APT28
Also reported as Sednit, Sofacy, Tsar Team, Forest Blizzard, Swallowtail and 40 other names. Linked to Russia by four sources.
Reports per quarter
Techniques seen in the last two years
- T1566.001 11 reports in ATT&CK
- T1071.001 9 reports in ATT&CK
- T1190 9 reports in ATT&CK
- T1204.002 9 reports in ATT&CK
- T1027 8 reports reports only
- T1041 7 reports reports only
- T1059.003 7 reports in ATT&CK
- T1082 7 reports reports only
- T1059.001 6 reports in ATT&CK
- T1070.004 6 reports in ATT&CK
Show all 320 techniques Show fewer
- T1114.002 6 reports in ATT&CK
- T1140 6 reports in ATT&CK
- T1203 6 reports in ATT&CK
- T1566.002 6 reports reports only
- T1005 5 reports in ATT&CK
- T1053.005 5 reports reports only
- T1057 5 reports in ATT&CK
- T1059 5 reports reports only
- T1090.003 5 reports in ATT&CK
- T1102 5 reports reports only
- T1189 5 reports in ATT&CK
- T1546.015 5 reports in ATT&CK
- T1547.001 5 reports in ATT&CK
- T1583.001 5 reports in ATT&CK
- T1583.006 5 reports in ATT&CK
- T1027.013 4 reports in ATT&CK
- T1059.005 4 reports reports only
- T1071 4 reports reports only
- T1083 4 reports in ATT&CK
- T1091 4 reports in ATT&CK
- T1114 4 reports reports only
- T1119 4 reports in ATT&CK
- T1199 4 reports in ATT&CK
- T1204.001 4 reports in ATT&CK
- T1213 4 reports in ATT&CK
- T1560 4 reports in ATT&CK
- T1567.002 4 reports reports only
- T1573.001 4 reports in ATT&CK
- T1573.002 4 reports reports only
- T1583.003 4 reports in ATT&CK
- T1586.002 4 reports in ATT&CK
- T1012 3 reports reports only
- T1016 3 reports reports only
- T1020 3 reports reports only
- T1036 3 reports in ATT&CK
- T1055 3 reports reports only
- T1056 3 reports reports only
- T1056.001 3 reports in ATT&CK
- T1068 3 reports in ATT&CK
- T1074.001 3 reports in ATT&CK
- T1090 3 reports reports only
- T1098.001 3 reports reports only
- T1105 3 reports in ATT&CK
- T1111 3 reports reports only
- T1113 3 reports in ATT&CK
- T1120 3 reports in ATT&CK
- T1133 3 reports in ATT&CK
- T1137.001 3 reports reports only
- T1210 3 reports in ATT&CK
- T1496 3 reports reports only
- T1497 3 reports reports only
- T1497.001 3 reports reports only
- T1505.003 3 reports in ATT&CK
- T1528 3 reports in ATT&CK
- T1556.006 3 reports reports only
- T1560.001 3 reports in ATT&CK
- T1567 3 reports in ATT&CK
- T1573 3 reports reports only
- T1574.001 3 reports reports only
- T1659 3 reports reports only
- T1003 2 reports in ATT&CK
- T1003.003 2 reports in ATT&CK
- T1010 2 reports reports only
- T1018 2 reports reports only
- T1021.001 2 reports reports only
- T1021.002 2 reports in ATT&CK
- T1021.004 2 reports reports only
- T1037.001 2 reports in ATT&CK
- T1039 2 reports in ATT&CK
- T1040 2 reports in ATT&CK
- T1046 2 reports reports only
- T1047 2 reports reports only
- T1048 2 reports reports only
- T1049 2 reports reports only
- T1053 2 reports reports only
- T1055.002 2 reports reports only
- T1059.006 2 reports reports only
- T1059.007 2 reports reports only
- T1069 2 reports reports only
- T1070 2 reports reports only
- T1070.006 2 reports in ATT&CK
- T1071.003 2 reports in ATT&CK
- T1071.004 2 reports reports only
- T1074.002 2 reports in ATT&CK
- T1078 2 reports in ATT&CK
- T1078.004 2 reports in ATT&CK
- T1087 2 reports reports only
- T1087.002 2 reports reports only
- T1087.003 2 reports reports only
- T1090.002 2 reports in ATT&CK
- T1095 2 reports reports only
- T1098 2 reports reports only
- T1098.002 2 reports in ATT&CK
- T1102.002 2 reports in ATT&CK
- T1104 2 reports reports only
- T1110 2 reports in ATT&CK
- T1110.001 2 reports in ATT&CK
- T1110.003 2 reports in ATT&CK
- T1114.003 2 reports reports only
- T1115 2 reports reports only
- T1125 2 reports reports only
- T1129 2 reports reports only
- T1132.001 2 reports reports only
- T1134.001 2 reports in ATT&CK
- T1136 2 reports reports only
- T1187 2 reports reports only
- T1195 2 reports reports only
- T1204 2 reports reports only
- T1212 2 reports reports only
- T1213.002 2 reports in ATT&CK
- T1218.011 2 reports in ATT&CK
- T1219 2 reports reports only
- T1222 2 reports reports only
- T1485 2 reports reports only
- T1486 2 reports reports only
- T1489 2 reports reports only
- T1490 2 reports reports only
- T1518 2 reports reports only
- T1518.001 2 reports reports only
- T1543 2 reports reports only
- T1546 2 reports reports only
- T1547 2 reports reports only
- T1547.009 2 reports reports only
- T1550.001 2 reports in ATT&CK
- T1550.002 2 reports in ATT&CK
- T1555.003 2 reports reports only
- T1564.001 2 reports in ATT&CK
- T1566 2 reports reports only
- T1566.003 2 reports reports only
- T1566.004 2 reports reports only
- T1572 2 reports reports only
- T1583.004 2 reports reports only
- T1584 2 reports reports only
- T1587.001 2 reports reports only
- T1587.004 2 reports reports only
- T1588.002 2 reports in ATT&CK
- T1591 2 reports in ATT&CK
- T1591.002 2 reports reports only
- T1595 2 reports reports only
- T1595.002 2 reports in ATT&CK
- T1598 2 reports in ATT&CK
- T1598.003 2 reports in ATT&CK
- T1608.001 2 reports reports only
- T1608.003 2 reports reports only
- T1614 2 reports reports only
- T1657 2 reports reports only
- T1001 1 report reports only
- T1001.001 1 report in ATT&CK
- T1003.001 1 report in ATT&CK
- T1003.004 1 report reports only
- T1003.006 1 report reports only
- T1007 1 report reports only
- T1008 1 report reports only
- T1014 1 report in ATT&CK
- T1016.001 1 report reports only
- T1021 1 report reports only
- T1021.005 1 report reports only
- T1021.006 1 report reports only
- T1025 1 report in ATT&CK
- T1027.002 1 report reports only
- T1027.010 1 report reports only
- T1029 1 report reports only
- T1030 1 report in ATT&CK
- T1033 1 report reports only
- T1036.005 1 report in ATT&CK
- T1037 1 report reports only
- T1037.004 1 report reports only
- T1048.002 1 report in ATT&CK
- T1048.003 1 report reports only
- T1053.003 1 report reports only
- T1055.001 1 report reports only
- T1055.003 1 report reports only
- T1055.004 1 report reports only
- T1055.009 1 report reports only
- T1055.012 1 report reports only
- T1056.003 1 report reports only
- T1059.002 1 report reports only
- T1059.004 1 report reports only
- T1059.009 1 report reports only
- T1059.010 1 report reports only
- T1059.011 1 report reports only
- T1069.001 1 report reports only
- T1069.002 1 report reports only
- T1069.003 1 report reports only
- T1072 1 report reports only
- T1074 1 report reports only
- T1087.001 1 report reports only
- T1087.004 1 report reports only
- T1090.001 1 report reports only
- T1092 1 report in ATT&CK
- T1098.003 1 report reports only
- T1098.004 1 report reports only
- T1098.005 1 report reports only
- T1098.006 1 report reports only
- T1098.007 1 report reports only
- T1114.001 1 report reports only
- T1123 1 report reports only
- T1124 1 report reports only
- T1132 1 report reports only
- T1134 1 report reports only
- T1135 1 report reports only
- T1136.001 1 report reports only
- T1136.002 1 report reports only
- T1137 1 report reports only
- T1137.002 1 report in ATT&CK
- T1137.006 1 report reports only
- T1185 1 report reports only
- T1195.002 1 report reports only
- T1200 1 report reports only
- T1201 1 report reports only
- T1211 1 report in ATT&CK
- T1213.001 1 report reports only
- T1213.003 1 report reports only
- T1217 1 report reports only
- T1218.005 1 report reports only
- T1221 1 report in ATT&CK
- T1222.002 1 report reports only
- T1480 1 report reports only
- T1482 1 report reports only
- T1484 1 report reports only
- T1484.001 1 report reports only
- T1491 1 report reports only
- T1491.001 1 report reports only
- T1491.002 1 report reports only
- T1497.003 1 report reports only
- T1498 1 report in ATT&CK
- T1499 1 report reports only
- T1505 1 report reports only
- T1505.004 1 report reports only
- T1529 1 report reports only
- T1530 1 report reports only
- T1534 1 report reports only
- T1537 1 report reports only
- T1538 1 report reports only
- T1539 1 report reports only
- T1542.003 1 report in ATT&CK
- T1543.001 1 report reports only
- T1543.002 1 report reports only
- T1543.003 1 report reports only
- T1543.004 1 report reports only
- T1546.003 1 report reports only
- T1546.004 1 report reports only
- T1546.008 1 report reports only
- T1546.012 1 report reports only
- T1547.002 1 report reports only
- T1547.005 1 report reports only
- T1548 1 report reports only
- T1548.002 1 report reports only
- T1550 1 report reports only
- T1552.006 1 report reports only
- T1554 1 report reports only
- T1556 1 report reports only
- T1556.009 1 report reports only
- T1557 1 report reports only
- T1559 1 report reports only
- T1559.002 1 report in ATT&CK
- T1560.002 1 report reports only
- T1564 1 report reports only
- T1564.003 1 report in ATT&CK
- T1564.004 1 report reports only
- T1565 1 report reports only
- T1565.001 1 report reports only
- T1567.001 1 report reports only
- T1567.004 1 report reports only
- T1569 1 report reports only
- T1569.002 1 report reports only
- T1570 1 report reports only
- T1571 1 report reports only
- T1574 1 report reports only
- T1574.011 1 report reports only
- T1578 1 report reports only
- T1580 1 report reports only
- T1583 1 report reports only
- T1584.001 1 report reports only
- T1584.005 1 report reports only
- T1585 1 report reports only
- T1585.002 1 report reports only
- T1586.003 1 report reports only
- T1587 1 report reports only
- T1587.003 1 report reports only
- T1588 1 report reports only
- T1588.003 1 report reports only
- T1588.004 1 report reports only
- T1588.007 1 report in ATT&CK
- T1589 1 report reports only
- T1589.001 1 report in ATT&CK
- T1589.002 1 report reports only
- T1590.005 1 report reports only
- T1591.004 1 report reports only
- T1592 1 report reports only
- T1592.002 1 report reports only
- T1602 1 report reports only
- T1602.001 1 report reports only
- T1602.002 1 report reports only
- T1608 1 report reports only
