Click here to download all references as Bib-File.•
2021-11-16
⋅
Blackberry
⋅
Finding Beacons in the dark Cobalt Strike |
2021-11-13
⋅
Trend Micro
⋅
QAKBOT Loader Returns With New Techniques and Tools QakBot |
2021-11-12
⋅
Trend Micro
⋅
The Prelude to Ransomware: A Look into Current QAKBOT Capabilities and Global Activities QakBot |
2021-11-10
⋅
Group-IB
⋅
REDCURL: The awakening RedCurl |
2021-11-10
⋅
Cisco Talos
⋅
North Korean attackers use malicious blogs to deliver malware to high-profile South Korean targets GoldDragon |
2021-10-27
⋅
Mandiant
⋅
Portable Executable File Infecting Malware Is Increasingly Found in OT Networks CCleaner Backdoor Floxif neshta Ramnit Sality Virut |
2021-10-22
⋅
Darkowl
⋅
“Page Not Found”: REvil Darknet Services Offline After Attack Last Weekend REvil REvil |
2021-10-21
⋅
Microsoft
⋅
Franken-phish: TodayZoo built from other phishing kits |
2021-10-07
⋅
Mandiant
⋅
FIN12: The Prolific Ransomware Intrusion Threat Actor That Has Aggressively Pursued Healthcare Targets BazarBackdoor GRIMAGENT Ryuk |
2021-09-13
⋅
Intezer
⋅
Vermilion Strike: Linux and Windows Re-implementation of Cobalt Strike Vermilion Strike Vermilion Strike |
2021-09-03
⋅
Sophos
⋅
Conti affiliates use ProxyShell Exchange exploit in ransomware attacks Cobalt Strike Conti |
2021-08-30
⋅
zero day initiative
⋅
ProxyToken: An Authentication Bypass in Microsoft Exchange Server |
2021-08-05
⋅
Twitter (@AltShiftPrtScn)
⋅
Tweet on Conti ransomware affiliates using AnyDesk, Atera, Splashtop, Remote Utilities and ScreenConnect to maintain network access Conti |
2021-08-05
⋅
Twitter (@AltShiftPrtScn)
⋅
Tweet on Lorenz ransomware tricking user into allowing OAuth permissions to "Thunderbird with ExQuilla" for O365 Lorenz |
2021-07-21
⋅
Twitter (@AltShiftPrtScn)
⋅
Tweet on Conti ransomware actor installing AnyDesk for remote access in victim environment Conti |
2021-07-19
⋅
Council of the European Union
⋅
China: Declaration by the High Representative on behalf of the European Union urging Chinese authorities to take action against malicious cyber activities undertaken from its territory APT40 |
2021-07-19
⋅
Council of the European Union
⋅
China: Declaration by the High Representative on behalf of the European Union urging Chinese authorities to take action against malicious cyber activities undertaken from its territory APT31 |
2021-07-13
⋅
Threat Post
⋅
Guess Fashion Brand Deals With Data Loss After Ransomware Attack DarkSide |
2021-07-07
⋅
Trend Micro
⋅
BIOPASS RAT: New Malware Sniffs Victims via Live Streaming BIOPASS Cobalt Strike Derusbi |
2021-06-12
⋅
Twitter (@AltShiftPrtScn)
⋅
A thread on RagnarLocker ransomware group's TTP seen in an Incident Response Cobalt Strike RagnarLocker |