Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2023-11-02 ⋅ Microsoft ⋅ Heike Ritter
Monthly news - November 2023
Storm-0249 Storm-0539
2023-11-02 ⋅ Microsoft ⋅ Heike Ritter
Monthly news - November 2023
Storm-0062
2023-10-25 ⋅ Microsoft ⋅ Microsoft Incident Response, Microsoft Threat Intelligence
Octo Tempest crosses boundaries to facilitate extortion, encryption, and destruction
BlackCat BlackCat Lumma Stealer
2023-10-18 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
Multiple North Korean threat actors exploiting the TeamCity CVE-2023-42793 vulnerability
FeedLoad ForestTiger HazyLoad RollSling Silent Chollima
2023-10-13 ⋅ Twitter (@MsftSecIntel) ⋅ Microsoft Threat Intelligence
Tweet on Storm-1575 and Dadsec phishing platform
Storm-1575
2023-10-11 ⋅ Microsoft ⋅ Amir Kutcher, Charles-Edouard Bettan, Edan Zwick, Noam Hadash, Yair Tsarfaty
Automatic disruption of human-operated attacks through containment of compromised user accounts
Akira Akira
2023-10-11 ⋅ Twitter (@MsftSecIntel) ⋅ Microsoft Threat Intelligence
Tweet on Storm-0062 exploiting CVE-2023-22515
Storm-0062
2023-09-14 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
Peach Sandstorm password spray campaigns enable intelligence collection at high-value targets
APT33
2023-09-12 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
Malware distributor Storm-0324 facilitates ransomware access
JSSLoader Storm-0324
2023-09-07 ⋅ Microsoft ⋅ Microsoft Threat Analysis Center (MTAC)
Sophistication, scope, and scale: Digital threats from East Asia increase in breadth and effectiveness
MUSTANG PANDA Raspberry Typhoon
2023-09-07 ⋅ Microsoft ⋅ Clint Watts
China, North Korea pursue new targets while honing cyber capabilities
2023-09-06 ⋅ Microsoft ⋅ Microsoft Security Response Center (MSRC)
Results of Major Technical Investigations for Storm-0558 Key Acquisition
2023-09-06 ⋅ TRUESEC ⋅ Jakob Nordenlund
DarkGate Loader Malware Delivered via Microsoft Teams
DarkGate
2023-09-01 ⋅ Microsoft ⋅ Microsoft Threat Analysis Center (MTAC)
Russia’s influence networks in Sahel activated after coups
2023-08-28 ⋅ Microsoft ⋅ Kirtar
Defender Experts Chronicles: A Deep Dive into Storm-0867
Storm-0867
2023-08-28 ⋅ Twitter (@MsftSecIntel) ⋅ Microsoft Threat Intelligence
Tweet on AiTM phishing trends
Storm-1295
2023-08-24 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
Flax Typhoon using legitimate software to quietly access Taiwanese organizations
Flax Typhoon
2023-08-18 ⋅ GTSC ⋅ Bảo Thanh
Warning: New attack campaign utilized a new 0-day RCE vulnerability on Microsoft Exchange Server
SharPyShell
2023-08-02 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
Midnight Blizzard conducts targeted social engineering over Microsoft Teams
UNC2452
2023-07-19 ⋅ Twitter (@MsftSecIntel) ⋅ Microsoft Threat Intelligence
Tweet on targeted attacks against the defense sector in Ukraine and Eastern Europe by the threat actor Secret Blizzard
DeliveryCheck Kazuar