Threat Group-3390
Also reported as TG-3390, Linen Typhoon, Earth Smilodon, APT27, Iron Tiger and 27 other names. Linked to China by four sources.
Reports per quarter
Techniques seen in the last two years
- T1059.001 6 reports in ATT&CK
- T1059.003 6 reports in ATT&CK
- T1082 6 reports reports only
- T1190 6 reports in ATT&CK
- T1071.001 5 reports in ATT&CK
- T1140 5 reports in ATT&CK
- T1547.001 5 reports in ATT&CK
- T1566.001 5 reports in ATT&CK
- T1027 4 reports reports only
- T1033 4 reports in ATT&CK
Show all 139 techniques Show fewer
- T1036.005 4 reports reports only
- T1053.005 4 reports reports only
- T1055 4 reports reports only
- T1059.005 4 reports reports only
- T1083 4 reports reports only
- T1204.002 4 reports in ATT&CK
- T1505.003 4 reports in ATT&CK
- T1543.003 4 reports in ATT&CK
- T1566.002 4 reports reports only
- T1573.001 4 reports reports only
- T1583.001 4 reports in ATT&CK
- T1587.001 4 reports reports only
- T1003.001 3 reports in ATT&CK
- T1016 3 reports in ATT&CK
- T1057 3 reports reports only
- T1078.002 3 reports reports only
- T1087.002 3 reports reports only
- T1090.001 3 reports reports only
- T1105 3 reports in ATT&CK
- T1112 3 reports in ATT&CK
- T1119 3 reports in ATT&CK
- T1132.001 3 reports reports only
- T1218 3 reports reports only
- T1569.002 3 reports reports only
- T1570 3 reports reports only
- T1620 3 reports reports only
- T1005 2 reports in ATT&CK
- T1018 2 reports in ATT&CK
- T1021.001 2 reports reports only
- T1021.002 2 reports reports only
- T1041 2 reports reports only
- T1047 2 reports in ATT&CK
- T1048 2 reports reports only
- T1071.004 2 reports reports only
- T1078.003 2 reports reports only
- T1090 2 reports reports only
- T1095 2 reports reports only
- T1106 2 reports reports only
- T1189 2 reports in ATT&CK
- T1484.001 2 reports reports only
- T1486 2 reports reports only
- T1505.004 2 reports reports only
- T1553.002 2 reports reports only
- T1555.003 2 reports reports only
- T1560.001 2 reports reports only
- T1572 2 reports reports only
- T1574.001 2 reports in ATT&CK
- T1583.003 2 reports reports only
- T1583.004 2 reports reports only
- T1588.002 2 reports in ATT&CK
- T1595.002 2 reports reports only
- T1608.001 2 reports in ATT&CK
- T1001.003 1 report reports only
- T1003 1 report reports only
- T1003.002 1 report in ATT&CK
- T1008 1 report reports only
- T1012 1 report in ATT&CK
- T1021.004 1 report reports only
- T1027.001 1 report reports only
- T1027.002 1 report in ATT&CK
- T1027.009 1 report reports only
- T1027.013 1 report in ATT&CK
- T1027.014 1 report reports only
- T1027.016 1 report reports only
- T1036.004 1 report reports only
- T1036.007 1 report reports only
- T1040 1 report reports only
- T1046 1 report in ATT&CK
- T1053 1 report reports only
- T1053.002 1 report in ATT&CK
- T1055.001 1 report reports only
- T1055.012 1 report in ATT&CK
- T1056.001 1 report in ATT&CK
- T1059.007 1 report reports only
- T1068 1 report in ATT&CK
- T1069 1 report reports only
- T1069.002 1 report reports only
- T1070.004 1 report in ATT&CK
- T1074.001 1 report in ATT&CK
- T1078 1 report in ATT&CK
- T1087.001 1 report in ATT&CK
- T1090.003 1 report reports only
- T1091 1 report reports only
- T1098.007 1 report reports only
- T1102 1 report reports only
- T1114 1 report reports only
- T1129 1 report reports only
- T1133 1 report in ATT&CK
- T1134.001 1 report reports only
- T1135 1 report reports only
- T1136.001 1 report reports only
- T1195 1 report reports only
- T1197 1 report reports only
- T1210 1 report in ATT&CK
- T1213.001 1 report reports only
- T1218.007 1 report reports only
- T1218.011 1 report reports only
- T1218.014 1 report reports only
- T1219 1 report reports only
- T1482 1 report reports only
- T1497.001 1 report reports only
- T1546.015 1 report reports only
- T1548 1 report reports only
- T1548.002 1 report in ATT&CK
- T1550.003 1 report reports only
- T1552 1 report reports only
- T1552.001 1 report reports only
- T1552.004 1 report reports only
- T1557 1 report reports only
- T1564.001 1 report reports only
- T1566 1 report reports only
- T1566.003 1 report reports only
- T1571 1 report reports only
