Carbanak
Also reported as Carbon Spider, ELBRUS, Sangria Tempest, Anunak, FIN7 and 9 other names. Sources disagree on the origin.
Reports per quarter
Techniques seen in the last two years
- T1057 9 reports reports only
- T1105 9 reports reports only
- T1053.005 8 reports reports only
- T1059.001 8 reports reports only
- T1059.003 8 reports reports only
- T1082 8 reports reports only
- T1016 6 reports reports only
- T1027 6 reports reports only
- T1071.001 6 reports reports only
- T1140 6 reports reports only
Show all 277 techniques Show fewer
- T1190 6 reports reports only
- T1204.002 6 reports reports only
- T1219 6 reports in ATT&CK
- T1018 5 reports reports only
- T1047 5 reports reports only
- T1068 5 reports reports only
- T1136.001 5 reports reports only
- T1566.001 5 reports reports only
- T1003.001 4 reports reports only
- T1005 4 reports reports only
- T1021.001 4 reports reports only
- T1033 4 reports reports only
- T1041 4 reports reports only
- T1071 4 reports reports only
- T1136 4 reports reports only
- T1189 4 reports reports only
- T1482 4 reports reports only
- T1518.001 4 reports reports only
- T1543.003 4 reports in ATT&CK
- T1566 4 reports reports only
- T1572 4 reports reports only
- T1007 3 reports reports only
- T1012 3 reports reports only
- T1036.005 3 reports in ATT&CK
- T1046 3 reports reports only
- T1055.002 3 reports reports only
- T1059 3 reports reports only
- T1059.005 3 reports reports only
- T1069.002 3 reports reports only
- T1070.004 3 reports reports only
- T1078 3 reports in ATT&CK
- T1083 3 reports reports only
- T1087.001 3 reports reports only
- T1087.002 3 reports reports only
- T1132.001 3 reports reports only
- T1204 3 reports reports only
- T1486 3 reports reports only
- T1505.003 3 reports reports only
- T1566.002 3 reports reports only
- T1570 3 reports reports only
- T1571 3 reports reports only
- T1574.001 3 reports reports only
- T1583.003 3 reports reports only
- T1620 3 reports reports only
- T1003 2 reports reports only
- T1003.002 2 reports reports only
- T1003.003 2 reports reports only
- T1008 2 reports reports only
- T1021 2 reports reports only
- T1021.002 2 reports reports only
- T1027.009 2 reports reports only
- T1036 2 reports reports only
- T1049 2 reports reports only
- T1053 2 reports reports only
- T1053.003 2 reports reports only
- T1055 2 reports reports only
- T1055.004 2 reports reports only
- T1056.001 2 reports reports only
- T1059.006 2 reports reports only
- T1059.007 2 reports reports only
- T1069.001 2 reports reports only
- T1071.004 2 reports reports only
- T1090 2 reports reports only
- T1090.001 2 reports reports only
- T1095 2 reports reports only
- T1098 2 reports reports only
- T1098.007 2 reports reports only
- T1104 2 reports reports only
- T1112 2 reports reports only
- T1119 2 reports reports only
- T1124 2 reports reports only
- T1129 2 reports reports only
- T1133 2 reports reports only
- T1134.002 2 reports reports only
- T1135 2 reports reports only
- T1203 2 reports reports only
- T1217 2 reports reports only
- T1496 2 reports reports only
- T1497.001 2 reports reports only
- T1505.004 2 reports reports only
- T1547.001 2 reports reports only
- T1548 2 reports reports only
- T1555.003 2 reports reports only
- T1560 2 reports reports only
- T1560.001 2 reports reports only
- T1566.004 2 reports reports only
- T1567 2 reports reports only
- T1569.002 2 reports reports only
- T1573.001 2 reports reports only
- T1583 2 reports reports only
- T1583.001 2 reports reports only
- T1583.004 2 reports reports only
- T1587.001 2 reports reports only
- T1590 2 reports reports only
- T1595 2 reports reports only
- T1595.002 2 reports reports only
- T1598 2 reports reports only
- T1608 2 reports reports only
- T1608.001 2 reports reports only
- T1608.002 2 reports reports only
- T1608.006 2 reports reports only
- T1649 2 reports reports only
- T1010 1 report reports only
- T1016.001 1 report reports only
- T1020 1 report reports only
- T1021.004 1 report reports only
- T1021.005 1 report reports only
- T1021.006 1 report reports only
- T1027.007 1 report reports only
- T1036.003 1 report reports only
- T1037 1 report reports only
- T1037.001 1 report reports only
- T1039 1 report reports only
- T1040 1 report reports only
- T1048 1 report reports only
- T1055.001 1 report reports only
- T1055.003 1 report reports only
- T1055.009 1 report reports only
- T1055.012 1 report reports only
- T1056 1 report reports only
- T1059.002 1 report reports only
- T1059.004 1 report reports only
