Click here to download all references as Bib-File.•
| 2026-03-19
⋅
cocomelonc
⋅
MacOS malware persistence 5: cron jobs. Simple C example |
| 2026-03-18
⋅
Google
⋅
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors GHOSTBLADE UNC6748 |
| 2026-03-18
⋅
Google
⋅
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors GHOSTBLADE |
| 2026-03-17
⋅
Hunt.io
⋅
Iranian Botnet Exposed via Open Directory: 15-Node Relay Network and Active C2 |
| 2026-03-16
⋅
Ransom-ISAC
⋅
Contagious Interview: VS Code to RAT StoatWaffle |
| 2026-03-12
⋅
IBM X-Force
⋅
A Slopoly start to AI-enhanced ransomware attacks Slopoly Hive0163 |
| 2026-03-12
⋅
Gdata
⋅
Endgame Harvesting: Inside ACRStealer’s Modern Infrastructure ACR Stealer |
| 2026-03-12
⋅
Check Point Research
⋅
“Handala Hack” – Unveiling Group’s Modus Operandi |
| 2026-03-10
⋅
Check Point Research
⋅
Iranian MOIS Actors & the Cyber Crime Connection Qilin Tsundere CASTLELOADER Rhadamanthys |
| 2026-03-10
⋅
Lumen
⋅
Silence of the hops: The KadNap botnet KadNap |
| 2026-03-10
⋅
ESET Research
⋅
Sednit reloaded: Back in the trenches BEARDSHELL GRUNT SLIMAGENT X-Agent XTunnel |
| 2026-03-09
⋅
Abstract Security
⋅
Contagious Interview: Evolution of VS Code and Cursor Tasks Infection Chains Part 2 GolangGhost PylangGhost GolangGhost |
| 2026-03-07
⋅
OpenSourceMalware
⋅
PolinRider: DPRK Threat Actor Implants Malware in Hundreds of GitHub Repos JADESNOW |
| 2026-03-06
⋅
Microsoft
⋅
AI as tradecraft: How threat actors operationalize AI OtterCookie |
| 2026-03-04
⋅
Huntress Labs
⋅
"Malware, from the Outside!": How a Threat Actor Used Fake OpenClaw Installers to Infect Systems with GhostSocks and Information Stealers GhostSocks Vidar |
| 2026-03-04
⋅
EG-FinCirt
⋅
Remcos RAT Operations: How Attackers Gain and Maintain Control Remcos |
| 2026-03-03
⋅
Radware
⋅
Retaliatory Hacktivist DDoS Activity Following Operation Epic Fury/Roaring Lion Conquerors Electronic Army |
| 2026-03-03
⋅
Sophos
⋅
Hacktivist campaigns increase as United States, Iran, and Israel conflict intensifies APTIran |
| 2026-03-03
⋅
Microsoft
⋅
Signed malware impersonating workplace apps deploys RMM backdoors TrustConnect RAT |
| 2026-02-28
⋅
Github (cocomelonc)
⋅
MacOS malware persistence 4: AutoLaunched Applications, Background Task Management (BTM). Simple C example |