Click here to download all references as Bib-File.•
| 2025-02-04
⋅
Trend Micro
⋅
CVE-2025-0411: Ukrainian Organizations Targeted in Zero-Day Campaign and Homoglyph Attacks SmokeLoader |
| 2025-02-03
⋅
SentinelOne
⋅
macOS FlexibleFerret | Further Variants of DPRK Malware Family Unearthed FlexibleFerret FriendlyFerret FrostyFerret |
| 2025-02-02
⋅
Team82
⋅
Do the CONTEC CMS8000 Patient Monitors Contain a Chinese Backdoor? The Reality is More Complicated… CMS8000 Backdoor |
| 2025-01-31
⋅
ConnectWise
⋅
Attackers Leveraging Microsoft Teams Defaults and Quick Assist for Social Engineering Attacks Black Basta Black Basta ReedBed |
| 2025-01-30
⋅
FortiGuard Labs
⋅
Coyote Banking Trojan: A Stealthy Attack via LNK Files |
| 2025-01-30
⋅
Bitdefender
⋅
UAC-0063: Cyber Espionage Operation Expanding from Central Asia HATVIBE |
| 2025-01-30
⋅
eSentire
⋅
Ongoing Email Bombing Campaigns leading to Remote Access and Post-Exploitation Black Basta ReedBed UNC4393 |
| 2025-01-30
⋅
Bleeping Computer
⋅
Backdoor found in two healthcare patient monitors, linked to IP in China |
| 2025-01-30
⋅
CISA
⋅
Contec CMS8000 Contains a Backdoor CMS8000 Backdoor |
| 2025-01-30
⋅
Department of Justice
⋅
Cybercrime websites selling hacking tools to transnational organized crime groups seized |
| 2025-01-29
⋅
Socket
⋅
North Korean APT Lazarus Targets Developers with Malicious npm Package BeaverTail InvisibleFerret |
| 2025-01-28
⋅
Hunt.io
⋅
SparkRAT: Server Detection, macOS Activity, and Malicious Connections SparkRAT |
| 2025-01-27
⋅
Cloudsek
⋅
Pivoting From PayTool: Tracking Various Frauds and E-Crime Targeting Canada PayTool |
| 2025-01-27
⋅
Youtube (MalwareAnalysisForHedgehogs)
⋅
Malware Analysis - Binary Refinery URL extraction of Multi-Layered PoshLoader for LummaStealer Lumma Stealer |
| 2025-01-25
⋅
Sophos
⋅
Sophos MDR tracks two ransomware campaigns using “email bombing,” Microsoft Teams “vishing” ReedBed STAC5143 UNC4393 |
| 2025-01-23
⋅
Github (PaloAltoNetworks)
⋅
Cluster of Infrastructure likely used by Affiliate of Dark Scorpius (Black Basta) ReedBed |
| 2025-01-23
⋅
Hunt.io
⋅
Mapping Suspected KEYPLUG Infrastructure: TLS Certificates, GhostWolf, and RedGolf/APT41 Activity KEYPLUG |
| 2025-01-23
⋅
AhnLab
⋅
RID Hijacking Technique Utilized by Andariel Attack Group CreateHiddenAccount JuicyPotato |
| 2025-01-23
⋅
Lumen
⋅
The J-Magic Show: Magic Packets and Where to find them J-Magic SEASPY |
| 2025-01-22
⋅
ESET Research
⋅
PlushDaemon compromises supply chain of Korean VPN service SlowStepper PlushDaemon |