- T1059.009 1 report reports only
- T1059.010 1 report reports only
- T1059.011 1 report reports only
- T1069 1 report reports only
- T1069.003 1 report reports only
- T1070 1 report reports only
- T1072 1 report reports only
- T1074 1 report reports only
- T1074.001 1 report reports only
- T1074.002 1 report reports only
- T1078.002 1 report reports only
- T1078.003 1 report reports only
- T1078.004 1 report reports only
- T1087 1 report reports only
- T1087.004 1 report reports only
- T1090.003 1 report reports only
- T1091 1 report reports only
- T1098.001 1 report reports only
- T1098.003 1 report reports only
- T1098.004 1 report reports only
- T1098.005 1 report reports only
- T1098.006 1 report reports only
- T1102 1 report reports only
- T1102.002 1 report in ATT&CK
- T1113 1 report reports only
- T1114 1 report reports only
- T1114.001 1 report reports only
- T1114.002 1 report reports only
- T1114.003 1 report reports only
- T1115 1 report reports only
- T1120 1 report reports only
- T1123 1 report reports only
- T1125 1 report reports only
- T1132 1 report reports only
- T1132.002 1 report reports only
- T1134 1 report reports only
- T1134.001 1 report reports only
- T1136.002 1 report reports only
- T1137 1 report reports only
- T1137.006 1 report reports only
- T1195 1 report reports only
- T1195.001 1 report reports only
- T1195.002 1 report reports only
- T1199 1 report reports only
- T1200 1 report reports only
- T1201 1 report reports only
- T1204.001 1 report reports only
- T1204.004 1 report reports only
- T1210 1 report reports only
- T1213 1 report reports only
- T1213.001 1 report reports only
- T1213.002 1 report reports only
- T1213.003 1 report reports only
- T1218.007 1 report reports only
- T1484 1 report reports only
- T1484.001 1 report reports only
- T1485 1 report reports only
- T1489 1 report reports only
- T1490 1 report reports only
- T1491.002 1 report reports only
- T1497 1 report reports only
- T1497.003 1 report reports only
- T1498 1 report reports only
- T1505 1 report reports only
- T1518 1 report reports only
- T1526 1 report reports only
- T1528 1 report reports only
- T1529 1 report reports only
- T1530 1 report reports only
- T1534 1 report reports only
- T1537 1 report reports only
- T1538 1 report reports only
- T1543 1 report reports only
- T1543.002 1 report reports only
- T1543.004 1 report reports only
- T1546 1 report reports only
- T1546.003 1 report reports only
- T1546.004 1 report reports only
- T1546.008 1 report reports only
- T1546.012 1 report reports only
- T1546.015 1 report reports only
- T1547 1 report reports only
- T1547.002 1 report reports only
- T1547.005 1 report reports only
- T1547.009 1 report reports only
- T1548.002 1 report reports only
- T1550 1 report reports only
- T1550.001 1 report reports only
- T1550.002 1 report reports only
- T1552 1 report reports only
- T1554 1 report reports only
- T1555 1 report reports only
- T1556 1 report reports only
- T1556.006 1 report reports only
- T1556.009 1 report reports only
- T1558.003 1 report reports only
- T1559 1 report reports only
- T1560.002 1 report reports only
- T1563.002 1 report reports only
- T1564.004 1 report reports only
- T1565 1 report reports only
- T1565.001 1 report reports only
- T1566.003 1 report reports only
- T1567.001 1 report reports only
- T1567.002 1 report reports only
- T1569 1 report reports only
- T1573 1 report reports only
- T1573.002 1 report reports only
- T1574 1 report reports only
- T1574.011 1 report reports only
- T1578 1 report reports only
- T1580 1 report reports only
- T1583.006 1 report reports only
- T1584 1 report reports only
- T1584.004 1 report reports only
- T1585 1 report reports only
- T1585.002 1 report reports only
- T1586.002 1 report reports only
- T1587 1 report reports only
- T1587.003 1 report reports only
- T1588 1 report reports only
- T1588.002 1 report in ATT&CK
- T1588.003 1 report reports only
- T1588.004 1 report reports only
- T1588.007 1 report reports only
- T1589.002 1 report reports only
- T1590.005 1 report reports only
- T1592 1 report reports only
- T1595.001 1 report reports only
- T1602 1 report reports only
- T1602.001 1 report reports only
- T1602.002 1 report reports only
- T1608.003 1 report reports only
- T1608.004 1 report reports only
- T1608.005 1 report reports only
- T1613 1 report reports only
- T1614 1 report reports only
- T1614.001 1 report reports only
- T1615 1 report reports only
- T1619 1 report reports only
- T1621 1 report reports only
