Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2026-10-01 ⋅ Proofpoint ⋅ Mark Kelly, Proofpoint Threat Research Team
Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles
Evilginx TA419
2026-08-27 ⋅ Proofpoint ⋅ Kyle Cucci, Proofpoint Threat Research Team, Rob Kinner, Tony Robinson
Carry-On Compromise: TA4922 Packs PackClient
donut_injector
2026-07-07 ⋅ Proofpoint ⋅ Greg Lesnewich, Mark Kelly, Proofpoint Threat Research Team
One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation
IceCube
2026-06-03 ⋅ Proofpoint ⋅ Proofpoint Threat Research Team
TA4922: The Suspected Chinese Crime Group is Going Global
Atlas RAT RomulusLoader SilentRunLoader TA4922
2026-01-28 ⋅ Proofpoint ⋅ Proofpoint Threat Research Team
Can’t stop, won’t stop: TA584 innovates initial access
XWorm TA584
2026-01-22 ⋅ Red Asgard ⋅ Red Asgard Threat Research Team
Hunting Lazarus Part II: When the Dead Drop Moved to the Blockchain
StoatWaffle
2026-01-16 ⋅ sysdig ⋅ Sysdig Threat Research Team
VoidLink threat analysis: Sysdig discovers C2-compiled kernel rootkits
VoidLink
2025-12-18 ⋅ Proofpoint ⋅ Proofpoint Threat Research Team
Access granted: phishing with device code authorization for account takeover
TA2723 UNK_AcademicFlare
2025-12-16 ⋅ sysdig ⋅ Sysdig Threat Research Team
EtherRAT dissected: How a React2Shell implant delivers 5 payloads through blockchain C2
EtherRAT
2025-12-08 ⋅ sysdig ⋅ Sysdig Threat Research Team
EtherRAT: DPRK uses novel Ethereum implant in React2Shell attacks
EtherRAT
2025-11-04 ⋅ Twitter (@nextronresearch) ⋅ Nextron Threat Research Team
Tweet about BQT ransomware on Linux
BQTlock
2025-10-14 ⋅ Reliaquest ⋅ RELIAQUEST THREAT RESEARCH TEAM
SOE-phisticated Persistence: Inside Flax Typhoon's ArcGIS Compromise
2025-10-13 ⋅ Proofpoint ⋅ Kyle Cucci, Proofpoint Threat Research Team, Selena Larson, Tommy Madjar
When the monster bytes: tracking TA585 and its arsenal
MonsterV2
2025-09-16 ⋅ Proofpoint ⋅ Greg Lesnewich, Mark Kelly, Nick Attfield, Proofpoint Threat Research Team
Going Underground: China-aligned TA415 Conducts U.S.-China Economic Relations Targeting Using VS Code Remote Tunnels
2025-09-03 ⋅ Proofpoint ⋅ Kyle Cucci, Proofpoint Threat Research Team, Rob Kinner
Not Safe for Work: Tracking and Investigating Stealerium and Phantom Infostealers
Phantom Stealer Stealerium
2025-07-16 ⋅ Proofpoint ⋅ Mark Kelly, Proofpoint Threat Research Team
Phish and Chips: China-Aligned Espionage Actors Ramp Up Taiwan Semiconductor Industry Targeting
Cobalt Strike Voldemort UNK_DropPitch UNK_FistBump UNK_SparkyCarp
2025-07-14 ⋅ Arda Büyükkaya ⋅ EclecticIQ Threat Research Team
GLOBAL GROUP: Emerging Ransomware-as-a-Service, Supporting AI Driven Negotiation and Mobile Control Panel for Their Affiliates
Global BlackLock
2025-06-30 ⋅ Proofpoint ⋅ David Galazin, Greg Lesnewich, Kelsey Merriman, Proofpoint Threat Research Team, Selena Larson
10 Things I Hate About Attribution: RomCom vs. TransferLoader
DustyHammock MeltingClaw RustyClaw ShadyHammock SlipScreen TransferLoader TA829
2025-06-16 ⋅ Proofpoint ⋅ Jeremy Hedges, Proofpoint Threat Research Team, Tommy Madjar
Amatera Stealer: Rebranded ACR Stealer With Improved Evasion, Sophistication
ACR Stealer Amatera
2025-06-05 ⋅ Reliaquest ⋅ RELIAQUEST THREAT RESEARCH TEAM
Scattered Spider Targets Tech Companies for Help-Desk Exploitation