Click here to download all references as Bib-File.•
| 2026-03-31
⋅
Google
⋅
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack WAVESHAPER |
| 2026-03-04
⋅
EG-FinCirt
⋅
Remcos RAT Operations: How Attackers Gain and Maintain Control Remcos |
| 2026-02-24
⋅
BlueVoyant
⋅
Mercenary Akula Hits Ukraine-Supporting Financial Institution RMS |
| 2026-01-19
⋅
OpenSourceMalware
⋅
Contagious Interview gets an upgrade for 2026 - A comprehensive analysis by OpenSourceMalware OtterCandy |
| 2026-01-12
⋅
Securonix
⋅
SHADOW#REACTOR – Text-Only Staging, .NET Reactor, and In-Memory Remcos RAT Deployment Remcos |
| 2025-11-25
⋅
Arctic Wolf
⋅
Russian RomCom Utilizing SocGholish to Deliver Mythic Agent to U.S. Companies Supporting Ukraine FAKEUPDATES |
| 2025-10-22
⋅
SentinelOne
⋅
PhantomCaptcha | Multi-Stage WebSocket RAT Targets Ukraine in Single-Day Spearphishing Operation Princess |
| 2025-10-10
⋅
McAfee
⋅
Astaroth: Banking Trojan Abusing GitHub for Resilience Astaroth |
| 2025-09-30
⋅
Google
⋅
Cybercrime Observations from the Frontlines: UNC6040 Proactive Hardening Recommendations |
| 2025-09-30
⋅
Elastic
⋅
WARMCOOKIE One Year Later: New Features and Fresh Insights WarmCookie |
| 2025-09-25
⋅
Koi Security
⋅
First Malicious MCP in the Wild: The Postmark Backdoor That's Stealing Your Emails |
| 2025-09-16
⋅
Wiz.io
⋅
Shai-Hulud: Ongoing Package Supply Chain Worm Delivering Data-Stealing Malware Shai-Hulud |
| 2025-09-09
⋅
Positive Technologies
⋅
Phantom pains: a large-scale cyberespionage campaign and a possible split within the PhantomCore APT group PhantomCore |
| 2025-09-02
⋅
At-Bay
⋅
Rhysida: Evading Detection, One Service at a Time Rhysida |
| 2025-08-26
⋅
Google
⋅
Widespread Data Theft Targets Salesforce Instances via Salesloft Drift UNC6395 |
| 2025-08-25
⋅
circleid
⋅
RomCom and TransferLoader IoCs in the Spotlight ROMCOM RAT TransferLoader |
| 2025-08-19
⋅
The Wall Street Journal
⋅
Oregon Man Accused of Operating One of Most Powerful Attack ‘Botnets’ Ever Seen RapperBot |
| 2025-08-11
⋅
ESET Research
⋅
Update WinRAR tools now: RomCom and others exploiting zero-day vulnerability dynamichttp |
| 2025-07-20
⋅
rmceoin.github.io
⋅
Perl based macOS/linux Stealer Pearl Stealer |
| 2025-06-30
⋅
Proofpoint
⋅
10 Things I Hate About Attribution: RomCom vs. TransferLoader DustyHammock MeltingClaw RustyClaw ShadyHammock SlipScreen TransferLoader TA829 |