- T1574 1 report reports only
- T1583.006 1 report reports only
- T1584.001 1 report reports only
- T1587.004 1 report reports only
- T1588.005 1 report reports only
- T1588.006 1 report reports only
- T1588.007 1 report reports only
- T1591.002 1 report reports only
- T1591.004 1 report reports only
- T1592.001 1 report reports only
- T1593.002 1 report reports only
- T1608.002 1 report in ATT&CK
- T1608.004 1 report in ATT&CK
- T1614.001 1 report reports only
- T1627.001 1 report reports only
- T1659 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2007-4723
- CVE-2007-5633
- CVE-2008-1436
- CVE-2008-3431 KEV
- CVE-2009-0796
- CVE-2009-0824
- CVE-2009-0927 KEV
- CVE-2009-3129 KEV
- CVE-2009-4324 KEV
- CVE-2010-0188 KEV ransomware
- CVE-2010-0232 KEV
- CVE-2010-0249 KEV
Show all 388 CVEs Show fewer
- CVE-2010-0738 KEV ransomware
- CVE-2010-1424
- CVE-2010-1592
- CVE-2010-2152
- CVE-2010-2883 KEV
- CVE-2010-3333 KEV
- CVE-2010-3915
- CVE-2010-3916
- CVE-2010-4398 KEV
- CVE-2011-0609 KEV
- CVE-2011-0611 KEV
- CVE-2011-1331
- CVE-2011-2005 KEV
- CVE-2011-2110
- CVE-2011-2462 KEV
- CVE-2011-3544 KEV
- CVE-2011-4369
- CVE-2012-0158 KEV ransomware
- CVE-2012-0422
- CVE-2012-0779
- CVE-2012-1535 KEV
- CVE-2012-1723 KEV ransomware
- CVE-2012-1823 KEV
- CVE-2012-1856 KEV
- CVE-2012-1875
- CVE-2012-1889 KEV
- CVE-2012-2311
- CVE-2012-4681 KEV ransomware
- CVE-2012-4792 KEV
- CVE-2012-5687
- CVE-2013-0074 KEV ransomware
- CVE-2013-0422 KEV ransomware
- CVE-2013-0707
- CVE-2013-0808
- CVE-2013-1331 KEV
- CVE-2013-1347 KEV
- CVE-2013-1493
- CVE-2013-2460
- CVE-2013-2551 KEV ransomware
- CVE-2013-2618
- CVE-2013-2729 KEV
- CVE-2013-3163 KEV
- CVE-2013-3346 KEV
- CVE-2013-3644
- CVE-2013-3660 KEV
- CVE-2013-3893 KEV
- CVE-2013-3896 KEV
- CVE-2013-3897 KEV
- CVE-2013-3900 KEV
- CVE-2013-3906 KEV
- CVE-2013-3918 KEV
- CVE-2013-4365
- CVE-2013-4979
- CVE-2013-5065 KEV
- CVE-2013-5947
- CVE-2013-5990
- CVE-2013-7331 KEV
- CVE-2013-7389
- CVE-2014-0322 KEV
- CVE-2014-0497 KEV
- CVE-2014-0515
- CVE-2014-0810
- CVE-2014-1225
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-4076
- CVE-2014-4078
- CVE-2014-4113 KEV
- CVE-2014-4114 KEV
- CVE-2014-4130
- CVE-2014-6271 KEV
- CVE-2014-6332 KEV
- CVE-2014-6352 KEV
- CVE-2014-7247
- CVE-2014-8361 KEV
- CVE-2014-8439 KEV
- CVE-2014-9583
- CVE-2015-0062
- CVE-2015-0311 KEV
- CVE-2015-0313 KEV
- CVE-2015-0336
- CVE-2015-0554
- CVE-2015-1641 KEV
- CVE-2015-1642 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-1805
- CVE-2015-2051 KEV
- CVE-2015-2387 KEV
- CVE-2015-2419 KEV
- CVE-2015-2424 KEV
- CVE-2015-2545 KEV
- CVE-2015-2546 KEV ransomware
- CVE-2015-2590 KEV
- CVE-2015-3043 KEV
- CVE-2015-3105
- CVE-2015-4902 KEV
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-5123 KEV
- CVE-2015-7248
- CVE-2015-7254
- CVE-2015-7645 KEV ransomware
- CVE-2015-7755 KEV
- CVE-2015-8651 KEV
- CVE-2016-0034 KEV ransomware
- CVE-2016-0099 KEV ransomware
- CVE-2016-0167 KEV ransomware
- CVE-2016-0189 KEV ransomware
- CVE-2016-1019 KEV ransomware
- CVE-2016-10401
- CVE-2016-3353
- CVE-2016-4117 KEV ransomware
- CVE-2016-4119
- CVE-2016-4171 KEV
- CVE-2016-5195 KEV
- CVE-2016-7255 KEV ransomware
- CVE-2016-7836 KEV
- CVE-2016-7855 KEV
- CVE-2017-0005 KEV
- CVE-2017-0143 KEV ransomware
- CVE-2017-0144 KEV ransomware
- CVE-2017-0146 KEV ransomware
- CVE-2017-0147 KEV ransomware
- CVE-2017-0176
- CVE-2017-0199 KEV ransomware
- CVE-2017-0199192
- CVE-2017-0213 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-1000353 KEV
- CVE-2017-10271 KEV ransomware
- CVE-2017-11317 KEV
- CVE-2017-11357 KEV ransomware
- CVE-2017-11467
- CVE-2017-11774 KEV
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-118822
- CVE-2017-12629
- CVE-2017-12824
- CVE-2017-15303
- CVE-2017-15944 KEV
- CVE-2017-17215
- CVE-2017-18368 KEV
- CVE-2017-5638 KEV ransomware
- CVE-2017-6327 KEV
- CVE-2017-6328
- CVE-2017-7269 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2017-9248 KEV
- CVE-2017-9822 KEV ransomware
- CVE-2018-0101
- CVE-2018-0171 KEV
- CVE-2018-0296 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-10088
- CVE-2018-1010
- CVE-2018-1012
- CVE-2018-1013
- CVE-2018-1015
- CVE-2018-10561 KEV
