Click here to download all references as Bib-File.•
| 2026-07-22
⋅
Huntress Labs
⋅
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT SectopRAT |
| 2026-07-22
⋅
bluecyber
⋅
Beyond the Archive: CVE-2025-8088 Stealer Targeting Ukraine GIFTEDCROOK |
| 2026-07-21
⋅
@oj-sec
⋅
TChCh-Changes: A Look at macOS TCC Manipulation in the Wild |
| 2026-07-21
⋅
kienmanowar Blog
⋅
[QuickNote] Mustang Panda ToneShell (APT S1239) Beacon Shellcode – RE Analysis TONESHELL |
| 2026-07-21
⋅
DTEX
⋅
From Payroll to Pyongyang: The DPRK IT Worker Money Trail |
| 2026-07-21
⋅
ANY.RUN
⋅
SnappyClient Analysis SnappyClient |
| 2026-07-20
⋅
Medium Ireneusz Tarnowski
⋅
INC Ransom: Infrastructure Analysis, Operational Tradecraft, and Detection Opportunities INC INC |
| 2026-07-18
⋅
Github (muhammadzidane632)
⋅
Hopeless Hopeless |
| 2026-07-17
⋅
Volexity
⋅
Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation Behinder UTA0533 |
| 2026-07-17
⋅
OpenSourceMalware
⋅
ChainVeil and ViteVenom are DPRK’s PolinRider Campaign JADESNOW |
| 2026-07-17
⋅
Elastic
⋅
New North Korean campaign uses fake coding interviews to steal developer credentials OtterCookie |
| 2026-07-16
⋅
Cisco Talos
⋅
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign CASTLESTEALER Remcos UAT-11795 |
| 2026-07-16
⋅
Hacking But Legal
⋅
North Korea Is Hiring StoatWaffle |
| 2026-07-16
⋅
Microsoft Security
⋅
ACR Stealer: Two observed intrusion chains amid increased threat activity ACR Stealer |
| 2026-07-16
⋅
Elastic
⋅
TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains TELEPUZ |
| 2026-07-15
⋅
Github (Yavuzhanzgen)
⋅
StealC V2 Malware Technical Analysis Stealc |
| 2026-07-15
⋅
Lx(Base) RAT: A Technical Deep Dive LxBase RAT |
| 2026-07-15
⋅
Zscaler
⋅
ClaudeFix: Shared Claude Chats Meet ClickFix MacSync |
| 2026-07-15
⋅
OpenSourceMalware
⋅
PolinRider Confirmed Footprint Grows 6.5x Since March JADESNOW |
| 2026-07-15
⋅
Expel
⋅
Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident Ghost RAT |