Click here to download all references as Bib-File.•
| 2026-05-22
⋅
Fox-IT
⋅
RemotePE: The Lazarus RAT that lives in memory DPAPILoader RemotePE |
| 2026-05-22
⋅
Check Point
⋅
Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict MiniFast |
| 2026-05-22
⋅
Trend Micro
⋅
Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware BeaverTail InvisibleFerret |
| 2026-05-21
⋅
Symantec
⋅
GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses win.beast MimiKatz Hyadina |
| 2026-05-21
⋅
Lumen
⋅
Introducing Showboat: A new malware family taunts defenses and targets international telecom firms Showboat |
| 2026-05-21
⋅
PWC
⋅
Inside Red Lamassu’s JFMBackdoor JFMBackdoor Calypso |
| 2026-05-20
⋅
Seqrite Labs
⋅
Operation Dragon Whistle: UNG0002 Targets Chinese Academia via Weaponized Institutional Lure Cobalt Strike |
| 2026-05-20
⋅
Hackernoon
⋅
ZeffSec Resurfaces on Telegram, Claims Breach of Gozine2.ir ZeffSec |
| 2026-05-20
⋅
K7 Security
⋅
Fake Microsoft Teams download sites are being used to deliver ValleyRAT via DLL sideloading ValleyRAT |
| 2026-05-19
⋅
Microsoft
⋅
Exposing Fox Tempest: A malware-signing service operation (Podcast) Akira Rhysida Akira BlackByte BlueSky Broomstick Lumma Stealer Rhysida Spyder Vidar Fox Tempest |
| 2026-05-19
⋅
Microsoft
⋅
Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomware Akira INC Qilin Rhysida AgendaCrypt Akira Broomstick INC Lumma Stealer Rhysida Vidar Fox Tempest |
| 2026-05-19
⋅
The Record
⋅
Microsoft disrupts Fox Tempest malware-signing-as-a-service platform tied to ransomware gangs Akira INC Qilin Rhysida AgendaCrypt Akira Broomstick INC Lumma Stealer Rhysida Vidar Fox Tempest |
| 2026-05-19
⋅
Github (microsoft)
⋅
MSTIC actor name mapping in JSON format Amethyst Rain Houndstooth Typhoon Pinstripe Lightning Storm-0252 Wisteria Tsunami |
| 2026-05-19
⋅
Trend Micro
⋅
Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud Banana RAT SHADOW-WATER-063 |
| 2026-05-18
⋅
Microsoft
⋅
How Storm-2949 turned a compromised identity into a cloud-wide breach Storm-2949 |
| 2026-05-18
⋅
Zynap
⋅
Zynap’s Next-Gen Sandbox Redefines Automatic Malware Analysis Black Basta HijackLoader |
| 2026-05-18
⋅
Gen Threat Labs
⋅
X.com - Gen Threat Labs - AuraStealer (version 1.8.0) Aura Stealer |
| 2026-05-17
⋅
neso.re
⋅
ClickFix x HijackLoader: Dissecting a Live Stealer Campaign HijackLoader |
| 2026-05-17
⋅
Github (zanez)
⋅
Analysis on Malware that attacks Israel's Water treatment facilities ZionSiphon |
| 2026-05-16
⋅
Symantec
⋅
Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations fast16 |