- CVE-2018-10562 KEV ransomware
- CVE-2018-11511
- CVE-2018-11776 KEV
- CVE-2018-1207
- CVE-2018-13379 KEV ransomware
- CVE-2018-14787
- CVE-2018-15454
- CVE-2018-15961 KEV
- CVE-2018-20250 KEV ransomware
- CVE-2018-2025036
- CVE-2018-2628 KEV
- CVE-2018-2893
- CVE-2018-4878 KEV ransomware
- CVE-2018-5002 KEV
- CVE-2018-7445 KEV
- CVE-2018-7600 KEV ransomware
- CVE-2018-7602 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8174507
- CVE-2018-8373 KEV
- CVE-2018-8440 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2018-8589 KEV
- CVE-2018-8639 KEV ransomware
- CVE-2018-9866
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0797 KEV
- CVE-2019-0803 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-11043 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-11539 KEV ransomware
- CVE-2019-1182
- CVE-2019-1367 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-1458 KEV ransomware
- CVE-2019-16098
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-16759 KEV
- CVE-2019-16920 KEV
- CVE-2019-17026 KEV
- CVE-2019-17100
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-2725 KEV ransomware
- CVE-2019-3396 KEV ransomware
- CVE-2019-5840
- CVE-2019-7609 KEV
- CVE-2019-8526 KEV
- CVE-2019-9489
- CVE-2019-9670 KEV
- CVE-2020-0601 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0968 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10148 KEV
- CVE-2020-10189 KEV
- CVE-2020-1040 KEV
- CVE-2020-1350 KEV
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-14882 KEV
- CVE-2020-1664
- CVE-2020-17144 KEV
- CVE-2020-17530 KEV
- CVE-2020-2021 KEV ransomware
- CVE-2020-2551 KEV
- CVE-2020-3125
- CVE-2020-4006 KEV
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-6789
- CVE-2020-8468 KEV
- CVE-2020-8515 KEV
- CVE-2021-1472
- CVE-2021-1473
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-20021 KEV ransomware
- CVE-2021-20022 KEV ransomware
- CVE-2021-20023 KEV ransomware
- CVE-2021-21220 KEV
- CVE-2021-2135
- CVE-2021-21551 KEV
- CVE-2021-21972 KEV ransomware
- CVE-2021-21975 KEV ransomware
- CVE-2021-21983
- CVE-2021-22555 KEV
- CVE-2021-22893 KEV ransomware
- CVE-2021-23017
- CVE-2021-24139
- CVE-2021-25323
- CVE-2021-25324
- CVE-2021-25325
- CVE-2021-26084 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-27857
- CVE-2021-28149
- CVE-2021-28152
- CVE-2021-28482
- CVE-2021-28799 KEV ransomware
- CVE-2021-29855
- CVE-2021-30116 KEV ransomware
- CVE-2021-3019
- CVE-2021-30657 KEV
- CVE-2021-30869 KEV
- CVE-2021-31195
- CVE-2021-31196 KEV
- CVE-2021-31206
- CVE-2021-31207 KEV ransomware
- CVE-2021-3156 KEV
- CVE-2021-31755 KEV
- CVE-2021-31805
- CVE-2021-32305
- CVE-2021-33044 KEV
- CVE-2021-33045 KEV
- CVE-2021-33617
- CVE-2021-33766 KEV
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-35394 KEV
- CVE-2021-3618
- CVE-2021-36942 KEV ransomware
- CVE-2021-37415 KEV
- CVE-2021-38001
- CVE-2021-39184
- CVE-2021-4034 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-40539 KEV ransomware
- CVE-2021-4104
- CVE-2021-42321 KEV ransomware
- CVE-2021-43908
- CVE-2021-44077 KEV
- CVE-2021-44165
- CVE-2021-44207 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-44832
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-1040 KEV
- CVE-2022-21587 KEV ransomware
- CVE-2022-21999 KEV ransomware
- CVE-2022-22963 KEV
- CVE-2022-22965 KEV
- CVE-2022-23597
- CVE-2022-24682 KEV ransomware
- CVE-2022-24934
- CVE-2022-26134 KEV ransomware
- CVE-2022-26138 KEV
- CVE-2022-26352 KEV ransomware
- CVE-2022-27518 KEV
- CVE-2022-27666
- CVE-2022-27924 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-29247
- CVE-2022-30190 KEV ransomware
- CVE-2022-30333 KEV ransomware
- CVE-2022-3236 KEV
- CVE-2022-34305
- CVE-2022-37042 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-41091 KEV ransomware
- CVE-2022-41328 KEV
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2022-49475
- CVE-2023-20867 KEV
- CVE-2023-2868 KEV
- CVE-2023-36884 KEV ransomware
- CVE-2023-38035 KEV ransomware
- CVE-2023-44487 KEV
- CVE-2023-46747 KEV ransomware
- CVE-2023-46805 KEV ransomware
- CVE-2024-0012 KEV ransomware
- CVE-2024-11182 KEV
- CVE-2024-1709 KEV ransomware
- CVE-2024-21887 KEV ransomware