- T1608.002 1 report reports only
- T1608.004 1 report reports only
- T1608.005 1 report reports only
- T1608.006 1 report reports only
- T1613 1 report reports only
- T1614.001 1 report reports only
- T1615 1 report reports only
- T1619 1 report reports only
- T1620 1 report reports only
- T1622 1 report reports only
- T1627 1 report reports only
- T1627.001 1 report reports only
- T1652 1 report reports only
- T1654 1 report reports only
- T1665 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2006-2389
- CVE-2006-2492 KEV
- CVE-2006-3439
- CVE-2006-6456
- CVE-2007-0071
- CVE-2007-5633
- CVE-2007-5659 KEV
- CVE-2008-0081
- CVE-2008-0655 KEV
- CVE-2008-1436
- CVE-2008-2551
- CVE-2008-2992 KEV ransomware
Show all 509 CVEs Show fewer
- CVE-2008-3005
- CVE-2008-3431 KEV
- CVE-2008-4250 KEV
- CVE-2008-4841
- CVE-2008-5353
- CVE-2009-0075
- CVE-2009-0556 KEV
- CVE-2009-0563 KEV
- CVE-2009-0658
- CVE-2009-0806
- CVE-2009-0824
- CVE-2009-0927 KEV
- CVE-2009-1129
- CVE-2009-1869
- CVE-2009-3129 KEV
- CVE-2009-3867
- CVE-2009-3957
- CVE-2009-4324 KEV
- CVE-2010-0188 KEV ransomware
- CVE-2010-0232 KEV
- CVE-2010-0249 KEV
- CVE-2010-0806 KEV
- CVE-2010-0840 KEV
- CVE-2010-1240
- CVE-2010-1256
- CVE-2010-1297 KEV
- CVE-2010-1592
- CVE-2010-1885
- CVE-2010-1899
- CVE-2010-2568 KEV
- CVE-2010-2729
- CVE-2010-2730
- CVE-2010-2743
- CVE-2010-2772
- CVE-2010-2883 KEV
- CVE-2010-3333 KEV
- CVE-2010-3336
- CVE-2010-3338
- CVE-2010-3653
- CVE-2010-3654
- CVE-2010-3970
- CVE-2010-3972
- CVE-2010-4091
- CVE-2010-4398 KEV
- CVE-2011-0097
- CVE-2011-0609 KEV
- CVE-2011-0611 KEV
- CVE-2011-1255
- CVE-2011-1823 KEV
- CVE-2011-1980
- CVE-2011-1991
- CVE-2011-2005 KEV
- CVE-2011-2110
- CVE-2011-2462 KEV
- CVE-2011-3402 KEV
- CVE-2011-3544 KEV
- CVE-2011-3874
- CVE-2011-4369
- CVE-2012-0056
- CVE-2012-0158 KEV ransomware
- CVE-2012-0422
- CVE-2012-0506
- CVE-2012-0507 KEV ransomware
- CVE-2012-0754 KEV
- CVE-2012-0779
- CVE-2012-1535 KEV
- CVE-2012-1723 KEV ransomware
- CVE-2012-1823 KEV
- CVE-2012-1856 KEV
- CVE-2012-1875
- CVE-2012-1889 KEV
- CVE-2012-2311
- CVE-2012-2531
- CVE-2012-2532
- CVE-2012-3015
- CVE-2012-4681 KEV ransomware
- CVE-2012-4792 KEV
- CVE-2012-4969 KEV
- CVE-2012-5076 KEV
- CVE-2012-5687
- CVE-2013-0074 KEV ransomware
- CVE-2013-0422 KEV ransomware
- CVE-2013-0640 KEV
- CVE-2013-0641 KEV
- CVE-2013-0808
- CVE-2013-1331 KEV
- CVE-2013-1347 KEV
- CVE-2013-1493
- CVE-2013-2423 KEV
- CVE-2013-2460
- CVE-2013-2551 KEV ransomware
- CVE-2013-2618
- CVE-2013-2729 KEV
- CVE-2013-3346 KEV
- CVE-2013-3660 KEV
- CVE-2013-3893 KEV
- CVE-2013-3896 KEV
- CVE-2013-3897 KEV
- CVE-2013-3906 KEV
- CVE-2013-3918 KEV
- CVE-2013-4979
- CVE-2013-5065 KEV
- CVE-2013-5947
- CVE-2013-7331 KEV
- CVE-2014-0160 KEV
- CVE-2014-0322 KEV
- CVE-2014-0497 KEV
- CVE-2014-0515
- CVE-2014-0751
- CVE-2014-1225
- CVE-2014-1510
- CVE-2014-1511
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-2962
- CVE-2014-3897
- CVE-2014-4019
- CVE-2014-4076
- CVE-2014-4113 KEV
- CVE-2014-4114 KEV
- CVE-2014-6271 KEV
- CVE-2014-6277
- CVE-2014-6278 KEV
- CVE-2014-6324 KEV
- CVE-2014-6332 KEV
- CVE-2014-6352 KEV
- CVE-2014-7169 KEV
- CVE-2014-7186
- CVE-2014-7187
- CVE-2014-8273
- CVE-2014-8361 KEV
- CVE-2014-8439 KEV
- CVE-2014-9583
- CVE-2015-0057
- CVE-2015-0072
- CVE-2015-0096
- CVE-2015-0097
- CVE-2015-0235
- CVE-2015-0310 KEV
- CVE-2015-0311 KEV
- CVE-2015-0313 KEV
- CVE-2015-0336
- CVE-2015-0359
- CVE-2015-0554
- CVE-2015-1635 KEV
- CVE-2015-1641 KEV
- CVE-2015-1642 KEV
- CVE-2015-1671 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-1769 KEV
- CVE-2015-1770 KEV
- CVE-2015-1805
- CVE-2015-2051 KEV
- CVE-2015-2360 KEV
- CVE-2015-2387 KEV
- CVE-2015-2419 KEV
- CVE-2015-2424 KEV
- CVE-2015-2545 KEV
- CVE-2015-2546 KEV ransomware
- CVE-2015-2590 KEV
- CVE-2015-3043 KEV
- CVE-2015-3090
- CVE-2015-3104
- CVE-2015-3105
- CVE-2015-3113 KEV
- CVE-2015-4902 KEV
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-6585
- CVE-2015-7248
- CVE-2015-7254
- CVE-2015-7547
- CVE-2015-7645 KEV ransomware
- CVE-2015-7755 KEV
- CVE-2015-8651 KEV
- CVE-2016-0034 KEV ransomware
- CVE-2016-0040 KEV
- CVE-2016-0147
- CVE-2016-0165 KEV
- CVE-2016-0167 KEV ransomware
- CVE-2016-0189 KEV ransomware
- CVE-2016-0728
- CVE-2016-0984 KEV
- CVE-2016-1010 KEV
- CVE-2016-1019 KEV ransomware
- CVE-2016-10401
- CVE-2016-3298 KEV
- CVE-2016-3353
- CVE-2016-4117 KEV ransomware
- CVE-2016-4119
- CVE-2016-4171 KEV
- CVE-2016-5195 KEV
- CVE-2016-7193 KEV
- CVE-2016-7255 KEV ransomware
- CVE-2016-725521
- CVE-2016-7855 KEV
- CVE-2016-9192
- CVE-2017-0001 KEV
- CVE-2017-0143 KEV ransomware
- CVE-2017-0144 KEV ransomware
- CVE-2017-0146 KEV ransomware
- CVE-2017-0147 KEV ransomware
- CVE-2017-0176
- CVE-2017-0199 KEV ransomware
- CVE-2017-0199192
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-1000353 KEV
- CVE-2017-10271 KEV ransomware
- CVE-2017-11292 KEV
- CVE-2017-11317 KEV
- CVE-2017-11357 KEV ransomware
- CVE-2017-11467
- CVE-2017-11774 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2017-12629
- CVE-2017-12824
- CVE-2017-15906
- CVE-2017-17215
- CVE-2017-18368 KEV
- CVE-2017-2063
- CVE-2017-3197
- CVE-2017-3506 KEV
- CVE-2017-5638 KEV ransomware
- CVE-2017-5689 KEV
- CVE-2017-6190
- CVE-2017-6742 KEV
- CVE-2017-7269 KEV
- CVE-2017-8464 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2017-9248 KEV
- CVE-2017-9822 KEV ransomware
- CVE-2018-0101
- CVE-2018-0171 KEV
- CVE-2018-0296 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-10088
- CVE-2018-1010
- CVE-2018-1012
- CVE-2018-1013
- CVE-2018-1015
- CVE-2018-10561 KEV
- CVE-2018-10562 KEV ransomware
- CVE-2018-11776 KEV
- CVE-2018-13379 KEV ransomware
- CVE-2018-14787
- CVE-2018-15454
- CVE-2018-1579
- CVE-2018-15961 KEV
- CVE-2018-15982 KEV ransomware
- CVE-2018-19320 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-2025036
- CVE-2018-2628 KEV
- CVE-2018-2893
- CVE-2018-4876
- CVE-2018-4878 KEV ransomware
- CVE-2018-5002 KEV
- CVE-2018-5407
- CVE-2018-6055
- CVE-2018-7445 KEV
- CVE-2018-7600 KEV ransomware
- CVE-2018-7602 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8174507
- CVE-2018-8242
- CVE-2018-8345
- CVE-2018-8346
- CVE-2018-8373 KEV
- CVE-2018-8405 KEV ransomware
- CVE-2018-8406 KEV ransomware
- CVE-2018-8414 KEV
- CVE-2018-8440 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2018-8589 KEV
- CVE-2018-8611 KEV
- CVE-2018-8641
- CVE-2018-9866
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0797 KEV
- CVE-2019-0803 KEV ransomware
- CVE-2019-0808 KEV
- CVE-2019-0859 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-1069 KEV ransomware
- CVE-2019-11043 KEV ransomware
- CVE-2019-1132 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-11707 KEV
- CVE-2019-11708 KEV
- CVE-2019-1188
- CVE-2019-1280
- CVE-2019-1367 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-1458 KEV ransomware
- CVE-2019-15126
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-17026 KEV
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-2215 KEV
- CVE-2019-2725 KEV ransomware
- CVE-2019-3568 KEV
- CVE-2019-5786 KEV
- CVE-2019-6225
- CVE-2019-7256 KEV
- CVE-2019-7286 KEV
- CVE-2019-7287 KEV
- CVE-2019-7609 KEV
- CVE-2019-8518
- CVE-2019-9670 KEV
- CVE-2020-0674 KEV
- CVE-2020-0684
- CVE-2020-0688 KEV ransomware
- CVE-2020-0729
- CVE-2020-0787 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-12641 KEV
- CVE-2020-1299
- CVE-2020-13965 KEV
- CVE-2020-1421
- CVE-2020-1472 KEV ransomware
- CVE-2020-1472122
- CVE-2020-14882 KEV
- CVE-2020-15479
- CVE-2020-15480
- CVE-2020-15481
- CVE-2020-15892
- CVE-2020-15893
- CVE-2020-15894
- CVE-2020-15895
- CVE-2020-15896
- CVE-2020-1664
- CVE-2020-17144 KEV
- CVE-2020-28921
- CVE-2020-28922
- CVE-2020-3529
- CVE-2020-35730 KEV
- CVE-2020-3702
- CVE-2020-4006 KEV
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-6418 KEV
- CVE-2020-6819 KEV
- CVE-2020-6820 KEV
- CVE-2020-8467 KEV
- CVE-2020-8468 KEV
- CVE-2021-1636
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-21148 KEV
- CVE-2021-2114810
- CVE-2021-21972 KEV ransomware
- CVE-2021-22205 KEV ransomware
- CVE-2021-26084 KEV ransomware
- CVE-2021-26334
- CVE-2021-26411 KEV ransomware
- CVE-2021-2641111
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-30116 KEV ransomware
- CVE-2021-30665 KEV
- CVE-2021-30666 KEV
- CVE-2021-31195
- CVE-2021-31196 KEV
- CVE-2021-31207 KEV ransomware
- CVE-2021-3156 KEV
- CVE-2021-31979 KEV
- CVE-2021-3197961
- CVE-2021-32648 KEV
- CVE-2021-33766 KEV
- CVE-2021-33771 KEV
- CVE-2021-3377162
- CVE-2021-34448 KEV
- CVE-2021-344486
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-35247 KEV
- CVE-2021-3970
- CVE-2021-3971
- CVE-2021-3972
- CVE-2021-4034 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-40539 KEV ransomware
- CVE-2021-42321 KEV ransomware
- CVE-2021-440077
- CVE-2021-44026 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-44515 KEV
- CVE-2021-44832
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-0609 KEV
- CVE-2022-0847 KEV
- CVE-2022-1040 KEV
- CVE-2022-1388 KEV ransomware
- CVE-2022-20821 KEV
- CVE-2022-21919 KEV
- CVE-2022-22954 KEV ransomware
- CVE-2022-22960 KEV
- CVE-2022-22963 KEV
- CVE-2022-22965 KEV
- CVE-2022-22972
- CVE-2022-26871 KEV
- CVE-2022-27518 KEV
- CVE-2022-27925 KEV ransomware
- CVE-2022-27926 KEV
- CVE-2022-28810 KEV
- CVE-2022-29499 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-3236 KEV
- CVE-2022-37042 KEV ransomware
- CVE-2022-3802
- CVE-2022-38028 KEV
- CVE-2022-40139 KEV
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-41128 KEV
- CVE-2022-41328 KEV
- CVE-2022-41352 KEV ransomware
- CVE-2022-42475 KEV ransomware
- CVE-2022-44698 KEV ransomware
- CVE-2022-45440
- CVE-2022-47966 KEV ransomware
- CVE-2023-20085
- CVE-2023-233397
- CVE-2023-23397 KEV
- CVE-2023-24880 KEV ransomware
- CVE-2023-27532 KEV ransomware
- CVE-2023-2868 KEV
- CVE-2023-28769
- CVE-2023-28770
- CVE-2023-28771 KEV
- CVE-2023-29324
- CVE-2023-34362 KEV ransomware
- CVE-2023-35636
