Click here to download all references as Bib-File.•
| 2026-06-17
⋅
Rapid7
⋅
Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain Unidentified 125 (RAT, Dropping Elephant) |
| 2026-05-13
⋅
Rapid7
⋅
When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise ModeloRAT |
| 2026-03-26
⋅
Rapid7
⋅
BPFdoor in Telecom Networks: Sleeper Cells in the Backbone BPFDoor tsh |
| 2026-03-11
⋅
Rapid7
⋅
Iran’s Cyber Playbook in the Escalating Regional Conflict Cyber Islamic Resistance |
| 2026-02-02
⋅
Rapid7
⋅
The Chrysalis Backdoor: A Deep Dive into Lotus Blossom’s toolkit Chrysalis |
| 2025-12-15
⋅
Rapid7
⋅
SantaStealer is Coming to Town: A New, Ambitious Infostealer Advertised on Underground Forums SantaStealer |
| 2025-10-07
⋅
Rapid7
⋅
Crimson Collective: A New Threat Group Observed Operating in the Cloud |
| 2025-07-03
⋅
Rapid7
⋅
Scattered Spider: Rapid7 Insights, Observations, and Recommendations MimiKatz POORTRY |
| 2025-06-10
⋅
Rapid7
⋅
BlackSuit Continues Social Engineering Attacks in Wake of Black Basta’s Internal Conflict BlackSuit |
| 2025-05-28
⋅
Rapid7
⋅
NSIS Abuse and sRDI Shellcode: Anatomy of the Winos 4.0 Campaign Winos |
| 2024-12-04
⋅
Rapid7
⋅
Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware Black Basta Cobalt Strike DarkGate SystemBC Zloader |
| 2024-11-27
⋅
Rapid7
⋅
New “CleverSoar” Installer Targets Chinese and Vietnamese Users ValleyRAT |
| 2024-11-21
⋅
Rapid7
⋅
A Bag of RATs: VenomRAT vs. AsyncRAT AsyncRAT Venom RAT |
| 2024-08-12
⋅
Rapid7
⋅
Ongoing Social Engineering Campaign Refreshes Payloads Black Basta Cobalt Strike GhostSocks Lumma Stealer SystemBC |
| 2024-07-24
⋅
Rapid7
⋅
Malware Campaign Lures Users With Fake W2 Form Latrodectus |
| 2024-06-17
⋅
Rapid7
⋅
Malvertising Campaign Leads to Execution of Oyster Backdoor Broomstick ChrGetPdsi Stealer |
| 2024-05-10
⋅
Rapid7 Labs
⋅
Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators Black Basta Black Basta Cobalt Strike NetSupportManager RAT |
| 2024-01-17
⋅
Rapid7
⋅
Whispers of Atlantida: Safeguarding Your Digital Treasure Atlantida |
| 2023-08-31
⋅
Rapid7 Labs
⋅
Fake Update Utilizes New IDAT Loader To Execute StealC and Lumma Infostealers FAKEUPDATES Amadey HijackLoader Lumma Stealer SectopRAT |
| 2023-07-13
⋅
Rapid7 Labs
⋅
Old Blackmoon Trojan, NEW Monetization Approach KrBanker |