Click here to download all references as Bib-File.

Enter keywords to filter the library entries below or Propose new Entry
2026-08-24Field EffectDamon Toumbourou, Hugh Whitewood
A ClickFix cluster: Observed activity from recent ClickFix campaigns
Lorem Ipsum
2026-08-19BitdefenderMartin Zugec
SilkParasite: Tracking a China-Nexus APT Across Central Asia
BloodAlchemy ShadowPad SNAPPYBEE SilkParasite
2026-08-10LevelBlueRodel Mendrez
CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain
Babadeda
2026-07-23NSANSA
NSA and Partners Alert Zimbra Collaboration Suite Users of a Russian State-Supported Phishing Campaign
ZimReaper
2026-07-23Group-IBGroup-IB
JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake
AdaptixC2 reGeorg
2026-07-22Huntress LabsMichael Tigges
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
SectopRAT
2026-07-16ElasticCyril François
TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains
TELEPUZ
2026-06-24JFrog SecurityGuy Korolevski, Yair Benamou
Hijacked npm Packages Use Novel VSCode Autorun and Blockchain Dead Drops to Deploy a Credential/Crypto Stealer
JADESNOW
2026-06-17Rapid7Anna Širokova
Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain
Unidentified 125 (RAT, Dropping Elephant)
2026-06-16Huntress LabsAnna Pham, Zach Rogers
Potemkin Loader & RMMProject - The Anatomy of a ClickFix Attack
EtherRAT Chisel Potemkin
2026-06-08SYGNIASygnia Team
Velvet Ant’s Operation Highland: How a China-Nexus Actor Infiltrated an Internal Network Undetected
2026-05-18MicrosoftMicrosoft Defender Security Research Team
How Storm-2949 turned a compromised identity into a cloud-wide breach
Storm-2949
2026-04-30Trend MicroDaniel Lunghi, Lucas Silva
Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia
FINALDRAFT ShadowPad VShell Shadow-Earth-053
2026-04-23MandiantJosh Kelley, JP Glab, Muhammad Umair, Tufail Ahmed
Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite
SNOWBASIN UNC6692
2026-04-21Trend MicroLucas Silva
Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories
BeaverTail JADESNOW OtterCookie InvisibleFerret
2026-04-09F6F6
Eastern Signature: Investigating a Cyberattack by an Asian Threat Group
ShadowPad
2026-04-08LookoutAlemdar Islamoglu, Justin Albrecht
Beyond BITTER: MENA Civil Society Targeted in Hack-For-Hire Operation Linked to BITTER APT
ProSpy
2026-03-06nadsecnadsec
Coruna: A Complete Technical Teardown
Coruna
2026-02-19ElasticElastic Security Labs, Salim Bitam
MIMICRAT: ClickFix Campaign Delivers Custom RAT via Compromised Legitimate Websites
AstarionRAT
2026-02-17Hunt.ioHunt.io
Fake Homebrew Typosquats Used to Deliver Cuckoo Stealer via ClickFix