APT29
Also reported as UNC2452, Midnight Blizzard, NOBELIUM, The Dukes, UNC3524 and 37 other names. Linked to Russia by four sources.
Reports per quarter
Techniques seen in the last two years
- T1027 8 reports reports only
- T1053.005 8 reports in ATT&CK
- T1566.001 8 reports in ATT&CK
- T1057 7 reports reports only
- T1071.001 7 reports reports only
- T1082 7 reports reports only
- T1041 6 reports reports only
- T1059.001 6 reports in ATT&CK
- T1059.003 6 reports reports only
- T1071 6 reports reports only
Show all 311 techniques Show fewer
- T1105 6 reports in ATT&CK
- T1204.002 6 reports in ATT&CK
- T1005 5 reports in ATT&CK
- T1007 5 reports reports only
- T1047 5 reports in ATT&CK
- T1068 5 reports in ATT&CK
- T1098 5 reports reports only
- T1190 5 reports in ATT&CK
- T1572 5 reports reports only
- T1003.001 4 reports reports only
- T1016 4 reports reports only
- T1021.001 4 reports reports only
- T1033 4 reports reports only
- T1046 4 reports reports only
- T1055.002 4 reports reports only
- T1056.001 4 reports reports only
- T1059 4 reports reports only
- T1059.007 4 reports reports only
- T1070.004 4 reports in ATT&CK
- T1071.004 4 reports reports only
- T1098.001 4 reports reports only
- T1114.002 4 reports in ATT&CK
- T1133 4 reports in ATT&CK
- T1140 4 reports reports only
- T1189 4 reports reports only
- T1199 4 reports in ATT&CK
- T1482 4 reports reports only
- T1505.003 4 reports in ATT&CK
- T1566 4 reports reports only
- T1583.003 4 reports reports only
- T1018 3 reports reports only
- T1020 3 reports reports only
- T1027.009 3 reports reports only
- T1036.005 3 reports in ATT&CK
- T1049 3 reports reports only
- T1059.005 3 reports reports only
- T1069.002 3 reports reports only
- T1078 3 reports in ATT&CK
- T1078.004 3 reports in ATT&CK
- T1083 3 reports reports only
- T1087.001 3 reports reports only
- T1087.002 3 reports reports only
- T1090.003 3 reports in ATT&CK
- T1095 3 reports reports only
- T1111 3 reports reports only
- T1132.001 3 reports reports only
- T1136 3 reports reports only
- T1136.001 3 reports reports only
- T1195.002 3 reports reports only
- T1203 3 reports in ATT&CK
- T1219 3 reports reports only
- T1486 3 reports reports only
- T1518.001 3 reports reports only
- T1528 3 reports in ATT&CK
- T1547.001 3 reports in ATT&CK
- T1555.003 3 reports reports only
- T1560.001 3 reports reports only
- T1567 3 reports reports only
- T1570 3 reports reports only
- T1571 3 reports reports only
- T1573.001 3 reports reports only
- T1574.001 3 reports reports only
- T1583 3 reports reports only
- T1583.001 3 reports reports only
- T1584 3 reports reports only
- T1588.003 3 reports reports only
- T1595 3 reports reports only
- T1003.002 2 reports in ATT&CK
- T1003.006 2 reports reports only
- T1008 2 reports reports only
- T1012 2 reports reports only
- T1016.001 2 reports in ATT&CK
- T1021.002 2 reports reports only
- T1021.004 2 reports reports only
- T1036 2 reports reports only
- T1039 2 reports reports only
- T1055 2 reports reports only
- T1055.004 2 reports reports only
- T1059.006 2 reports in ATT&CK
- T1069 2 reports reports only
- T1069.001 2 reports reports only
- T1070 2 reports reports only
- T1074 2 reports reports only
- T1090 2 reports reports only
- T1090.001 2 reports reports only
- T1098.005 2 reports in ATT&CK
- T1098.007 2 reports reports only
- T1104 2 reports reports only
- T1114 2 reports reports only
- T1119 2 reports reports only
- T1120 2 reports reports only
- T1124 2 reports reports only
- T1129 2 reports reports only
- T1134.001 2 reports reports only
- T1135 2 reports reports only
- T1195 2 reports reports only
- T1204 2 reports reports only
- T1213 2 reports reports only
- T1213.002 2 reports reports only
- T1213.003 2 reports reports only
- T1217 2 reports reports only
- T1218.005 2 reports in ATT&CK
- T1496 2 reports reports only
- T1497.003 2 reports reports only
- T1505.004 2 reports reports only
- T1518 2 reports reports only
- T1543.003 2 reports reports only
- T1547.009 2 reports reports only
- T1548 2 reports reports only
- T1550 2 reports reports only
- T1550.001 2 reports reports only
- T1552 2 reports reports only
- T1552.004 2 reports reports only
- T1558.003 2 reports reports only
- T1560 2 reports reports only
- T1566.002 2 reports in ATT&CK
- T1566.004 2 reports reports only
- T1567.001 2 reports reports only
- T1573.002 2 reports reports only
- T1583.006 2 reports in ATT&CK
- T1586.002 2 reports in ATT&CK
- T1587.001 2 reports in ATT&CK
- T1590 2 reports reports only
- T1595.002 2 reports in ATT&CK
- T1608 2 reports reports only
- T1608.001 2 reports reports only
- T1608.002 2 reports reports only
- T1608.003 2 reports reports only
- T1608.006 2 reports reports only
- T1620 2 reports reports only
- T1649 2 reports in ATT&CK
- T1003 1 report reports only
- T1003.003 1 report reports only
- T1003.004 1 report in ATT&CK
- T1003.008 1 report reports only
- T1010 1 report reports only
- T1021 1 report reports only
- T1021.005 1 report reports only
- T1021.006 1 report reports only
- T1027.003 1 report reports only
- T1027.005 1 report reports only
- T1027.006 1 report in ATT&CK
- T1027.007 1 report reports only
- T1030 1 report reports only
- T1036.003 1 report reports only
- T1037 1 report in ATT&CK
- T1037.001 1 report reports only
- T1037.004 1 report in ATT&CK
- T1040 1 report reports only
- T1048 1 report reports only
- T1048.003 1 report reports only
- T1053 1 report reports only
- T1053.003 1 report reports only
- T1055.001 1 report reports only
- T1055.003 1 report reports only
- T1055.009 1 report reports only
- T1055.012 1 report reports only
- T1056 1 report reports only
- T1059.002 1 report reports only
- T1059.004 1 report reports only
- T1059.009 1 report in ATT&CK
- T1059.010 1 report reports only
- T1059.011 1 report reports only
- T1069.003 1 report reports only
- T1070.006 1 report in ATT&CK
- T1072 1 report reports only
- T1074.001 1 report reports only
- T1074.002 1 report reports only
- T1078.002 1 report reports only
- T1078.003 1 report in ATT&CK
- T1087 1 report reports only
- T1087.003 1 report reports only
- T1087.004 1 report in ATT&CK
- T1090.002 1 report in ATT&CK
- T1091 1 report reports only
- T1098.002 1 report in ATT&CK
- T1098.003 1 report reports only
- T1098.004 1 report reports only
- T1098.006 1 report reports only
- T1102 1 report reports only
- T1102.002 1 report reports only
- T1110 1 report reports only
- T1110.003 1 report in ATT&CK
- T1113 1 report reports only
- T1114.001 1 report reports only
- T1114.003 1 report reports only
- T1115 1 report reports only
- T1123 1 report reports only
- T1125 1 report reports only
- T1132 1 report reports only
- T1134 1 report reports only
- T1136.002 1 report reports only
- T1137 1 report reports only
- T1137.006 1 report reports only
- T1185 1 report reports only
- T1195.001 1 report reports only
- T1200 1 report reports only
- T1201 1 report reports only
- T1204.001 1 report in ATT&CK
- T1204.004 1 report reports only
- T1210 1 report reports only
- T1213.001 1 report reports only
- T1218.007 1 report reports only
- T1218.011 1 report reports only
- T1480 1 report reports only
- T1484 1 report reports only
- T1484.001 1 report reports only
- T1484.002 1 report reports only
- T1485 1 report reports only
- T1489 1 report reports only
- T1490 1 report reports only
- T1491.001 1 report reports only
- T1491.002 1 report reports only
- T1497 1 report reports only
- T1497.001 1 report reports only
- T1498 1 report reports only
- T1499 1 report reports only
- T1505 1 report reports only
- T1526 1 report reports only
- T1529 1 report reports only
- T1530 1 report reports only
- T1534 1 report reports only
- T1537 1 report reports only
- T1538 1 report reports only
- T1539 1 report reports only
- T1543 1 report reports only
- T1543.002 1 report reports only
- T1543.004 1 report reports only
- T1546 1 report reports only
- T1546.003 1 report in ATT&CK
- T1546.004 1 report reports only
- T1546.008 1 report in ATT&CK
- T1546.012 1 report reports only
- T1546.015 1 report reports only
- T1547 1 report reports only
- T1547.002 1 report reports only
- T1547.005 1 report reports only
- T1548.002 1 report in ATT&CK
- T1550.002 1 report reports only
- T1552.001 1 report reports only
- T1552.006 1 report reports only
- T1554 1 report reports only
- T1555 1 report reports only
- T1555.005 1 report reports only
- T1556 1 report reports only
