Click here to download all references as Bib-File.•
| 2025-09-15
⋅
Huntress Labs
⋅
Huntress Threat Advisory: The Dangers of Storing Unencrypted Passwords Akira |
| 2025-09-09
⋅
Huntress Labs
⋅
How an Attacker’s Blunder Gave Us a Rare Look Inside Their Day-to-Day Operations |
| 2025-06-18
⋅
Huntress Labs
⋅
Feeling Blue(Noroff): Inside a Sophisticated DPRK Web3 Intrusion |
| 2024-11-14
⋅
Huntress Labs
⋅
It’s Not Safe to Pay SafePay SafePay |
| 2024-08-08
⋅
Huntress Labs
⋅
X Octowave Loader |
| 2024-07-17
⋅
Huntress Labs
⋅
Fake Browser Updates Lead to BOINC Volunteer Computing Software FAKEUPDATES MintsLoader AsyncRAT |
| 2023-09-07
⋅
Huntress Labs
⋅
Evolution of USB-Borne Malware, Raspberry Robin Raspberry Robin |
| 2023-08-23
⋅
Twitter (@embee_research)
⋅
Extracting Xworm from Bloated Golang Executable XWorm |
| 2023-05-09
⋅
Huntress Labs
⋅
Advanced Cyberchef Tips - AsyncRAT Loader AsyncRAT |
| 2023-03-30
⋅
Huntress Labs
⋅
3CX VoIP Software Compromise & Supply Chain Threats 3CX Backdoor |
| 2023-02-08
⋅
Huntress Labs
⋅
Investigating Intrusions From Intriguing Exploits Silence |
| 2023-02-08
⋅
Huntress Labs
⋅
AsyncRAT: Analysing the Three Stages of Execution AsyncRAT |
| 2023-02-03
⋅
Huntress Labs
⋅
Ave Maria and the Chambers of Warzone RAT Ave Maria |
| 2022-10-12
⋅
Twitter (@embee_research)
⋅
Tweets on detection of Brute Ratel via API Hashes Brute Ratel C4 |
| 2022-10-11
⋅
Twitter (@embee_research)
⋅
Tweet on Havoc C2 - Static Detection Via Ntdll API Hashes Havoc |
| 2022-08-16
⋅
Huntress Labs
⋅
Cleartext Shenanigans: Gifting User Passwords to Adversaries With NPPSPY |
| 2022-03-01
⋅
Huntress Labs
⋅
Targeted APT Activity: BABYSHARK Is Out for Blood BabyShark |
| 2022-02-18
⋅
Huntress Labs
⋅
Hackers No Hashing: Randomizing API Hashes to Evade Cobalt Strike Shellcode Detection Cobalt Strike |
| 2022-01-15
⋅
Huntress Labs
⋅
Threat Advisory: VMware Horizon Servers Actively Being Hit With Cobalt Strike (by DEV-0401) Cobalt Strike |
| 2021-10-22
⋅
Huntress Labs
⋅
Threat Advisory: Hackers Are Exploiting a Vulnerability in Popular Billing Software to Deploy Ransomware |