Click here to download all references as Bib-File.•
| 2020-06-17
⋅
Twitter (@MsftSecIntel)
⋅
A tweet thread on TA505 using CAPTCHA to avoid detection and infecting victims with FlawedGrace FlawedGrace |
| 2020-06-17
⋅
Github (f0wl)
⋅
deICEr: A Go tool for extracting config from IcedID second stage Loaders IcedID |
| 2020-06-16
⋅
Microsoft
⋅
Exploiting a crisis: How cybercriminals behaved during the outbreak |
| 2020-06-16
⋅
IBM
⋅
Cloud ThreatLandscape Report 2020 QNAPCrypt RokRAT |
| 2020-06-16
⋅
PTSecurity
⋅
Cobalt: tactics and tools update CobInt |
| 2020-06-11
⋅
Talos Intelligence
⋅
Tor2Mine is up to their old tricks — and adds a few new ones Azorult Remcos |
| 2020-06-09
⋅
Malwarebytes
⋅
Honda and Enel impacted by cyber attack suspected to be ransomware Snake |
| 2020-06-04
⋅
PTSecurity
⋅
COVID-19 and New Year greetings: an investigation into the tools and methods used by the Higaisa group Ghost RAT SongXY |
| 2020-05-28
⋅
⋅
Qianxin
⋅
Analysis of recent rattlesnake APT attacks against surrounding countries and regions SideWinder |
| 2020-05-28
⋅
National Security Agency
⋅
Sandworm Actors Exploiting Vulnerability in EXIM Mail Transfer Agent |
| 2020-05-28
⋅
CyberScoop
⋅
German intelligence agencies warn of Russian hacking threats to critical infrastructure |
| 2020-05-26
⋅
CISA
⋅
Alert (AA21-116A): Russian Foreign Intelligence Service (SVR) Cyber Operations: Trends and Best Practices for Network Defenders elf.wellmess WellMess |
| 2020-05-26
⋅
ESET Research
⋅
From Agent.BTZ to ComRAT v4: A ten‑year journey (White Paper) Agent.BTZ |
| 2020-05-26
⋅
ESET Research
⋅
From Agent.BTZ to ComRAT v4: A ten‑year journey Agent.BTZ |
| 2020-05-24
⋅
Positive Technologies
⋅
Operation TA505: network infrastructure. Part 3. AndroMut Buhtrap SmokeLoader |
| 2020-05-23
⋅
InfoSec Handlers Diary Blog
⋅
AgentTesla Delivered via a Malicious PowerPoint Add-In Agent Tesla |
| 2020-05-22
⋅
Positive Technologies
⋅
Operation TA505: investigating the ServHelper backdoor with NetSupport RAT. Part 2. NetSupportManager RAT ServHelper |
| 2020-05-20
⋅
PTSecurity
⋅
Operation TA505: how we analyzed new tools from the creators of the Dridex trojan, Locky ransomware, and Neutrino botnet FlawedAmmyy |
| 2020-05-19
⋅
Advanced Intelligence
⋅
NetWalker Ransomware Group Enters Advanced Targeting “Game” Mailto |
| 2020-05-19
⋅
Symantec
⋅
Sophisticated Espionage Group Turns Attention to Telecom Providers in South Asia ISMAgent ISMDoor |