Click here to download all references as Bib-File.•
| 2023-12-14
⋅
Mandiant
⋅
Opening a Can of Whoop Ads: Detecting and Disrupting a Malvertising Campaign Distributing Backdoors DanaBot DarkGate |
| 2023-12-13
⋅
Fortinet
⋅
TeamCity Intrusion Saga: APT29 Suspected Among the Attackers Exploiting CVE-2023-42793 GraphDrop |
| 2023-12-13
⋅
CISA
⋅
Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally GraphDrop |
| 2023-12-07
⋅
⋅
Cert-UA
⋅
UAC-0050 mass cyberattack using RemcosRAT/MeduzaStealer against Ukraine and Poland (CERT-UA#8218) Meduza Stealer Remcos |
| 2023-11-23
⋅
Infosec Writeups
⋅
Malware analysis Remcos RAT- 4.9.2 Pro Remcos |
| 2023-11-14
⋅
SOC Prime
⋅
Remcos RAT Detection: UAC-0050 Hackers Launch Phishing Attacks Impersonating the Security Service of Ukraine Remcos UAC-0050 |
| 2023-11-09
⋅
Mandiant
⋅
Sandworm Disrupts Power in Ukraine Using a Novel Attack Against Operational Technology CaddyWiper |
| 2023-10-27
⋅
Twitter (@embee_research)
⋅
Remcos Downloader Analysis - Manual Deobfuscation of Visual Basic and Powershell Remcos |
| 2023-10-26
⋅
Medium walmartglobaltech
⋅
SmartApeSG NetSupportManager RAT |
| 2023-10-18
⋅
Microsoft
⋅
Multiple North Korean threat actors exploiting the TeamCity CVE-2023-42793 vulnerability FeedLoad ForestTiger HazyLoad RollSling Silent Chollima |
| 2023-09-28
⋅
Confiant
⋅
Exploring ScamClub Payloads via Deobfuscation Using Abstract Syntax Trees ScamClub |
| 2023-09-21
⋅
ESET Research
⋅
OilRig’s Outer Space and Juicy Mix: Same ol’ rig, new drill pipes Mango Solar |
| 2023-09-19
⋅
Checkpoint
⋅
Unveiling the Shadows: The Dark Alliance between GuLoader and Remcos CloudEyE Remcos |
| 2023-09-08
⋅
K7 Security
⋅
RomCom RAT: Not Your Typical Love Story ROMCOM RAT RomCom |
| 2023-08-31
⋅
Rapid7 Labs
⋅
Fake Update Utilizes New IDAT Loader To Execute StealC and Lumma Infostealers FAKEUPDATES Amadey HijackLoader Lumma Stealer SectopRAT |
| 2023-08-26
⋅
rmceoin.github.io
⋅
ClearFake Malware Analysis ClearFake |
| 2023-07-18
⋅
Medium walmartglobaltech
⋅
NemesisProject Nemesis |
| 2023-07-10
⋅
Mandiant
⋅
Defend Against the Latest Active Directory Certificate Services Threats |
| 2023-07-08
⋅
Blackberry
⋅
RomCom Threat Actor Suspected of Targeting Ukraine's NATO Membership Talks at the NATO Summit ROMCOM RAT |
| 2023-06-28
⋅
Mandiant
⋅
Detection, Containment, and Hardening Opportunities for Privileged Guest Operations, Anomalous Behavior, and VMCI Backdoors on Compromised VMware Hosts UNC3886 |