Click here to download all references as Bib-File.•
2023-12-14
⋅
Mandiant
⋅
Opening a Can of Whoop Ads: Detecting and Disrupting a Malvertising Campaign Distributing Backdoors DanaBot DarkGate |
2023-12-14
⋅
Checkpoint
⋅
Rhadamanthys v0.5.0 – A Deep Dive into the Stealer’s Components Rhadamanthys |
2023-12-14
⋅
Medium (Cryptax)
⋅
Bad Zip and new Packer for Android/BianLian BianLian |
2023-12-13
⋅
Trend Micro
⋅
Vishing via Microsoft Teams Facilitates DarkGate Malware Intrusion DarkGate |
2023-12-13
⋅
Sekoia
⋅
CALISTO doxxing: Sekoia.io findings concurs to Reuters’ investigation on FSB-related Andrey Korinets Callisto |
2023-12-13
⋅
Microsoft
⋅
Disrupting the gateway services to cybercrime Storm-1152 |
2023-12-13
⋅
Kaspersky Labs
⋅
FakeSG campaign, Akira ransomware and AMOS macOS stealer AMOS Akira Storm-1567 |
2023-12-13
⋅
cocomelonc
⋅
Malware in the wild book AsyncRAT Babuk BlackCat BlackLotus Carbanak HelloKitty Paradise Stealc WinDealer |
2023-12-13
⋅
Fortinet
⋅
TeamCity Intrusion Saga: APT29 Suspected Among the Attackers Exploiting CVE-2023-42793 GraphDrop |
2023-12-13
⋅
CISA
⋅
Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally GraphDrop |
2023-12-13
⋅
Stairwell
⋅
Kuiper ransomware analysis: Stairwell’s technical report |
2023-12-13
⋅
HackRead
⋅
Scammers Weaponize Google Forms in New BazarCall Attack |
2023-12-13
⋅
Lumen
⋅
Routers Roasting on an Open Firewall: the KV-botnet Investigation KV |
2023-12-13
⋅
ShadowStackRE
⋅
Rhysida Ransomware Rhysida Rhysida |
2023-12-12
⋅
Proofpoint
⋅
Security Brief: TA4557 Targets Recruiters Directly via Email More_eggs FIN6 |
2023-12-12
⋅
eSentire
⋅
Unraveling BatLoader and FakeBat EugenLoader |
2023-12-12
⋅
Fourcore
⋅
Rhysida Ransomware: History, TTPs And Adversary Emulation Plans Rhysida Rhysida Vanilla Tempest |
2023-12-12
⋅
Youtube (OALabs)
⋅
Tips For Analyzing Delphi Binaries in IDA (Danabot) DanaBot |
2023-12-12
⋅
Ukrainska Pravda
⋅
Ukrainian intelligence attacks and paralyses Russia's tax system |
2023-12-12
⋅
Microsoft
⋅
Threat actors misuse OAuth applications to automate financially driven attacks Storm-1283 Storm-1286 |