- T1556.006 1 report reports only
- T1556.009 1 report reports only
- T1558 1 report reports only
- T1559 1 report reports only
- T1560.002 1 report reports only
- T1564.001 1 report reports only
- T1564.004 1 report reports only
- T1565 1 report reports only
- T1565.001 1 report reports only
- T1566.003 1 report in ATT&CK
- T1567.002 1 report reports only
- T1568.002 1 report reports only
- T1569 1 report reports only
- T1569.002 1 report reports only
- T1573 1 report in ATT&CK
- T1574 1 report reports only
- T1574.008 1 report reports only
- T1574.011 1 report reports only
- T1578 1 report reports only
- T1580 1 report reports only
- T1583.004 1 report reports only
- T1584.004 1 report reports only
- T1584.005 1 report reports only
- T1584.006 1 report reports only
- T1585 1 report reports only
- T1585.002 1 report reports only
- T1587 1 report reports only
- T1587.003 1 report in ATT&CK
- T1588 1 report reports only
- T1588.002 1 report in ATT&CK
- T1588.004 1 report reports only
- T1588.007 1 report reports only
- T1589 1 report reports only
- T1589.002 1 report reports only
- T1590.005 1 report reports only
- T1592 1 report reports only
- T1595.001 1 report reports only
- T1598 1 report reports only
- T1602 1 report reports only
- T1602.001 1 report reports only
- T1602.002 1 report reports only
- T1606.001 1 report reports only
- T1606.002 1 report reports only
- T1608.004 1 report reports only
- T1608.005 1 report reports only
- T1613 1 report reports only
- T1614 1 report reports only
- T1614.001 1 report reports only
- T1615 1 report reports only
- T1619 1 report reports only
- T1621 1 report in ATT&CK
- T1622 1 report reports only
- T1652 1 report reports only
- T1654 1 report reports only
- T1657 1 report reports only
- T1665 1 report in ATT&CK
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
- T1021.007
- T1027.001
- T1027.002
- T1090.004
- T1110.001
- T1136.003
- T1550.003
- T1553.005
- T1556.007
- T1568
- T1586.003
- T1651
Show all 13 techniques Show fewer
CVEs named in reports
- CVE-2006-2389
- CVE-2006-2492 KEV
- CVE-2007-0071
- CVE-2007-5633
- CVE-2007-5659 KEV
- CVE-2008-0081
- CVE-2008-0655 KEV
- CVE-2008-2463
- CVE-2008-2992 KEV ransomware
- CVE-2008-3005
- CVE-2008-3431 KEV
- CVE-2008-4841
Show all 440 CVEs Show fewer
- CVE-2008-5353
- CVE-2009-0556 KEV
- CVE-2009-0563 KEV
- CVE-2009-0658
- CVE-2009-0806
- CVE-2009-0824
- CVE-2009-0927 KEV
- CVE-2009-1129
- CVE-2009-1869
- CVE-2009-3129 KEV
- CVE-2009-3867
- CVE-2009-3957
- CVE-2009-4324 KEV
- CVE-2010-0188 KEV ransomware
- CVE-2010-0232 KEV
- CVE-2010-0806 KEV
- CVE-2010-1240
- CVE-2010-1297 KEV
- CVE-2010-1592
- CVE-2010-1885
- CVE-2010-2568 KEV
- CVE-2010-2883 KEV
- CVE-2010-3333 KEV
- CVE-2010-3654
- CVE-2010-3970
- CVE-2010-4091
- CVE-2010-4398 KEV
- CVE-2011-0609 KEV
- CVE-2011-0611 KEV
- CVE-2011-1255
- CVE-2011-1980
- CVE-2011-1991
- CVE-2011-2462 KEV
- CVE-2011-3402 KEV
- CVE-2012-0151 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-0506
- CVE-2012-0507 KEV ransomware
- CVE-2012-0754 KEV
- CVE-2012-0779
- CVE-2012-1535 KEV
- CVE-2012-1875
- CVE-2012-1889 KEV
- CVE-2012-4681 KEV ransomware
- CVE-2012-4969 KEV
- CVE-2012-5076 KEV
- CVE-2012-5687
- CVE-2013-0640 KEV
- CVE-2013-0641 KEV
- CVE-2013-2618
- CVE-2013-2729 KEV
- CVE-2013-3893 KEV
- CVE-2013-3900 KEV
- CVE-2013-5947
- CVE-2014-1225
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-1812 KEV ransomware
- CVE-2014-2962
- CVE-2014-3393
- CVE-2014-4019
- CVE-2014-4113 KEV
- CVE-2014-4114 KEV
- CVE-2014-4404 KEV
- CVE-2014-6332 KEV
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-1130 KEV
- CVE-2015-1635 KEV
- CVE-2015-1641 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-1805
- CVE-2015-2051 KEV
- CVE-2015-2360 KEV
- CVE-2015-2424 KEV
- CVE-2015-2545 KEV
- CVE-2015-2590 KEV
- CVE-2015-3043 KEV
- CVE-2015-4852 KEV
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-6585
- CVE-2015-7248
- CVE-2015-7645 KEV ransomware
- CVE-2015-7755 KEV
- CVE-2015-8651 KEV
- CVE-2016-0147
- CVE-2016-0167 KEV ransomware
- CVE-2016-0189 KEV ransomware
- CVE-2016-0984 KEV
- CVE-2016-1010 KEV
- CVE-2016-10401
- CVE-2016-3353
- CVE-2016-4117 KEV ransomware
- CVE-2016-4171 KEV
- CVE-2016-7255 KEV ransomware
- CVE-2016-7855 KEV
- CVE-2017-0143 KEV ransomware
- CVE-2017-0144 KEV ransomware
- CVE-2017-0176
- CVE-2017-0199 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-1000353 KEV
- CVE-2017-10271 KEV ransomware
- CVE-2017-1099
- CVE-2017-11292 KEV
- CVE-2017-11317 KEV
- CVE-2017-11357 KEV ransomware
- CVE-2017-11467
- CVE-2017-11774 KEV
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-12149 KEV ransomware
- CVE-2017-12629
- CVE-2017-12824
- CVE-2017-15399
- CVE-2017-15944 KEV
- CVE-2017-17215
- CVE-2017-5638 KEV ransomware
- CVE-2017-6327 KEV
- CVE-2017-6328
- CVE-2017-7269 KEV
- CVE-2017-8291 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2017-9805 KEV
- CVE-2017-9822 KEV ransomware
- CVE-2018-0101
- CVE-2018-0171 KEV
- CVE-2018-0296 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-0824 KEV
- CVE-2018-10088
- CVE-2018-10561 KEV
- CVE-2018-10562 KEV ransomware
- CVE-2018-11776 KEV
- CVE-2018-1207
- CVE-2018-13379 KEV ransomware
- CVE-2018-15454
- CVE-2018-15961 KEV
- CVE-2018-15982 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-2628 KEV
- CVE-2018-2893
- CVE-2018-4878 KEV ransomware
- CVE-2018-4939 KEV
- CVE-2018-4990 KEV
- CVE-2018-5002 KEV
- CVE-2018-6055
- CVE-2018-6789 KEV ransomware
- CVE-2018-7600 KEV ransomware
- CVE-2018-7602 KEV ransomware
- CVE-2018-8120 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8242
- CVE-2018-8373 KEV
- CVE-2018-8414 KEV
- CVE-2018-8440 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2018-8581 KEV ransomware
- CVE-2018-8589 KEV
- CVE-2018-8611 KEV
- CVE-2018-8639 KEV ransomware
- CVE-2018-9866
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0797 KEV
- CVE-2019-0803 KEV ransomware
- CVE-2019-0808 KEV
- CVE-2019-0859 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-1040
- CVE-2019-1132 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-11580 KEV ransomware
- CVE-2019-11707 KEV
- CVE-2019-11708 KEV
- CVE-2019-1367 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-1458 KEV ransomware
- CVE-2019-16098
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-16920 KEV
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-2215 KEV
- CVE-2019-2725 KEV ransomware
- CVE-2019-3396 KEV ransomware
- CVE-2019-3398 KEV
- CVE-2019-3568 KEV
- CVE-2019-5786 KEV
- CVE-2019-6225
- CVE-2019-7286 KEV
- CVE-2019-7287 KEV
- CVE-2019-7609 KEV
- CVE-2019-8394 KEV
- CVE-2019-8518
- CVE-2019-8917
- CVE-2019-9621 KEV
- CVE-2019-9670 KEV
- CVE-2020-0601 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0787 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10148 KEV
- CVE-2020-10189 KEV
- CVE-2020-10198
- CVE-2020-1040 KEV
- CVE-2020-116511
- CVE-2020-11652 KEV
- CVE-2020-11899 KEV
- CVE-2020-12641 KEV
- CVE-2020-1350 KEV
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-1472122
- CVE-2020-14750 KEV
- CVE-2020-14871 KEV
- CVE-2020-14882 KEV
- CVE-2020-15505 KEV
- CVE-2020-1599
- CVE-2020-1664
- CVE-2020-2021 KEV ransomware
- CVE-2020-2555 KEV
- CVE-2020-3118 KEV
- CVE-2020-3125
- CVE-2020-3529
- CVE-2020-35730 KEV
- CVE-2020-4006 KEV
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-6789
- CVE-2020-7961 KEV
- CVE-2020-8193 KEV
- CVE-2020-8195 KEV
- CVE-2020-8196 KEV
- CVE-2020-8243 KEV
- CVE-2020-8260 KEV
- CVE-2020-8515 KEV
- CVE-2021-1636
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-1844
- CVE-2021-1879 KEV
- CVE-2021-20016 KEV ransomware
- CVE-2021-21148 KEV
- CVE-2021-2114810
- CVE-2021-21166 KEV
- CVE-2021-21972 KEV ransomware
- CVE-2021-21974
- CVE-2021-22205 KEV ransomware
- CVE-2021-22893 KEV ransomware
- CVE-2021-22894 KEV
- CVE-2021-22899 KEV
- CVE-2021-22900 KEV
- CVE-2021-26084 KEV ransomware
- CVE-2021-26411 KEV ransomware
- CVE-2021-2641111
- CVE-2021-26605
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-26868
- CVE-2021-27065 KEV ransomware
- CVE-2021-27850
- CVE-2021-28310 KEV
- CVE-2021-28550 KEV
- CVE-2021-30116 KEV ransomware
- CVE-2021-30551 KEV
- CVE-2021-30665 KEV
- CVE-2021-30666 KEV
- CVE-2021-31195
- CVE-2021-31196 KEV
- CVE-2021-31199 KEV
- CVE-2021-31201 KEV
- CVE-2021-31206
- CVE-2021-31207 KEV ransomware
- CVE-2021-3120710
- CVE-2021-3156 KEV
- CVE-2021-31955 KEV
- CVE-2021-31956 KEV
- CVE-2021-31979 KEV
- CVE-2021-3197961
- CVE-2021-32648 KEV
