Click here to download all references as Bib-File.•
| 2026-07-22
⋅
Prophet Security
⋅
EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain |
| 2026-06-17
⋅
Medium
⋅
MetaStealer traffic, new DGAs and analyzing the “tracker” backdoor DGA with AI Potemkin |
| 2026-06-16
⋅
BlueVoyant
⋅
Lorem Ipsum Revisited Lorem Ipsum |
| 2026-05-04
⋅
BlueVoyant
⋅
Lorem Ipsum Malware: Trojanized MS Teams Installers Deliver Multi-Stage Loader and Backdoor Lorem Ipsum |
| 2026-04-23
⋅
Mandiant
⋅
Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite SNOWBASIN UNC6692 |
| 2026-04-01
⋅
YouTube (Mandiant)
⋅
EP24 The Glupteba Takedown: What Happens When Botnet Operators Show Up in Court with Pierre-Marc Bureau Glupteba |
| 2026-02-24
⋅
BlueVoyant
⋅
Mercenary Akula Hits Ukraine-Supporting Financial Institution RMS |
| 2025-09-24
⋅
Google
⋅
Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors BRICKSTORM |
| 2025-09-11
⋅
IBM X-Force
⋅
Hive0154, aka Mustang Panda, drops updated Toneshell backdoor and novel SnakeDisk USB worm PUBLOAD SnakeDisk TONESHELL Yokai |
| 2025-09-11
⋅
Trend Micro
⋅
EvilAI Operators Use AI-Generated Code and Fake Apps for Far-Reaching Attacks TamperedChef |
| 2025-07-28
⋅
Invoke RE
⋅
Scavenger Malware Distributed via num2words PyPI Supply Chain Compromise Scavenger |
| 2025-07-20
⋅
Invoke RE
⋅
Scavenger Malware Distributed via eslint-config-prettier NPM Package Supply Chain Compromise Scavenger |
| 2025-07-20
⋅
Invoke RE
⋅
Install Linters, Get Malware - DevSecOps Speedrun Edition Scavenger |
| 2025-07-16
⋅
Mandiant
⋅
Ongoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoor UNC6148 |
| 2025-04-22
⋅
Volexity
⋅
Phishing for Codes: Russian Threat Actors Target Microsoft 365 OAuth Workflows UTA0352 UTA0355 |
| 2025-04-17
⋅
Proofpoint
⋅
Around the World in 90 Days: State-Sponsored Actors Try ClickFix Quasar RAT UNK_RemoteRogue |
| 2025-04-03
⋅
Mandiant
⋅
Suspected China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457) SPAWNSNARE |
| 2025-02-28
⋅
Medium walmartglobaltech
⋅
Agent AI, Basta Parser Extraordinaire Black Basta Black Basta |
| 2025-01-20
⋅
Medium walmartglobaltech
⋅
Qbot is Back.Connect ReedBed UNC4393 |
| 2024-12-19
⋅
Sophos
⋅
Phishing platform Rockstar 2FA trips, and “FlowerStorm” picks up the pieces FlowerStorm |