Click here to download all references as Bib-File.

Enter keywords to filter the library entries below or Propose new Entry
2021-05-17TalosBrad Garnett
Case Study: Incident Response is a relationship-driven business
Cobalt Strike
2021-05-13TalosAsheer Malhotra, Justin Thattil, Kendall McKay
Transparent Tribe APT expands its Windows malware arsenal
Crimson RAT Oblique RAT
2021-05-07Cisco TalosAndrew Windsor, Caitlin Huey, Edmund Brumaghin
Lemon Duck spreads its wings: Actors target Microsoft Exchange servers, incorporate new TTPs
CHINACHOPPER Cobalt Strike Lemon Duck
2021-04-21TalosVanja Svajcer
A year of Fajan evolution and Bloomberg themed campaigns
MASS Logger Nanocore RAT NetWire RC Revenge RAT XpertRAT
2021-04-07TalosChris Neal, Edmund Brumaghin, Nick Biasini, Paul Eubanks.
Sowing Discord: Reaping the benefits of collaboration app abuse
2021-03-09Cisco TalosCisco Talos
Hafnium Update: Continued Microsoft Exchange Server Exploitation
2021-03-02Cisco TalosAsheer Malhotra
ObliqueRAT returns with new campaign using hijacked websites
Oblique RAT
2021-02-23TalosVitor Ventura, Warren Mercer
Gamaredon - When nation states don’t pay all the bills
2021-02-17Cisco TalosVanja Svajcer
Masslogger campaigns exfiltrates user credentials
MASS Logger
2021-02-09TalosChris Neal, Vitor Ventura, Warren Mercer
Kasablanka Group's LodaRAT improves espionage capabilities on Android and Windows
Loda
2021-01-06TalosHolger Unterbrink, Irshad Muhammad
A Deep Dive into Lokibot Infection Chain
Loki Password Stealer (PWS)
2021-01-04Cisco TalosAzim Khodjibaev, Dmytro Korzhevin, Kendall McKay
Interview with a LockBit ransomware operator
LockBit
2021-01-01TalosTalos Incident Response
Evicting Maze
Cobalt Strike Maze
2021-01-01TalosTalos Incident Response
Cobalt Strikes Out
Cobalt Strike
2020-12-21Cisco TalosJON MUNSHAW
2020: The year in malware
WolfRAT Prometei Poet RAT Agent Tesla Astaroth Ave Maria CRAT Emotet Gozi IndigoDrop JhoneRAT Nanocore RAT NjRAT Oblique RAT SmokeLoader StrongPity WastedLocker Zloader
2020-12-14Cisco TalosNick Biasini
Threat Advisory: SolarWinds supply chain attack
SUNBURST TEARDROP
2020-12-01TalosAdam Pridgen, Vanja Svajcer
Xanthe - Docker aware miner
Xanthe
2020-11-17Cisco TalosNikhil Hegde
Nibiru ransomware variant decryptor
Nibiru
2020-11-12TalosAsheer Malhotra
CRAT wants to plunder your endpoints
CRAT
2020-10-29Cisco TalosPaul Rascagnères, Vitor Ventura, Warren Mercer
DoNot’s Firestarter abuses Google Firebase Cloud Messaging to spread
KnSpy