Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2024-10-31 ⋅ Sophos X-Ops ⋅ Andrew Brandt, Ross McKerchar
Pacific Rim timeline: Information for defenders from a braid of interlocking attack campaigns
Asnarök Tstark
2023-05-03 ⋅ Sophos ⋅ Andrew Brandt, Gabor Szappanos, Xinran Wu
A doubled “Dragon Breath” adds new air to DLL sideloading attacks
Ghost RAT DragonBreath
2023-02-06 ⋅ Sophos ⋅ Andrew Brandt
Qakbot mechanizes distribution of malicious OneNote notebooks
QakBot
2022-12-13 ⋅ Sophos ⋅ Andreas Klopsch, Andrew Brandt
Signed driver malware moves up the software trust chain
KillAV
2022-11-30 ⋅ Sophos ⋅ Andrew Brandt
LockBit 3.0 ‘Black’ attacks and leaks reveal wormable capabilities and tooling
LockBit
2022-07-14 ⋅ Sophos ⋅ Andrew Brandt, Andy French, Bill Kearney, Elida Leite, Harinder Bhathal, Lee Kirkpatrick, Peter Mackenzie, Robert Weiland, Sergio Bestulic
BlackCat ransomware attacks not merely a byproduct of bad luck
BlackCat BlackCat
2022-06-16 ⋅ SophosLabs Uncut ⋅ Andrew Brandt
Confluence exploits used to drop ransomware on vulnerable servers
Cerber
2022-04-12 ⋅ Sophos ⋅ Andrew Brandt, Angela Gunn, Ferenc László Nagy, Johnathan Fern, Linda Smith, Matthew Everts, Mauricio Valdivieso, Melissa Kelly, Peter Mackenzie, Sergio Bestulic
Attackers linger on government agency computers before deploying Lockbit ransomware
LockBit
2022-02-23 ⋅ SophosLabs Uncut ⋅ Andrew Brandt
Dridex bots deliver Entropy ransomware in recent attacks
Cobalt Strike Dridex Entropy
2022-02-23 ⋅ Sophos ⋅ Abhijit Gupta, Anand Ajjan, Andrew Brandt, Colin Cowie, Felix Weyne, Rahil Shah, Steven Lott, Syed Zaidi, Vikas Singh, Xiaochuan Zhang
Dridex bots deliver Entropy ransomware in recent attacks
Entropy
2022-01-25 ⋅ Sophos ⋅ Andrew Brandt
Windows services lay the groundwork for a Midas ransomware attack
Midas
2022-01-25 ⋅ Sophos ⋅ Andrew Brandt, Jason Jenkins
Windows services lay the groundwork for a Midas ransomware attack
2021-12-22 ⋅ Sophos ⋅ Anand Ajjan, Andrew Brandt, Ferenc László Nagy, Fraser Howard, Peter Mackenzie, Sergio Bestulic, Timothy Easton
Avos Locker remotely accesses boxes, even running in Safe Mode
AvosLocker
2021-12-21 ⋅ Sophos ⋅ Andrew Brandt, Stephen Ormandy
Attackers test “CAB-less 40444” exploit in a dry run
2021-11-11 ⋅ SophosLabs Uncut ⋅ Andrew Brandt
BazarLoader ‘call me back’ attack abuses Windows 10 Apps mechanism
BazarBackdoor
2021-10-05 ⋅ Sophos ⋅ Andrew Brandt, Andrew O’Donnell, Mauricio Valdivieso, Rajesh Nataraj
Python ransomware script targets ESXi server for encryption
2021-09-21 ⋅ Sophos ⋅ Andrew Brandt, Chaitanya Ghorpade, Krisztián Diriczi, Shefali Gupta, Vikas Singh
Cring ransomware group exploits ancient ColdFusion server
Cobalt Strike Cring
2021-09-01 ⋅ Sophos ⋅ Anand Ajjan, Andrew Brandt, Sean Gallagher, Yusuf Polat
Fake pirated software sites serve up malware droppers as a service
Raccoon
2021-08-12 ⋅ Sophos ⋅ Andrew Brandt, Gabor Szappanos
Gootloader’s “mothership” controls malicious content
GootLoader
2021-07-22 ⋅ Sophos ⋅ Andrew Brandt, Sean Gallagher
Malware increasingly targets Discord for abuse