Click here to download all references as Bib-File.•
| 2026-06-17
⋅
Rapid7
⋅
Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain Unidentified 125 (RAT, Dropping Elephant) |
| 2026-05-13
⋅
Rapid7
⋅
When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise ModeloRAT |
| 2026-04-23
⋅
Sentinel LABS
⋅
fast16 | Mystery ShadowBrokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet fast16 |
| 2026-01-02
⋅
Synthient
⋅
A Broken System Fueling Botnets Kimwolf Aisuru |
| 2025-12-09
⋅
Huntress Labs
⋅
AMOS Stealer Exploits AI Trust: Malware Delivered Through ChatGPT and Grok AMOS |
| 2025-07-21
⋅
AhnLab
⋅
RokRAT Malware Using Malicious Hangul (.HWP) Documents RokRAT |
| 2025-05-31
⋅
The Insider
⋅
Hidden Bear: The GRU hackers of Russia’s most notorious kill squad |
| 2025-05-28
⋅
Rapid7
⋅
NSIS Abuse and sRDI Shellcode: Anatomy of the Winos 4.0 Campaign Winos |
| 2025-04-23
⋅
Cisco Talos
⋅
Introducing ToyMaker, an initial access broker working in cahoots with double extortion gangs HOLERUN |
| 2025-02-20
⋅
Cyber Security News
⋅
APT-C-28 Group Launched New Cyber Attack With Fileless RokRat Malware RokRAT |
| 2024-11-21
⋅
Rapid7
⋅
A Bag of RATs: VenomRAT vs. AsyncRAT AsyncRAT Venom RAT |
| 2024-08-14
⋅
Kroll
⋅
REDLINESTEALER Malware Driving the Initial Access Broker Market RedLine Stealer |
| 2024-06-24
⋅
CySecurity News
⋅
Infamous Hacker IntelBroker Breaches Apple's Security, Leaks Internal Tool Source Code IntelBroker |
| 2024-05-13
⋅
Malsada Tech
⋅
Gootloader Isn’t Broken GootLoader |
| 2024-05-07
⋅
AhnLab
⋅
LNK File Disguised as Certificate Distributing RokRAT Malware RokRAT |
| 2024-04-17
⋅
Mandiant
⋅
Unearthing APT44: Russia’s Notorious Cyber Sabotage Unit Sandworm Sandworm |
| 2024-04-16
⋅
Mandiant
⋅
APT44: Unearthing Sandworm VPNFilter BlackEnergy CaddyWiper EternalPetya HermeticWiper Industroyer INDUSTROYER2 Olympic Destroyer PartyTicket RoarBAT Sandworm |
| 2024-03-21
⋅
Mandiant
⋅
Bringing Access Back — Initial Access Brokers Exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect GOREVERSE SNOWLIGHT Sliver UNC5174 |
| 2024-03-21
⋅
Mandiant
⋅
Bringing Access Back — Initial Access Brokers Exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect GOREVERSE SNOWLIGHT |
| 2024-03-01
⋅
0x0v1
⋅
APT37's ROKRAT HWP Object Linking and Embedding RokRAT |