- CVE-2021-33742 KEV
- CVE-2021-33771 KEV
- CVE-2021-3377162
- CVE-2021-34448 KEV
- CVE-2021-344486
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-345239
- CVE-2021-34527 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-36798
- CVE-2021-36934 KEV
- CVE-2021-36942 KEV ransomware
- CVE-2021-36948 KEV
- CVE-2021-38647 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-40449 KEV ransomware
- CVE-2021-40539 KEV ransomware
- CVE-2021-4104
- CVE-2021-41379 KEV ransomware
- CVE-2021-41773 KEV ransomware
- CVE-2021-42013 KEV ransomware
- CVE-2021-440077
- CVE-2021-44026 KEV
- CVE-2021-44077 KEV
- CVE-2021-44207 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-44515 KEV
- CVE-2021-44832
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-1388 KEV ransomware
- CVE-2022-21587 KEV ransomware
- CVE-2022-21882 KEV ransomware
- CVE-2022-21919 KEV
- CVE-2022-22047 KEV
- CVE-2022-2294 KEV ransomware
- CVE-2022-22954 KEV ransomware
- CVE-2022-22957
- CVE-2022-22958
- CVE-2022-22960 KEV
- CVE-2022-22972
- CVE-2022-24500
- CVE-2022-24521 KEV ransomware
- CVE-2022-24682 KEV ransomware
- CVE-2022-24934
- CVE-2022-26134 KEV ransomware
- CVE-2022-26809
- CVE-2022-26923 KEV
- CVE-2022-27924 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-27926 KEV
- CVE-2022-2794
- CVE-2022-30170
- CVE-2022-30190 KEV ransomware
- CVE-2022-30333 KEV ransomware
- CVE-2022-31199 KEV ransomware
- CVE-2022-33891 KEV
- CVE-2022-37042 KEV ransomware
- CVE-2022-38028 KEV
- CVE-2022-40507
- CVE-2022-41040 KEV ransomware
- CVE-2022-41080 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-41091 KEV ransomware
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2023-0669 KEV ransomware
- CVE-2023-20198 KEV
- CVE-2023-21715 KEV
- CVE-2023-21746
- CVE-2023-23397 KEV
- CVE-2023-24023
- CVE-2023-24955 KEV ransomware
- CVE-2023-27350 KEV ransomware
- CVE-2023-27532 KEV ransomware
- CVE-2023-27997 KEV ransomware
- CVE-2023-28252 KEV ransomware
- CVE-2023-28461 KEV ransomware
- CVE-2023-2868 KEV
- CVE-2023-28771 KEV
- CVE-2023-29357 KEV ransomware
- CVE-2023-32315 KEV
- CVE-2023-34362 KEV ransomware
- CVE-2023-3466
- CVE-2023-3467
- CVE-2023-35078 KEV ransomware
- CVE-2023-3519 KEV ransomware
- CVE-2023-36025 KEV
- CVE-2023-36033 KEV
- CVE-2023-36745
- CVE-2023-37580 KEV
- CVE-2023-38545
- CVE-2023-38546
- CVE-2023-38831 KEV ransomware
- CVE-2023-40076
- CVE-2023-40077
- CVE-2023-40088
- CVE-2023-40289
- CVE-2023-41993 KEV
- CVE-2023-42793 KEV ransomware
- CVE-2023-45727 KEV
- CVE-2023-45866
- CVE-2023-46805 KEV ransomware
- CVE-2023-48788 KEV ransomware
- CVE-2023-4911 KEV
- CVE-2023-4966 KEV ransomware
- CVE-2023-5044
- CVE-2023-5631 KEV
- CVE-2023-6345 KEV
- CVE-2024-0012 KEV ransomware
- CVE-2024-21412 KEV ransomware
- CVE-2024-21887 KEV ransomware
- CVE-2024-21893 KEV ransomware
- CVE-2024-21983
- CVE-2024-24919 KEV ransomware
- CVE-2024-27564
- CVE-2024-27956
- CVE-2024-30051 KEV ransomware
- CVE-2024-3400 KEV ransomware
- CVE-2024-36401 KEV
- CVE-2024-42009 KEV
- CVE-2024-4577 KEV ransomware
- CVE-2024-4671 KEV
- CVE-2024-47575 KEV
- CVE-2024-5274 KEV
- CVE-2024-6473
- CVE-2024-9474 KEV ransomware
- CVE-2025-24813 KEV
- CVE-2025-2783 KEV
- CVE-2025-31324 KEV ransomware
- CVE-2025-49704 KEV ransomware
- CVE-2025-55182 KEV ransomware
- CVE-2025-66376 KEV
- CVE-2026-21236
- CVE-2027-11882
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Cozy Bear
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor TEARDROP (Malware Family)
Show all 1,179 reports Show fewer
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor APT 29, Cozy Bear, The Dukes
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor APT 29, Cozy Bear, The Dukes
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor elf.wellmess (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor SUNBURST (Malware Family)
-
Living off the Land - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Living off the Land - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor APT 29, Cozy Bear, The Dukes
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor GoldMax (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor No Easy Breach DerbyCon 2016
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor No Easy Breach DerbyCon 2016
-
BlueTeam CheatSheet * SolarWinds Events* | Last updated: 2020-12-24 1334 UTC
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BlueTeam CheatSheet * SolarWinds Events* | Last updated: 2020-12-24 1334 UTC
-
Cobalt Strike (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Cobalt Strike (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BONDUPDATER (Malware Family)
-
Sofacy, APT 28, Fancy Bear, Sednit
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Sofacy, APT 28, Fancy Bear, Sednit
-
Team46 and TaxOff: two sides of the same coin
The original link failed its last check. Original publisher Detailsfor Team46 and TaxOff: two sides of the same coin
-
The original link failed its last check. Original publisher Detailsfor Binary Defense
-
CVE-2024-21412_ Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CVE-2024-21412_ Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day
-
Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally
-
APT29 attacks Embassies using CVE-2023-38831 - report en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Detailsfor APT29 attacks Embassies using CVE-2023-38831 - report en
-
Unleashing the Power of Shimcache with Chainsaw
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Unleashing the Power of Shimcache with Chainsaw
-
Tomiris called, they want their Turla malware back
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tomiris called, they want their Turla malware back
-
Espionage campaign linked to Russian intelligence services
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Espionage campaign linked to Russian intelligence services
-
CERT Polska and SKW warn against the activities of Russian spies
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CERT Polska and SKW warn against the activities of Russian spies
-
PwC Cyber Threats 2022: A Year in Retrospect.pdf
The original link failed its last check. Original publisher Detailsfor PwC Cyber Threats 2022: A Year in Retrospect.pdf
-
NOBELIUM Uses Poland's Ambassador’s Visit to the U.S. to Target EU Governments Assisting Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor NOBELIUM Uses Poland's Ambassador’s Visit to the U.S. to Target EU Governments Assisting Ukraine
-
Sophisticated APT29 Campaign Abuses Notion API to Target the European Commission
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sophisticated APT29 Campaign Abuses Notion API to Target the European Commission
-
Invitation to a Secret Event- Uncovering Earth Yako’s Campaigns
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Invitation to a Secret Event- Uncovering Earth Yako’s Campaigns
-
Hunting Cyber Evil Ratels: From the targeted attacks to the widespread usage of Brute Ratel - Yoroi
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Hunting Cyber Evil Ratels: From the targeted attacks to the widespread usage of Brute Ratel - Yoroi
-
Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
The original link failed its last check. Original publisher Detailsfor Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
-
Analysis of APT29's attack activities against Italy
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis of APT29's attack activities against Italy
-
Suspected Russian Activity Targeting Government and Business Entities Around the Globe
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Suspected Russian Activity Targeting Government and Business Entities Around the Globe
-
Conceptualizing a Continuum of Cyber Threat Attribution
The original link failed its last check. Original publisher Detailsfor Conceptualizing a Continuum of Cyber Threat Attribution
-
The art and science behind Microsoft threat hunting- Part 2
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The art and science behind Microsoft threat hunting- Part 2
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
What to Expect When You’re Electing- Preparing for Cyber Threats to the 2022 U.S. Midterm Elections
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor What to Expect When You’re Electing- Preparing for Cyber Threats to the 2022 U.S. Midterm Elections
-
Russian Cyberwarfare- Unpacking the Kremlin’s Capabilities
