Click here to download all references as Bib-File.•
2021-03-11
⋅
Bleeping Computer
⋅
Ransomware now attacks Microsoft Exchange servers with ProxyLogon exploits |
2021-03-11
⋅
IBM
⋅
Dridex Campaign Propelled by Cutwail Botnet and Poisonous PowerShell Scripts Cutwail Dridex |
2021-03-11
⋅
Palo Alto Networks Unit 42
⋅
Microsoft Exchange Server Attack Timeline CHINACHOPPER |
2021-03-11
⋅
Cofense
⋅
AutoHotKey Leveraged by Metamorfo/Mekotio Banking Trojan Metamorfo |
2021-03-11
⋅
YouTube ( Malware_Analyzing_&_RE_Tips_Tricks)
⋅
Formbook Reversing - Part1 [Formbook .NET loader/injector analyzing, decrypting, unpacking, patching] Formbook |
2021-03-10
⋅
Center for Security Studies (CSS)
⋅
Publicly attributing cyber attacks: a framework |
2021-03-10
⋅
Twitter (@MSSPete)
⋅
Tweet on Sample KQL query for detecting usage of HAFNIUM PoC code floating ITW |
2021-03-10
⋅
DomainTools
⋅
Examining Exchange Exploitation and its Lessons for Defenders CHINACHOPPER |
2021-03-10
⋅
US-CERT
⋅
Remediating Networks Affected by the SolarWinds and Active Directory/M365 Compromise SUNBURST |
2021-03-10
⋅
Bleeping Computer
⋅
Norway parliament data stolen in Microsoft Exchange attack |
2021-03-10
⋅
Bitdefender
⋅
FIN8 Returns with Improved BADHATCH Toolkit BADHATCH |
2021-03-10
⋅
⋅
NTT Security
⋅
日本を標的としたPseudoGateキャンペーンによるSpelevo Exploit Kitを用いた攻撃について Zloader |
2021-03-10
⋅
Intezer
⋅
New Linux Backdoor RedXOR Likely Operated by Chinese Nation-State Actor RedXOR XOR DDoS |
2021-03-09
⋅
Youtube (SANS Digital Forensics and Incident Response)
⋅
Jackpotting ESXi Servers For Maximum Encryption | Eric Loui & Sergei Frankoff | SANS CTI Summit 2021 DarkSide RansomEXX DarkSide RansomEXX GOLD DUPONT |
2021-03-09
⋅
Malwarebytes
⋅
Microsoft Exchange attacks cause panic as criminals go shell collecting |
2021-03-09
⋅
Check Point Research
⋅
Clast82 – A new Dropper on Google Play Dropping the AlienBot Banker and MRAT Alien |
2021-03-09
⋅
CyberArk
⋅
Kinsing: The Malware with Two Faces Kinsing |
2021-03-09
⋅
splunk
⋅
Cloud Federated Credential Abuse & Cobalt Strike: Threat Research February 2021 Cobalt Strike |
2021-03-09
⋅
PRAETORIAN
⋅
Reproducing the Microsoft Exchange Proxylogon Exploit Chain CHINACHOPPER |
2021-03-09
⋅
Red Canary
⋅
Microsoft Exchange server exploitation: how to detect, mitigate, and stay calm CHINACHOPPER |