- CVE-2023-36025 KEV
- CVE-2023-36884 KEV ransomware
- CVE-2023-3883
- CVE-2023-38831 KEV ransomware
- CVE-2023-42793 KEV ransomware
- CVE-2023-43770 KEV
- CVE-2023-46805 KEV ransomware
- CVE-2023-48788 KEV ransomware
- CVE-2023-4966 KEV ransomware
- CVE-2023-5631 KEV
- CVE-2024-0012 KEV ransomware
- CVE-2024-11182 KEV
- CVE-2024-1708 KEV ransomware
- CVE-2024-1709 KEV ransomware
- CVE-2024-21410 KEV
- CVE-2024-21412 KEV ransomware
- CVE-2024-21413 KEV
- CVE-2024-21887 KEV ransomware
- CVE-2024-21893 KEV ransomware
- CVE-2024-21983
- CVE-2024-23692 KEV ransomware
- CVE-2024-26229
- CVE-2024-27443 KEV
- CVE-2024-3400 KEV ransomware
- CVE-2024-40766 KEV ransomware
- CVE-2024-42009 KEV
- CVE-2024-4577 KEV ransomware
- CVE-2024-47575 KEV
- CVE-2024-49039 KEV ransomware
- CVE-2024-7262 KEV
- CVE-2024-7263
- CVE-2024-9474 KEV ransomware
- CVE-2024-9680 KEV ransomware
- CVE-2025-0282 KEV ransomware
- CVE-2025-10035 KEV ransomware
- CVE-2025-12562
- CVE-2025-27915 KEV
- CVE-2025-3929
- CVE-2025-49113 KEV
- CVE-2025-49704 KEV ransomware
- CVE-2025-49706 KEV ransomware
- CVE-2025-55182 KEV ransomware
- CVE-2025-5777 KEV ransomware
- CVE-2025-61882 KEV ransomware
- CVE-2025-6218 KEV
- CVE-2025-66376 KEV
- CVE-2025-8088 KEV ransomware
- CVE-2026-1281 KEV
- CVE-2026-1340 KEV
- CVE-2026-21509 KEV
- CVE-2026-8496
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Cozy Bear
Show all 867 reports Show fewer
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor APT 29, Cozy Bear, The Dukes
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor APT 29, Cozy Bear, The Dukes
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Olympic Destroyer (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Olympic Destroyer (Malware Family)
-
Pawn Storm Abuses OAuth In Social Engineering Attacks
The original link failed its last check. Original publisher Detailsfor Pawn Storm Abuses OAuth In Social Engineering Attacks
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
The original link failed its last check. Original publisher Detailsfor Council on Foreign Relations
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor APT 29, Cozy Bear, The Dukes
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Sofacy, APT 28, Fancy Bear, Sednit
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Sofacy, APT 28, Fancy Bear, Sednit
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor VPNFilter (Malware Family)
-
Cyber Caliphate Army (CCA), United Cyber Caliphate (UCC)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Cyber Caliphate Army (CCA), United Cyber Caliphate (UCC)
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor APT28 Targets Hospitality Sector, Presents Threat to Travelers « APT28 Targets Hospitality Sector, Presents Threat to Travelers
-
ITG05 leverages malware arsenal
The original link failed its last check. Original publisher Detailsfor ITG05 leverages malware arsenal
-
APT28’s Campaign Leveraging CVE‑2026‑21509 and Cloud C2 Infrastructure
The original link failed its last check. Original publisher Detailsfor APT28’s Campaign Leveraging CVE‑2026‑21509 and Cloud C2 Infrastructure
-
Pawn Storm Uses Brute Force and Stealth Against High-Value Targets | Trend Micro (US)
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Pawn Storm Uses Brute Force and Stealth Against High-Value Targets | Trend Micro (US)
-
Staying ahead of threat actors in the age of AI _ Microsoft Security Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Staying ahead of threat actors in the age of AI _ Microsoft Security Blog
-
CVE-2024-21412_ Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CVE-2024-21412_ Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day
-
APT28: From Initial Damage to Domain Controller Threats in an Hour
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor APT28: From Initial Damage to Domain Controller Threats in an Hour
-
New UAC-0050 attack using RemcosRAT
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor New UAC-0050 attack using RemcosRAT
-
ITG05 operations leverage Israel-Hamas conflict lures to deliver Headlace malware
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor ITG05 operations leverage Israel-Hamas conflict lures to deliver Headlace malware
-
APT29 attacks Embassies using CVE-2023-38831 - report en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Detailsfor APT29 attacks Embassies using CVE-2023-38831 - report en
-
APT28 leverages multiple phishing techniques to target Ukrainian civil society
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT28 leverages multiple phishing techniques to target Ukrainian civil society
-
Ukraine remains Russia’s biggest cyber focus in 2023
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ukraine remains Russia’s biggest cyber focus in 2023
-
Move, Patch, Get Out the Way- 2022 Zero-Day Exploitation Continues at an Elevated Pace
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Move, Patch, Get Out the Way- 2022 Zero-Day Exploitation Continues at an Elevated Pace
-
PwC Cyber Threats 2022: A Year in Retrospect.pdf
The original link failed its last check. Original publisher Detailsfor PwC Cyber Threats 2022: A Year in Retrospect.pdf
-
Microsoft Security Compliance and Identity
The original link failed its last check. Original publisher Detailsfor Microsoft Security Compliance and Identity
-
Sophisticated APT29 Campaign Abuses Notion API to Target the European Commission
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sophisticated APT29 Campaign Abuses Notion API to Target the European Commission
-
WIP26 Espionage - Threat Actors Abuse Cloud Infrastructure in Targeted Telco Attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor WIP26 Espionage - Threat Actors Abuse Cloud Infrastructure in Targeted Telco Attacks
-
Detailing Daily Domain Hunting
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Detailing Daily Domain Hunting
-
Operation Russiandoll: Adobe & Windows ZeroDay Exploits Likely leveraged By Russia's APT28
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Russiandoll: Adobe & Windows ZeroDay Exploits Likely leveraged By Russia's APT28
-
Conceptualizing a Continuum of Cyber Threat Attribution
The original link failed its last check. Original publisher Detailsfor Conceptualizing a Continuum of Cyber Threat Attribution
-
A Deep Dive Into the APT28’s stealer called CredoMap
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Deep Dive Into the APT28’s stealer called CredoMap
-
APT techniques- Access Token manipulation. Token theft. Simple Cplusplus example.
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT techniques- Access Token manipulation. Token theft. Simple Cplusplus example.
-
In the footsteps of the Fancy Bear- PowerPoint mouse-over event abused to deliver Graphite implants
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor In the footsteps of the Fancy Bear- PowerPoint mouse-over event abused to deliver Graphite implants
-
GRU- Rise of the (Telegram) MinIOns
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor GRU- Rise of the (Telegram) MinIOns
-
The original link failed its last check. Original publisher Detailsfor The Cluster25 Blog - Duskrise
-
Russian Cyberwarfare- Unpacking the Kremlin’s Capabilities
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian Cyberwarfare- Unpacking the Kremlin’s Capabilities
-
Overview of the Cyber Weapons Used in the Ukraine - Russia War
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Overview of the Cyber Weapons Used in the Ukraine - Russia War
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q2 2020
-
Burned and Blinded - Escalation Risks of Intelligence Loss from Countercyber Operations in Crisis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Burned and Blinded - Escalation Risks of Intelligence Loss from Countercyber Operations in Crisis
-
North Korean hackers attack EU targets with Konni RAT malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor North Korean hackers attack EU targets with Konni RAT malware
-
CALISTO continues its credential harvesting campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CALISTO continues its credential harvesting campaign
-
Burrowing your way into VPNs, Proxies, and Tunnels
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Burrowing your way into VPNs, Proxies, and Tunnels
-
Overview of Russian GRU and SVR Cyberespionage Campaigns 1H 2022
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Overview of Russian GRU and SVR Cyberespionage Campaigns 1H 2022
-
Overview of Russian GRU and SVR Cyberespionage Campaigns 1H 2022
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Overview of Russian GRU and SVR Cyberespionage Campaigns 1H 2022
-
Russia’s APT28 uses fear of nuclear war to spread Follina docs in Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russia’s APT28 uses fear of nuclear war to spread Follina docs in Ukraine
-
Growling Bears Make Thunderous Noise
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Growling Bears Make Thunderous Noise
-
THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
The original link failed its last check. Original publisher Detailsfor THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t12022
-
Gamaredon Group Understanding the Russian APT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Gamaredon Group Understanding the Russian APT
-
The IO Offensive Information Operations Surrounding the Russian Invasion of Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The IO Offensive Information Operations Surrounding the Russian Invasion of Ukraine
-
GreyEnergys overlap with Zebrocy.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor GreyEnergys overlap with Zebrocy.pdf
-
Russian Cyber Attack campaigns and actors - NOBELIUM has struck again.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian Cyber Attack campaigns and actors - NOBELIUM has struck again.pdf
-