- CVE-2024-21888
- CVE-2024-21893 KEV ransomware
- CVE-2024-23204
- CVE-2024-24919 KEV ransomware
- CVE-2024-3400 KEV ransomware
- CVE-2024-4577 KEV ransomware
- CVE-2024-49039 KEV ransomware
- CVE-2024-8190 KEV
- CVE-2024-8963 KEV
- CVE-2024-9379 KEV
- CVE-2024-9380 KEV
- CVE-2024-9381
- CVE-2024-9680 KEV ransomware
- CVE-2025-31324 KEV ransomware
- CVE-2025-4427 KEV
- CVE-2025-4428 KEV
- CVE-2025-49704 KEV ransomware
- CVE-2025-49706 KEV ransomware
- CVE-2025-53770 KEV ransomware
- CVE-2025-53771
- CVE-2025-55182 KEV ransomware
- CVE-2026-21236
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Bankshot (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor StoneDrill (Malware Family)
Show all 511 reports Show fewer
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ghost RAT (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Oblique RAT (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor METALJACK (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor elf.wellmess (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor SUNBURST (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CHINACHOPPER (Malware Family)
-
Emissary Panda, APT 27, LuckyMouse, Bronze Union
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Emissary Panda, APT 27, LuckyMouse, Bronze Union
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor HyperBro (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor MimiKatz (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor TwoFace (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor ZXShell (Malware Family)
-
Turbine Panda, APT 26, Shell Crew, WebMasters, KungFu Kittens
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Turbine Panda, APT 26, Shell Crew, WebMasters, KungFu Kittens
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PlugX (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PowGoop (Malware Family)
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
China Chopper - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor China Chopper - Threat Group Cards: A Threat Actor Encyclopedia
-
Emissary Panda, APT 27, LuckyMouse, Bronze Union
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Emissary Panda, APT 27, LuckyMouse, Bronze Union
-
The original link failed its last check. Original publisher Detailsfor Dragons in Thunder
-
Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausge…
The title opens archive.today, not the publisher’s page. Archived copy on ORKL Detailsfor Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausge…
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Modern Asia APT groups TTPs
-
Lancefly- Group Uses Custom Backdoor to Target Orgs in Government, Aviation, Other Sectors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Lancefly- Group Uses Custom Backdoor to Target Orgs in Government, Aviation, Other Sectors
-
PwC Cyber Threats 2022: A Year in Retrospect.pdf
The original link failed its last check. Original publisher Detailsfor PwC Cyber Threats 2022: A Year in Retrospect.pdf
-
Iron Tiger’s SysUpdate Reappears, Adds Linux Targeting
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iron Tiger’s SysUpdate Reappears, Adds Linux Targeting
-
Iron Tiger's SysUpdate Reappears, Adds Linux Targeting
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Iron Tiger's SysUpdate Reappears, Adds Linux Targeting
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Mac Malware of 2022
-
Conceptualizing a Continuum of Cyber Threat Attribution
The original link failed its last check. Original publisher Detailsfor Conceptualizing a Continuum of Cyber Threat Attribution
-
APT27 – One Year To Exfiltrate Them All- Intrusion In-Depth Analysis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT27 – One Year To Exfiltrate Them All- Intrusion In-Depth Analysis
-
MustangPanda%20-%20Enemy%20at%20the%20gate_final.pdf
The original link failed its last check. Original publisher Detailsfor MustangPanda%20-%20Enemy%20at%20the%20gate_final.pdf
-
Threat Analysis Report- PlugX RAT Loader Evolution
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Analysis Report- PlugX RAT Loader Evolution
-
