Click here to download all references as Bib-File.•
2025-01-28
⋅
Group-IB
⋅
Cat’s out of the bag: Lynx Ransomware-as-a-Service Lynx |
2025-01-28
⋅
Hunt.io
⋅
SparkRAT: Server Detection, macOS Activity, and Malicious Connections SparkRAT |
2025-01-27
⋅
SecurityScorecard
⋅
Operation Phantom Circuit: North Korea’s Global Data Exfiltration Campaign |
2025-01-26
⋅
⋅
Youtube (greenplan)
⋅
[BINARY REFINERY] (Emmenhtal) - Deobfuscation stage JavaScript and PowerShell Emmenhtal |
2025-01-23
⋅
Github (PaloAltoNetworks)
⋅
Cluster of Infrastructure likely used by Affiliate of Dark Scorpius (Black Basta) ReedBed |
2025-01-23
⋅
Hunt.io
⋅
Mapping Suspected KEYPLUG Infrastructure: TLS Certificates, GhostWolf, and RedGolf/APT41 Activity KEYPLUG |
2025-01-23
⋅
AhnLab
⋅
RID Hijacking Technique Utilized by Andariel Attack Group CreateHiddenAccount JuicyPotato |
2025-01-23
⋅
ThreatMon
⋅
Helldown Ransomware Malware Analysis Report HellDown |
2025-01-22
⋅
Vertex
⋅
Categorizing Software with Code Families WarmCookie |
2025-01-21
⋅
KrCert
⋅
Analysis of Attack Strategies Targeting Centralized Management Solutions |
2025-01-21
⋅
Knownsec
⋅
Love and hate under war: The GamaCopy organization, which imitates the Russian Gamaredon, uses military — related bait to launch attacks on Russia GamaCopy |
2025-01-21
⋅
Twitter (@MsftSecIntel)
⋅
Twitter Thread describing spotting of ReedBed in a Storm-1811 campaign ReedBed UNC4393 |
2025-01-21
⋅
Seqrite
⋅
Silent Lynx APT Targets Various Entities Across Kyrgyzstan & Neighbouring Nations Unidentified PS 005 (Telegram Bot) |
2025-01-20
⋅
⋅
JPCERT/CC
⋅
APT actor classification “addiction” - Practical issues of attribution seen in Lazarus subgroup classification |
2025-01-20
⋅
Medium walmartglobaltech
⋅
Qbot is Back.Connect ReedBed UNC4393 |
2025-01-19
⋅
cocomelonc
⋅
Malware development trick 44: Stealing data via legit GitHub API. Simple C example. OceanLotus BitRAT RecordBreaker |
2025-01-17
⋅
Google Cloud Security
⋅
Threat Horizons - H1 2025 Threat Horizons Report FAKEUPDATES Conti Hades LockBit Phoenix Locker RansomHub TRIPLESTRENGTH |
2025-01-17
⋅
Twitter (@Unit42_Intel)
⋅
Tweet about affiliates of DarkScorpius using Social Engineering via MS Teams UNC4393 |
2025-01-16
⋅
Microsoft
⋅
New Star Blizzard spear-phishing campaign targets WhatsApp accounts |
2025-01-16
⋅
eSentire
⋅
MintsLoader: StealC and BOINC Delivery MintsLoader Stealc |