Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2025-04-25 ⋅ Twitter (@teamcymru_S2) ⋅ TEAM CYMRU S2 THREAT RESEARCH
Tweet on North Korean Cyber Ops Leveraging Russian Infrastructure
2025-04-24 ⋅ Kaspersky ⋅ Sojun Ryu, Vasily Berdnikov
Operation SyncHole: Lazarus APT goes back to the well
Bankshot DRATzarus PostNapTea wAgentTea
2025-04-24 ⋅ 0xreverse ⋅ Utku Çorbacı
Understanding Alcatraz ~ Obfuscator Analysis [EN]
2025-04-24 ⋅ Silent Push ⋅ Silent Push
Contagious Interview (DPRK) Launches a New Campaign Creating Three Front Companies to Deliver a Trio of Malware: BeaverTail, InvisibleFerret, and OtterCookie
BeaverTail OtterCookie FrostyFerret GolangGhost InvisibleFerret GolangGhost
2025-04-23 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
Understanding the threat landscape for Kubernetes and containerized assets
Storm-1977
2025-04-23 ⋅ Trend Micro ⋅ Feike Hacquebord, Stephen Hilt
Russian Infrastructure Plays Crucial Role in North Korean Cybercrime Operations
BeaverTail FrostyFerret GolangGhost InvisibleFerret GolangGhost WageMole
2025-04-23 ⋅ Medium b.magnezi ⋅ 0xMrMagnezi
AsyncRAT Malware Analysis
AsyncRAT
2025-04-22 ⋅ SentinelOne ⋅ SentinelOne
What Is Fog Ransomware?
Fog
2025-04-22 ⋅ Kaspersky Labs ⋅ Alexander Demidov, Georgy Kucherin, Igor Kuznetsov
Russian organizations targeted by backdoor masquerading as secure networking software updates
2025-04-22 ⋅ Volexity ⋅ Charlie Gardner, Josh Duke, Matthew Meltzer, Sean Koessel, Steven Adair, Tom Lancaster
Phishing for Codes: Russian Threat Actors Target Microsoft 365 OAuth Workflows
UTA0352 UTA0355
2025-04-21 ⋅ Trellix ⋅ Mohideen Abdul Khader
Unmasking the Evolving Threat: A Deep Dive into the Latest Version of Lumma InfoStealer with Code Flow Obfuscation
Lumma Stealer
2025-04-17 ⋅ Trail of Bits ⋅ Trail of Bits
Mitigating ELUSIVE COMET Zoom remote control attacks
ELUSIVE COMET
2025-04-17 ⋅ Porthas ⋅ Hassan Faraz, Mohamed Talaat
Breaking the B0 ransomware: Investigation & Decryption
B0
2025-04-17 ⋅ Proofpoint ⋅ Greg Lesnewich, Josh Miller, Mark Kelly, Saher Naumaan
Around the World in 90 Days: State-Sponsored Actors Try ClickFix
Quasar RAT UNK_RemoteRogue
2025-04-17 ⋅ Kaspersky Labs ⋅ GReAT
IronHusky updates the forgotten MysterySnail RAT to target Russia and Mongolia
MysterySnail
2025-04-17 ⋅ FORTRA ⋅ Max Ickert
Threat Actor Profile: SheByte Phishing-as-a-Service
2025-04-16 ⋅ Trendmicro ⋅ Cj Arsley Mateo, Ieriz Nicolle Gonzalez, Jacob Santos, Maristel Policarpio, Sarah Pearl Camiling
CrazyHunter Campaign Targets Taiwanese Critical Sectors
CrazyHunter
2025-04-16 ⋅ IBM X-Force ⋅ IBM Security X-Force Team
IBM X-Force 2025 Threat Intelligence Index
2025-04-16 ⋅ SpyCloud ⋅ Aurora Johnson, Keegan Keplinger
Exposed Credentials & Ransomware Operations: Using LLMs to Digest 200K Messages from the Black Basta Chats
Black Basta Black Basta
2025-04-15 ⋅ ⋅ Orange Cyberdefense ⋅ André Henschel, Friedl Holzner
CyberSOC Insights: Analysis of a Black Basta Attack Campaign
Black Basta DarkGate Lumma Stealer