- T1622 1 report reports only
- T1652 1 report reports only
- T1654 1 report reports only
- T1657 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-1999-0191
- CVE-1999-0262
- CVE-2008-2938
- CVE-2008-3431 KEV
- CVE-2008-4250 KEV
- CVE-2010-0232 KEV
- CVE-2010-2861 KEV ransomware
- CVE-2010-4398 KEV
- CVE-2011-1255
- CVE-2011-3402 KEV
- CVE-2012-0151 KEV
- CVE-2012-0158 KEV ransomware
Show all 312 CVEs Show fewer
- CVE-2012-1823 KEV
- CVE-2012-1856 KEV
- CVE-2012-2311
- CVE-2012-2539 KEV
- CVE-2012-5687
- CVE-2013-0640 KEV
- CVE-2013-3660 KEV
- CVE-2013-3893 KEV
- CVE-2013-3900 KEV
- CVE-2013-3906 KEV
- CVE-2013-4979
- CVE-2013-5947
- CVE-2014-0160 KEV
- CVE-2014-0497 KEV
- CVE-2014-1225
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-1812 KEV ransomware
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-4113 KEV
- CVE-2014-4114 KEV
- CVE-2014-4404 KEV
- CVE-2014-6332 KEV
- CVE-2014-6352 KEV
- CVE-2014-8361 KEV
- CVE-2014-8439 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-1130 KEV
- CVE-2015-1635 KEV
- CVE-2015-1641 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-1770 KEV
- CVE-2015-2051 KEV
- CVE-2015-2291 KEV ransomware
- CVE-2015-2360 KEV
- CVE-2015-2387 KEV
- CVE-2015-2419 KEV
- CVE-2015-2426 KEV
- CVE-2015-2545 KEV
- CVE-2015-3105
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-6585
- CVE-2015-7248
- CVE-2015-7254
- CVE-2015-7645 KEV ransomware
- CVE-2015-8651 KEV
- CVE-2016-0034 KEV ransomware
- CVE-2016-0147
- CVE-2016-0167 KEV ransomware
- CVE-2016-0189 KEV ransomware
- CVE-2016-0984 KEV
- CVE-2016-1010 KEV
- CVE-2016-1019 KEV ransomware
- CVE-2016-4117 KEV ransomware
- CVE-2016-4171 KEV
- CVE-2016-5165
- CVE-2016-5195 KEV
- CVE-2017-0143 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0199192
- CVE-2017-01996
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-10271 KEV ransomware
- CVE-2017-1099
- CVE-2017-11292 KEV
- CVE-2017-11774 KEV
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-118827
- CVE-2017-12149 KEV ransomware
- CVE-2017-12611
- CVE-2017-12824
- CVE-2017-15399
- CVE-2017-15944 KEV
- CVE-2017-17215
- CVE-2017-5638 KEV ransomware
- CVE-2017-6327 KEV
- CVE-2017-6328
- CVE-2017-8291 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2017-9805 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-0824 KEV
- CVE-2018-1010
- CVE-2018-1012
- CVE-2018-1013
- CVE-2018-1015
- CVE-2018-10562 KEV ransomware
- CVE-2018-11776 KEV
- CVE-2018-1207
- CVE-2018-13379 KEV ransomware
- CVE-2018-14787
- CVE-2018-15961 KEV
- CVE-2018-15982 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-4878 KEV ransomware
- CVE-2018-5407
- CVE-2018-7445 KEV
- CVE-2018-7600 KEV ransomware
- CVE-2018-7602 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8174507
- CVE-2018-8373 KEV
- CVE-2018-8405 KEV ransomware
- CVE-2018-8406 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2018-8581 KEV ransomware
- CVE-2018-8611 KEV
- CVE-2018-8639 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0803 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-11580 KEV ransomware
- CVE-2019-1322 KEV ransomware
- CVE-2019-1405 KEV ransomware
- CVE-2019-1458 KEV ransomware
- CVE-2019-15126
- CVE-2019-1579 KEV ransomware
- CVE-2019-16098
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-16920 KEV
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-3396 KEV ransomware
- CVE-2019-3398 KEV
- CVE-2019-5591 KEV ransomware
- CVE-2019-8394 KEV
- CVE-2019-9621 KEV
- CVE-2020-0601 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0787 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-10198
- CVE-2020-1040 KEV
- CVE-2020-116511
- CVE-2020-11652 KEV
- CVE-2020-11899 KEV
- CVE-2020-12641 KEV
- CVE-2020-1350 KEV
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-14750 KEV
- CVE-2020-14871 KEV
- CVE-2020-14882 KEV
- CVE-2020-15892
- CVE-2020-15893
- CVE-2020-15894
- CVE-2020-15895
- CVE-2020-15896
- CVE-2020-1599
- CVE-2020-1664
- CVE-2020-17144 KEV
- CVE-2020-2021 KEV ransomware
- CVE-2020-3125
- CVE-2020-3529
- CVE-2020-35730 KEV
- CVE-2020-3702
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-6789
- CVE-2020-7961 KEV
- CVE-2020-8243 KEV
- CVE-2020-8260 KEV
- CVE-2020-8515 KEV
- CVE-2021-1636
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-1844
- CVE-2021-1879 KEV
- CVE-2021-20016 KEV ransomware
- CVE-2021-21166 KEV
- CVE-2021-22894 KEV
- CVE-2021-22899 KEV
- CVE-2021-22900 KEV
- CVE-2021-22941 KEV ransomware
- CVE-2021-26084 KEV ransomware
- CVE-2021-26411 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-26868
- CVE-2021-27065 KEV ransomware
