctive rattle of APT SideWinder SideWinder |
2023-05-09
⋅
Medium walmartglobaltech
⋅
MetaStealer string decryption and DGA overview MetaStealer |
2023-03-23
⋅
Mandiant
⋅
UNC961 in the Multiverse of Mandiant: Three Encounters with a Financially Motivated Threat Actor HOLERUN LIGHTBUNNY Prophet Spider |
2023-03-16
⋅
Intego
⋅
FBI shuts down 11-year-old NetWire RAT malware NetWire |
2023-03-10
⋅
Medium walmartglobaltech
⋅
From Royal With Love Cobalt Strike Conti PLAY Royal Ransom Somnia |
2023-02-24
⋅
Medium walmartglobaltech
⋅
Qbot testing malvertising campaigns? QakBot |
2023-02-04
⋅
Youtube (Dr Josh Stroschein)
⋅
Investigating NullMixer Network Traffic: Utilizing Suricata and Evebox (Part 3) Nullmixer |
2023-02-03
⋅
Youtube (Dr Josh Stroschein)
⋅
Unpacking NullMixer - Identifying and Unraveling ASPack (Part 2) Nullmixer |
2023-01-31
⋅
Investigating NullMixer - Identifying Initial Packing Techniques (Part 1) Nullmixer |
2022-12-12
⋅
Reuters
⋅
North Korean cyber spies deploy new tactic: tricking foreign experts into writing research for them |
2022-09-13
⋅
Proofpoint
⋅
Look What You Made Me Do: TA453 Uses Multi-Persona Impersonation to Capitalize on FOMO |
2022-08-09
⋅
Medium walmartglobaltech
⋅
Pivoting on a SharpExt to profile Kimusky panels for great good Kimsuky |
2022-08-04
⋅
Medium walmartglobaltech
⋅
IcedID leverages PrivateLoader IcedID PrivateLoader |
2022-07-14
⋅
Proofpoint
⋅
Above the Fold and in Your Inbox: Tracing State-Aligned Activity Targeting Journalists, Media Chinoxy APT31 Lazarus Group TA482 |
2022-07-06
⋅
Trend Micro
⋅
Brand-New HavanaCrypt Ransomware Poses as Google Software Update App, Uses Microsoft Hosting Service IP Address as C&C Server HavanaCrypt |
2022-05-25
⋅
Medium walmartglobaltech
⋅
SocGholish Campaigns and Initial Access Kit FAKEUPDATES Blister Cobalt Strike NetSupportManager RAT |
2022-05-02
⋅
Mandiant
⋅
UNC3524: Eye Spy on Your Email QUIETEXIT UNC3524 |