Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2021-09-01 ⋅ Medium s2wlab ⋅ Chaewon Moon, Denise Dasom Kim, Jungyeon Lim, S2W LAB INTELLIGENCE TEAM, Sujin Lim, Yeonghyeon Jeong
BlackMatter x Babuk : Using the same web server for sharing leaked files
Babuk BlackMatter Babuk BlackMatter
2021-09-01 ⋅ FireEye ⋅ Adrien Bataille, Blaine Stancill
Too Log; Didn't Read — Unknown Actor Using CLFS Log Files for Stealth
PRIVATELOG STASHLOG
2021-09-01 ⋅ InfoSec Handlers Diary Blog ⋅ Brad Duncan
STRRAT: a Java-based RAT that doesn't care if you have Java
STRRAT
2021-09-01 ⋅ SentinelOne ⋅ SentinelOne
WatchTower | August 2021 TLP: WHITE | Intelligence-Driven Threat Hunting
2021-09-01 ⋅ Prevailion ⋅ Prevailion
Diving Deep into UNC1151’s Infrastructure: Ghostwriter and beyond
2021-08-31 ⋅ ebryx ⋅ Ahmad Muneeb Khan, Syed Hasan Akhtar
Exposing Sidewinder’s Arsenal against Windows
2021-08-31 ⋅ BreakPoint Labs ⋅ BreakPoint Labs
Cobalt Strike and Ransomware – Tracking An Effective Ransomware Campaign
Cobalt Strike
2021-08-31 ⋅ ⋅ Seguranca Informatica ⋅ Pedro Tavares
Phishing+Telegram: Solicitação de reembolso da Autoridade Tributária?
2021-08-31 ⋅ Minerva Labs ⋅ Minerva Labs
BlackMatter - The New Star Of Ransomware
BlackMatter
2021-08-31 ⋅ ⋅ Qianxin ⋅ Red Raindrop Team
Analysis of suspected Russian-speaking attackers using COVID-19 vaccine bait to attack the Middle East
GRUNT
2021-08-31 ⋅ Yoroi ⋅ Luca Mella, Luigi Martire, Yoroi
Financial Institutions in the Sight of New JsOutProx Attack Waves
JSOutProx
2021-08-31 ⋅ Cisco Talos ⋅ Edmund Brumaghin, Vitor Ventura
Attracting flies with Honey(gain): Adversarial abuse of proxyware
2021-08-31 ⋅ CrowdStrike ⋅ Alexander Hanel
Sidoh: WIZARD SPIDER’s Mysterious Exfiltration Tool
Ryuk Stealer
2021-08-30 ⋅ Twitter (@Arkbird_SOLG) ⋅ Arkbird
Tweet on MercurialGrabber
MercurialGrabber
2021-08-30 ⋅ ⋅ Qianxin ⋅ Red Raindrop Team
Operation (Thủy Tinh) OceanStorm: The evil lotus hidden under the abyss
Cobalt Strike MimiKatz
2021-08-30 ⋅ CrowdStrike ⋅ Eric Loui, Josh Reynolds
CARBON SPIDER Embraces Big Game Hunting, Part 1
Bateleur Griffon Carbanak DarkSide JSSLoader PILLOWMINT REvil
2021-08-30 ⋅ CrowdStrike ⋅ Michael Dawson
Hypervisor Jackpotting, Part 2: eCrime Actors Increase Targeting of ESXi Servers with Ransomware
Babuk HelloKitty REvil
2021-08-30 ⋅ Palo Alto Networks Unit 42 ⋅ Brock Mammen, Haozhe Zhang
New Mirai Variant Targets WebSVN Command Injection Vulnerability (CVE-2021-32305)
Mirai
2021-08-30 ⋅ CSO Online ⋅ Lucian Constantin
LockFile ransomware uses intermittent encryption to evade detection
LockFile
2021-08-30 ⋅ zero day initiative ⋅ Simon Zuckerbraun
ProxyToken: An Authentication Bypass in Microsoft Exchange Server