Click here to download all references as Bib-File.•
2020-11-04
⋅
Sophos
⋅
A new APT uses DLL side-loads to “KilllSomeOne” KilllSomeOne PlugX |
2020-11-04
⋅
⋅
ESTsecurity
⋅
북한 연계 해킹조직 탈륨, 미국 대선 예측 언론 문서로 위장한 APT 공격 수행 출처 BabyShark |
2020-11-03
⋅
Comodo
⋅
Versions of PsiXBot PsiX |
2020-11-03
⋅
BleepingComputer
⋅
New RegretLocker ransomware targets Windows virtual machines RegretLocker |
2020-11-03
⋅
InfoSec Handlers Diary Blog
⋅
Attackers Exploiting WebLogic Servers via CVE-2020-14882 to install Cobalt Strike Cobalt Strike |
2020-11-03
⋅
Objective-See
⋅
Adventures in Anti-Gravity: Deconstructing the Mac Variant of GravityRAT |
2020-11-03
⋅
Kaspersky Labs
⋅
APT trends report Q3 2020 WellMail EVILNUM Janicab Poet RAT AsyncRAT Ave Maria Cobalt Strike Crimson RAT CROSSWALK Dtrack LODEINFO MoriAgent Okrum PlugX POISONPLUG Rover ShadowPad SoreFang Winnti |
2020-11-03
⋅
⋅
Gcow-Sec
⋅
美人鱼(Infy)APT组织的归来——使用最新的Foudre后门进行攻击活动的分析 Infy |
2020-11-02
⋅
One Night in Norfolk
⋅
TinyPOS and ProLocker: An Odd Relationship AbaddonPOS PwndLocker |
2020-11-02
⋅
FireEye
⋅
Live off the Land? How About Bringing Your Own Island? An Overview of UNC1945 SLAPSTICK STEELCORGI |
2020-11-02
⋅
SUCURI
⋅
CSS-JS Steganography in Fake Flash Player Update Malware magecart NetSupportManager RAT |
2020-11-02
⋅
Cybereason
⋅
Back to the Future: Inside the Kimsuky KGH Spyware Suite BabyShark GoldDragon KGH_SPY Kimsuky |
2020-11-01
⋅
Toli Security
⋅
SSH-backdoor Botnet With ‘Research’ Infection Technique |
2020-11-01
⋅
AppRiver
⋅
Vjw0rm Is Back With New Tactics Vjw0rm |
2020-11-01
⋅
Vulnerability.ch Blog
⋅
Observed Malware Campaigns – October 2020 |
2020-10-31
⋅
splunk
⋅
Ryuk and Splunk Detections Ryuk |
2020-10-30
⋅
YouTube (Kaspersky Tech)
⋅
Around the world in 80 days 4.2bn packets Cobalt Strike Derusbi HyperBro Poison Ivy ShadowPad Winnti |
2020-10-30
⋅
⋅
360 Core Security
⋅
肚脑虫组织( APT-C-35)疑似针对巴基斯坦军事人员的最新攻击活动 KnSpy |
2020-10-30
⋅
Github (ThreatConnect-Inc)
⋅
UNC 1878 Indicators from Threatconnect BazarBackdoor Cobalt Strike Ryuk |
2020-10-30
⋅
US-CERT
⋅
Alert (AA20-304A): Iranian Advanced Persistent Threat Actor Identified Obtaining Voter Registration Data |