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian Cyberwarfare- Unpacking the Kremlin’s Capabilities
-
CosmicDuke Malware Analysis Report
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CosmicDuke Malware Analysis Report
-
MagicWeb- NOBELIUM’s post-compromise trick to authenticate as anyone
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MagicWeb- NOBELIUM’s post-compromise trick to authenticate as anyone
-
A Cyber Threat Intelligence Self-Study Plan- Part 2
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Cyber Threat Intelligence Self-Study Plan- Part 2
-
You Can’t Audit Me- APT29 Continues Targeting Microsoft 365
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor You Can’t Audit Me- APT29 Continues Targeting Microsoft 365
-
Overview of the Cyber Weapons Used in the Ukraine - Russia War
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Overview of the Cyber Weapons Used in the Ukraine - Russia War
-
SUNSPOT Malware A Technical Analysis
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor SUNSPOT Malware A Technical Analysis
-
PART 3- How I Met Your Beacon – Brute Ratel
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor PART 3- How I Met Your Beacon – Brute Ratel
-
The original link failed its last check. Original publisher Detailsfor PowerPoint Presentation
-
Space Invaders- Cyber Threats That Are Out Of This World
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Space Invaders- Cyber Threats That Are Out Of This World
-
Burned and Blinded - Escalation Risks of Intelligence Loss from Countercyber Operations in Crisis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Burned and Blinded - Escalation Risks of Intelligence Loss from Countercyber Operations in Crisis
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Abused Slack Service Analysis of APT29's Attack on Italy
The original link failed its last check. Detailsfor Abused Slack Service Analysis of APT29's Attack on Italy
-
Russian APT29 Hackers Use Online Storage Services, DropBox and Google Drive
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian APT29 Hackers Use Online Storage Services, DropBox and Google Drive
-
A look into APT29's new early-stage Google Drive downloader
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A look into APT29's new early-stage Google Drive downloader
-
Russian Ransomware C2 Network Discovered in Censys Data
The original link failed its last check. Original publisher Detailsfor Russian Ransomware C2 Network Discovered in Censys Data
-
Analyzing a Brute Ratel Badger
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analyzing a Brute Ratel Badger
-
Il malware EnvyScout (APT29) è stato veicolato anche in Italia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Il malware EnvyScout (APT29) è stato veicolato anche in Italia
-
Brute Ratel Utilized By Threat Actors In New Ransomware Operations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Brute Ratel Utilized By Threat Actors In New Ransomware Operations
-
When Pentest Tools Go Brutal- Red-Teaming Tool Being Abused by Malicious Actors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor When Pentest Tools Go Brutal- Red-Teaming Tool Being Abused by Malicious Actors
-
Overview of Russian GRU and SVR Cyberespionage Campaigns 1H 2022
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Overview of Russian GRU and SVR Cyberespionage Campaigns 1H 2022
-
Overview of Russian GRU and SVR Cyberespionage Campaigns 1H 2022
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Overview of Russian GRU and SVR Cyberespionage Campaigns 1H 2022
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
To HADES and Back- UNC2165 Shifts to LOCKBIT to Evade Sanctions
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor To HADES and Back- UNC2165 Shifts to LOCKBIT to Evade Sanctions
-
2020-12 - Solarwinds Breach Resource Center
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 2020-12 - Solarwinds Breach Resource Center
-
Gamaredon Group Understanding the Russian APT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Gamaredon Group Understanding the Russian APT
-
Cozy Smuggled Into The Box- APT29 Abusing Legitimate Software For Targeted Operations In Europe
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cozy Smuggled Into The Box- APT29 Abusing Legitimate Software For Targeted Operations In Europe
-
Operation RestyLink- Targeted attack campaign targeting Japanese companies
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation RestyLink- Targeted attack campaign targeting Japanese companies
-
Russian Cyber Attack campaigns and actors - NOBELIUM has struck again.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian Cyber Attack campaigns and actors - NOBELIUM has struck again.pdf
-
Russian cyber attack campaigns and actors.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian cyber attack campaigns and actors.pdf
-
How a secret Dutch mole aided the US-Israeli Stuxnet cyberattack on Iran.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How a secret Dutch mole aided the US-Israeli Stuxnet cyberattack on Iran.pdf
-
UNC3524: Eye Spy on Your Email
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor UNC3524: Eye Spy on Your Email
-
SOLARDEFLECTION C2 Infrastructure Used by NOBELIUM in Company Brand Misuse
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SOLARDEFLECTION C2 Infrastructure Used by NOBELIUM in Company Brand Misuse
-
UNC3524- Eye Spy on Your Email
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor UNC3524- Eye Spy on Your Email
-
UNC3524_ Eye Spy on Your Email _ Mandiant
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor UNC3524_ Eye Spy on Your Email _ Mandiant
-
Trello From the Other Side- Tracking APT29 Phishing Campaigns
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Trello From the Other Side- Tracking APT29 Phishing Campaigns
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
yir-cyber-threats-report-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-report-download.pdf
-
Assembling the Russian Nesting Doll- UNC2452 Merged into APT29
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Assembling the Russian Nesting Doll- UNC2452 Merged into APT29
-
Russian State-Sponsored and Criminal Cyber .pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian State-Sponsored and Criminal Cyber .pdf
-
Alert (AA22-110A)- Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (AA22-110A)- Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure
-
Nobelium - Israeli Embassy Maldoc
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Nobelium - Israeli Embassy Maldoc
-
Nobelium - Israeli Embassy Maldoc
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Nobelium - Israeli Embassy Maldoc
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Conti Leaks- Examining the Panama Papers of Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Conti Leaks- Examining the Panama Papers of Ransomware
-
Legitimate Sites used as Cobalt Strike C2s against Indian Government
The original link failed its last check. Original publisher Detailsfor Legitimate Sites used as Cobalt Strike C2s against Indian Government
-
Legitimate Sites Used As Cobalt Strike C2s Against Indian Government
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Legitimate Sites Used As Cobalt Strike C2s Against Indian Government
-
Responses to Russia's Invasion of Ukraine Likely to Spur Retaliation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Responses to Russia's Invasion of Ukraine Likely to Spur Retaliation
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor 2021trends.pdf
-
Nobelium Returns to the Political World Stage
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Nobelium Returns to the Political World Stage
-
Nobelium Returns to the Political World Stage
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Nobelium Returns to the Political World Stage
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Observations from the StellarParticle Campaign
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Observations from the StellarParticle Campaign
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2022GTR
-
VMware Exposing Malware In Linux Based Multi Cloud Environments
The original link failed its last check. Original publisher Detailsfor VMware Exposing Malware In Linux Based Multi Cloud Environments
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t32021
-
