Click here to download all references as Bib-File.•
2021-11-24
⋅
Sansec
⋅
CronRAT malware hides behind February 31st CronRAT |
2021-11-23
⋅
Anomali
⋅
Mummy Spider’s Emotet Malware is Back After a Year Hiatus; Wizard Spider’s TrickBot Observed in Its Return Emotet |
2021-11-19
⋅
⋅
360 Threat Intelligence Center
⋅
It is suspected that the APT-C-55 organization used the commercial software Web Browser Password Viewer to carry out the attack |
2021-11-18
⋅
Blackberry
⋅
Threat Thursday: DanaBot’s Evolution from Bank Fraud to DDos Attacks DanaBot |
2021-11-18
⋅
Sansec
⋅
Linux malware agent hits eCommerce sites |
2021-11-16
⋅
IronNet
⋅
How IronNet's Behavioral Analytics Detect REvil and Conti Ransomware Cobalt Strike Conti IcedID REvil |
2021-11-16
⋅
Twitter (@_CPResearch_)
⋅
Tweet on 32bit version of CVE-2021-1732 exploited by BITTER group |
2021-11-16
⋅
Digital Shadows
⋅
Vulnerability Intelligence: What’s the Word in Dark Web Forums? |
2021-11-16
⋅
ESET Research
⋅
Strategic web compromises in the Middle East with a pinch of Candiru Caramel Tsunami Karkadann |
2021-11-16
⋅
Mandiant
⋅
UNC1151 Assessed with High Confidence to have Links to Belarus, Ghostwriter Campaign Aligned with Belarusian Government Interests Ghostwriter |
2021-11-15
⋅
Check Point Research
⋅
Uncovering MosesStaff techniques: Ideology over Money DCSrv MosesStaff |
2021-11-11
⋅
vmware
⋅
Research Recap: How To Automate Malware Campaign Detection With Telemetry Peak Analyzer Phorpiex QakBot |
2021-11-11
⋅
Blackberry
⋅
Threat Thursday: SquirrelWaffle Takes a Bite Out of Victim's Bank Accounts Squirrelwaffle |
2021-11-11
⋅
splunk
⋅
FIN7 Tools Resurface in the Field – Splinter or Copycat? JSSLoader Remcos |
2021-11-10
⋅
Twitter (@ESETresearch)
⋅
Tweet on a discovery of a trojanized IDA Pro installer, distributed by the LABYRINTH CHOLLIMA group. |
2021-11-10
⋅
Trend Micro
⋅
Void Balaur and the Rise of the Cybermercenary Industry ZStealer Void Balaur |
2021-11-10
⋅
Trend Micro
⋅
Void Balaur and the Rise of the Cybermercenary Industry (IOCs) |
2021-11-09
⋅
Trend Micro
⋅
Compromised Docker Hub Accounts Abused for Cryptomining Linked to TeamTNT |
2021-11-08
⋅
NCC Group
⋅
TA505 exploits SolarWinds Serv-U vulnerability (CVE-2021-35211) for initial access |
2021-11-05
⋅
Blackberry
⋅
Hunter Becomes Hunted: Zebra2104 Hides a Herd of Malware Cobalt Strike DoppelDridex Mount Locker Phobos StrongPity |