Click here to download all references as Bib-File.

Enter keywords to filter the library entries below or Propose new Entry
2023-04-28Twitter (@MichalKoczwara)Michael Koczwara
Tweet on hunting BRC4 infrastructure
Brute Ratel C4
2023-04-28Twitter (@MalGamy12)Gameel Ali
Tweet explaning similarity between Conti and Akira code
Akira
2023-04-18Twitter (@1ZRR4H)Germán Fernández
Tweet on CrossLock
CrossLock
2023-04-18Twitter (@threatinsight)Threat Insight
Tweet on TA581 using Keitaro TDS URL to download a .MSI file to deliver BumbleBee malware
BumbleBee
2023-04-16Twitter (@malwrhunterteam)MalwareHunterTeam
Tweet on MacOS Lockbit sample
LockBit
2023-04-11Twitter (@Unit42_Intel)Unit42
Tweet on change of IcedID backconnect traffic port from 8080 to 443
IcedID
2023-04-10Twitter (@embee_research)Matthew
Redline Stealer - Static Analysis and C2 Extraction
Amadey RedLine Stealer
2023-04-08Twitter (@embee_research)Embee_research
Dcrat - Manual De-obfuscation of .NET Malware
DCRat
2023-04-03Twitter (@kucher1n)Georgy Kucherin
Tweet on an alternative Guporam sample
Gopuram
2023-03-21Twitter (@splinter_code)Antonio Cocomazzi
Tweet on BlackByte ransomware rewrite in C++
BlackByte
2023-03-18Twitter (@k3dg3)Kelsey Merriman
Tweet on TA579 distributing AresLoader via WeTransfer URLs
AresLoader
2023-02-24Twitter (@Sebdraven)Sébastien Larinier
Tweet on IOCTL manipulation in TDL4 and HermeticWiper
Alureon HermeticWiper
2023-02-17Twitter (@luc4m)Luca Mella
Tweets about Darkbit's intermittent encryption
DarkBit
2023-01-18Twitter (@Gi7w0rm)Gi7w0rm
A long way to SectopRat
SectopRAT
2023-01-16Twitter (@zachxbt)ZachXBT
Tweet on ETH movement of Lazarus
2023-01-13Twitter (@Ishusoka)Ishu
Tweets on updates regarding Lumma Stealer
Lumma Stealer
2023-01-09Twitter (@SethKingHi)SKII
Tweet on HuskLoader
HuskLoader
2022-12-20Twitter (@Gi7w0rm)Gi7w0rm
Twitter posts discussing recent sighting of Laplas
LaplasClipper
2022-12-19Twitter (@jaydinbas)Johann Aydinbas
Twitter thread describing ISO drop for Kami
Kami
2022-12-06Twitter (@URSNIFleak)URSNIFleak
Twitter account with leaked data about the group behind URSNIF
RM3