Early Bird Catches the Wormhole- Observations from the StellarParticle Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Early Bird Catches the Wormhole- Observations from the StellarParticle Campaign
-
APT29_StellarParticle-Campaing_CrowdStrike
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT29_StellarParticle-Campaing_CrowdStrike
-
Anticipating Cyber Threats as the Ukraine Crisis Escalates
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Anticipating Cyber Threats as the Ukraine Crisis Escalates
-
Patchwork APT caught in its own web
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Patchwork APT caught in its own web
-
NOBELIUM’s EnvyScout infection chain goes in the registry, targeting embassies
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor NOBELIUM’s EnvyScout infection chain goes in the registry, targeting embassies
-
Winnti is Coming - Evolution after Prosecution@HITCON2021
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Winnti is Coming - Evolution after Prosecution@HITCON2021
-
No Unaccompanied Miners- Supply Chain Compromises Through Node.js Packages (UNC3379)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor No Unaccompanied Miners- Supply Chain Compromises Through Node.js Packages (UNC3379)
-
Phishing campaigns by the Nobelium intrusion set
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Phishing campaigns by the Nobelium intrusion set
-
Suspected Russian Activity Targeting Government and Business Entities Around the Globe (UNC2452)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Suspected Russian Activity Targeting Government and Business Entities Around the Globe (UNC2452)
-
FINDING BEACONS IN THE DARK 1650728751599
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor FINDING BEACONS IN THE DARK 1650728751599
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor HTML smuggling surges- Highly evasive loader technique increasingly used in banking malware, targeted attacks
-
The hunt for NOBELIUM, the most sophisticated nation-state attack in history
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The hunt for NOBELIUM, the most sophisticated nation-state attack in history
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Technical report Armagedon
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q3 2021
-
NOBELIUM targeting delegated administrative privileges to facilitate broader attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor NOBELIUM targeting delegated administrative privileges to facilitate broader attacks
-
New activity from Russian actor Nobelium
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New activity from Russian actor Nobelium
-
The layered infrastructure operated by APT29
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The layered infrastructure operated by APT29
-
Global_APT_Research_Report_for_the_first_half_of_2021-360
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Global_APT_Research_Report_for_the_first_half_of_2021-360
-
sneak-peek-ch1-2-finding-beacons-in-the-dark.pdf
The original link failed its last check. Original publisher Detailsfor sneak-peek-ch1-2-finding-beacons-in-the-dark.pdf
-
Masters of Mimicry: new APT group ChamelGang and its arsenal
The original link failed its last check. Original publisher Detailsfor Masters of Mimicry: new APT group ChamelGang and its arsenal
-
Masters of Mimicry: new APT group ChamelGang and its arsenal
The original link failed its last check. Original publisher Detailsfor Masters of Mimicry: new APT group ChamelGang and its arsenal
-
How to defeat the Russian Dukes- A step-by-step analysis of MiniDuke used by APT29-Cozy Bear
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How to defeat the Russian Dukes- A step-by-step analysis of MiniDuke used by APT29-Cozy Bear
-
DarkHalo after SolarWinds- the Tomiris connection (UNC2849)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DarkHalo after SolarWinds- the Tomiris connection (UNC2849)
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Zircolite vs Defense Evasion & Nobellium FoggyWeb
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Zircolite vs Defense Evasion & Nobellium FoggyWeb
-
FoggyWeb_ Targeted NOBELIUM malware leads to persistent backdoor _ Microsoft Security Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor FoggyWeb_ Targeted NOBELIUM malware leads to persistent backdoor _ Microsoft Security Blog
-
FoggyWeb- Targeted NOBELIUM malware leads to persistent backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FoggyWeb- Targeted NOBELIUM malware leads to persistent backdoor
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t22021
-
Microsoft Digital Defense Report OCTOBER 2021
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Digital Defense Report OCTOBER 2021
-
APT_trends_report_Q2_2021_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2021_Securelist
-
Autodesk reveals it was targeted by Russian SolarWinds hackers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Autodesk reveals it was targeted by Russian SolarWinds hackers
-
Diving Deep into UNC1151’s Infrastructure- Ghostwriter and beyond
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Diving Deep into UNC1151’s Infrastructure- Ghostwriter and beyond
-
Cobalt Strike, a Defender’s Guide
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cobalt Strike, a Defender’s Guide
-
Cobalt Strike- Detect this Persistent Threat
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cobalt Strike- Detect this Persistent Threat
-
Nationstate_ransomware_with_consecutive_endnotes.pdf
The original link failed its last check. Original publisher Detailsfor Nationstate_ransomware_with_consecutive_endnotes.pdf
-
APT Cobalt Strike Campaign targeting Slovakia (DEF CON talk)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Cobalt Strike Campaign targeting Slovakia (DEF CON talk)
-
DOJ- SolarWinds hackers breached emails from 27 US Attorneys’ offices
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DOJ- SolarWinds hackers breached emails from 27 US Attorneys’ offices
-
ISOMorph Infection- In-Depth Analysis of a New HTML Smuggling Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ISOMorph Infection- In-Depth Analysis of a New HTML Smuggling Campaign
-
Ghosts on the Wire- Expanding Conceptions of Network Anomalies
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ghosts on the Wire- Expanding Conceptions of Network Anomalies
-
report-old-dogs-new-tricks.pdf
The original link failed its last check. Original publisher Detailsfor report-old-dogs-new-tricks.pdf
-
Ryuk Ransomware Now Targeting Webservers
The original link failed its last check. Original publisher Detailsfor Ryuk Ransomware Now Targeting Webservers
-
Cobalt Strike- Favorite Tool from APT to Crimeware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cobalt Strike- Favorite Tool from APT to Crimeware
-
Danmarks National Bank hacked as part of 'the world's most sophisticated hacker attack' (NOBELIUM)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Danmarks National Bank hacked as part of 'the world's most sophisticated hacker attack' (NOBELIUM)
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Nobelium activity
-
SecurityScorecard Finds USAID Hack Much Larger Than Initially Thought
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SecurityScorecard Finds USAID Hack Much Larger Than Initially Thought
-
CrowdStrike Falcon Protects Customers from Recent COZY BEAR Sophisticated Phishing Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CrowdStrike Falcon Protects Customers from Recent COZY BEAR Sophisticated Phishing Campaign
-
Russian hackers breached Dutch police systems in 2017
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian hackers breached Dutch police systems in 2017
-
New sophisticated email-based attack from NOBELIUM
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New sophisticated email-based attack from NOBELIUM
-
Breaking down NOBELIUM’s latest early-stage toolset - Microsoft Security
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Breaking down NOBELIUM’s latest early-stage toolset - Microsoft Security
-
Looks like the page you're looking for doesn't exist or has moved.
The original link failed its last check. Original publisher Detailsfor Looks like the page you're looking for doesn't exist or has moved.
-
NobleBaron - New Poisoned Installers Could Be Used In Supply Chain Attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor NobleBaron - New Poisoned Installers Could Be Used In Supply Chain Attacks
