Click here to download all references as Bib-File.•
| 2024-05-10
⋅
⋅
Qianxin Threat Intelligence Center
⋅
Recruitment trap for blockchain practitioners: Analysis of suspected Lazarus (APT-Q-1) stealing operations BeaverTail |
| 2024-04-22
⋅
Microsoft
⋅
Analyzing Forest Blizzard’s custom post-compromise tool for exploiting CVE-2022-38028 to obtain credentials GooseEgg |
| 2024-04-04
⋅
Twitter (@embee_research)
⋅
TLS Certificate For Threat Intelligence - Identifying MatanBuchus Domains Through Hardcoded Certificate Values Matanbuchus |
| 2024-03-06
⋅
Trend Micro
⋅
Unveiling Earth Kapre aka RedCurl's Cyberespionage Tactics With Trend Micro MDR, Threat Intelligence RedCurl Earth Kapre |
| 2024-02-07
⋅
Microsoft
⋅
Iran surges cyber-enabled influence operations in support of Hamas |
| 2024-02-06
⋅
Group-IB
⋅
Dead-end job: ResumeLooters gang infects websites with XSS scripts and SQL injections to vacuum up job seekers' personal data and CVs ResumeLooters |
| 2024-01-25
⋅
JSAC 2024
⋅
Threat Intelligence of Abused Public Post-Exploitation Frameworks AsyncRAT DCRat Empire Downloader GRUNT Havoc Koadic Merlin PoshC2 Quasar RAT Sliver |
| 2024-01-25
⋅
Microsoft
⋅
Midnight Blizzard: Guidance for responders on nation-state attack UNC2452 |
| 2024-01-17
⋅
Microsoft
⋅
New TTPs observed in Mint Sandstorm campaign targeting high-profile individuals at universities and research orgs MediaPI APT35 |
| 2023-12-12
⋅
Microsoft
⋅
Threat actors misuse OAuth applications to automate financially driven attacks Storm-1283 Storm-1286 |
| 2023-12-07
⋅
Microsoft
⋅
Star Blizzard increases sophistication and evasion in ongoing attacks Callisto |
| 2023-12-05
⋅
PWC
⋅
The Tortoise and The Malwahare SnappyTCP |
| 2023-12-01
⋅
Twitter (@MsftSecIntel)
⋅
Tweet about Storm-1044 and Storm-0216, Danabot leading to Cactus ransomware Cactus DanaBot TA2101 |
| 2023-12-01
⋅
Twitter (@MsftSecIntel)
⋅
Tweet on Danabot leading to cactus ransomware Cactus DanaBot Storm-1044 |
| 2023-11-22
⋅
Microsoft
⋅
Diamond Sleet supply chain compromise distributes a modified CyberLink installer LambLoad |
| 2023-11-09
⋅
Microsoft
⋅
Microsoft shares threat intelligence at CYBERWARCON 2023 Blue Tsunami |
| 2023-10-31
⋅
Infoblox
⋅
Prolific Puma: Shadowy Link Shortening Service Enables Cybercrime Prolific Puma |
| 2023-10-30
⋅
Checkpoint
⋅
30TH OCTOBER – THREAT INTELLIGENCE REPORT SingularityMD |
| 2023-10-25
⋅
Microsoft
⋅
Octo Tempest crosses boundaries to facilitate extortion, encryption, and destruction BlackCat BlackCat Lumma Stealer |
| 2023-10-18
⋅
Microsoft
⋅
Multiple North Korean threat actors exploiting the TeamCity CVE-2023-42793 vulnerability FeedLoad ForestTiger HazyLoad RollSling Silent Chollima |