Click here to download all references as Bib-File.•
2025-03-20
⋅
Cisco Talos
⋅
UAT-5918 targets critical infrastructure entities in Taiwan LaZagne JuicyPotato Meterpreter MimiKatz |
2025-02-20
⋅
Cisco Talos
⋅
Weathering the storm: In the midst of a Typhoon |
2025-02-13
⋅
Recorded Future
⋅
RedMike (Salt Typhoon) Exploits Vulnerable Cisco Devices of Global Telecommunications Providers GhostEmperor |
2024-11-07
⋅
Cisco Talos
⋅
Unwrapping the emerging Interlock ransomware attack Rhysida |
2024-10-24
⋅
Cisco Talos
⋅
Writing a BugSleep C2 server and detecting its traffic with Snort bugsleep |
2024-10-23
⋅
Cisco Talos
⋅
Highlighting TA866/Asylum Ambuscade Activity Since 2021 WasabiSeed Cobalt Strike csharp-streamer RAT Resident Rhadamanthys WarmCookie |
2024-10-23
⋅
Cisco Talos
⋅
Threat Spotlight: WarmCookie/BadSpace Cobalt Strike csharp-streamer RAT WarmCookie |
2024-10-22
⋅
Cisco Talos
⋅
Threat actor abuses Gophish to deliver new PowerRAT and DCRAT PowerRAT |
2024-10-17
⋅
Cisco Talos
⋅
UAT-5647 targets Ukrainian and Polish entities with RomCom malware variants MeltingClaw ROMCOM RAT ShadyHammock RomCom |
2024-08-21
⋅
Cisco Talos
⋅
MoonPeak malware from North Korean actors unveils new details on attacker infrastructure MoonPeak XenoRAT UAT-5394 |
2024-08-01
⋅
Cisco
⋅
APT41 likely compromised Taiwanese government-affiliated research institute with ShadowPad and Cobalt Strike Cobalt Strike ShadowPad |
2024-06-21
⋅
Cisco Talos
⋅
SneakyChef espionage group targets government agencies with SugarGh0st and more infection techniques SneakyChef |
2024-06-17
⋅
Trellix
⋅
Info Stealing Campaign Uses DLL Sideloading Through Legitimate Cisco Webex’s Binaries for Initial Execution and Defense Evasion HijackLoader Lumma Stealer |
2024-06-13
⋅
Cisco Talos
⋅
Operation Celestial Force employs mobile and desktop malware to target Indian entities Gravity RAT Gravity RAT |
2024-06-05
⋅
Cisco Talos
⋅
DarkGate switches up its tactics with new payload, email templates DarkGate |
2024-05-30
⋅
Cisco Talos
⋅
LilacSquid: The stealthy trilogy of PurpleInk, InkBox and InkLoader purpleink LilacSquid |
2024-04-24
⋅
Cisco
⋅
ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices ArcaneDoor Storm-1849 |
2024-04-24
⋅
NCSC UK
⋅
Line Dancer - In-memory shellcode loader targeting Cisco Adaptive Security Appliance (ASA) devices. |
2024-04-24
⋅
NCSC UK
⋅
Line Runner: Persistent webshell targeting Cisco Adaptive Security Appliance (ASA) devices. |
2024-02-15
⋅
Cisco Talos
⋅
TinyTurla Next Generation - Turla APT spies on Polish NGOs TinyTurlaNG |