Russian cyber attack campaigns and actors.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian cyber attack campaigns and actors.pdf
-
UNC3524: Eye Spy on Your Email
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor UNC3524: Eye Spy on Your Email
-
Update on cyber activity in Eastern Europe
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Update on cyber activity in Eastern Europe
-
UNC3524- Eye Spy on Your Email
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor UNC3524- Eye Spy on Your Email
-
UNC3524_ Eye Spy on Your Email _ Mandiant
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor UNC3524_ Eye Spy on Your Email _ Mandiant
-
Russian State-Sponsored and Criminal Cyber .pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian State-Sponsored and Criminal Cyber .pdf
-
Alert (AA22-110A)- Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (AA22-110A)- Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure
-
Zebrocy Malware Technical Analysis Report
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Zebrocy Malware Technical Analysis Report
-
Microsoft Obtains Court Order to Take Down Domains Used to Target Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Obtains Court Order to Take Down Domains Used to Target Ukraine
-
Disrupting cyberattacks targeting Ukraine (APT28)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Disrupting cyberattacks targeting Ukraine (APT28)
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ukraine CyberWar Overview
-
Threat Thursday- Malicious Macros Still Causing Chaos
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Thursday- Malicious Macros Still Causing Chaos
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who is EMBER BEAR-
-
Sandworm- A tale of disruption told anew
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sandworm- A tale of disruption told anew
-
Cyclops Blink Sets Sights on Asus Routers
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cyclops Blink Sets Sights on Asus Routers
-
Cyclops Blink Sets Sights on Asus Routers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyclops Blink Sets Sights on Asus Routers
-
An update on the threat landscape (APT28, UNC1151, MUSTANG PANDA)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor An update on the threat landscape (APT28, UNC1151, MUSTANG PANDA)
-
Responses to Russia's Invasion of Ukraine Likely to Spur Retaliation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Responses to Russia's Invasion of Ukraine Likely to Spur Retaliation
-
Threat Update – Ukraine & Russia conflict
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Update – Ukraine & Russia conflict
-
Shadowserver Special Reports – Cyclops Blink
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shadowserver Special Reports – Cyclops Blink
-
Prime Minister's Office Compromised: Details of Recent Espionage Campaign
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Prime Minister's Office Compromised: Details of Recent Espionage Campaign
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (AA22-047A) Russian State-Sponsored Cyber Actors Target Cleared Defense Contractor Networks to Obtain Sensitive U.S. Defense Information and Technology
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2022GTR
-
The APT Fallout of Vulnerabilities such as ProxyLogon, OGNL Injection, and log4shell
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The APT Fallout of Vulnerabilities such as ProxyLogon, OGNL Injection, and log4shell
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat actor of in-Tur-est
-
Prime Minister’s Office Compromised_ Details of Recent Espionage Campaign
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Prime Minister’s Office Compromised_ Details of Recent Espionage Campaign
-
Prime Minister’s Office Compromised- Details of Recent Espionage Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Prime Minister’s Office Compromised- Details of Recent Espionage Campaign
-
Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation
-
Anticipating Cyber Threats as the Ukraine Crisis Escalates
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Anticipating Cyber Threats as the Ukraine Crisis Escalates
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_jumping_the_air_gap_wp
-
Void Balaur: Tracking a Cybermercenary’s Activities
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Void Balaur: Tracking a Cybermercenary’s Activities
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Technical report Armagedon
-
A step-by-step analysis of the new malware used by APT28_Sofacy called SkinnyBoy – CYBER GEEKS
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor A step-by-step analysis of the new malware used by APT28_Sofacy called SkinnyBoy – CYBER GEEKS
-
Global_APT_Research_Report_for_the_first_half_of_2021-360
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Global_APT_Research_Report_for_the_first_half_of_2021-360
-
Countering threats from Iran (APT35)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Countering threats from Iran (APT35)
-
Google notifies 14,000 Gmail users of targeted APT28 attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Google notifies 14,000 Gmail users of targeted APT28 attacks
-
Microsoft Digital Defense Report OCTOBER 2021
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Digital Defense Report OCTOBER 2021
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
Diving Deep into UNC1151’s Infrastructure- Ghostwriter and beyond
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Diving Deep into UNC1151’s Infrastructure- Ghostwriter and beyond
-
The Ghostwriter Scenario (UNC1151)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Ghostwriter Scenario (UNC1151)
-
A step-by-step analysis of the new malware used by APT28-Sofacy called SkinnyBoy
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A step-by-step analysis of the new malware used by APT28-Sofacy called SkinnyBoy
-
report-old-dogs-new-tricks.pdf
The original link failed its last check. Original publisher Detailsfor report-old-dogs-new-tricks.pdf
-
Targeted Phishing Attack against Ukrainian Government Expands to Georgia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Targeted Phishing Attack against Ukrainian Government Expands to Georgia
-
Ransom DDoS Extortion Actor “Fancy Lazarus” Returns
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransom DDoS Extortion Actor “Fancy Lazarus” Returns
-
Russian hackers breached Dutch police systems in 2017
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian hackers breached Dutch police systems in 2017
-
NobleBaron - New Poisoned Installers Could Be Used In Supply Chain Attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor NobleBaron - New Poisoned Installers Could Be Used In Supply Chain Attacks
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Another Nobelium Cyberattack
-
Elizabethan England has nothing on modern-day Russia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Elizabethan England has nothing on modern-day Russia
-
The original link failed its last check. Original publisher Detailsfor mtrends-2018.pdf
-
Threat Thursday- SombRAT — Always Leave Yourself a Backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Thursday- SombRAT — Always Leave Yourself a Backdoor
-
The original link failed its last check. Original publisher Detailsfor 2021-05_FancyBear
-
A Deep Dive into Zebrocy’s Dropper Docs
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Deep Dive into Zebrocy’s Dropper Docs
-
2021.04.19.A_Deep_Dive_into_Zebrocys_Dropper_Docs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2021.04.19.A_Deep_Dive_into_Zebrocys_Dropper_Docs
-
Intezer-2020-Go-Malware-Round-Up.pdf
The original link failed its last check. Original publisher Detailsfor Intezer-2020-Go-Malware-Round-Up.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor LazyScripter
-
On attribution- APT28, APT29…Turla- No, they are NOT the same
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor On attribution- APT28, APT29…Turla- No, they are NOT the same
-
The Devil’s in the Details- SUNBURST Attribution
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Devil’s in the Details- SUNBURST Attribution
-
ReconHellcat Uses NIST Theme as Lure To Deliver New BlackSoul Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ReconHellcat Uses NIST Theme as Lure To Deliver New BlackSoul Malware
-
quointelligence.eu-ReconHellcat Uses NIST Theme as Lure To Deliver New BlackSoul Malware
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor quointelligence.eu-ReconHellcat Uses NIST Theme as Lure To Deliver New BlackSoul Malware
-
Russian cyber attack campaigns and actors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian cyber attack campaigns and actors
-
Pawn Storm’s Lack of Sophistication as a Strategy
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Pawn Storm’s Lack of Sophistication as a Strategy
-
Russian APT Uses COVID-19 Lures to Deliver Zebrocy - Intezer
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Russian APT Uses COVID-19 Lures to Deliver Zebrocy - Intezer
-
A Zebra in Gopher's Clothing- Russian APT Uses COVID-19 Lures to Deliver Zebrocy
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Zebra in Gopher's Clothing- Russian APT Uses COVID-19 Lures to Deliver Zebrocy
-
Norway says Russian hacking group APT28 is behind August 2020 Parliament hack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Norway says Russian hacking group APT28 is behind August 2020 Parliament hack
-
Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
-
Analyzing Network Infrastructure as Composite Objects
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analyzing Network Infrastructure as Composite Objects
-
Ukraine’s Top Cyber Cop on Defending Against Disinformation and Russian Hackers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ukraine’s Top Cyber Cop on Defending Against Disinformation and Russian Hackers
