Click here to download all references as Bib-File.•
| 2020-11-06
⋅
⋅
LAC WATCH
⋅
分析レポート:Emotetの裏で動くバンキングマルウェア「Zloader」に注意 Emotet Zloader |
| 2020-11-06
⋅
Advanced Intelligence
⋅
Anatomy of Attack: Inside BazarBackdoor to Ryuk Ransomware "one" Group via Cobalt Strike BazarBackdoor Cobalt Strike Ryuk |
| 2020-11-05
⋅
Morphisec
⋅
Agent Tesla: A Day in a Life of IR Agent Tesla |
| 2020-10-30
⋅
⋅
360
⋅
蓝色魔眼(APT-C-41)组织首次针对我国重要机构定向攻击活动披露 StrongPity |
| 2020-10-30
⋅
⋅
Qianxin
⋅
攻击武器再升级:Donot组织利用伪造签名样本的攻击活动分析 |
| 2020-10-30
⋅
Cofense
⋅
The Ryuk Threat: Why BazarBackdoor Matters Most BazarBackdoor Ryuk |
| 2020-10-29
⋅
Mandiant
⋅
FIN11: A Widespread Ransomware and Extortion Operation (Webinar) FIN11 |
| 2020-10-26
⋅
⋅
Qianxin
⋅
Analysis of the attack activities of the Rattlesnake organization using the Buffy bilateral agreement as bait SideWinder |
| 2020-10-23
⋅
F-Secure Labs
⋅
Catching Lazarus: Threat Intelligence to Real Detection Logic - Part Two MimiKatz |
| 2020-10-23
⋅
⋅
360
⋅
APT28携小众压缩包诱饵对北约、中亚目标的定向攻击分析 Zebrocy |
| 2020-10-20
⋅
National Security Agency
⋅
Chinese State-Sponsored Actors Exploit Publicly Known Vulnerabilities |
| 2020-10-14
⋅
FBI
⋅
FBI FLASH MU-000136-MW: Cyber ActorsTarget Misconfigured SonarQube Instances to Access Proprietary Source Code of US Government Agencies and Businesses |
| 2020-10-14
⋅
FireEye
⋅
FIN11: Widespread Email Campaigns as Precursor for Ransomware and Data Theft FIN11 |
| 2020-10-14
⋅
Malwarebytes
⋅
Silent Librarian APT right on schedule for 20/21 academic year |
| 2020-10-12
⋅
Malwarebytes Labs
⋅
Winnti APT group docks in Sri Lanka for new campaign DBoxAgent SerialVlogger Winnti |
| 2020-10-12
⋅
Advanced Intelligence
⋅
"Front Door" into BazarBackdoor: Stealthy Cybercrime Weapon BazarBackdoor Cobalt Strike Ryuk |
| 2020-10-12
⋅
Microsoft
⋅
Trickbot disrupted TrickBot |
| 2020-10-08
⋅
ZDNet
⋅
Waterbear malware used in attack wave against government agencies Waterbear |
| 2020-10-08
⋅
Malwarebytes
⋅
Credit card skimmer targets virtual conference platform |
| 2020-10-06
⋅
Twitter (@MsftSecIntel)
⋅
Tweet on TA505 threat actor exploiting Zerologon (CVE-2020-1472) Vulnerability |