- CVE-2021-27857
- CVE-2021-27876 KEV ransomware
- CVE-2021-27877 KEV ransomware
- CVE-2021-27878 KEV ransomware
- CVE-2021-29855
- CVE-2021-30116 KEV ransomware
- CVE-2021-30551 KEV
- CVE-2021-31195
- CVE-2021-31196 KEV
- CVE-2021-31206
- CVE-2021-31207 KEV ransomware
- CVE-2021-3156 KEV
- CVE-2021-33742 KEV
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-35464 KEV ransomware
- CVE-2021-36798
- CVE-2021-36934 KEV
- CVE-2021-36942 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-40449 KEV ransomware
- CVE-2021-40539 KEV ransomware
- CVE-2021-4104
- CVE-2021-41379 KEV ransomware
- CVE-2021-42278 KEV ransomware
- CVE-2021-42287 KEV ransomware
- CVE-2021-42321 KEV ransomware
- CVE-2021-43890 KEV ransomware
- CVE-2021-44026 KEV
- CVE-2021-44077 KEV
- CVE-2021-44207 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-44515 KEV
- CVE-2021-44832
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-21587 KEV ransomware
- CVE-2022-21882 KEV ransomware
- CVE-2022-22954 KEV ransomware
- CVE-2022-22957
- CVE-2022-22958
- CVE-2022-24500
- CVE-2022-24521 KEV ransomware
- CVE-2022-24682 KEV ransomware
- CVE-2022-24934
- CVE-2022-26134 KEV ransomware
- CVE-2022-26809
- CVE-2022-26923 KEV
- CVE-2022-27924 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-30333 KEV ransomware
- CVE-2022-31199 KEV ransomware
- CVE-2022-37042 KEV ransomware
- CVE-2022-37969 KEV ransomware
- CVE-2022-41080 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2023-0669 KEV ransomware
- CVE-2023-21715 KEV
- CVE-2023-21746
- CVE-2023-22518 KEV ransomware
- CVE-2023-22527 KEV ransomware
- CVE-2023-23376 KEV ransomware
- CVE-2023-23397 KEV
- CVE-2023-24880 KEV ransomware
- CVE-2023-27350 KEV ransomware
- CVE-2023-27532 KEV ransomware
- CVE-2023-27997 KEV ransomware
- CVE-2023-28252 KEV ransomware
- CVE-2023-28461 KEV ransomware
- CVE-2023-32315 KEV
- CVE-2023-34362 KEV ransomware
- CVE-2023-3466
- CVE-2023-3467
- CVE-2023-3519 KEV ransomware
- CVE-2023-36033 KEV
- CVE-2023-38831 KEV ransomware
- CVE-2023-45727 KEV
- CVE-2023-46805 KEV ransomware
- CVE-2023-48788 KEV ransomware
- CVE-2024-0012 KEV ransomware
- CVE-2024-1708 KEV ransomware
- CVE-2024-1709 KEV ransomware
- CVE-2024-21887 KEV ransomware
- CVE-2024-21893 KEV ransomware
- CVE-2024-21983
- CVE-2024-24919 KEV ransomware
- CVE-2024-27956
- CVE-2024-30051 KEV ransomware
- CVE-2024-3400 KEV ransomware
- CVE-2024-36401 KEV
- CVE-2024-42009 KEV
- CVE-2024-4577 KEV ransomware
- CVE-2024-47575 KEV
- CVE-2024-6473
- CVE-2024-9474 KEV ransomware
- CVE-2025-2783 KEV
- CVE-2025-31324 KEV ransomware
- CVE-2025-55182 KEV ransomware
- CVE-2026-21236
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BlackCat (Malware Family)
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
Show all 905 reports Show fewer
-
Cobalt Group - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Cobalt Group - Threat Group Cards: A Threat Actor Encyclopedia
-
Carbanak, Anunak - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Carbanak, Anunak - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor FIN7 Spear Phishing Campaign Targets Personnel Involved in SEC Filings « FIN7 Spear Phishing Campaign Targets Personnel Involved in SEC Filings
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor REvil (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor IcedID (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor MimiKatz (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Griffon (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor DarkSide (Malware Family)
-
Cobalt Strike (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Cobalt Strike (Malware Family)
-
Team46 and TaxOff: two sides of the same coin
The original link failed its last check. Original publisher Detailsfor Team46 and TaxOff: two sides of the same coin
-
Ex-Conti and FIN7 Actors Collaborate with New Domino Backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ex-Conti and FIN7 Actors Collaborate with New Domino Backdoor
-
Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
The original link failed its last check. Original publisher Detailsfor Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
-
Black Basta Ransomware - Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Black Basta Ransomware - Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor
-
Noberus Ransomware- Darkside and BlackMatter Successor Continues to Evolve its Tactics
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Noberus Ransomware- Darkside and BlackMatter Successor Continues to Evolve its Tactics
