Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2026-06-16 ⋅ BlueVoyant ⋅ Joshua Green, Thomas Elkins
Lorem Ipsum Revisited
Lorem Ipsum
2026-05-04 ⋅ BlueVoyant ⋅ Joshua Green, Thomas Elkins
Lorem Ipsum Malware: Trojanized MS Teams Installers Deliver Multi-Stage Loader and Backdoor
Lorem Ipsum
2026-04-15 ⋅ Orange Cyberdefense ⋅ Alexis Bonnefoi, Marine PICHON, Thomas Brossard
Smoking Out an Affiliate: SmokedHam, Qilin, a few Google Ads and some Bossware
Qilin AgendaCrypt SMOKEDHAM
2026-04-15 ⋅ Orange Cyberdefense ⋅ Alexis Bonnefoi, Marine PICHON, Thomas Brossard
Smoking Out an Affiliate: SmokedHam, Qilin, a few Google ads and some bossware
AgendaCrypt SMOKEDHAM
2026-01-21 ⋅ Team Cymru ⋅ william thomas
Scattered Spider Attacks | Infrastructure and TTP Analysis
2025-02-27 ⋅ BushidoToken ⋅ william thomas
BlackBasta Leaks: Lessons from the Ascension Health attack
Black Basta
2024-09-10 ⋅ Palo Alto Networks Unit 42 ⋅ Jerome Tujague, Navin Thomas
Threat Assessment: Repellent Scorpius, Distributors of Cicada3301 Ransomware
Cicada3301
2024-08-02 ⋅ Volexity ⋅ Ankur Saini, Paul Rascagnères, Steven Adair, Thomas Lancaster
StormBamboo Compromises ISP to Abuse Insecure Software Update Mechanisms
CDDS DUSTPAN MgBot
2024-05-10 ⋅ Rapid7 Labs ⋅ Evan McCann, Thomas Elkins, Tyler McGraw
Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators
Black Basta Black Basta Cobalt Strike NetSupportManager RAT
2024-03-31 ⋅ Twitter (@fr0gger) ⋅ Thomas Roccia
Tweet with visual summary of the execution flow
xzbot
2024-01-10 ⋅ Volexity ⋅ Matthew Meltzer, Robert Jan Mora, Sean Koessel, Steven Adair, Thomas Lancaster
Active Exploitation of Two Zero-Day Vulnerabilities in Ivanti Connect Secure VPN
UTA0178
2023-11-21 ⋅ Trellix ⋅ Ciana Driscoll, Ernesto Fernández Provecho, Pham Duy Phuc, Vinoo Thomas
The Continued Evolution of the DarkGate Malware-as-a-Service
DarkGate
2023-08-31 ⋅ Rapid7 Labs ⋅ Evan McCann, Natalie Zargarov, Thomas Elkins, Tyler McGraw
Fake Update Utilizes New IDAT Loader To Execute StealC and Lumma Infostealers
FAKEUPDATES Amadey HijackLoader Lumma Stealer SectopRAT
2023-08-30 ⋅ Forbes ⋅ Thomas Brewster
A Fake Signal App Was Planted On Google Play By China-Linked Hackers
2023-05-14 ⋅ unfinished.bike ⋅ Thomas Strömberg
Fun with the new bpfdoor (2023)
BPFDoor
2023-05-10 ⋅ Github (MythicAgents) ⋅ Cody Thomas
Github Repository for Nimplant
Nimplant
2023-05-10 ⋅ Github (MythicAgents) ⋅ Cody Thomas
Github Repository for Poseidon
Poseidon Poseidon
2023-03-30 ⋅ Volexity ⋅ Ankur Saini, Callum Roxan, Charlie Gardner, Paul Rascagnères, Steven Adair, Thomas Lancaster
3CX Supply Chain Compromise Leads to ICONIC Incident
3CX Backdoor IconicStealer
2022-12-05 ⋅ Accenture ⋅ Paul Mansfield, Thomas Willkan
Popularity spikes for information stealer malware on the dark web
MetaStealer Rhadamanthys
2022-11-21 ⋅ BSides Sydney ⋅ Thomas Roccia
X-Ray of Malware Evasion Techniques - Analysis, Dissection, Cure?
Emotet