-
Detecting Initial Access- HTML Smuggling and ISO Images — Part 1
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Detecting Initial Access- HTML Smuggling and ISO Images — Part 1
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Defend and deter
-
Breaking down NOBELIUM’s latest early-stage toolset
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Breaking down NOBELIUM’s latest early-stage toolset
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (AA21-148A)- Sophisticated Spearphishing Campaign Targets Government Organizations, IGOs, and NGOs
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Another Nobelium Cyberattack
-
Suspected APT29 Operation Launches Election Fraud Themed Phishing Campaigns
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Suspected APT29 Operation Launches Election Fraud Themed Phishing Campaigns
-
New sophisticated email-based attack from NOBELIUM - Microsoft Security
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor New sophisticated email-based attack from NOBELIUM - Microsoft Security
-
Elizabethan England has nothing on modern-day Russia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Elizabethan England has nothing on modern-day Russia
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis Report (AR21-134A)- Eviction Guidance for Networks Affected by the SolarWinds and Active Directory-M365 Compromise
-
Advisory Further TTPs associated with SVR cyber actors
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Advisory Further TTPs associated with SVR cyber actors
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CTIR_casestudy_2.pdf
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CTIR_casestudy_1.pdf
-
Are The Notorious Cyber Criminals Evil Corp actually Russian Spies-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Are The Notorious Cyber Criminals Evil Corp actually Russian Spies-
-
Multi-Factor Authentication- Headache for Cyber Actors Inspires New Attack Techniques
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Multi-Factor Authentication- Headache for Cyber Actors Inspires New Attack Techniques
-
the-operations-of-winnti-group.pdf
The original link failed its last check. Original publisher Detailsfor the-operations-of-winnti-group.pdf
-
Abusing Replication- Stealing AD FS Secrets Over the Network
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Abusing Replication- Stealing AD FS Secrets Over the Network
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SVR snaps back at Biden
-
Malware Analysis Report (AR21-105A)- SUNSHUTTLE
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware Analysis Report (AR21-105A)- SUNSHUTTLE
-
Statement on SolarWinds Cyber Compromise
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Statement on SolarWinds Cyber Compromise
-
FACT SHEET- Imposing Costs for Harmful Foreign Activities by the Russian Government
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FACT SHEET- Imposing Costs for Harmful Foreign Activities by the Russian Government
-
Russia- UK exposes Russian involvement in SolarWinds cyber compromise
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russia- UK exposes Russian involvement in SolarWinds cyber compromise
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor mtrends-2021
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2021-Threat-Detection-Report
-
report-bb-2021-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor report-bb-2021-threat-report.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor SilverFish_TLPWHITE
-
The original link failed its last check. Original publisher Detailsfor wp-m-unc2452.pdf
-
Technical Analysis of Operation Diànxùn
The original link failed its last check. Original publisher Detailsfor Technical Analysis of Operation Diànxùn
-
Remediating Networks Affected by the SolarWinds and Active Directory-M365 Compromise
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Remediating Networks Affected by the SolarWinds and Active Directory-M365 Compromise
-
Monitoring the Software Supply Chain with Azure Sentinel
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Monitoring the Software Supply Chain with Azure Sentinel
-
GoldMax, GoldFinder, and Sibot- Analyzing NOBELIUM’s layered persistence
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor GoldMax, GoldFinder, and Sibot- Analyzing NOBELIUM’s layered persistence
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New SUNSHUTTLE Second-Stage Backdoor Uncovered Targeting U.S.-Based Entity; Possible Connection to UNC2452
-
Intezer-2020-Go-Malware-Round-Up.pdf
The original link failed its last check. Original publisher Detailsfor Intezer-2020-Go-Malware-Round-Up.pdf
-
File not found · github/codeql
The original link failed its last check. Original publisher Detailsfor File not found · github/codeql
-
Microsoft open sources CodeQL queries used to hunt for Solorigate activity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft open sources CodeQL queries used to hunt for Solorigate activity
-
NASA and the FAA were also breached by the SolarWinds hackers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor NASA and the FAA were also breached by the SolarWinds hackers
-
The_CrowdStrike_2021_Global_Threat_Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The_CrowdStrike_2021_Global_Threat_Report
-
Cyber Attribution Is More Art Than Science. This Researcher Has a Plan to Change That
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber Attribution Is More Art Than Science. This Researcher Has a Plan to Change That
-
Cloudy with a Chance of Persistent Email Access
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cloudy with a Chance of Persistent Email Access
-
Mimecast links security breach to SolarWinds hackers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Mimecast links security breach to SolarWinds hackers
-
On attribution- APT28, APT29…Turla- No, they are NOT the same
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor On attribution- APT28, APT29…Turla- No, they are NOT the same
-
Deep dive into the Solorigate second-stage activation- From SUNBURST to TEARDROP and Raindrop
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Deep dive into the Solorigate second-stage activation- From SUNBURST to TEARDROP and Raindrop
-
Remediation and Hardening Strategies for Microsoft 365 to Defend Against UNC2452
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Remediation and Hardening Strategies for Microsoft 365 to Defend Against UNC2452
-
Mandiant Azure AD Investigator- Focusing on UNC2452 TTPs
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Mandiant Azure AD Investigator- Focusing on UNC2452 TTPs
-
Increasing resilience against Solorigate and other sophisticated attacks with Microsoft Defender
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Increasing resilience against Solorigate and other sophisticated attacks with Microsoft Defender
-
The Devil’s in the Details- SUNBURST Attribution
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Devil’s in the Details- SUNBURST Attribution
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor UNC2452- What We Know So Far
-
crowdstrike.com-SUNSPOT An Implant in the Build Process
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor crowdstrike.com-SUNSPOT An Implant in the Build Process
-
Sunburst backdoor – code overlaps with Kazuar
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sunburst backdoor – code overlaps with Kazuar
-
SUNSPOT- An Implant in the Build Process
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SUNSPOT- An Implant in the Build Process
-
securelist.com-Sunburst backdoor code overlaps with Kazuar
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor securelist.com-Sunburst backdoor code overlaps with Kazuar
-
Robust Indicators of Compromise for SUNBURST
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Robust Indicators of Compromise for SUNBURST
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Supply Chain Compromise
-
Finding Targeted SUNBURST Victims with pDNS
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Finding Targeted SUNBURST Victims with pDNS
-
SolarWinds_SUNBURST- Behavioral analytics and Collective Defense in action
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SolarWinds_SUNBURST- Behavioral analytics and Collective Defense in action
-
