Click here to download all references as Bib-File.•
| 2026-08-24
⋅
Field Effect
⋅
A ClickFix cluster: Observed activity from recent ClickFix campaigns Lorem Ipsum |
| 2026-08-19
⋅
Bitdefender
⋅
SilkParasite: Tracking a China-Nexus APT Across Central Asia BloodAlchemy ShadowPad SNAPPYBEE SilkParasite |
| 2026-08-10
⋅
LevelBlue
⋅
CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain Babadeda |
| 2026-07-23
⋅
NSA
⋅
NSA and Partners Alert Zimbra Collaboration Suite Users of a Russian State-Supported Phishing Campaign ZimReaper |
| 2026-07-23
⋅
Group-IB
⋅
JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake AdaptixC2 reGeorg |
| 2026-07-22
⋅
Huntress Labs
⋅
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT SectopRAT |
| 2026-07-16
⋅
Elastic
⋅
TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains TELEPUZ |
| 2026-06-24
⋅
JFrog Security
⋅
Hijacked npm Packages Use Novel VSCode Autorun and Blockchain Dead Drops to Deploy a Credential/Crypto Stealer JADESNOW |
| 2026-06-17
⋅
Rapid7
⋅
Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain Unidentified 125 (RAT, Dropping Elephant) |
| 2026-06-16
⋅
Huntress Labs
⋅
Potemkin Loader & RMMProject - The Anatomy of a ClickFix Attack EtherRAT Chisel Potemkin |
| 2026-06-08
⋅
SYGNIA
⋅
Velvet Ant’s Operation Highland: How a China-Nexus Actor Infiltrated an Internal Network Undetected |
| 2026-05-18
⋅
Microsoft
⋅
How Storm-2949 turned a compromised identity into a cloud-wide breach Storm-2949 |
| 2026-04-30
⋅
Trend Micro
⋅
Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia FINALDRAFT ShadowPad VShell Shadow-Earth-053 |
| 2026-04-23
⋅
Mandiant
⋅
Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite SNOWBASIN UNC6692 |
| 2026-04-21
⋅
Trend Micro
⋅
Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories BeaverTail JADESNOW OtterCookie InvisibleFerret |
| 2026-04-09
⋅
⋅
F6
⋅
Eastern Signature: Investigating a Cyberattack by an Asian Threat Group ShadowPad |
| 2026-04-08
⋅
Lookout
⋅
Beyond BITTER: MENA Civil Society Targeted in Hack-For-Hire Operation Linked to BITTER APT ProSpy |
| 2026-03-06
⋅
nadsec
⋅
Coruna: A Complete Technical Teardown Coruna |
| 2026-02-19
⋅
Elastic
⋅
MIMICRAT: ClickFix Campaign Delivers Custom RAT via Compromised Legitimate Websites AstarionRAT |
| 2026-02-17
⋅
Hunt.io
⋅
Fake Homebrew Typosquats Used to Deliver Cuckoo Stealer via ClickFix |