Click here to download all references as Bib-File.•
| 2026-05-27
⋅
Straiker
⋅
Fake Claude Code, Real Malware: Inside the Campaign Targeting AI Developers ACR Stealer Amatera |
| 2026-05-27
⋅
Group-IB
⋅
The GHOST STADIUM Score: Billions At Stake At The World’s Largest Football Tournament GHOST STADIUM |
| 2026-05-27
⋅
Wiz.io
⋅
Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure JINX-0164 |
| 2026-05-27
⋅
bluecyber
⋅
MUSTANG PANDA x PLUGX - Analysis of the January 2026 sample: a multi-layer execution chain PlugX |
| 2026-05-26
⋅
Intrinsec
⋅
Pivoting on a malspam infrastructure delivering JS malware backed by bulletproof networks |
| 2026-05-24
⋅
cocomelonc
⋅
Malware shellcode delivery via signal - part 1. FSK Basics. Simple python script |
| 2026-05-22
⋅
Fox-IT
⋅
RemotePE: The Lazarus RAT that lives in memory DPAPILoader RemotePE |
| 2026-05-22
⋅
Check Point
⋅
Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict MiniFast |
| 2026-05-22
⋅
Trend Micro
⋅
Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware BeaverTail InvisibleFerret |
| 2026-05-21
⋅
Lumen
⋅
Introducing Showboat: A new malware family taunts defenses and targets international telecom firms Showboat |
| 2026-05-21
⋅
PWC
⋅
Inside Red Lamassu’s JFMBackdoor JFMBackdoor Calypso |
| 2026-05-20
⋅
Seqrite Labs
⋅
Operation Dragon Whistle: UNG0002 Targets Chinese Academia via Weaponized Institutional Lure Cobalt Strike |
| 2026-05-20
⋅
Hackernoon
⋅
ZeffSec Resurfaces on Telegram, Claims Breach of Gozine2.ir ZeffSec |
| 2026-05-20
⋅
K7 Security
⋅
Fake Microsoft Teams download sites are being used to deliver ValleyRAT via DLL sideloading ValleyRAT |
| 2026-05-19
⋅
Github (microsoft)
⋅
MSTIC actor name mapping in JSON format Amethyst Rain Houndstooth Typhoon Pinstripe Lightning Storm-0252 Wisteria Tsunami |
| 2026-05-19
⋅
Trend Micro
⋅
Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud Banana RAT SHADOW-WATER-063 |
| 2026-05-18
⋅
Microsoft
⋅
How Storm-2949 turned a compromised identity into a cloud-wide breach Storm-2949 |
| 2026-05-18
⋅
Zynap
⋅
Zynap’s Next-Gen Sandbox Redefines Automatic Malware Analysis Black Basta HijackLoader |
| 2026-05-18
⋅
Gen Threat Labs
⋅
X.com - Gen Threat Labs - AuraStealer (version 1.8.0) Aura Stealer |
| 2026-05-17
⋅
neso.re
⋅
ClickFix x HijackLoader: Dissecting a Live Stealer Campaign HijackLoader |