-
ALPHV-BlackCat ransomware family becoming more dangerous
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ALPHV-BlackCat ransomware family becoming more dangerous
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Russian Ransomware C2 Network Discovered in Censys Data
The original link failed its last check. Original publisher Detailsfor Russian Ransomware C2 Network Discovered in Censys Data
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Russian Cyber Attack campaigns and actors - NOBELIUM has struck again.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian Cyber Attack campaigns and actors - NOBELIUM has struck again.pdf
-
Russian cyber attack campaigns and actors.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian cyber attack campaigns and actors.pdf
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Denys Iarmak, Member of hacking group (FIN7) sentenced for scheme that compromised tens of millions of debit and credit cards
-
FIN7 Power Hour Adversary Archaeology and the Evolution of FIN7
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FIN7 Power Hour Adversary Archaeology and the Evolution of FIN7
-
FIN7 Power Hour- Adversary Archaeology and the Evolution of FIN7
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FIN7 Power Hour- Adversary Archaeology and the Evolution of FIN7
-
Conti ransomware source code investigation - part 1
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Conti ransomware source code investigation - part 1
-
The Ransomware Threat Landscape: What to Expect in 2022
The original link failed its last check. Original publisher Detailsfor The Ransomware Threat Landscape: What to Expect in 2022
-
Conti Ransomware source code- a well-designed COTS ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Conti Ransomware source code- a well-designed COTS ransomware
-
Legitimate Sites used as Cobalt Strike C2s against Indian Government
The original link failed its last check. Original publisher Detailsfor Legitimate Sites used as Cobalt Strike C2s against Indian Government
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor 2021trends.pdf
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
VMware Exposing Malware In Linux Based Multi Cloud Environments
The original link failed its last check. Original publisher Detailsfor VMware Exposing Malware In Linux Based Multi Cloud Environments
-
Winnti is Coming - Evolution after Prosecution@HITCON2021
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Winnti is Coming - Evolution after Prosecution@HITCON2021
-
FIN7 Tools Resurface in the Field – Splinter or Copycat-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FIN7 Tools Resurface in the Field – Splinter or Copycat-
-
Understanding the Windows JavaScript Threat Landscape
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Understanding the Windows JavaScript Threat Landscape
-
BlackMatter- New Data Exfiltration Tool Used in Attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BlackMatter- New Data Exfiltration Tool Used in Attacks
-
FIN7 Recruits Talent For Push Into Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FIN7 Recruits Talent For Push Into Ransomware
-
sneak-peek-ch1-2-finding-beacons-in-the-dark.pdf
The original link failed its last check. Original publisher Detailsfor sneak-peek-ch1-2-finding-beacons-in-the-dark.pdf
-
Masters of Mimicry: new APT group ChamelGang and its arsenal
The original link failed its last check. Original publisher Detailsfor Masters of Mimicry: new APT group ChamelGang and its arsenal
-
Masters of Mimicry: new APT group ChamelGang and its arsenal
The original link failed its last check. Original publisher Detailsfor Masters of Mimicry: new APT group ChamelGang and its arsenal
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t22021
-
FIN7 Using Windows 11 Alpha-Themed Docs to Drop Javascript Backdoor
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor FIN7 Using Windows 11 Alpha-Themed Docs to Drop Javascript Backdoor
-
Cybercrime Group FIN7 Using Windows 11 Alpha-Themed Docs to Drop Javascript Backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cybercrime Group FIN7 Using Windows 11 Alpha-Themed Docs to Drop Javascript Backdoor
-
report-old-dogs-new-tricks.pdf
The original link failed its last check. Original publisher Detailsfor report-old-dogs-new-tricks.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Notorious Cybercrime Gang, FIN7, Lands Malware in Law Firm Using Fake Legal Complaint Against Jack Daniels’ Owner, Brown-Forman Inc.