Rising Tide- Chasing the Currents of Espionage in the South China Sea
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Rising Tide- Chasing the Currents of Espionage in the South China Sea
-
Iron Tiger Compromises Chat Application Mimi, Targets Windows, Mac, and Linux Users (IOCs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iron Tiger Compromises Chat Application Mimi, Targets Windows, Mac, and Linux Users (IOCs)
-
LuckyMouse uses a backdoored Electron app to target MacOS
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor LuckyMouse uses a backdoored Electron app to target MacOS
-
LuckyMouse uses a backdoored Electron app to target MacOS - SEKOIA.IO Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor LuckyMouse uses a backdoored Electron app to target MacOS - SEKOIA.IO Blog
-
Iron Tiger Compromises Chat Application Mimi, Targets Windows, Mac, and Linux Users
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iron Tiger Compromises Chat Application Mimi, Targets Windows, Mac, and Linux Users
-
Iron Tiger Compromises Chat Application Mimi, Targets Windows, Mac, and Linux Users
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iron Tiger Compromises Chat Application Mimi, Targets Windows, Mac, and Linux Users
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
The original link failed its last check. Original publisher Detailsfor THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
-
Space Pirates analyzing the tools and connections of a new hacker group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Space Pirates analyzing the tools and connections of a new hacker group
-
APT_trends_report_Q2_2022_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2022_Securelist
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
State-sponsored Attack Groups Capitalise on Russia-Ukraine War for Cyber Espionage
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor State-sponsored Attack Groups Capitalise on Russia-Ukraine War for Cyber Espionage
-
New -SockDetour- Fileless, Socketless Backdoor Targets U.S. Defense Contractors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New -SockDetour- Fileless, Socketless Backdoor Targets U.S. Defense Contractors
-
SockDetour Backdoor Targets U.S. Defense Contractors
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor SockDetour Backdoor Targets U.S. Defense Contractors
-
SockDetour - a Silent Fileless Socketless Backdoor - Targets US Defense Contractors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SockDetour - a Silent Fileless Socketless Backdoor - Targets US Defense Contractors
-
Defense contractors hit by stealthy SockDetour Windows backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Defense contractors hit by stealthy SockDetour Windows backdoor
-
Red Cross blames hack on Zoho vulnerability, suspects APT attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Red Cross blames hack on Zoho vulnerability, suspects APT attack
-
The APT Fallout of Vulnerabilities such as ProxyLogon, OGNL Injection, and log4shell
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The APT Fallout of Vulnerabilities such as ProxyLogon, OGNL Injection, and log4shell
-
APT27 Group Targets German Organizations with HyperBro
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT27 Group Targets German Organizations with HyperBro
-
German govt warns of APT27 hackers backdooring business networks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor German govt warns of APT27 hackers backdooring business networks
-
The link to Mirror on Box failed its last check. Detailsfor BfV Cyber-Brief Nr. 01/2022
-
APT Expands Attack on ManageEngine With Active Campaign Against ServiceDesk Plus
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Expands Attack on ManageEngine With Active Campaign Against ServiceDesk Plus
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BlackTech, an East Asian hacking group, has launched attacks in sectors such as finance and education
-
Threat actor DEV-0322 exploiting ZOHO ManageEngine ADSelfService Plus
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat actor DEV-0322 exploiting ZOHO ManageEngine ADSelfService Plus