-
Cyberattacks targeting health care must stop
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyberattacks targeting health care must stop
-
The CostaRicto Campaign- Cyber-Espionage Outsourced
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The CostaRicto Campaign- Cyber-Espionage Outsourced
-
The CostaRicto Campaign_ Cyber-Espionage Outsourced
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The CostaRicto Campaign_ Cyber-Espionage Outsourced
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Enigmatic Energetic Bear
-
Russian hackers targeted California, Indiana Democratic parties
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian hackers targeted California, Indiana Democratic parties
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q32020
-
Exploit Developer Spotlight- The Story of PlayBit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Exploit Developer Spotlight- The Story of PlayBit
-
The Russian Hackers (BERSERK BEAR) Playing 'Chekhov's Gun' With US Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Russian Hackers (BERSERK BEAR) Playing 'Chekhov's Gun' With US Infrastructure
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT28携小众压缩包诱饵对北约、中亚目标的定向攻击分析
-
EU sanctions Russia over 2015 German Parliament hack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor EU sanctions Russia over 2015 German Parliament hack
-
Revisited- Fancy Bear's New Faces...and Sandworms' too
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Revisited- Fancy Bear's New Faces...and Sandworms' too
-
US Indicts Sandworm, Russia's Most Destructive Cyberwar Unit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor US Indicts Sandworm, Russia's Most Destructive Cyberwar Unit
-
MosaicRegressor- Lurking in the Shadows of UEFI
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MosaicRegressor- Lurking in the Shadows of UEFI
-
Graphology of an Exploit – Hunting for exploits by looking for the author’s fingerprints
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Graphology of an Exploit – Hunting for exploits by looking for the author’s fingerprints
-
Russia’s Fancy Bear Hackers Likely Penetrated a US Federal Agency
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russia’s Fancy Bear Hackers Likely Penetrated a US Federal Agency
-
FY20 Microsoft Digital Defense Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor FY20 Microsoft Digital Defense Report
-
Russian hackers use fake NATO training docs to breach govt networks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian hackers use fake NATO training docs to breach govt networks
-
APT28 Delivers Zebrocy Malware Campaign using NATO Theme as Lure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT28 Delivers Zebrocy Malware Campaign using NATO Theme as Lure
-
APT28 Delivers Zebrocy Malware Campaign Using NATO Theme as Lure
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT28 Delivers Zebrocy Malware Campaign Using NATO Theme as Lure
-
New cyberattacks targeting U.S. elections
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New cyberattacks targeting U.S. elections
-
An overview of targeted attacks and APTs on Linux
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor An overview of targeted attacks and APTs on Linux
-
STRONTIUM- Detecting new patterns in credential harvesting
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor STRONTIUM- Detecting new patterns in credential harvesting
-
Lifting the veil on DeathStalker, a mercenary triumvirate _ Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Lifting the veil on DeathStalker, a mercenary triumvirate _ Securelist
-
Lifting the veil on DeathStalker, a mercenary triumvirate
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Lifting the veil on DeathStalker, a mercenary triumvirate
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attribution- A Puzzle
-
APT_trends_report_Q2_2020_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2020_Securelist
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q22020
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q2 2020
-
Russia's GRU Hackers Hit US Government and Energy Targets
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russia's GRU Hackers Hit US Government and Energy Targets
-
Who is behind APT29- What we know about this nation-state cybercrime group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who is behind APT29- What we know about this nation-state cybercrime group
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 游走在东欧和中亚的奇幻熊
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 0628-2020APT上半年报告-画册
-
Looking at Big Threats Using Code Similarity. Part 1
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Looking at Big Threats Using Code Similarity. Part 1
-
Russian Cyber Attack Campaigns and Actors - Threat Research
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Russian Cyber Attack Campaigns and Actors - Threat Research
-
Russian hacker Pavel Sitnikov arrested for sharing malware source code
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian hacker Pavel Sitnikov arrested for sharing malware source code
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor T1055 Process Injection
-
039- Deconstructing the Dukes- A Researcher’s Retrospective of APT29
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 039- Deconstructing the Dukes- A Researcher’s Retrospective of APT29
-
Who Is Dmitry Badin, The GRU Hacker Indicted By Germany Over The Bundestag Hacks-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who Is Dmitry Badin, The GRU Hacker Indicted By Germany Over The Bundestag Hacks-
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Bärenjagd
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q12020
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
APT36 jumps on the coronavirus bandwagon, delivers Crimson RAT _ Malwarebytes Labs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT36 jumps on the coronavirus bandwagon, delivers Crimson RAT _ Malwarebytes Labs
-
cybersecurity-threatscape-2019-q4-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor cybersecurity-threatscape-2019-q4-eng
-
Pawn Storm in 2019: A Year of Scanning and Credential Phishing on High-Profile Targets
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Pawn Storm in 2019: A Year of Scanning and Credential Phishing on High-Profile Targets
-
Report2020CrowdStrikeGlobalThreatReport
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2020CrowdStrikeGlobalThreatReport
-
2020.02.22_APT_threat_report_2019_CN_version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2020.02.22_APT_threat_report_2019_CN_version
-
Drilling Deep: A Look at Cyberattacks on the Oil and Gas Industry
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Drilling Deep: A Look at Cyberattacks on the Oil and Gas Industry
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT28 Attacks Evolution
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor APT Trends Report Q2 2018
-
10-24-2019 - APT28- Targeted attacks against mining corporations in Kazakhstan
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 10-24-2019 - APT28- Targeted attacks against mining corporations in Kazakhstan
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Ghost
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Kittens Are Back in Town 2 - Charming Kitten Campaign Keeps Going on, Using New Impersonation Methods - ClearSky Cyber Security
-
The-Kittens-Are-Back-in-Town-2
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The-Kittens-Are-Back-in-Town-2
-
Mapping the connections inside Russia APT Ecosystem
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Mapping the connections inside Russia APT Ecosystem
-
No summer vacations for Zebrocy
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor No summer vacations for Zebrocy
-
Inside the APT28 DLL Backdoor Blitz
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Inside the APT28 DLL Backdoor Blitz
-
The original link failed its last check. Original publisher Detailsfor Analytics
-
Operation-Taskmasters-2019-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation-Taskmasters-2019-eng
-
APT_trends_report_Q2_2019_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2019_Securelist
-
2019 Cyber Threatscape Report I Accenture
The original link failed its last check. Original publisher Detailsfor 2019 Cyber Threatscape Report I Accenture
-
Corporate IoT – a path to intrusion (APT28-STRONTIUM)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Corporate IoT – a path to intrusion (APT28-STRONTIUM)
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q2 2019
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Flirting With IDA and APT28
-
Threat Group Cards: A Threat Actor Encyclopedia
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Zebrocy Multilanguage Malware Salad
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Zebrocy Multilanguage Malware Salad
-
Zebrocy’s Multilanguage Malware Salad
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Zebrocy’s Multilanguage Malware Salad
-
One year later- The VPNFilter catastrophe that wasn't
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor One year later- The VPNFilter catastrophe that wasn't
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor A journey to Zebrocy land
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A journey to Zebrocy land
-
Malware Against the C Monoculture
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware Against the C Monoculture
-
APT28 and Upcoming Elections- Evidence of Possible Interference (Part II)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT28 and Upcoming Elections- Evidence of Possible Interference (Part II)
-
APT28 and Upcoming Elections Evidence of Possible Interference (Part II)
The original link failed its last check. Detailsfor APT28 and Upcoming Elections Evidence of Possible Interference (Part II)
