Click here to download all references as Bib-File.•
| 2025-12-19
⋅
cyble
⋅
Stealth in Layers: Unmasking the Loader used in Targeted Email Campaigns DCRat Katz Stealer PhantomVAI PureLogs Stealer Remcos XWorm |
| 2025-12-18
⋅
HelpNetSecurity
⋅
Clipping Scripted Sparrow’s wings: Tracking a global phishing ring Scripted Sparrow |
| 2025-12-18
⋅
Acronis
⋅
Acronis TRU Alliance {Hunt.io}: Hunting DPRK threats - New Global Lazarus & Kimsuky campaigns BADCALL POOLRAT Quasar RAT |
| 2025-12-18
⋅
Gen Digital Inc
⋅
Gen Blogs | Defeating AuraStealer: Practical Deobfuscation Workflows for Modern Infostealers Aura Stealer |
| 2025-12-18
⋅
ESET Research
⋅
LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan NosyDownloader |
| 2025-12-18
⋅
BlackPoint
⋅
New MintsLoader Variant Using Hashtable Obfuscation MintsLoader |
| 2025-12-17
⋅
Reporters Without Borders
⋅
ResidentBat: A new spyware family used by Belarusian KGB ResidentBat |
| 2025-12-17
⋅
Recorded Future
⋅
PurpleBravo’s Targeting of the IT Software Supply Chain BeaverTail InvisibleFerret PylangGhost GolangGhost |
| 2025-12-17
⋅
Crystal Intelligence
⋅
How we proved North Korea’s blockchain malware campaign JADESNOW |
| 2025-12-17
⋅
XLab
⋅
Kimwolf Exposed: The Massive Android Botnet with 1.8 Million Infected Devices Kimwolf Aisuru |
| 2025-12-17
⋅
Recorded Future
⋅
BlueDelta’s Persistent Campaign Against UKR.NET |
| 2025-12-16
⋅
sysdig
⋅
EtherRAT dissected: How a React2Shell implant delivers 5 payloads through blockchain C2 EtherRAT |
| 2025-12-15
⋅
Rapid7
⋅
SantaStealer is Coming to Town: A New, Ambitious Infostealer Advertised on Underground Forums SantaStealer |
| 2025-12-15
⋅
Squiblydoo
⋅
SolarMarker: Actions-On-Target solarmarker |
| 2025-12-15
⋅
StrikeReady
⋅
Russian APT actor phishes the Baltics and the Balkans |
| 2025-12-15
⋅
Bleeping Computer
⋅
French Interior Ministry confirms cyberattack on email servers |
| 2025-12-12
⋅
Cyfirma
⋅
Weekly Intelligence Report – 12 December 2025 BreachLaboratory |
| 2025-12-12
⋅
Google
⋅
Multiple Threat Actors Exploit React2Shell (CVE-2025-55182) ANGRYREBEL MINOCAT SNOWLIGHT Earth Lamia |
| 2025-12-12
⋅
⋅
Tagesschau
⋅
German government summons Russian ambassador |
| 2025-12-11
⋅
Trend Micro
⋅
SHADOW-VOID-042 Targets Multiple Industries with Void Rabisu-like Tactics ROMCOM RAT SHADOW-VOID-042 |