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor TA505 exploits SolarWinds Serv-U vulnerability (CVE-2021-35211) for initial access – NCC Group Research
-
TA505 exploits SolarWinds Serv-U vulnerability (CVE-2021-35211) for initial access
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA505 exploits SolarWinds Serv-U vulnerability (CVE-2021-35211) for initial access
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Targeted Attack Campaign Against ManageEngine ADSelfService Plus Delivers Godzilla Webshells, NGLite Trojan and KdcSponge Stealer
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Targeted Attack Campaign Against ManageEngine ADSelfService Plus Delivers Godzilla Webshells, NGLite Trojan and KdcSponge Stealer
-
GhostEmperor- From ProxyLogon to kernel mode
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor GhostEmperor- From ProxyLogon to kernel mode
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
A deep-dive into the SolarWinds Serv-U SSH vulnerability (DEV-0322)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A deep-dive into the SolarWinds Serv-U SSH vulnerability (DEV-0322)
-
UNC215_ Spotlight on a Chinese Espionage Campaign in Israel _ FireEye Inc
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor UNC215_ Spotlight on a Chinese Espionage Campaign in Israel _ FireEye Inc
-
UNC215- Spotlight on a Chinese Espionage Campaign in Israel
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor UNC215- Spotlight on a Chinese Espionage Campaign in Israel
-
DeadRinger_ Exposing Chinese Threat Actors Targeting Major Telcos
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor DeadRinger_ Exposing Chinese Threat Actors Targeting Major Telcos
-
DeadRinger- Exposing Chinese Threat Actors Targeting Major Telcos
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DeadRinger- Exposing Chinese Threat Actors Targeting Major Telcos
-
Ongoing Campaign Leveraging Exchange Vulnerability Potentially Linked to Iran
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ongoing Campaign Leveraging Exchange Vulnerability Potentially Linked to Iran
-
Old trees and new flowers- Analysis of the new version of KGH spy components used by Kimsuky
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Old trees and new flowers- Analysis of the new version of KGH spy components used by Kimsuky
-
Triage analysis of Serv-U FTP user backdoor deployed by CVE-2021-35211 (DEV-0322)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Triage analysis of Serv-U FTP user backdoor deployed by CVE-2021-35211 (DEV-0322)
-
Microsoft discovers threat actor (DEV-0322) targeting SolarWinds Serv-U software with 0-day exploit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft discovers threat actor (DEV-0322) targeting SolarWinds Serv-U software with 0-day exploit
-
Kimsuky APT organization's targeted attacks on South Korean defense and security related departments
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Kimsuky APT organization's targeted attacks on South Korean defense and security related departments
-
Evilnum organizes recent attacks against European financial companies
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Evilnum organizes recent attacks against European financial companies
-
Analysis of Lazarus's recent targeted attacks against military industry and other industries
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis of Lazarus's recent targeted attacks against military industry and other industries
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t12021
-
Mustang Panda PlugX - 45.251.240.55 Pivot
The original link failed its last check. Original publisher Detailsfor Mustang Panda PlugX - 45.251.240.55 Pivot
-
APT Threat Landscape of Taiwan in 2020
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Threat Landscape of Taiwan in 2020
-
APT_trends_report_Q1_2021_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q1_2021_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q1 2021
-
Analysing a malware PCAP with IcedID and Cobalt Strike traffic
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysing a malware PCAP with IcedID and Cobalt Strike traffic