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
The original link failed its last check. Original publisher Detailsfor rpt-mtrends-2019.pdf
-
mpressioncss_ta_report_2019.pdf
The original link failed its last check. Original publisher Detailsfor mpressioncss_ta_report_2019.pdf
-
New steps to protect customers from hacking
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New steps to protect customers from hacking
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT Trends report Q2 2017
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber Security Report 2019
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor rpt-mtrends-2019
-
2018 APT Summary Report CN version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2018 APT Summary Report CN version
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2018 Master Table
-
GreyEnergy’s overlap with Zebrocy
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor GreyEnergy’s overlap with Zebrocy
-
ENISA Threat Landscape Report 2018
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ENISA Threat Landscape Report 2018
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Zebrocy Go Downloader
-
Let's Learn- In-Depth on APT28-Sofacy Zebrocy Golang Loader
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Let's Learn- In-Depth on APT28-Sofacy Zebrocy Golang Loader
-
Let's Learn In-Depth on APT28Sofacy Zebrocy Golang Loader
The original link failed its last check. Detailsfor Let's Learn In-Depth on APT28Sofacy Zebrocy Golang Loader
-
Sofacy Creates New ‘Go’ Variant of Zebrocy Tool
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sofacy Creates New ‘Go’ Variant of Zebrocy Tool
-
Dear Joohn- The Sofacy Group’s Global Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Dear Joohn- The Sofacy Group’s Global Campaign
-
Seedworm- Group Compromises Government Agencies, Oil & Gas, NGOs, Telecoms, and IT Firms
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Seedworm- Group Compromises Government Agencies, Oil & Gas, NGOs, Telecoms, and IT Firms
-
Snakemackerel delivers Zekapab malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Snakemackerel delivers Zekapab malware
-
Snakemackerel delivers Zekapab malware I Accenture
The original link failed its last check. Original publisher Detailsfor Snakemackerel delivers Zekapab malware I Accenture
-
Let's Learn- In-Depth on Sofacy Cannon Loader-Backdoor Review
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Let's Learn- In-Depth on Sofacy Cannon Loader-Backdoor Review
-
Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan
-
Sednit- What’s going on with Zebrocy-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sednit- What’s going on with Zebrocy-
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CozyBear – In from the Cold-
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Threat Actor TEMP.Periscope Targets UK-Based Engineering Company Using Russian APT Techniques
-
Octopus-infested seas of Central Asia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Octopus-infested seas of Central Asia
-
Russian-language actor exploits hype over Telegram ban in Central Asia
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Russian-language actor exploits hype over Telegram ban in Central Asia
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cobalt Group 2.0
-
APT28- New Espionage Operations Target Military and Government Organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT28- New Espionage Operations Target Military and Government Organizations
-
Indicators of Compromise for Malware used by APT28
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Indicators of Compromise for Malware used by APT28
-
APT28 Uses LoJax, First UEFI Rootkit Seen in the Wild
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT28 Uses LoJax, First UEFI Rootkit Seen in the Wild
-
LoJax- First UEFI rootkit found in the wild, courtesy of the Sednit group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor LoJax- First UEFI rootkit found in the wild, courtesy of the Sednit group
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET-LoJax
-
Silence: Moving into the darkside
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Silence: Moving into the darkside
-
HITB-SG-2018-E - In the trails of WINDSHIFT [Autosaved]
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor HITB-SG-2018-E - In the trails of WINDSHIFT [Autosaved]
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Remember Fancy Bear-
-
Microsoft claims win over 'Russian political hackers'
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft claims win over 'Russian political hackers'
-
Microsoft Disrupts APT28 Hacking Campaign Aimed at US Midterm Elections
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Disrupts APT28 Hacking Campaign Aimed at US Midterm Elections
-
We are taking new steps against broadening threats to democracy
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor We are taking new steps against broadening threats to democracy
-
20180713_CSE_APT28_X-Agent_Op-Roman Holiday-Report_v6_1
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 20180713_CSE_APT28_X-Agent_Op-Roman Holiday-Report_v6_1
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Trends Report Q2 2018
-
adobe-flash-zero-day-targeted-attack
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor adobe-flash-zero-day-targeted-attack
-
Sofacy Group’s Parallel Attacks - Palo Alto Networks Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Sofacy Group’s Parallel Attacks - Palo Alto Networks Blog
-
Sofacy Group’s Parallel Attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sofacy Group’s Parallel Attacks
-
APT28 Rollercoaster- The Lowdown on Hijacked Lo
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT28 Rollercoaster- The Lowdown on Hijacked Lo
-
VPNFilter EXIF to C2 mechanism analysed
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor VPNFilter EXIF to C2 mechanism analysed
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Justice Department Announces Actions to Disrupt Advanced Persistent Threat 28 Botnet of Infected Routers and Network Storage Devices
-
Swedish sports body says anti-doping unit hit by hacking attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Swedish sports body says anti-doping unit hit by hacking attack
-
Russian hackers posed as IS to threaten military wives
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian hackers posed as IS to threaten military wives
-
Who's who in the Zoo - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Who's who in the Zoo - Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Lojack Becomes a Double-Agent
-
Lojack Becomes a Double-Agent | NETSCOUT
The original link failed its last check. Original publisher Detailsfor Lojack Becomes a Double-Agent | NETSCOUT
-
Zebrocy used heavily by the Sednit group over last two years
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Zebrocy used heavily by the Sednit group over last two years
-
Sednit update- Analysis of Zebrocy
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sednit update- Analysis of Zebrocy
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Trends report Q1 2018
-
Masha and these Bears - 2018 Sofacy Activity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Masha and these Bears - 2018 Sofacy Activity
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor masha-and-these-bears
-
OlympicDestroyer is here to trick the industry
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OlympicDestroyer is here to trick the industry
-
OlympicDestroyer is here to trick the industry - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor OlympicDestroyer is here to trick the industry - Securelist
-
Sofacy Attacks Multiple Government Entities
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Sofacy Attacks Multiple Government Entities
-
ukatemicrysys_territorialdispute
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ukatemicrysys_territorialdispute
-
Sofacy Attacks Multiple Government Entities
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sofacy Attacks Multiple Government Entities
-
A Slice of 2017 Sofacy Activity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Slice of 2017 Sofacy Activity
-
A Slice of 2017 Sofacy Activity - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor A Slice of 2017 Sofacy Activity - Securelist
-
Threat Group APT28 Slips Office Malware into Doc Citing NYC Terror Attack
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Threat Group APT28 Slips Office Malware into Doc Citing NYC Terror Attack
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Update on Pawn Storm: New Targets and Politically Motivated Campaigns - TrendLabs Security Intelligence Blog
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor New KillDisk Variant Hits Financial Organizations in Latin America - TrendLabs Security Intelligence Blog
-
Update on Pawn Storm: New Targets and Politically Motivated Campaigns
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Update on Pawn Storm: New Targets and Politically Motivated Campaigns
-
Hack Brief- Russian Hackers Release Apparent IOC Emails in Wake of Olympic Ban
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hack Brief- Russian Hackers Release Apparent IOC Emails in Wake of Olympic Ban
-
Sednit update- How Fancy Bear Spent the Year
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sednit update- How Fancy Bear Spent the Year
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Advanced Persistent Threat Groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threat Groups
-
Threat Group APT28 Slips Office Malware into Doc Citing NYC Terror Attack
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group APT28 Slips Office Malware into Doc Citing NYC Terror Attack
-
russian-federation-country-profile.pdf
