Click here to download all references as Bib-File.•
2021-11-10
⋅
Group-IB
⋅
REDCURL: The awakening RedCurl |
2021-11-10
⋅
Twitter (@ESETresearch)
⋅
Tweet on a discovery of a trojanized IDA Pro installer, distributed by the LABYRINTH CHOLLIMA group. |
2021-11-10
⋅
CIRCL
⋅
TR-64 - Exploited Exchange Servers - Mails with links to malware from known/valid senders QakBot |
2021-11-10
⋅
⋅
RT on the Russian
⋅
"He does not get in touch": what is known about Barnaul, wanted by the FBI on charges of cybercrime REvil REvil |
2021-11-10
⋅
zimperium
⋅
PhoneSpy: The App-Based Cyberattack Snooping South Korean Citizens PhoneSpy |
2021-11-10
⋅
Trend Micro
⋅
Void Balaur and the Rise of the Cybermercenary Industry ZStealer Void Balaur |
2021-11-10
⋅
Trend Micro
⋅
Void Balaur and the Rise of the Cybermercenary Industry (IOCs) |
2021-11-10
⋅
CrowdStrike
⋅
Ploutus ATM Malware Case Study: Automated Deobfuscation of a Strongly Obfuscated .NET Binary Ploutus ATM |
2021-11-10
⋅
open source dfir
⋅
Use EVTX files on VirusTotal with Timesketch and Sigma (Part 2) |
2021-11-10
⋅
Blackberry
⋅
REvil Under the Microscope GootKit REvil |
2021-11-10
⋅
Microsoft
⋅
The hunt for NOBELIUM, the most sophisticated nation-state attack in history |
2021-11-10
⋅
Cisco Talos
⋅
North Korean attackers use malicious blogs to deliver malware to high-profile South Korean targets GoldDragon |
2021-11-10
⋅
Randori
⋅
Zero-Day Disclosure: Palo Alto Networks GlobalProtect VPN CVE-2021-3064 |
2021-11-10
⋅
Twitter (@billyleonard)
⋅
Tweet on Rekoobe (used by APT31), being a fork of open source tool called Tiny SHell, used by different actor since at least 2012 Rekoobe |
2021-11-10
⋅
AT&T
⋅
Stories from the SOC - Powershell, Proxyshell, Conti TTPs OH MY! Cobalt Strike Conti |
2021-11-10
⋅
McAfee
⋅
The Newest Malicious Actor: “Squirrelwaffle” Malicious Doc. Squirrelwaffle |
2021-11-10
⋅
Sekoia
⋅
Walking on APT31 infrastructure footprints Rekoobe Unidentified ELF 004 Cobalt Strike |
2021-11-10
⋅
⋅
mai1zhi2 / SharpBeacon - CobaltStrike Beacon written in .Net 4 SharpBeacon |
2021-11-09
⋅
Cybereason
⋅
THREAT ANALYSIS REPORT: From Shatak Emails to the Conti Ransomware Cobalt Strike Conti |
2021-11-09
⋅
Certitude
⋅
The Invisible JavaScript Backdoor |