-
Ryuk Ransomware Now Targeting Webservers
The original link failed its last check. Original publisher Detailsfor Ryuk Ransomware Now Targeting Webservers
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor High-Level Member of Hacking Group Sentenced to Prison for Scheme that Compromised Tens of Millions of Debit and Credit Cards
-
Two Carbanak hackers sentenced to eight years in prison in Kazakhstan
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Two Carbanak hackers sentenced to eight years in prison in Kazakhstan
-
Looks like the page you're looking for doesn't exist or has moved.
The original link failed its last check. Original publisher Detailsfor Looks like the page you're looking for doesn't exist or has moved.
-
Ransomware Groups Use Tor-Based Backdoor for Persistent Access
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware Groups Use Tor-Based Backdoor for Persistent Access
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CTIR_casestudy_2.pdf
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CTIR_casestudy_1.pdf
-
the-operations-of-winnti-group.pdf
The original link failed its last check. Original publisher Detailsfor the-operations-of-winnti-group.pdf
-
Carbanak and FIN7 Attack Techniques
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Carbanak and FIN7 Attack Techniques
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor High-level organizer of notorious hacking group FIN7 sentenced to ten years in prison for scheme that compromised tens of millions of debit and credit cards
-
report-bb-2021-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor report-bb-2021-threat-report.pdf
-
Technical Analysis of Operation Diànxùn
The original link failed its last check. Original publisher Detailsfor Technical Analysis of Operation Diànxùn
-
Intezer-2020-Go-Malware-Round-Up.pdf
The original link failed its last check. Original publisher Detailsfor Intezer-2020-Go-Malware-Round-Up.pdf
-
Joker’s Stash, the Largest Carding Marketplace, Shuts Down
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Joker’s Stash, the Largest Carding Marketplace, Shuts Down
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
[Morphisec]_The_Evolution_of_the_FIN7_JssLoader
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor [Morphisec]_The_Evolution_of_the_FIN7_JssLoader
-
blog.truesec.com-Collaboration between FIN7 and the RYUK group a Truesec Investigation
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor blog.truesec.com-Collaboration between FIN7 and the RYUK group a Truesec Investigation
-
Collaboration between FIN7 and the RYUK group, a Truesec Investigation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Collaboration between FIN7 and the RYUK group, a Truesec Investigation
-
Collaboration Between FIN7 and the RYUK Group
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Collaboration Between FIN7 and the RYUK Group
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Active Directory 侵害と推奨対策
-
Russian cyber attack campaigns and actors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian cyber attack campaigns and actors
-
yoroi.company-Shadows From the Past Threaten Italian Enterprises
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor yoroi.company-Shadows From the Past Threaten Italian Enterprises
-
Shadows From The Past Threaten Italian Enterprises
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shadows From The Past Threaten Italian Enterprises
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q32020
-
Incident readiness: preparing a proactive response to attacks
The original link failed its last check. Original publisher Detailsfor Incident readiness: preparing a proactive response to attacks
-
OpBlueRaven- Unveiling Fin7-Carbanak - Part II - BadUSB Attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OpBlueRaven- Unveiling Fin7-Carbanak - Part II - BadUSB Attacks
-
Banking Trojans- A Reference Guide to the Malware Family Tree
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Banking Trojans- A Reference Guide to the Malware Family Tree
-
OpBlueRaven- Unveiling Fin7-Carbanak - Part 1 - Tirion
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OpBlueRaven- Unveiling Fin7-Carbanak - Part 1 - Tirion
-
2020-q2-spamhaus-botnet-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor 2020-q2-spamhaus-botnet-threat-report.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q22020
-
In-Memory shellcode decoding to evade AVs/EDRs
The original link failed its last check. Original publisher Detailsfor In-Memory shellcode decoding to evade AVs/EDRs
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CERTFR-2020-CTI-008
-
WastedLocker- A New Ransomware Variant Developed By The Evil Corp Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor WastedLocker- A New Ransomware Variant Developed By The Evil Corp Group
-
WastedLocker_ A New Ransomware Variant Developed By The Evil Corp Group – NCC Group Research
