Click here to download all references as Bib-File.•
| 2024-05-15
            
            ⋅
            
            X (@bryceabdo)
            ⋅ Tweet on UNC5449 exploiting CVE-2024-30051 to deliver QAKBOT QakBot | 
| 2022-10-06
            
            ⋅
            
            Aon
            ⋅ Amazon Web Services: Exploring The Cost Of Exfil | 
| 2022-04-04
            
            ⋅
            
            Mandiant
            ⋅ FIN7 Power Hour: Adversary Archaeology and the Evolution of FIN7 Griffon BABYMETAL Carbanak Cobalt Strike JSSLoader Termite | 
| 2021-02-25
            
            ⋅
            
            Mandiant
            ⋅ So Unchill: Melting UNC2198 ICEDID to Ransomware Operations IcedID TA2101 | 
| 2021-02-25
            
            ⋅
            
            FireEye
            ⋅ So Unchill: Melting UNC2198 ICEDID to Ransomware Operations MOUSEISLAND Cobalt Strike Egregor IcedID Maze SystemBC | 
| 2021-01-22
            
            ⋅
            
            Twitter (@bryceabdo)
            ⋅ Tweet on GRIMAGENT malware used by UNC1878 during some #RYUK intrusions in 2020 GRIMAGENT |