Click here to download all references as Bib-File.

Enter keywords to filter the library entries below or Propose new Entry
2026-08-30Medium 0xzyadelzyatZyad Elzyat
Reverse Engineering the Auto-Color Linux Backdoor
Auto-Color
2026-08-27ProofpointKyle Cucci, Proofpoint Threat Research Team, Rob Kinner, Tony Robinson
Carry-On Compromise: TA4922 Packs PackClient
donut_injector
2026-08-26MicrosoftParasharan Raghavan, Sagar Patil, Suriyaraj Natarajan
TerminalFix campaign deploys a reverse tunnel through multistage intrusion
Lorem Ipsum
2026-08-24Field EffectDamon Toumbourou, Hugh Whitewood
A ClickFix cluster: Observed activity from recent ClickFix campaigns
Lorem Ipsum
2026-08-21Bitso Quetzal TeamMauro Eldritch, Nelson Colon
North Korea’s Crypt: Hunting Ghosts
StoatWaffle
2026-08-21NetresecErik Hjelmvik
CNCMachineRMS C2 Protocol
Babadeda
2026-08-20trendaiAliakbar Zahravi
Prompting the Payload: How an npm Supply Chain Attack Delivers the RedC2 AI-Powered Linux Implant
redshell
2026-08-19BitdefenderMartin Zugec
SilkParasite: Tracking a China-Nexus APT Across Central Asia
BloodAlchemy ShadowPad SNAPPYBEE SilkParasite
2026-08-19abuse.chabuse.ch
MalwareBazaar | SHA256 9768b7e31324805672cfcba91cf4d6da91494e9899db58f22da9dda6c91931d6 (NeedleStealer)
NeedleStealer
2026-08-17ZscalerZscaler ThreatLabz
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
C2Looper
2026-08-14Ministere de l'Economie et des FinancesElvire MACE
Illegitimate access to the information system of the Directorate General of Public Finances
ZeroBytes
2026-08-11Aryaka NetworkAditya K Sood, bikash dash
Beyond the Batch File Analysis of a Multi-Stage DonutLoader Infection Chain
donut_injector
2026-08-11abuse.chabuse.ch
MalwareBazaar | SHA256 29e97b2ae2e4c12dddaa69995462ffce950409f222242725f3aab323949ed8ee (HypeAgent)
HypeAgent
2026-08-10AhnLabASEC
Attack Cases for Domestic Web Servers Running SoftEther VPN in Korea
Larva-26010
2026-08-10LevelBlueRodel Mendrez
CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain
Babadeda
2026-08-10sonatypeSonatype Research Team
Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads
JADESNOW
2026-08-07KasperskyKaspersky
The APT group Head Mare exploits vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph malware to video conferencing participants
PhantomCore PhantomGraph
2026-08-05SOC PrimeSOC Prime
SmartApeSG Pushes an Unknown RAT Through ClickFix Lures
SmartApeSG
2026-08-03AhnLabASEC
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)
CRAT DRATzarus Larva-26005
2026-07-31Medium @prtheusPrtheus
1337_GTWK Linux Malware Analysis
1337_GTWK