Click here to download all references as Bib-File.•
| 2026-04-13
⋅
Tweet about HanGhost HanGhost |
| 2026-04-13
⋅
Twitter (@anyrun_app)
⋅
Tweet about HanGhost |
| 2026-04-13
⋅
Dataminr
⋅
Cyber Intel Brief: Pro-Iranian Actor Ababil of Minab Claims Cyberattack on LA Metro (LACMTA) Ababil of Minab |
| 2026-04-13
⋅
Cleafy
⋅
Mirax: a new Android RAT turning infected devices into potential residential proxy nodes Mirax |
| 2026-04-12
⋅
cocomelonc
⋅
Mobile malware development trick 3. CPU info logger: anti-VM and anti-sandbox. Simple Android (Kotlin) example. |
| 2026-04-11
⋅
Breakglass Intelligence
⋅
We Dumped a Live Kimsuky C2 and Recovered Every Stage of the Kill Chain: CHM Dropper, VBScript Stager, PowerShell Keylogger RandomQuery RandomQuery |
| 2026-04-10
⋅
Infoblox
⋅
Scams, Slaves and (Malware-as-a) Service: Tracking a Trojan to Cambodia’s Scam Centers |
| 2026-04-09
⋅
⋅
F6
⋅
Eastern Signature: Investigating a Cyberattack by an Asian Threat Group ShadowPad |
| 2026-04-08
⋅
Lookout
⋅
Beyond BITTER: MENA Civil Society Targeted in Hack-For-Hire Operation Linked to BITTER APT ProSpy |
| 2026-04-08
⋅
Black Lotus Labs
⋅
FrostArmada: All thriller, no (malware) filler |
| 2026-04-07
⋅
Talos Intelligence
⋅
New Lua-based malware “LucidRook” observed in targeted attacks against Taiwanese organizations LucidKnight LucidPawn LucidRook UAT-10362 |
| 2026-04-07
⋅
RedPacket Security
⋅
[KRYBIT] – Ransomware Victim: fraper[.]com Krybit |
| 2026-04-07
⋅
Microsoft
⋅
SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks |
| 2026-04-07
⋅
IC3
⋅
AA26-097A: Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure |
| 2026-04-07
⋅
NCSC UK
⋅
APT28 exploit routers to enable DNS hijacking operations |
| 2026-04-07
⋅
Gen Digital
⋅
Remus: Unmasking The 64-bit Variant of the Infamous Lumma Stealer Lumma Stealer Remus Tenzor |
| 2026-04-06
⋅
PICUS Security
⋅
How NoName057(16) Uses DDoSia to Attack NATO Targets Z-Pentest Alliance |
| 2026-04-05
⋅
0x3oBAD
⋅
Deep Technical Analysis Of Payload Ransomware Targeting ESXi Environment Payload |
| 2026-04-03
⋅
Panther
⋅
jsonspack: Multi-Tenant Node.js RAT — DPRK Supply Chain Campaign OtterCookie |
| 2026-04-03
⋅
Trend Micro
⋅
Weaponizing Trust Signals: Claude Code Lures and GitHub Release Payloads GhostSocks Vidar |