Click here to download all references as Bib-File.•
| 2026-02-05
⋅
Symantec
⋅
Black Basta: Defense Evasion Capability Embedded in Ransomware Payload Black Basta |
| 2026-01-30
⋅
LevelBlue
⋅
19 Shades of LockBit5.0, Inside the Latest Cross-Platform Ransomware: Part 1 LockBit LockBit |
| 2026-01-28
⋅
Hunt.io
⋅
Exposed Open Directory Leaks a Full BYOB Deployment Across Windows, Linux, and macOS |
| 2026-01-12
⋅
Securonix
⋅
SHADOW#REACTOR – Text-Only Staging, .NET Reactor, and In-Memory Remcos RAT Deployment Remcos |
| 2025-11-02
⋅
Symantec
⋅
Multi-Stage In-Memory Agent Tesla Campaign Targets LATAM Agent Tesla |
| 2025-10-15
⋅
Symantec
⋅
Jewelbug: Chinese APT Group Widens Reach to Russia REF7707 |
| 2025-09-03
⋅
Darkrym
⋅
PXA Stealers Evolution to PureRAT: Part 6 - Finally, the Final Stage PureRAT (Stage 9) PureRAT |
| 2025-08-31
⋅
Darkrym
⋅
PXA Stealers Evolution to PureRAT: Part 3 - Weaponised Python Stage (Stage 5) PXA Stealer |
| 2025-08-19
⋅
IBM X-Force
⋅
IBM X-Force Threat Analysis: QuirkyLoader - A new malware loader delivering infostealers and RATs QuirkyLoader |
| 2025-06-20
⋅
K7 Security
⋅
SpyMax SpyMax |
| 2025-06-18
⋅
Elastic
⋅
A Wretch Client: From ClickFix deception to information stealer deployment HijackLoader Lumma Stealer SectopRAT |
| 2025-06-12
⋅
Symantec
⋅
Fog Ransomware: Unusual Toolset Used in Recent Attack Fog |
| 2025-05-02
⋅
Arctic Wolf
⋅
Venom Spider Uses Server-Side Polymorphism to Weave a Web Around Victims More_eggs |
| 2025-04-25
⋅
Twitter (@teamcymru_S2)
⋅
Tweet on North Korean Cyber Ops Leveraging Russian Infrastructure |
| 2025-04-23
⋅
Cisco Talos
⋅
Introducing ToyMaker, an initial access broker working in cahoots with double extortion gangs HOLERUN |
| 2025-04-10
⋅
Symantec
⋅
Shuckworm Targets Foreign Military Mission Based in Ukraine |
| 2025-04-08
⋅
Team Cymru
⋅
Inside DanaBot’s Infrastructure: In Support of Operation Endgame II DanaBot |
| 2025-04-08
⋅
Trustwave
⋅
A deep Dive into the Leaked Black Basta Chat Logs Black Basta Black Basta |
| 2025-02-21
⋅
cyjax
⋅
How’s that for a malicious Linkc, new group launches DLS LinkC Pub |
| 2025-02-20
⋅
Trend Micro
⋅
Updated Shadowpad Malware Leads to Ransomware Deployment EvilExtractor PlugX ShadowPad Teleboyi |