Click here to download all references as Bib-File.•
2020-10-29
⋅
FBI
⋅
Alert Number ME-000138-TT: Indicators of Compromise Pertaining to Iranian Interference in the 2020 US Presidential Election |
2020-10-29
⋅
Cofense
⋅
Online Leader Invites You to This Webex Phish |
2020-10-29
⋅
Twitter (@SophosLabs)
⋅
Tweet on similarities between BUER in-memory loader & RYUK in-memory loader Buer Ryuk |
2020-10-29
⋅
Red Canary
⋅
A Bazar start: How one hospital thwarted a Ryuk ransomware outbreak Cobalt Strike Ryuk TrickBot |
2020-10-29
⋅
Palo Alto Networks Unit 42
⋅
Threat Assessment: Ryuk Ransomware and Trickbot Targeting U.S. Healthcare and Public Health Sector Anchor BazarBackdoor Ryuk TrickBot |
2020-10-29
⋅
McAfee
⋅
McAfee Labs Threat Advisory Ransom-Ryuk Ryuk |
2020-10-29
⋅
Palo Alto Networks Unit 42
⋅
Domain Parking: A Gateway to Attackers Spreading Emotet and Impersonating McAfee Emotet |
2020-10-29
⋅
US-CERT
⋅
Malware Analysis Report (AR20-303A): PowerShell Script: ComRAT Agent.BTZ |
2020-10-29
⋅
Github (Swisscom)
⋅
List of CobaltStrike C2's used by RYUK Cobalt Strike |
2020-10-29
⋅
CNN
⋅
Several hospitals targeted in new wave of ransomware attacks Ryuk |
2020-10-29
⋅
Bleeping Computer
⋅
Hacking group is targeting US hospitals with Ryuk ransomware Ryuk |
2020-10-29
⋅
Reuters
⋅
Building wave of ransomware attacks strike U.S. hospitals Ryuk |
2020-10-29
⋅
Bleeping Computer
⋅
Maze ransomware is shutting down its cybercrime operation Egregor Maze |
2020-10-29
⋅
Bleeping Computer
⋅
REvil ransomware gang claims over $100 million profit in a year REvil |
2020-10-29
⋅
Security Boulevard
⋅
Egregor: Sekhmet’s Cousin Egregor |
2020-10-28
⋅
Twitter (@BitsOfBinary)
⋅
Tweet on macOS version of Manuscrypt Manuscrypt |
2020-10-28
⋅
Tweet about RegretLocker from MHT RegretLocker |
2020-10-28
⋅
Youtube (SANS Institute)
⋅
Spooky RYUKy: The Return of UNC1878 | SANS STAR Webcast Ryuk UNC1878 |
2020-10-28
⋅
Github (aaronst)
⋅
UNC1878 indicators Ryuk UNC1878 |
2020-10-28
⋅
Risky.biz
⋅
The many personalities of Lazarus |