Click here to download all references as Bib-File.•
| 2025-08-26
⋅
Sophos
⋅
Velociraptor incident response tool abused for remote access |
| 2025-08-25
⋅
Google
⋅
Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats PlugX UNC6384 |
| 2025-08-25
⋅
zimperium
⋅
Hook Version 3: The Banking Trojan with The Most Advanced Capabilities Hook |
| 2025-08-25
⋅
Google
⋅
Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats STATICPLUGIN |
| 2025-08-24
⋅
cocomelonc
⋅
MacOS hacking part 10: shellcode injection via task_for_pid - create remote thread. Simple C (Intel) example |
| 2025-08-21
⋅
Zscaler
⋅
Android Document Readers and Deception: Tracking the Latest Updates to Anatsa Anatsa |
| 2025-08-21
⋅
GBHackers on Security
⋅
Threat Actors Weaponize PDF Editor Trojan to Convert Devices into Proxies TamperedChef |
| 2025-08-21
⋅
Trellix
⋅
The Silent, Fileless Threat of VShell VShell |
| 2025-08-21
⋅
CrowdStrike
⋅
MURKY PANDA: A Trusted-Relationship Threat in the Cloud |
| 2025-08-20
⋅
Ctrl-Alt-Intel
⋅
From Campus to C2: Tracking a Persistent Chinese Operation Against Vietnamese Universities GOREVERSE SNOWLIGHT Cobalt Strike reGeorg VShell |
| 2025-08-20
⋅
Hunt.io
⋅
APT MuddyWater Deploys Multi-Stage Phishing to Target CFOs |
| 2025-08-19
⋅
securelist
⋅
GodRAT – New RAT targeting financial institutions GodRAT |
| 2025-08-19
⋅
The Wall Street Journal
⋅
Oregon Man Accused of Operating One of Most Powerful Attack ‘Botnets’ Ever Seen RapperBot |
| 2025-08-19
⋅
IBM X-Force
⋅
IBM X-Force Threat Analysis: QuirkyLoader - A new malware loader delivering infostealers and RATs QuirkyLoader |
| 2025-08-19
⋅
Red Canary
⋅
Patching for persistence: How DripDropper Linux malware moves through the cloud |
| 2025-08-18
⋅
Trellix
⋅
The Coordinated Embassy Hunt: Unmasking the DPRK-linked GitHub C2 Espionage Campaign XenoRAT |
| 2025-08-18
⋅
Medium RaghavtiResearch
⋅
Qilin Ransomware-as-a-Service: Threat Analysis and Strategic Outlook Qilin AgendaCrypt |
| 2025-08-15
⋅
cocomelonc
⋅
Malware development trick 50: phishing attack using a fake login page with Telegram exfiltration. Simple Javascript example. |
| 2025-08-15
⋅
Cisco Talos
⋅
UAT-7237 targets Taiwanese web hosting infrastructure SoundBill UAT-7237 |
| 2025-08-15
⋅
Bleeping Computer
⋅
Colt Telecom attack claimed by WarLock ransomware, data up for sale WarLock |