The original link failed its last check. Original publisher Detailsfor russian-federation-country-profile.pdf
-
Introducing WhiteBear - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Introducing WhiteBear - Securelist
-
“Cyber Conflict” Decoy Document Used In Real Cyber Conflict
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor “Cyber Conflict” Decoy Document Used In Real Cyber Conflict
-
Cyber Conflict Decoy Document Used In Real Cyber Conflict
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Cyber Conflict Decoy Document Used In Real Cyber Conflict
-
APT28 racing to exploit CVE-2017-11292 Flash vulnerability before patches are deployed
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT28 racing to exploit CVE-2017-11292 Flash vulnerability before patches are deployed
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Introducing WhiteBear
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Introducing WhiteBear
-
Cyberespionage Group Turla Deploys Backdoor Ahead of G20 Task Force Summit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyberespionage Group Turla Deploys Backdoor Ahead of G20 Task Force Summit
-
Analysis of APT28 hospitality malware (Part 2)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis of APT28 hospitality malware (Part 2)
-
APT28 Targets Hospitality Sector, Presents Threat to Travelers « Threat Research Blog | FireEye Inc
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT28 Targets Hospitality Sector, Presents Threat to Travelers « Threat Research Blog | FireEye Inc
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Threat Group-4127 Targets Google Accounts | Secureworks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group-4127 Targets Google Accounts | Secureworks
-
The New and Improved macOS Backdoor from OceanLotus - Palo Alto Networks Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The New and Improved macOS Backdoor from OceanLotus - Palo Alto Networks Blog
-
Open Source Malware - Sharing is caring?
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Open Source Malware - Sharing is caring?
-
Open Source Malware - Sharing is caring-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Open Source Malware - Sharing is caring-
-
TAINTED LEAKS Disinformation and Phishing With a Russian Nexus
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor TAINTED LEAKS Disinformation and Phishing With a Russian Nexus
-
Sednit adds two zero‑day exploits using ‘Trump’s attack on Syria’ as a decoy
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sednit adds two zero‑day exploits using ‘Trump’s attack on Syria’ as a decoy
-
Snake- Coming soon in Mac OS X flavour
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Snake- Coming soon in Mac OS X flavour
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Update on the Fancy Bear Android malware (poprd30.apk)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Update on the Fancy Bear Android malware (poprd30.apk)
-
The Deception Project: A New Japanese-Centric Threat
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor The Deception Project: A New Japanese-Centric Threat
-
The Deception Project- A New Japanese-Centric Threat
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Deception Project- A New Japanese-Centric Threat
-
Bear Spotting Vol. 1: Russian Nation State Targeting of Government and Military Interests
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Bear Spotting Vol. 1: Russian Nation State Targeting of Government and Military Interests
-
Threat Group-4127 Targets Google Accounts
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Threat Group-4127 Targets Google Accounts
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor MacProStorage:_2017Final:Bitdefender-Whitepaper-APT-Mac-A4-en_EN:Bitdefender-Whitepaper-APT-Mac-A4-en_EN.indd
-
Part I. Russian APT - APT28 collection of samples including OSX XAgent
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Part I. Russian APT - APT28 collection of samples including OSX XAgent
-
XAgentOSX- Sofacy’s XAgent macOS Tool
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor XAgentOSX- Sofacy’s XAgent macOS Tool
-
Enhanced Analysis of GRIZZLY STEPPE Activity
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Enhanced Analysis of GRIZZLY STEPPE Activity
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor [tr1adx]_ Intel
-
At the Center of the Storm: Russia's APT28 Strategically Evolves its Cyber Operations
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor At the Center of the Storm: Russia's APT28 Strategically Evolves its Cyber Operations
-
Technical details on the Fancy Bear Android malware (poprd30.apk)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Technical details on the Fancy Bear Android malware (poprd30.apk)
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Mac Malware of 2016
-
GRIZZLY STEPPE - Russian Malicious Cyber Activity
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor GRIZZLY STEPPE - Russian Malicious Cyber Activity
-
Bear Hunting Season: Tracking APT28
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Bear Hunting Season: Tracking APT28
-
Use of Fancy Bear Android Malware tracking of Ukrainian Artillery Units
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Use of Fancy Bear Android Malware tracking of Ukrainian Artillery Units
-
Danger Close: Fancy Bear Tracking of Ukrainian Field Artillery Units
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Danger Close: Fancy Bear Tracking of Ukrainian Field Artillery Units
-
Russia Hacks Bellingcat MH17 Investigation _ ThreatConnect
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Russia Hacks Bellingcat MH17 Investigation _ ThreatConnect
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor TrendLabs Security Intelligence BlogBLACKGEAR Espionage Campaign Evolves, Adds Japan To Target List - TrendLabs Security Intelligence Blog
-
Let It Ride- The Sofacy Group’s DealersChoice Attacks Continue
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Let It Ride- The Sofacy Group’s DealersChoice Attacks Continue
-
Let It Ride: The Sofacy Group's DealersChoice Attacks Continue
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Let It Ride: The Sofacy Group's DealersChoice Attacks Continue
-
Microsoft_Security_Intelligence_Report_Volume_21_English
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft_Security_Intelligence_Report_Volume_21_English
-
Threat Group 4127 Targets Hillary Clinton Presidential Campaign
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Threat Group 4127 Targets Hillary Clinton Presidential Campaign
-
En Route with Sednit Part 2: Observing the Comings and Goings
The link to Mirror on Box failed its last check. Detailsfor En Route with Sednit Part 2: Observing the Comings and Goings
-
En Route with Sednit Part 2: Observing the Comings and Goings
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor En Route with Sednit Part 2: Observing the Comings and Goings
-
En Route with Sednit Part 1: Approaching the Target
The link to Mirror on Box failed its last check. Detailsfor En Route with Sednit Part 1: Approaching the Target
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Belling the BEAR
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Sofacy's Komplex OS X Trojan
-
‘DealersChoice’ is Sofacy’s Flash Player Exploit Platform
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ‘DealersChoice’ is Sofacy’s Flash Player Exploit Platform
-
How France's TV5 was almost destroyed by 'Russian hackers'
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How France's TV5 was almost destroyed by 'Russian hackers'
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Belling the BEAR
-
Komplex Mac backdoor answers old questions
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Komplex Mac backdoor answers old questions
-
Sofacy’s ‘Komplex’ OS X Trojan - Palo Alto Networks BlogPalo Alto Networks Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Sofacy’s ‘Komplex’ OS X Trojan - Palo Alto Networks BlogPalo Alto Networks Blog
-
Sofacy’s ‘Komplex’ OS X Trojan
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sofacy’s ‘Komplex’ OS X Trojan
-
Hackers lurking, parliamentarians told _ News _ DW _ 20.09.2016
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hackers lurking, parliamentarians told _ News _ DW _ 20.09.2016
-
Hackers lurking, parliamentarians told
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hackers lurking, parliamentarians told
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
En Route with Sednit Part 3: A Mysterious Downloader
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor En Route with Sednit Part 3: A Mysterious Downloader
-
Bartholomew-GuerreroSaade-VB2016.indd
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Bartholomew-GuerreroSaade-VB2016.indd
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Russian hackers 'Fancy Bear' likely breached Olympic drug-testing agency and DNC, experts say
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian hackers 'Fancy Bear' likely breached Olympic drug-testing agency and DNC, experts say
-
Russian_Cyber_Operations_On_Steroids
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Russian_Cyber_Operations_On_Steroids
-
Running for Office_ Russian APT Toolkits Revealed
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Running for Office_ Russian APT Toolkits Revealed
-
En Route with Sednit Part 1: Approaching the Target
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor En Route with Sednit Part 1: Approaching the Target
-
Bears in the Midst_ Intrusion into the Democratic National Committee »
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Bears in the Midst_ Intrusion into the Democratic National Committee »
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Please Read
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Russian government hackers penetrated DNC, stole opposition research on Trump - The Washington Post
