Click here to download all references as Bib-File.

Enter keywords to filter the library entries below or Propose new Entry
2026-07-31Microsoft Threat Intelligence
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
ChocoShell CornFlake
2026-06-25Microsoft SecurityMicrosoft Defender Experts, Microsoft Defender Security Research Team, Parth Jomadkar
Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access
TonRAT
2026-06-17MicrosoftMicrosoft Defender Research Team
From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet
2026-06-03MicrosoftMicrosoft
How Microsoft names threat actors
Wisteria Tsunami
2026-05-28eSentireeSentire
Nimbus RAT: How Threat Actors Are Abusing Microsoft Teams and Google Drive to Deploy a Java RAT
2026-05-20K7 SecuritySrinivasan E
Fake Microsoft Teams download sites are being used to deliver ValleyRAT via DLL sideloading
ValleyRAT
2026-05-19Github (microsoft)Microsoft
MSTIC actor name mapping in JSON format
Amethyst Rain Houndstooth Typhoon Pinstripe Lightning Storm-0252 Wisteria Tsunami
2026-05-18MicrosoftMicrosoft Defender Security Research Team
How Storm-2949 turned a compromised identity into a cloud-wide breach
Storm-2949
2026-05-14MicrosoftMicrosoft Threat Intelligence
Kazuar: Anatomy of a nation-state botnet
Kazuar
2026-04-07MicrosoftMicrosoft Threat Intelligence
SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks
2026-03-12MicrosoftMicrosoft Threat Intelligence
Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft
Storm-2561
2026-03-11MicrosoftMicrosoft Defender Experts, Microsoft Defender Security Research Team
Contagious Interview: Malware delivered through fake developer job interviews
BeaverTail OtterCookie StoatWaffle InvisibleFerret PylangGhost GolangGhost Contagious Interview
2026-03-06MicrosoftMicrosoft Threat Intelligence
AI as tradecraft: How threat actors operationalize AI
OtterCookie
2026-03-03MicrosoftMicrosoft
Signed malware impersonating workplace apps deploys RMM backdoors
TrustConnect RAT
2026-03-02MicrosoftMicrosoft Defender Security Research Team
OAuth redirection abuse enables phishing and malware delivery
2026-02-24MicrosoftMicrosoft Defender Experts
Developer-targeting campaign using malicious Next.js repositories
StoatWaffle
2026-01-20JamfThijs Xhaflaire
Threat Actors Expand Abuse of Microsoft Visual Studio Code
StoatWaffle
2026-01-14MicrosoftMicrosoft Threat Intelligence
Inside RedVDS: How a single virtual desktop provider fueled worldwide cybercriminal operations
2025-12-01LinkedIn (Microsoft)Microsoft Threat Intelligence
Post about Phishing Campaign pushing XWorm
XWorm TA584
2025-11-28OpenSourceMalwareOpenSourceMalware
"Contagious Interview" campaign abuses Microsoft VSCode tasks to drop malware and gain persistence
BeaverTail InvisibleFerret