Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2026-07-29 ⋅ Proofpoint ⋅ Greg Lesnewich, Konstantin Klinger, Mark Kelly, Nick Attfield, Saher Naumaan, Stuart Del Caliz
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit
ZimReaper Void Blizzard
2026-07-23 ⋅ Proofpoint ⋅ Greg Lesnewich, Konstantin Klinger, Mark Kelly, Nick Attfield, Saher Naumaan
Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458
SpyPress
2026-07-23 ⋅ Proofpoint ⋅ Greg Lesnewich, Konstantin Klinger, Mark Kelly, Nick Attfield, Saher Naumaan
TA488 Targets Zimbra Mailservers with Half-Click Exploits
ZimReaper
2026-06-11 ⋅ ZeroBEC ⋅ Vedant Bhalgama
Introducing LX RAT: ITR Phishing Targets Finance and Tech
AsyncRAT LxBase RAT
2026-05-20 ⋅ Seqrite Labs ⋅ Dixit Panchal, Kartik Jivani, Vaibhav Krushna Billade
Operation Dragon Whistle: UNG0002 Targets Chinese Academia via Weaponized Institutional Lure
Cobalt Strike
2026-04-16 ⋅ Darktrace ⋅ Calum Hall, Ryan Traill
Inside ZionSiphon: Darktrace’s Analysis of OT Malware Targeting Israeli Water Systems
ZionSiphon
2026-02-24 ⋅ BlueVoyant ⋅ Joshua Green, Patrick Mchale
Mercenary Akula Hits Ukraine-Supporting Financial Institution
RMS
2026-01-11 ⋅ Medium APOPHIS ⋅ Michelle Khalil
ValleyRAT_S2 Chinese campaign
ValleyRAT
2025-11-22 ⋅ LinkedIn (Idan Tarab) ⋅ Idan Tarab
India‑Aligned "Dropping Elephant" Pushes a New Stealth Marshalled‑Python Backdoor via MSBuild Dropper in Observed Activity Targeting Pakistan’s Defense Sector
2025-09-24 ⋅ Natto Thoughts ⋅ Natto Team
Who is Salt Typhoon Really? Unraveling the Attribution Challenge
2025-05-16 ⋅ Gdata ⋅ Karsten Hahn
Printer company provided infected software downloads for half a year
SnipVex
2025-04-30 ⋅ Seqrite ⋅ Mahua Chakrabarthy, Sanjay Katkar
Advisory: Pahalgam Attack themed decoys used by APT36 to target the Indian Government
Crimson RAT
2025-04-29 ⋅ Trustwave ⋅ Trustwave SpiderLabs
Yet Another NodeJS Backdoor (YaNB): A Modern Challenge
KongTuke
2025-04-14 ⋅ Palo Alto Networks Unit 42 ⋅ Prashil Pattni
Slow Pisces Targets Developers With Coding Challenges and Introduces New Customized Python Malware
RN Stealer
2025-03-25 ⋅ JPCERT/CC ⋅ Hayato Sasaki
Tempted to Classifying APT Actors: Practical Challenges of Attribution in the Case of Lazarus’s Subgroup
2025-03-04 ⋅ Department of Justice ⋅ U.S. Attorney's Office Southern District of New York
10 Chinese Nationals Charged With Large-Scale Hacking Of U.S. And International Victims On Behalf Of The Chinese Government
2025-01-13 ⋅ Halcyon ⋅ Halcyon Research Team
Abusing AWS Native Services: Ransomware Encrypting S3 Buckets with SSE-C
Codefinger
2024-12-30 ⋅ Fortinet ⋅ Chris Hall
Catching "EC2 Grouper"- no indicators required!
EC2 Grouper
2024-12-19 ⋅ SpyCloud ⋅ James
LummaC2 Revisited: What’s Making this Stealer Stealthier and More Lethal
GhostSocks Lumma Stealer
2024-08-09 ⋅ Palo Alto Networks Unit 42 ⋅ Amanda Tanner, Kristopher Bleich
Ransomware Review: First Half of 2024
Ukrainian Cyber Alliance