Click here to download all references as Bib-File.

Enter keywords to filter the library entries below or Propose new Entry
2021-01-25Trend MicroFyodor Yarochkin, Loseway Lu, Marshall Chen, Matsukawa Bakuei, Vladimir Kropotov
Fake Office 365 Used for Phishing Attacks on C-Suite Targets
2021-01-25CYBER GEEKS All Things InfosecCyberMasterV
A detailed analysis of ELMER Backdoor used by APT16
ELMER
2021-01-25ZenGoTal Be'ery
Ungilded Secrets: A New Paradigm for Key Security
SUNBURST
2021-01-25SOC PrimeEmanuele De Lucia
Affiliates vs Hunters: Fighting the DarkSide
DarkSide
2021-01-25Medium CSIS TechblogBenoît Ancel
The Nemty affiliate model
Nemty
2021-01-25Twitter (@IntelAdvanced)Advanced Intelligence
Tweet on Ryuk Ransomware group's post exploitation tactics including usage of Keethief tool
Ryuk
2021-01-25NetresecErik Hjelmvik
Twenty-three SUNBURST Targets Identified
SUNBURST
2021-01-24malwareandstuff blogAndreas Klopsch
Catching Debuggers with Section Hashing
2021-01-24evotecPrzemyslaw Klys
The only command you will ever need to understand and fix your Group Policies (GPO)
2021-01-24Darren’s WebsiteDarren Martyn
VisualDoor: SonicWall SSL-VPN Exploit
2021-01-24Medium vrieshdVriesHD
Finding SUNBURST victims and targets by using passive DNS, OSINT
SUNBURST
2021-01-24Medium nasbenchNasreddine Bencherchali
Common Tools & Techniques Used By Threat Actors and Malware — Part I
2021-01-24Bleeping ComputerLawrence Abrams
Another ransomware (Avaddon) now uses DDoS attacks to force victims to pay
Avaddon
2021-01-23Youtube (MalwareAnalysisForHedgehogs)Karsten Hahn
Malware Analysis - Fileless GooLoad static analysis and unpacking
2021-01-23vxhive blog0xastrovax
Deep Dive Into SectopRat
SectopRAT
2021-01-23Johannes Bader's BlogJohannes Bader
Yet Another Bazar Loader DGA
BazarBackdoor
2021-01-23NCC GroupNCC RIFT
RIFT: Analysing a Lazarus Shellcode Execution Method
2021-01-22Quick HealDigvijay Mane
Stay Alert, Joker still making its way on Google Play Store!
Joker
2021-01-22360 netlabJinye
Necro is going to version 3 and using PyInstaller and DGA
N3Cr0m0rPh
2021-01-22Twitter (@bryceabdo)Bryce
Tweet on GRIMAGENT malware used by UNC1878 during some #RYUK intrusions in 2020
GRIMAGENT