Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2025-02-18 ⋅ Proofpoint ⋅ Proofpoint Threat Research Team
An Update on Fake Updates: Two New Actors, and New Mac Malware
Marcher FAKEUPDATES FrigidStealer Lumma Stealer
2025-02-15 ⋅ Medium TRAC Labs ⋅ TRAC Labs
Don’t Ghost the SocGholish: GhostWeaver Backdoor
FAKEUPDATES GhostWeaver
2025-02-13 ⋅ Securonix ⋅ Den Iyzvyk, Tim Peck
Analyzing DEEP#DRIVE: North Korean Threat Actors Observed Exploiting Trusted Platforms for Targeted Attacks
RandomQuery
2025-02-13 ⋅ Symantec ⋅ Threat Hunter Team
China-linked Espionage Tools Used in Ransomware Attacks
PlugX
2025-02-13 ⋅ Volexity ⋅ Charlie Gardner, Steven Adair, Tom Lancaster
Multiple Russian Threat Actors Targeting Microsoft Device Code Authentication
2025-02-12 ⋅ Hunt.io ⋅ Hunt.io
Tracking Pyramid C2: Identifying Post-Exploitation Servers in Hunt
Pyramid
2025-02-12 ⋅ ⋅ Donga ⋅ Shin Gyu-jin
Suspected North Korean hacker hacks a large number of data from a government document system developer
2025-02-12 ⋅ cyber.wtf blog ⋅ Hendrik Eckardt, Leonard Rapp
Unpacking Pyarmor v8+ scripts
AsyncRAT DCRat XWorm
2025-02-12 ⋅ Red Canary ⋅ Phil Hagen, Tony Lambert
Defying tunneling: A Wicked approach to detecting malicious network traffic
AsyncRAT DCRat NjRAT XWorm
2025-02-12 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
The BadPilot campaign: Seashell Blizzard subgroup conducts multiyear global access operation
LocalOlive
2025-02-12 ⋅ Bleeping Computer ⋅ Bill Toulas
Surge in attacks exploiting old ThinkPHP and ownCloud flaws
2025-02-12 ⋅ The Hacker News ⋅ Ravie Lakshmanan
North Korean Hackers Exploit PowerShell Trick to Hijack Devices in New Cyberattack
2025-02-11 ⋅ EclecticIQ ⋅ Arda Büyükkaya
Sandworm APT Targets Ukrainian Users with Trojanized Microsoft KMS Activation Tools in Cyber Espionage Campaigns
Kalambur BACKORDER DCRat
2025-02-11 ⋅ Twitter (@MsftSecIntel) ⋅ Microsoft Threat Intelligence
Twitter Thread on a new Kimsuky tactic inciting admins to paste powershell
2025-02-10 ⋅ Cyfirma ⋅ cyfirma
Tracking Ransomware: January 2025
TRIPLESTRENGTH
2025-02-06 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
Code injection attacks using publicly disclosed ASP.NET machine keys
2025-02-05 ⋅ Cloudflare ⋅ Cloudforce One, Jorge Pacheco, Omer Yoachimik
2025 Q4 DDoS threat report: A record-setting 31.4 Tbps attack caps a year of massive DDoS assaults
Kimwolf Aisuru
2025-02-05 ⋅ cyble ⋅ Cyble
Stealthy Attack: Dual Injection Undermines Chrome’s App-Bound Encryption
2025-02-04 ⋅ Team Cymru ⋅ S2 Research Team
Tracing the Path From SmartApeSG to NetSupport RAT
SmartApeSG NetSupportManager RAT Quasar RAT
2025-02-04 ⋅ Censys ⋅ Aidan Holland
Unpacking the BADBOX Botnet with Censys
BADBOX