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor WastedLocker_ A New Ransomware Variant Developed By The Evil Corp Group – NCC Group Research
-
Pillowmint- FIN7’s Monkey Thief
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Pillowmint- FIN7’s Monkey Thief
-
Russian Cyber Attack Campaigns and Actors - Threat Research
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Russian Cyber Attack Campaigns and Actors - Threat Research
-
CTNT_Q1_2020_COVID-Report_Final.pdf
The original link failed its last check. Original publisher Detailsfor CTNT_Q1_2020_COVID-Report_Final.pdf
-
Catching APT41 exploiting a zero-day vulnerability
The original link failed its last check. Detailsfor Catching APT41 exploiting a zero-day vulnerability
-
TA505's Box of Chocolate - On Hidden Gems packed with the TA505 Packer
The original link failed its last check. Original publisher Detailsfor TA505's Box of Chocolate - On Hidden Gems packed with the TA505 Packer
-
Introducing BIOLOAD- FIN7 BOOSTWRITE’s Lost Twin
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Introducing BIOLOAD- FIN7 BOOSTWRITE’s Lost Twin
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor [CB19] Cyber Threat Landscape in Japan – Revealing Threat in the Shadow by Chi En Shen (Ashley) Oleg Bondarenko
-
The original link failed its last check. Original publisher Detailsfor Aarhus_miniseminar_291118.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Mahalo_FIN7
-
Mahalo FIN7- Responding to the Criminal Operators’ New Tools and Techniques
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Mahalo FIN7- Responding to the Criminal Operators’ New Tools and Techniques
-
CARBANAK Week Part Two: Continuing the CARBANAK Source Code Analysis
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor CARBANAK Week Part Two: Continuing the CARBANAK Source Code Analysis
-
CARBANAK Week Part Three: Behind the CARBANAK Backdoor
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor CARBANAK Week Part Three: Behind the CARBANAK Backdoor
-
2019 Cyber Threatscape Report I Accenture
The original link failed its last check. Original publisher Detailsfor 2019 Cyber Threatscape Report I Accenture
-
The original link failed its last check. Original publisher Detailsfor APT-Attacks-eng.pdf
-
Threat Group Cards: A Threat Actor Encyclopedia
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor MacProStorage02:_Final:Bitdefender-WhitePaper-APTBluePrint-CREAT3496-31M1416s-en_EN:Bitdefender-WhitePaper-APTBluePrint-CREAT3496-31M1416s-en_EN.indd
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Talos Blog __ Cisco Talos Intelligence Group - Comprehensive Threat Intelligence_ 10 years of virtual dynamite_ A high-level retrospective of ATM malware
-
10 years of virtual dynamite- A high-level retrospective of ATM malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 10 years of virtual dynamite- A high-level retrospective of ATM malware
-
The Rise of Dridex and the Role of ESPs
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Rise of Dridex and the Role of ESPs
-
FIN7.5_ the infamous cybercrime rig “FIN7” continues its activities
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor FIN7.5_ the infamous cybercrime rig “FIN7” continues its activities
-
Fin7 hacking group targets more than 130 companies after leaders’ arrest
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Fin7 hacking group targets more than 130 companies after leaders’ arrest
-
FIN7.5- the infamous cybercrime rig “FIN7” continues its activities
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FIN7.5- the infamous cybercrime rig “FIN7” continues its activities
-
CARBANAK Week Part Four: The CARBANAK Desktop Video Player
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor CARBANAK Week Part Four: The CARBANAK Desktop Video Player
-
CARBANAK Week Part One: A Rare Occurrence
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor CARBANAK Week Part One: A Rare Occurrence
-
CARBANAK Week Part One- A Rare Occurrence
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CARBANAK Week Part One- A Rare Occurrence
-
mpressioncss_ta_report_2019.pdf
The original link failed its last check. Original publisher Detailsfor mpressioncss_ta_report_2019.pdf
-
FIN7 Revisited- Inside Astra Panel and SQLRat Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FIN7 Revisited- Inside Astra Panel and SQLRat Malware
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2019GlobalThreatReport
-
The original link failed its last check. Original publisher Detailsfor CrowdStrike_GTR_2019.pdf
-
ENISA Threat Landscape Report 2018
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ENISA Threat Landscape Report 2018
-
Silence: Moving into the darkside
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Silence: Moving into the darkside
-
HITB-SG-2018-E - In the trails of WINDSHIFT [Autosaved]
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor HITB-SG-2018-E - In the trails of WINDSHIFT [Autosaved]
-
Three Carbanak cyber heist gang members arrested
