Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2025-12-19 ⋅ PolySwarm Tech Team ⋅ PolySwarm
Multiple Threat Actors Leveraging CVE-2025-55182 (React2Shell)
ANGRYREBEL COMPOOD MINOCAT Mirai SNOWLIGHT XMRIG EtherRAT Cobalt Strike Mirai VShell xmrig JACKPOT PANDA
2025-12-19 ⋅ Botbrawl ⋅ Sean Doyle
Chinese APT LongNosedGoblin Targets Government Networks in Southeast Asia and Japan
NosyDownloader LongNosedGoblin
2025-12-19 ⋅ Intezer ⋅ Nicole Fishbein
Tracing a Paper Werewolf campaign through AI-generated decoys and Excel XLLs
EchoGather
2025-12-19 ⋅ cyble ⋅ Cyble
Stealth in Layers: Unmasking the Loader used in Targeted Email Campaigns
DCRat Katz Stealer PhantomVAI PureLogs Stealer Remcos XWorm
2025-12-18 ⋅ Proofpoint ⋅ Proofpoint Threat Research Team
Access granted: phishing with device code authorization for account takeover
TA2723 UNK_AcademicFlare
2025-12-18 ⋅ HelpNetSecurity ⋅ John Wilson
Clipping Scripted Sparrow’s wings: Tracking a global phishing ring
Scripted Sparrow
2025-12-18 ⋅ Huntress Labs ⋅ Austin Worline, Lindsey O'Donnell-Welch
A Series of Unfortunate (RMM) Events
2025-12-18 ⋅ Acronis ⋅ Acronis Security
Acronis TRU Alliance {Hunt.io}: Hunting DPRK threats - New Global Lazarus & Kimsuky campaigns
BADCALL POOLRAT Quasar RAT
2025-12-18 ⋅ Gen Digital Inc ⋅ Vojtěch Krejsa
Gen Blogs | Defeating AuraStealer: Practical Deobfuscation Workflows for Modern Infostealers
Aura Stealer
2025-12-18 ⋅ safebreach ⋅ Tomer Bar
Prince of Persia: A decade of Iranian Nation State APT Campaign Activity
Infy Tonnerre
2025-12-18 ⋅ ESET Research ⋅ Anton Cherepanov, Peter Strýček
LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan
NosyDownloader
2025-12-18 ⋅ Cyderes ⋅ Rahul Ramesh
From Loader to Looter: ACR Stealer Rides on Upgraded CountLoader
ACR Stealer CountLoader
2025-12-18 ⋅ BlackPoint ⋅ Nevan Beal, Sam Decker
New MintsLoader Variant Using Hashtable Obfuscation
MintsLoader
2025-12-17 ⋅ BI.ZONE ⋅ BI.ZONE
Arcane Werewolf revamps its arsenal with Loki 2.1 implant
Havoc Loki (Mythic) Mythic Likho
2025-12-17 ⋅ Reporters Without Borders ⋅ Janik Besendor, Maximilian Paß, RESIDENT.NGO Team, Viktor Schlüter
ResidentBat: A new spyware family used by Belarusian KGB
ResidentBat
2025-12-17 ⋅ Recorded Future ⋅ Insikt Group
PurpleBravo’s Targeting of the IT Software Supply Chain
BeaverTail InvisibleFerret PylangGhost GolangGhost
2025-12-17 ⋅ Cisco Talos ⋅ Cisco Talos
UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager
UAT-9686
2025-12-17 ⋅ Crystal Intelligence ⋅ Crystal Intelligence
How we proved North Korea’s blockchain malware campaign
JADESNOW
2025-12-17 ⋅ XLab ⋅ Acey9, Alex.Turing, RootKiter, Wang Hao
Kimwolf Exposed: The Massive Android Botnet with 1.8 Million Infected Devices
Kimwolf Aisuru
2025-12-17 ⋅ Recorded Future ⋅ Insikt Group
BlueDelta’s Persistent Campaign Against UKR.NET