Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2022-06-16 ⋅ SophosLabs Uncut ⋅ Andrew Brandt
Confluence exploits used to drop ransomware on vulnerable servers
Cerber
2022-02-23 ⋅ SophosLabs Uncut ⋅ Andrew Brandt
Dridex bots deliver Entropy ransomware in recent attacks
Cobalt Strike Dridex Entropy
2021-11-18 ⋅ SophosLabs Uncut ⋅ Sean Gallagher
New ransomware actor uses password protected archives to bypass encryption protection
2021-11-11 ⋅ SophosLabs Uncut ⋅ Andrew Brandt
BazarLoader ‘call me back’ attack abuses Windows 10 Apps mechanism
BazarBackdoor
2021-07-09 ⋅ Twitter (@SophosLabs) ⋅ SophosLabs
Tweet on speed at which Kaseya REvil attack was conducted
REvil
2021-07-05 ⋅ Twitter (@SophosLabs) ⋅ SophosLabs
Tweet with a REvil ransomware execution demo
REvil
2021-06-11 ⋅ SophosLabs Uncut ⋅ Anand Ajjan, Andrew Brandt, Hajnalka Kope, Mark Loman, Peter Mackenzie
Relentless REvil, revealed: RaaS as variable as the criminals who use it
REvil
2021-05-28 ⋅ SophosLabs Uncut ⋅ Andrew Brandt
A new ransomware enters the fray: Epsilon Red
Epsilon Red
2021-05-07 ⋅ SophosLabs Uncut ⋅ Rajesh Nataraj
New Lemon Duck variants exploiting Microsoft Exchange Server
CHINACHOPPER Cobalt Strike Lemon Duck
2021-05-05 ⋅ SophosLabs Uncut ⋅ Andrew Brandt, Gabor Szappanos, Peter Mackenzie, Vikas Singh
Intervention halts a ProxyLogon-enabled attack
Cobalt Strike
2021-04-21 ⋅ SophosLabs Uncut ⋅ Anand Aijan, Andrew Brandt, Markel Picado, Michael Wood, Sean Gallagher, Sivagnanam Gn, Suriya Natarajan
Nearly half of malware now use TLS to conceal communications
Agent Tesla Cobalt Strike Dridex SystemBC
2021-04-15 ⋅ SophosLabs Uncut ⋅ Andrew Brandt
BazarLoader deploys a pair of novel spam vectors
BazarBackdoor
2021-04-13 ⋅ SophosLabs Uncut ⋅ Andrew Brandt
Compromised Exchange server hosting cryptojacker targeting other Exchange servers
2021-03-24 ⋅ SophosLabs Uncut ⋅ Mark Loman
Black Kingdom ransomware begins appearing on Exchange servers
2021-02-16 ⋅ SophosLabs Uncut ⋅ Peter Mackenzie, Tilly Travers
What to expect when you’ve been hit with Conti ransomware
Conti
2021-02-16 ⋅ SophosLabs Uncut ⋅ Anand Ajjan, Andrew Brandt
Conti ransomware: Evasive by nature
Conti
2021-02-16 ⋅ SophosLabs Uncut ⋅ Michael Heller
A Conti ransomware attack day-by-day
Conti
2021-01-26 ⋅ SophosLabs Uncut ⋅ Bill Kearney, David Anderson, Michael Heller, Peter Mackenzie, Sergio Bestulic
Nefilim Ransomware Attack Uses “Ghost” Credentials
Nefilim
2020-12-21 ⋅ SophosLabs Uncut ⋅ SophosLabs Threat Research
How SunBurst malware does defense evasion
SUNBURST UNC2452
2020-12-16 ⋅ SophosLabs Uncut ⋅ Sean Gallagher, Sivagnanam Gn
Ransomware operators use SystemBC RAT as off-the-shelf Tor backdoor
SystemBC