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Three Carbanak cyber heist gang members arrested
-
Accenture-Cyber-Threatscape-Report-2018.pdf
The original link failed its last check. Original publisher Detailsfor Accenture-Cyber-Threatscape-Report-2018.pdf
-
On the Hunt for FIN7- Pursuing an Enigmatic and Evasive Global Criminal Operation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor On the Hunt for FIN7- Pursuing an Enigmatic and Evasive Global Criminal Operation
-
Arrests Put New Focus on CARBON SPIDER Adversary Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Arrests Put New Focus on CARBON SPIDER Adversary Group
-
NotCarbanak Mystery - Source Code Leak
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor NotCarbanak Mystery - Source Code Leak
-
Cobalt Renaissance- new attacks and joint operations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cobalt Renaissance- new attacks and joint operations
-
Anunak: Apt Against Financial Institutions
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Anunak: Apt Against Financial Institutions
-
Inside the Response of a Unique CARBANAK Intrusion
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Inside the Response of a Unique CARBANAK Intrusion
-
The Shadows of Ghosts: Inside the Response of a... | RSA Link
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Shadows of Ghosts: Inside the Response of a... | RSA Link
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor The Carbanak/Fin7 syndicate
-
Inside the Response of a Unique CARABANK Intrusion
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Inside the Response of a Unique CARABANK Intrusion
-
Silence – a new Trojan attacking financial organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Silence – a new Trojan attacking financial organizations
-
FIN7-Carbanak threat actor unleashes Bateleur JScript backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FIN7-Carbanak threat actor unleashes Bateleur JScript backdoor
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Behind the CARBANAK Backdoor
-
To SDB, Or Not To SDB- FIN7 Leveraging Shim Databases for Persistence
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor To SDB, Or Not To SDB- FIN7 Leveraging Shim Databases for Persistence
-
FIN7 Evolution and the Phishing LNK
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FIN7 Evolution and the Phishing LNK
-
FIN7 Spear Phishing Campaign Targets Personnel Involved in SEC Filings
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor FIN7 Spear Phishing Campaign Targets Personnel Involved in SEC Filings
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Grand Mars
-
Carbanak Group uses Google for malware command-and-control
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Carbanak Group uses Google for malware command-and-control
-
The Digital Plagiarist Campaign: TelePorting the Carbanak Crew to a New Dimension
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor The Digital Plagiarist Campaign: TelePorting the Carbanak Crew to a New Dimension
-
New Carbanak / Anunak Attack Methodology
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor New Carbanak / Anunak Attack Methodology
-
Visa Alert and Update on the Oracle Breach
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Visa Alert and Update on the Oracle Breach
-
The link to Mirror on Box failed its last check. Detailsfor Carbanak Oracle Breach
-
proofpoint-threat-insight-carbanak-group-en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor proofpoint-threat-insight-carbanak-group-en
-
APT-style bank robberies increase with Metel, GCMAN and Carbanak 2.0 attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT-style bank robberies increase with Metel, GCMAN and Carbanak 2.0 attacks
-
The original link failed its last check. Original publisher Detailsfor Group-IB-Corkow-Report-EN.pdf
-
Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups
-
Evolution of Cyber Threats in the Corporate Sector
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Evolution of Cyber Threats in the Corporate Sector
-
Russian financial cybercrime_ how it works - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Russian financial cybercrime_ how it works - Securelist
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Без названия
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Carbanak is packing new guns
-
Carbanak gang is back and packing new guns
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Carbanak gang is back and packing new guns
-
Operation Buhtrap, the trap for Russian accountants
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Buhtrap, the trap for Russian accountants
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Carbanak
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Carbanak
-
Carbanak APT The Great Bank Robbery
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Carbanak APT The Great Bank Robbery
Newest first. Details opens the report in Explore.