Click here to download all references as Bib-File.•
2020-11-04
⋅
Sophos
⋅
A new APT uses DLL side-loads to “KilllSomeOne” KilllSomeOne PlugX |
2020-11-03
⋅
BleepingComputer
⋅
New RegretLocker ransomware targets Windows virtual machines RegretLocker |
2020-11-03
⋅
InfoSec Handlers Diary Blog
⋅
Attackers Exploiting WebLogic Servers via CVE-2020-14882 to install Cobalt Strike Cobalt Strike |
2020-11-03
⋅
Objective-See
⋅
Adventures in Anti-Gravity: Deconstructing the Mac Variant of GravityRAT |
2020-11-03
⋅
Kaspersky Labs
⋅
APT trends report Q3 2020 WellMail EVILNUM Janicab Poet RAT AsyncRAT Ave Maria Cobalt Strike Crimson RAT CROSSWALK Dtrack LODEINFO MoriAgent Okrum PlugX POISONPLUG Rover ShadowPad SoreFang Winnti |
2020-11-02
⋅
One Night in Norfolk
⋅
TinyPOS and ProLocker: An Odd Relationship AbaddonPOS PwndLocker |
2020-11-02
⋅
FireEye
⋅
Live off the Land? How About Bringing Your Own Island? An Overview of UNC1945 SLAPSTICK STEELCORGI |
2020-11-02
⋅
SUCURI
⋅
CSS-JS Steganography in Fake Flash Player Update Malware magecart NetSupportManager RAT |
2020-11-02
⋅
Cybereason
⋅
Back to the Future: Inside the Kimsuky KGH Spyware Suite BabyShark GoldDragon KGH_SPY Kimsuky |
2020-11-01
⋅
Toli Security
⋅
SSH-backdoor Botnet With ‘Research’ Infection Technique |
2020-11-01
⋅
AppRiver
⋅
Vjw0rm Is Back With New Tactics Vjw0rm |
2020-10-31
⋅
splunk
⋅
Ryuk and Splunk Detections Ryuk |
2020-10-30
⋅
YouTube (Kaspersky Tech)
⋅
Around the world in 80 days 4.2bn packets Cobalt Strike Derusbi HyperBro Poison Ivy ShadowPad Winnti |
2020-10-30
⋅
Cofense
⋅
The Ryuk Threat: Why BazarBackdoor Matters Most BazarBackdoor Ryuk |
2020-10-30
⋅
Reuters
⋅
Russian hackers targeted California, Indiana Democratic parties |
2020-10-29
⋅
GitHub (LimerBoy)
⋅
StormKitty StormKittyRAT |
2020-10-29
⋅
Mandiant
⋅
FIN11: A Widespread Ransomware and Extortion Operation (Webinar) FIN11 |
2020-10-29
⋅
RiskIQ
⋅
Ryuk Ransomware: Extensive Attack Infrastructure Revealed Cobalt Strike Ryuk |
2020-10-29
⋅
US-CERT
⋅
Malware Analysis Report (AR20-303B): ZEBROCY Backdoor Zebrocy |
2020-10-29
⋅
Twitter (@SophosLabs)
⋅
Tweet on similarities between BUER in-memory loader & RYUK in-memory loader Buer Ryuk |