Click here to download all references as Bib-File.•
| 2026-07-31
⋅
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft ChocoShell CornFlake |
| 2026-06-25
⋅
Microsoft Security
⋅
Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access TonRAT |
| 2026-06-17
⋅
Microsoft
⋅
From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet |
| 2026-06-03
⋅
Microsoft
⋅
How Microsoft names threat actors Wisteria Tsunami |
| 2026-05-28
⋅
eSentire
⋅
Nimbus RAT: How Threat Actors Are Abusing Microsoft Teams and Google Drive to Deploy a Java RAT |
| 2026-05-20
⋅
K7 Security
⋅
Fake Microsoft Teams download sites are being used to deliver ValleyRAT via DLL sideloading ValleyRAT |
| 2026-05-19
⋅
Github (microsoft)
⋅
MSTIC actor name mapping in JSON format Amethyst Rain Houndstooth Typhoon Pinstripe Lightning Storm-0252 Wisteria Tsunami |
| 2026-05-18
⋅
Microsoft
⋅
How Storm-2949 turned a compromised identity into a cloud-wide breach Storm-2949 |
| 2026-05-14
⋅
Microsoft
⋅
Kazuar: Anatomy of a nation-state botnet Kazuar |
| 2026-04-07
⋅
Microsoft
⋅
SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks |
| 2026-03-12
⋅
Microsoft
⋅
Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft Storm-2561 |
| 2026-03-11
⋅
Microsoft
⋅
Contagious Interview: Malware delivered through fake developer job interviews BeaverTail OtterCookie StoatWaffle InvisibleFerret PylangGhost GolangGhost Contagious Interview |
| 2026-03-06
⋅
Microsoft
⋅
AI as tradecraft: How threat actors operationalize AI OtterCookie |
| 2026-03-03
⋅
Microsoft
⋅
Signed malware impersonating workplace apps deploys RMM backdoors TrustConnect RAT |
| 2026-03-02
⋅
Microsoft
⋅
OAuth redirection abuse enables phishing and malware delivery |
| 2026-02-24
⋅
Microsoft
⋅
Developer-targeting campaign using malicious Next.js repositories StoatWaffle |
| 2026-01-20
⋅
Jamf
⋅
Threat Actors Expand Abuse of Microsoft Visual Studio Code StoatWaffle |
| 2026-01-14
⋅
Microsoft
⋅
Inside RedVDS: How a single virtual desktop provider fueled worldwide cybercriminal operations |
| 2025-12-01
⋅
LinkedIn (Microsoft)
⋅
Post about Phishing Campaign pushing XWorm XWorm TA584 |
| 2025-11-28
⋅
OpenSourceMalware
⋅
"Contagious Interview" campaign abuses Microsoft VSCode tasks to drop malware and gain persistence BeaverTail InvisibleFerret |