Golden SAML Revisited- The Solorigate Connection
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Golden SAML Revisited- The Solorigate Connection
-
Using Microsoft 365 Defender to protect against Solorigate
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Using Microsoft 365 Defender to protect against Solorigate
-
The original link failed its last check. Original publisher Detailsfor SUNBURST & Memory Analysis
-
SUNBURST Additional Technical Details
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SUNBURST Additional Technical Details
-
SolarStorm Supply Chain Attack Timeline
The original link failed its last check. Original publisher Detailsfor SolarStorm Supply Chain Attack Timeline
-
SolarStorm Supply Chain Attack Timeline
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SolarStorm Supply Chain Attack Timeline
-
Identifying UNC2452-Related Techniques for ATT&CK
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Identifying UNC2452-Related Techniques for ATT&CK
-
How A Device to Cloud Architecture Defends Against the SolarWinds Supply Chain Compromise
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How A Device to Cloud Architecture Defends Against the SolarWinds Supply Chain Compromise
-
Top Linux Cloud Threats of 2020
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Top Linux Cloud Threats of 2020
-
Russian cyber attack campaigns and actors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian cyber attack campaigns and actors
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Solorigate Resource Center
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor High Value Malicious Domains.
-
Sunburst- connecting the dots in the DNS requests
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sunburst- connecting the dots in the DNS requests
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analyzing Solorigate, the compromised DLL file that started a sophisticated cyberattack, and how Microsoft Defender helps protect customers
-
Tracking Sunburst-Related Activity with ThreatConnect Dashboards
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tracking Sunburst-Related Activity with ThreatConnect Dashboards
-
Continuous Eruption- Further Analysis of the SolarWinds Supply Chain Incident
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Continuous Eruption- Further Analysis of the SolarWinds Supply Chain Incident
-
The Strategic Implications of SolarWinds
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Strategic Implications of SolarWinds
-
DebUNCing Attribution How Mandiant Tracks Uncategorized Threat Actors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DebUNCing Attribution How Mandiant Tracks Uncategorized Threat Actors
-
SUPERNOVA: A Novel .NET Webshell
The original link failed its last check. Original publisher Detailsfor SUPERNOVA: A Novel .NET Webshell
-
SUPERNOVA- SolarStorm’s Novel .NET Webshell
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SUPERNOVA- SolarStorm’s Novel .NET Webshell
-
The SolarWinds Orion SUNBURST supply-chain Attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The SolarWinds Orion SUNBURST supply-chain Attack
-
SUPERNOVA SolarWinds .NET Webshell Analysis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SUPERNOVA SolarWinds .NET Webshell Analysis
-
subdomain & #DGA domain names , #SolarWinds, attacked by #UNC2452 @0xrb - Pastebin.com
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor subdomain & #DGA domain names , #SolarWinds, attacked by #UNC2452 @0xrb - Pastebin.com
-
List of domain infrastructure including DGA domain used by UNC2452
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor List of domain infrastructure including DGA domain used by UNC2452
-
The original link failed its last check. Original publisher Detailsfor Intel 471
-
Threat Hunt Deep Dives- SolarWinds Supply Chain Compromise (Solorigate - SUNBURST Backdoor)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Hunt Deep Dives- SolarWinds Supply Chain Compromise (Solorigate - SUNBURST Backdoor)
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A quick note from Nick Carr on COSMICGALE and SUPERNOVA that those are unrelated to UC2452 intrusion campaign
-
Dark Halo Leverages SolarWinds Compromise to Breach Organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Dark Halo Leverages SolarWinds Compromise to Breach Organizations
-
Threat Brief SolarStorm and SUNBURST Customer Coverage
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Brief SolarStorm and SUNBURST Customer Coverage
-
SolarWinds Orion and UNC2452 – Summary and Recommendations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SolarWinds Orion and UNC2452 – Summary and Recommendations
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Trojan-MSIL-Solorigate.B!dha
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SUNBURST Countermeasures
-
Tactics, Techniques and Procedures (TTPs) Utilized by FireEye’s Red Team Tools
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tactics, Techniques and Procedures (TTPs) Utilized by FireEye’s Red Team Tools
-
Advanced Persistent Infrastructure Tracking
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Infrastructure Tracking
-
Genetic Analysis of CryptoWall Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Genetic Analysis of CryptoWall Ransomware
-
Ukraine’s Top Cyber Cop on Defending Against Disinformation and Russian Hackers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ukraine’s Top Cyber Cop on Defending Against Disinformation and Russian Hackers
-
APT_trends_report_Q3_2020_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q3_2020_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Enigmatic Energetic Bear
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q3 2020
-
FY20 Microsoft Digital Defense Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor FY20 Microsoft Digital Defense Report
-
The original link failed its last check. Original publisher Detailsfor Insights
-
An overview of targeted attacks and APTs on Linux
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor An overview of targeted attacks and APTs on Linux
-
WellMess malware- analysis of its Command and Control (C2) server
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor WellMess malware- analysis of its Command and Control (C2) server
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attribution- A Puzzle
-
In-Memory shellcode decoding to evade AVs/EDRs
The original link failed its last check. Original publisher Detailsfor In-Memory shellcode decoding to evade AVs/EDRs
-
Who is behind APT29- What we know about this nation-state cybercrime group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who is behind APT29- What we know about this nation-state cybercrime group
-
US, UK, and Canada’s COVID-19 research targeted by APT29
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor US, UK, and Canada’s COVID-19 research targeted by APT29
-
Malware Analysis Report (AR20-198C)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware Analysis Report (AR20-198C)
-
Malware Analysis Report (AR20-198A)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware Analysis Report (AR20-198A)
-
How WellMess malware has been used to target Covid-19 vaccines
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How WellMess malware has been used to target Covid-19 vaccines
-
Malware Analysis Report (AR20-198B)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware Analysis Report (AR20-198B)
-
Advisory-APT29-targets-COVID-19-vaccine-development
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Advisory-APT29-targets-COVID-19-vaccine-development
-
The original link failed its last check. Original publisher Detailsfor Intel 471
-
Russian Cyber Attack Campaigns and Actors - Threat Research
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Russian Cyber Attack Campaigns and Actors - Threat Research
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (AA21-116A)- Russian Foreign Intelligence Service (SVR) Cyber Operations- Trends and Best Practices for Network Defenders
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Looking Back at LiteDuke
-
039- Deconstructing the Dukes- A Researcher’s Retrospective of APT29
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 039- Deconstructing the Dukes- A Researcher’s Retrospective of APT29
-
Catching APT41 exploiting a zero-day vulnerability
