Click here to download all references as Bib-File.•
2022-03-22
⋅
The Hacker News
⋅
Microsoft and Okta Confirm Breach by LAPSUS$ Extortion Group RedLine Stealer |
2022-03-21
⋅
Github (trendmicro)
⋅
Python script to check a Cyclops Blink C&C CyclopsBlink |
2022-03-14
⋅
Bleeping Computer
⋅
Android malware Escobar steals your Google Authenticator MFA codes Aberebot |
2022-03-13
⋅
Security Affairs
⋅
The hidden C2: Lampion trojan release 212 is on the rise and using a C2 server for two years lampion |
2022-03-03
⋅
LIFARS
⋅
A Closer Look at the Russian Actors Targeting Organizations in Ukraine HermeticWiper IsaacWiper Saint Bot WhisperGate |
2022-03-01
⋅
Proofpoint
⋅
Asylum Ambuscade: State Actor Uses Compromised Private Ukrainian Military Emails to Target European Governments and Refugee Movement SunSeed |
2022-02-26
⋅
Seguranca Informatica
⋅
The hidden C2: Lampion trojan release 212 is on the rise and using a C2 server for two years lampion |
2022-02-24
⋅
nviso
⋅
Threat Update – Ukraine & Russia conflict EternalPetya GreyEnergy HermeticWiper Industroyer KillDisk WhisperGate |
2022-02-17
⋅
Twitter (@Honeymoon_IoC)
⋅
Tweets on win.prometei caught via Cowrie Prometei |
2022-02-14
⋅
Morphisec
⋅
Journey of a Crypto Scammer - NFT-001 AsyncRAT BitRAT Remcos |
2022-02-09
⋅
Cisco
⋅
What’s with the shared VBA code between Transparent Tribe and other threat actors? |
2022-02-08
⋅
GuidePoint Security
⋅
Using Hindsight to Close a Cuba Cold Case Cuba |
2022-01-27
⋅
BleepingComputer
⋅
Taiwanese Apple and Tesla contractor hit by Conti ransomware Conti |
2022-01-25
⋅
Palo Alto Networks Unit 42
⋅
Weaponization of Excel Add-Ins Part 1: Malicious XLL Files and Agent Tesla Case Studies Agent Tesla |
2022-01-24
⋅
Trend Micro
⋅
Analysis and Impact of LockBit Ransomware’s First Linux and VMware ESXi Variant LockBit LockBit |
2022-01-24
⋅
Proofpoint
⋅
DTPacker – a .NET Packer with a Curious Password Agent Tesla TA2536 |
2022-01-18
⋅
Trend Micro
⋅
New Ransomware Spotted: White Rabbit and Its Evasion Tactics |
2022-01-17
⋅
Trend Micro
⋅
Delving Deep: An Analysis of Earth Lusca’s Operations BIOPASS Cobalt Strike FunnySwitch JuicyPotato ShadowPad Winnti Earth Lusca |
2022-01-16
⋅
forensicitguy
⋅
Analyzing a CACTUSTORCH HTA Leading to Cobalt Strike CACTUSTORCH Cobalt Strike |
2022-01-11
⋅
Twitter (@cglyer)
⋅
Thread on DEV-0401, a china based ransomware operator exploiting VMware Horizon with log4shell and deploying NightSky ransomware Cobalt Strike NightSky |