Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2026-05-27 ⋅ Wiz.io ⋅ Andre Maccarone, Benjamin Read, Eden Abergil, Shira Ayal, Yuval Dan
Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure
JINX-0164
2026-05-22 ⋅ Fox-IT ⋅ Mick Koomen, Yun Zheng Hu
RemotePE: The Lazarus RAT that lives in memory
DPAPILoader RemotePE
2026-05-22 ⋅ Check Point ⋅ Checkpoint Research
Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict
MiniFast
2026-05-21 ⋅ Symantec ⋅ Threat Hunter Team
GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses
win.beast MimiKatz Hyadina
2026-05-21 ⋅ Lumen ⋅ Danny Adamitis, Ryan English, Steve Rudd
Introducing Showboat: A new malware family taunts defenses and targets international telecom firms
Showboat
2026-05-21 ⋅ PWC ⋅ PwC Threat Intelligence
Inside Red Lamassu’s JFMBackdoor
JFMBackdoor Calypso
2026-05-20 ⋅ Seqrite Labs ⋅ Dixit Panchal, Kartik Jivani, Vaibhav Krushna Billade
Operation Dragon Whistle: UNG0002 Targets Chinese Academia via Weaponized Institutional Lure
Cobalt Strike
2026-05-20 ⋅ K7 Security ⋅ Srinivasan E
Fake Microsoft Teams download sites are being used to deliver ValleyRAT via DLL sideloading
ValleyRAT
2026-05-19 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
Exposing Fox Tempest: A malware-signing service operation (Podcast)
Akira Rhysida Akira BlackByte BlueSky Broomstick Lumma Stealer Rhysida Spyder Vidar Fox Tempest
2026-05-19 ⋅ Microsoft ⋅ Steven Masada
Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomware
Akira INC Qilin Rhysida AgendaCrypt Akira Broomstick INC Lumma Stealer Rhysida Vidar Fox Tempest
2026-05-19 ⋅ The Record ⋅ Jonathan Greig
Microsoft disrupts Fox Tempest malware-signing-as-a-service platform tied to ransomware gangs
Akira INC Qilin Rhysida AgendaCrypt Akira Broomstick INC Lumma Stealer Rhysida Vidar Fox Tempest
2026-05-19 ⋅ Github (microsoft) ⋅ Microsoft
MSTIC actor name mapping in JSON format
Amethyst Rain Houndstooth Typhoon Pinstripe Lightning Storm-0252 Wisteria Tsunami
2026-05-19 ⋅ Trend Micro ⋅ Aldrin Ceriola, Gabriel Nicoleta, Jovit Samaniego, Mohamed Fahmy
Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud
Banana RAT SHADOW-WATER-063
2026-05-18 ⋅ Zynap ⋅ Oscar Gallego
Zynap’s Next-Gen Sandbox Redefines Automatic Malware Analysis
Black Basta HijackLoader
2026-05-18 ⋅ Gen Threat Labs ⋅ Gen Threat Labs
X.com - Gen Threat Labs - AuraStealer (version 1.8.0)
Aura Stealer
2026-05-17 ⋅ Github (zanez) ⋅ Irvin Martínez González
Analysis on Malware that attacks Israel's Water treatment facilities
ZionSiphon
2026-05-16 ⋅ Symantec ⋅ Threat Hunter Team
Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations
fast16
2026-05-16 ⋅ Derp ⋅ Matt Kirkland
Vidar v1.5 in Go: same family, new language, heavy sandbox checks
Vidar
2026-05-14 ⋅ eSentire ⋅ eSentire Threat Response Unit (TRU)
Amatera Stealer 4.0.2 Beta: What's New in This Variant
Amatera
2026-05-14 ⋅ ANY.RUN ⋅ Moises Cerqueira
LATAM Under Siege: Agent Tesla’s 18-Month Credential Theft Campaign Against Chilean Enterprises
Agent Tesla