The original link failed its last check. Detailsfor Catching APT41 exploiting a zero-day vulnerability
-
2020.02.22_APT_threat_report_2019_CN_version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2020.02.22_APT_threat_report_2019_CN_version
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor [CB19] Cyber Threat Landscape in Japan – Revealing Threat in the Shadow by Chi En Shen (Ashley) Oleg Bondarenko
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020
-
The original link failed its last check. Original publisher Detailsfor Aarhus_miniseminar_291118.pdf
-
Operation Ghost- The Dukes aren’t back – they never left
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Ghost- The Dukes aren’t back – they never left
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Ghost
-
LNKR- More than Just a Browser Extension
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor LNKR- More than Just a Browser Extension
-
Mapping the connections inside Russia APT Ecosystem
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Mapping the connections inside Russia APT Ecosystem
-
Revealed- How a secret Dutch mole aided the U.S.-Israeli Stuxnet cyberattack on Iran
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Revealed- How a secret Dutch mole aided the U.S.-Israeli Stuxnet cyberattack on Iran
-
The original link failed its last check. Original publisher Detailsfor APT-Attacks-eng.pdf
-
Threat Group Cards: A Threat Actor Encyclopedia
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Hunting and detecting Cobalt Strike
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hunting and detecting Cobalt Strike
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
mpressioncss_ta_report_2019.pdf
The original link failed its last check. Original publisher Detailsfor mpressioncss_ta_report_2019.pdf
-
2019.01.03.Tencent_APT_Summary_report_2018_CN_Version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2019.01.03.Tencent_APT_Summary_report_2018_CN_Version
-
2018 APT Summary Report CN version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2018 APT Summary Report CN version
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2018 Master Table
-
Analysis of cyberattack on U.S. think tanks, non-profits, public sector by unidentified attackers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis of cyberattack on U.S. think tanks, non-profits, public sector by unidentified attackers
-
Not So Cozy: An Uncomfortable Examination of a Suspected APT29 Phishing Campaign
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Not So Cozy: An Uncomfortable Examination of a Suspected APT29 Phishing Campaign
-
Not So Cozy- An Uncomfortable Examination of a Suspected APT29 Phishing Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Not So Cozy- An Uncomfortable Examination of a Suspected APT29 Phishing Campaign
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CozyBear – In from the Cold-
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Remember Fancy Bear-
-
A Slice of 2017 Sofacy Activity - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor A Slice of 2017 Sofacy Activity - Securelist
-
russian-federation-country-profile.pdf
The original link failed its last check. Original publisher Detailsfor russian-federation-country-profile.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT29
-
Snake- Coming soon in Mac OS X flavour
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Snake- Coming soon in Mac OS X flavour
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor POSHSPY backdoor code
-
Dissecting One of APT29’s Fileless WMI and PowerShell Backdoors (POSHSPY)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Dissecting One of APT29’s Fileless WMI and PowerShell Backdoors (POSHSPY)
-
APT29 Domain Fronting With TOR
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor APT29 Domain Fronting With TOR
-
Bear Spotting Vol. 1: Russian Nation State Targeting of Government and Military Interests
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Bear Spotting Vol. 1: Russian Nation State Targeting of Government and Military Interests
-
Part I. Russian APT - APT28 collection of samples including OSX XAgent
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Part I. Russian APT - APT28 collection of samples including OSX XAgent
-
Enhanced Analysis of GRIZZLY STEPPE Activity
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Enhanced Analysis of GRIZZLY STEPPE Activity
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor [tr1adx]_ Intel
-
At the Center of the Storm: Russia's APT28 Strategically Evolves its Cyber Operations
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor At the Center of the Storm: Russia's APT28 Strategically Evolves its Cyber Operations
-
GRIZZLY STEPPE - Russian Malicious Cyber Activity
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor GRIZZLY STEPPE - Russian Malicious Cyber Activity
-
Running for Office_ Russian APT Toolkits Revealed
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Running for Office_ Russian APT Toolkits Revealed
-
Bears in the Midst_ Intrusion into the Democratic National Committee »
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Bears in the Midst_ Intrusion into the Democratic National Committee »
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Please Read
-
Russian government hackers penetrated DNC, stole opposition research on Trump - The Washington Post
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Russian government hackers penetrated DNC, stole opposition research on Trump - The Washington Post
-
Findings from Analysis of DNC Intrusion Malware
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Findings from Analysis of DNC Intrusion Malware
-
Bears in the Midst- Intrusion into the Democratic National Committee
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Bears in the Midst- Intrusion into the Democratic National Committee
-
Bears in the Midst: Intrusion into the Democratic National Committee
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Bears in the Midst: Intrusion into the Democratic National Committee
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor PowerPoint Presentation
-
The original link failed its last check. Original publisher Detailsfor rpt-mtrends-2016.pdf
-
Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups
-
Cyber war in perspective: Russian aggression against Ukraine
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Cyber war in perspective: Russian aggression against Ukraine
-
The Dukes- 7 Years Of Russian Cyber-Espionage
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Dukes- 7 Years Of Russian Cyber-Espionage
-
The Dukes: 7 years of Russian cyberespionage
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Dukes: 7 years of Russian cyberespionage
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Fancy Bear
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Fancy Bear
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Fancy Bear
-
Hammertoss: Stealthy Tactics Define A Russian Cyber Threat Group
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Hammertoss: Stealthy Tactics Define A Russian Cyber Threat Group
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Duke APT group's latest tools: cloud services and Linux support - F-Secure Weblog : News from the Lab
-
Duke APT group's latest tools- cloud services and Linux support
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Duke APT group's latest tools- cloud services and Linux support
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Tracking MiniDionis: CozyCar’s New Ride Is Related to Seaduke - Palo Alto Networks BlogPalo Alto Networks Blog
-
"Forkmeiamfamous": Seaduke, latest weapon in the Duke armory
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor "Forkmeiamfamous": Seaduke, latest weapon in the Duke armory
-
“Forkmeiamfamous”- Seaduke, latest weapon in the Duke armory
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor “Forkmeiamfamous”- Seaduke, latest weapon in the Duke armory
-
The original link failed its last check. Original publisher Detailsfor rpt-apt29-hammertoss.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CozyDuke: Malware Analysis
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Cozyduke APT
-
OnionDuke APT Attacks Via the Tor Network
The original link failed its last check. Detailsfor OnionDuke APT Attacks Via the Tor Network
Newest first. Details opens the report in Explore.