Click here to download all references as Bib-File.•
| 2025-09-24
            
            ⋅
            
            Google
            ⋅ Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors BRICKSTORM | 
| 2025-04-03
            
            ⋅
            
            Mandiant
            ⋅ Suspected China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457) SPAWNSNARE | 
| 2024-04-17
            
            ⋅
            
            Mandiant
            ⋅ Unearthing APT44: Russia’s Notorious Cyber Sabotage Unit Sandworm Sandworm | 
| 2024-04-16
            
            ⋅
            
            Mandiant
            ⋅ APT44: Unearthing Sandworm VPNFilter BlackEnergy CaddyWiper EternalPetya HermeticWiper Industroyer INDUSTROYER2 Olympic Destroyer PartyTicket RoarBAT Sandworm | 
| 2024-04-04
            
            ⋅
            
            Mandiant
            ⋅ Cutting Edge, Part 4: Ivanti Connect Secure VPN Post-Exploitation Lateral Movement Case Studies UNC3569 UNC5266 UNC5291 UNC5330 UNC5337 UTA0178 | 
| 2024-04-04
            
            ⋅
            
            Mandiant
            ⋅ Cutting Edge, Part 4: Ivanti Connect Secure VPN Post-Exploitation Lateral Movement Case Studies TONERJAM | 
| 2024-01-12
            
            ⋅
            
            Mandiant
            ⋅ Cutting Edge: Suspected APT Targets Ivanti Connect Secure VPN in New Zero-Day Exploitation UTA0178 | 
| 2023-11-09
            
            ⋅
            
            Mandiant
            ⋅ Sandworm Disrupts Power in Ukraine Using a Novel Attack Against Operational Technology CaddyWiper | 
| 2023-08-29
            
            ⋅
            
            Mandiant
            ⋅ Diving Deep into UNC4841 Operations Following Barracuda ESG Zero-Day Remediation (CVE-2023-2868) GhostEmperor | 
| 2023-08-29
            
            ⋅
            
            Google
            ⋅ Diving Deep into UNC4841 Operations Following Barracuda ESG Zero-Day Remediation (CVE-2023-2868) GhostEmperor UNC4841 | 
| 2023-06-15
            
            ⋅
            
            Google
            ⋅ Barracuda ESG Zero-Day Vulnerability (CVE-2023-2868) Exploited Globally by Aggressive and Skilled Actor, Suspected Links to China SALTWATER SEASPY WHIRLPOOL UNC4841 | 
| 2023-06-15
            
            ⋅
            
            Mandiant
            ⋅ Barracuda ESG Zero-Day Vulnerability (CVE-2023-2868) Exploited Globally by Aggressive and Skilled Actor, Suspected Links to China SALTWATER SEASPY UNC4841 | 
| 2023-01-05
            
            ⋅
            
            Mandiant
            ⋅ Turla: A Galaxy of Opportunity KopiLuwak Andromeda QUIETCANARY | 
| 2022-11-28
            
            ⋅
            
            Mandiant
            ⋅ Always Another Secret: Lifting the Haze on China-nexus Espionage in Southeast Asia BLUEHAZE DARKDEW MISTCLOAK UNC4191 | 
| 2022-04-29
            
            ⋅
            
            Mandiant
            ⋅ Trello From the Other Side: Tracking APT29 Phishing Campaigns BEATDROP VaporRage | 
| 2022-04-28
            
            ⋅
            
            Mandiant
            ⋅ Trello From the Other Side: Tracking APT29 Phishing Campaigns Cobalt Strike | 
| 2022-03-28
            
            ⋅
            
            Mandiant
            ⋅ Forged in Fire: A Survey of MobileIron Log4Shell Exploitation KEYPLUG | 
| 2022-03-08
            
            ⋅
            
            Mandiant
            ⋅ Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments KEYPLUG Cobalt Strike LOWKEY | 
| 2021-09-03
            
            ⋅
            
            FireEye
            ⋅ PST, Want a Shell? ProxyShell Exploiting Microsoft Exchange Servers CHINACHOPPER HTran |