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Russian government hackers penetrated DNC, stole opposition research on Trump - The Washington Post
-
Findings from Analysis of DNC Intrusion Malware
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Findings from Analysis of DNC Intrusion Malware
-
Threat Group 4127 Targets Hillary Clinton Presidential Campaign | SecureWorks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group 4127 Targets Hillary Clinton Presidential Campaign | SecureWorks
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Visiting The Bear Den A Journey in the Land of (Cyber-)Espionage
The link to Mirror on Box failed its last check. Detailsfor Visiting The Bear Den A Journey in the Land of (Cyber-)Espionage
-
Threat Group-4127 Targets Hillary Clinton Presidential Campaign
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Threat Group-4127 Targets Hillary Clinton Presidential Campaign
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor PowerPoint Presentation
-
Bears in the Midst- Intrusion into the Democratic National Committee
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Bears in the Midst- Intrusion into the Democratic National Committee
-
New Sofacy Attacks Against US Government Agency
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor New Sofacy Attacks Against US Government Agency
-
New Sofacy Attacks Against US Government Agency
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Sofacy Attacks Against US Government Agency
-
Bears in the Midst: Intrusion into the Democratic National Committee
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Bears in the Midst: Intrusion into the Democratic National Committee
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Keep Calm and (Don’t) Enable Macros- A New Threat Actor Targets UAE Dissidents
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Keep Calm and (Don’t) Enable Macros- A New Threat Actor Targets UAE Dissidents
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Stealth Falcon
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor TrendLabs Security Intelligence BlogIXESHE Derivative IHEATE Targets Users in America - TrendLabs Security Intelligence Blog
-
Operation C-Major Actors Also Used Android BlackBerry Mobile Spyware Against Targets
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Operation C-Major Actors Also Used Android BlackBerry Mobile Spyware Against Targets
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
The original link failed its last check. Original publisher Detailsfor ib-entertainment.pdf
-
Looking Into a Cyber-Attack Facilitator in the Netherlands
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Looking Into a Cyber-Attack Facilitator in the Netherlands
-
Looking Into a Cyber-Attack Facilitator in the Netherlands (Appendix)
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Looking Into a Cyber-Attack Facilitator in the Netherlands (Appendix)
-
A Look Into Fysbis: Sofacy's Linux Backdoor
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor A Look Into Fysbis: Sofacy's Linux Backdoor
-
Russian Police Prevented Massive Banking Sector Cyber Attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian Police Prevented Massive Banking Sector Cyber Attack
-
A Look Into Fysbis: Sofacy’s Linux Backdoor - Palo Alto Networks BlogPalo Alto Networks Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor A Look Into Fysbis: Sofacy’s Linux Backdoor - Palo Alto Networks BlogPalo Alto Networks Blog
-
A Look Into Fysbis- Sofacy’s Linux Backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Look Into Fysbis- Sofacy’s Linux Backdoor
-
Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2015年中国高持续性威胁(APT)研究报告
-
Конференция UISGCON11. Итоги по киберугрозам в Украине в 2015 году | CyS Centrum
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Конференция UISGCON11. Итоги по киберугрозам в Украине в 2015 году | CyS Centrum
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Black Atlas Endangers In-Store Card Payments and SMBs Worldwide; Switches between BlackPOS and Other Tools
-
Bitdefender_In-depth_analysis_of_APT28__The_Political_Cyber-Espionage
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Bitdefender_In-depth_analysis_of_APT28__The_Political_Cyber-Espionage
-
Operation Black Atlas: How Cybercriminals Used Gorynych Botnet, BlackPOS, and other Malware
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Black Atlas: How Cybercriminals Used Gorynych Botnet, BlackPOS, and other Malware
-
Sofacy APT hits high profile targets with updated toolset - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Sofacy APT hits high profile targets with updated toolset - Securelist
-
Sofacy APT hits high profile targets with updated toolset
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sofacy APT hits high profile targets with updated toolset
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Cyber war in perspective: Russian aggression against Ukraine
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Cyber war in perspective: Russian aggression against Ukraine
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Introducing LogPOS
-
Microsoft Security Intelligence Report (Volume 19)
The link to Mirror on Box failed its last check. Detailsfor Microsoft Security Intelligence Report (Volume 19)
-
Microsoft PowerPoint - CCT-W08_Evolving-Threats-Dissection-of-a-Cyber-Espionage-Attack.pptx
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft PowerPoint - CCT-W08_Evolving-Threats-Dissection-of-a-Cyber-Espionage-Attack.pptx
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor rpt-witchcoven
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Pawn Storm Targets MH17 Investigation Team
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Pawn Storm Targets MH17 Investigation Team
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
New Adobe Flash Zero-Day Used in Pawn Storm Campaign Targeting Foreign Affairs Ministries
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Adobe Flash Zero-Day Used in Pawn Storm Campaign Targeting Foreign Affairs Ministries
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Operation Iron Tiger: Exploring Chinese Cyber-Espionage Attacks on United States Defense Contractors
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Iron Tiger: Exploring Chinese Cyber-Espionage Attacks on United States Defense Contractors
-
The Dukes: 7 years of Russian cyberespionage
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Dukes: 7 years of Russian cyberespionage
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Fancy Bear
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Fancy Bear
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Fancy Bear
-
New Spear Phishing Campaign Pretends to be EFF
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Spear Phishing Campaign Pretends to be EFF
-
Islamic State Hacking Division
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Islamic State Hacking Division
-
Islamic State Hacking Division
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Islamic State Hacking Division
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor HTExploitTelemetry
-
An In-Depth Look at How Pawn Storm’s Java Zero-Day Was Used
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor An In-Depth Look at How Pawn Storm’s Java Zero-Day Was Used
-
Sednit APT Group Meets Hacking Team
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sednit APT Group Meets Hacking Team
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Digital Attack on German Parliament- Investigative Report on the Hack of the Left Party Infrastructure in Bundestag
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor R9b_FSOFACY_0
-
APT28 Targets Financial Markets: Zero Day Hashes Released
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT28 Targets Financial Markets: Zero Day Hashes Released
-
APT28 Targets Financial Markets
The original link failed its last check. Detailsfor APT28 Targets Financial Markets
-
Sofacy II_ Same Sofacy, Different Day
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Sofacy II_ Same Sofacy, Different Day
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation RussianDoll- Adobe & Windows Zero-Day Exploits Likely Leveraged by Russia’s APT28 in Highly-Targeted Attack
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
The original link failed its last check. Original publisher Detailsfor rpt-m-trends-2015.pdf
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Global Threat Intel Report
-
Pawn Storm Update- iOS Espionage App Found
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Pawn Storm Update- iOS Espionage App Found
-
Pawn Storm Update: iOS Espionage App Found
The original link failed its last check. Original publisher Detailsfor Pawn Storm Update: iOS Espionage App Found
-
Pawn Storm Update: iOS Espionage App Found
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Pawn Storm Update: iOS Espionage App Found
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor apt28
-
APT28: A Window into Russia’s Cyber Espionage Operations? | FireEye
The original link failed its last check. Original publisher Detailsfor APT28: A Window into Russia’s Cyber Espionage Operations? | FireEye
-
The original link failed its last check. Original publisher Detailsfor APT28 Report | FireEye
-
Operation Pawn Storm: Using Decoys to Evade Detection
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Pawn Storm: Using Decoys to Evade Detection
-
Tactical Intelligence Bulletin Sofacy Phishing
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Tactical Intelligence Bulletin Sofacy Phishing
-
OPERATION QUANTUM ENTANGLEMENT
The original link failed its last check. Original publisher Detailsfor OPERATION QUANTUM ENTANGLEMENT
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
Newest first. Details opens the report in Explore.