Click here to download all references as Bib-File.•
| 2021-03-12
⋅
360 netlab
⋅
New Threat: ZHtrap botnet implements honeypot to facilitate finding more victims ZHtrap |
| 2021-03-12
⋅
splunk
⋅
Detecting Microsoft Exchange Vulnerabilities - 0 + 8 Days Later… |
| 2021-03-11
⋅
Qurium
⋅
Myanmar – Multi-stage malware attack targets elected lawmakers Cobalt Strike |
| 2021-03-11
⋅
Fortinet
⋅
Whitelist Me, Maybe? “Netbounce” Threat Actor Tries A Bold Approach To Evade Detection |
| 2021-03-11
⋅
Check Point
⋅
Exploits on Organizations Worldwide Tripled after Microsoft’s Revelation of Four Zero-days |
| 2021-03-11
⋅
DEVO
⋅
Detection and Investigation Using Devo: HAFNIUM 0-day Exploits on Microsoft Exchange Service CHINACHOPPER MimiKatz |
| 2021-03-11
⋅
Bleeping Computer
⋅
Ransomware now attacks Microsoft Exchange servers with ProxyLogon exploits |
| 2021-03-11
⋅
Palo Alto Networks Unit 42
⋅
Microsoft Exchange Server Attack Timeline CHINACHOPPER |
| 2021-03-11
⋅
Flashpoint
⋅
CL0P and REvil Escalate Their Ransomware Tactics Clop REvil |
| 2021-03-11
⋅
YouTube ( Malware_Analyzing_&_RE_Tips_Tricks)
⋅
Formbook Reversing - Part1 [Formbook .NET loader/injector analyzing, decrypting, unpacking, patching] Formbook |
| 2021-03-11
⋅
Elastic
⋅
Update - Detection and Response for HAFNIUM Activity |
| 2021-03-10
⋅
Center for Security Studies (CSS)
⋅
Publicly attributing cyber attacks: a framework |
| 2021-03-10
⋅
Twitter (@MSSPete)
⋅
Tweet on Sample KQL query for detecting usage of HAFNIUM PoC code floating ITW |
| 2021-03-10
⋅
Proofpoint
⋅
NimzaLoader: TA800’s New Initial Access Malware BazarNimrod Cobalt Strike |
| 2021-03-10
⋅
DomainTools
⋅
Examining Exchange Exploitation and its Lessons for Defenders CHINACHOPPER |
| 2021-03-10
⋅
US-CERT
⋅
Remediating Networks Affected by the SolarWinds and Active Directory/M365 Compromise SUNBURST |
| 2021-03-10
⋅
Bleeping Computer
⋅
Norway parliament data stolen in Microsoft Exchange attack |
| 2021-03-10
⋅
Lemon's InfoSec Ramblings
⋅
Microsoft Exchange & the HAFNIUM Threat Actor CHINACHOPPER |
| 2021-03-10
⋅
ESET Research
⋅
Exchange servers under siege from at least 10 APT groups Microcin MimiKatz PlugX Winnti APT27 APT41 Calypso Tick ToddyCat Tonto Team Vicious Panda |
| 2021-03-10
⋅
Bitdefender
⋅
FIN8 Returns with Improved BADHATCH Toolkit BADHATCH |