-
Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware
-
Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware
-
The leap of a Cycldek-related threat actor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The leap of a Cycldek-related threat actor
-
Examining Exchange Exploitation and its Lessons for Defenders
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Examining Exchange Exploitation and its Lessons for Defenders
-
Tactics, Techniques, and Procedures (TTPs) Used by HAFNIUM to Target Microsoft Exchange Servers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tactics, Techniques, and Procedures (TTPs) Used by HAFNIUM to Target Microsoft Exchange Servers
-
Exchange servers under siege from at least 10 APT groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Exchange servers under siege from at least 10 APT groups
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT27+turns+to+ransomware
-
China's APT hackers move to ransomware attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor China's APT hackers move to ransomware attacks
-
China cyber attacks- the current threat landscape
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor China cyber attacks- the current threat landscape
-
Operation StealthyTrident- corporate software under attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation StealthyTrident- corporate software under attack
-
APT Group Targeting Governmental Agencies in East Asia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Group Targeting Governmental Agencies in East Asia
-
Investigation with a twist_ an accidental APT attack and averted data destruction
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Investigation with a twist_ an accidental APT attack and averted data destruction
-
Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
-
Palmerworm_ Espionage Gang Targets the Media, Finance, and Other Sectors _ Symantec Blogs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Palmerworm_ Espionage Gang Targets the Media, Finance, and Other Sectors _ Symantec Blogs
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor What even is Winnti-
-
BRONZE VINEWOOD Targets Supply Chains _ Secureworks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor BRONZE VINEWOOD Targets Supply Chains _ Secureworks
-
BRONZE VINEWOOD Targets Supply Chains
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BRONZE VINEWOOD Targets Supply Chains
-
Mustang Panda Recent Activity- Dll-Sideloading trojans with temporal C2 servers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Mustang Panda Recent Activity- Dll-Sideloading trojans with temporal C2 servers
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor WastedLoader or DridexLoader-
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor T1055 Process Injection
-
What happened between the BigBadWolf and the Tiger-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor What happened between the BigBadWolf and the Tiger-
-
WINNTI GROUP_ Insights From the Past
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor WINNTI GROUP_ Insights From the Past
-
WINNTI GROUP- Insights From the Past
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor WINNTI GROUP- Insights From the Past
-
Deobfuscating and hunting for OSTAP, Trickbot’s dropper and best friend
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Deobfuscating and hunting for OSTAP, Trickbot’s dropper and best friend
-
How the Iranian Cyber Security Agency Detects Emissary Panda Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How the Iranian Cyber Security Agency Detects Emissary Panda Malware
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor report-bb-decade-of-the-rats
-
Is APT 27 Abusing COVID-19 To Attack People -!
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Is APT 27 Abusing COVID-19 To Attack People -!
-
Is APT 27 Abusing COVID-19 To Attack People !
The original link failed its last check. Detailsfor Is APT 27 Abusing COVID-19 To Attack People !
-
cybersecurity-threatscape-2019-q4-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor cybersecurity-threatscape-2019-q4-eng
-
New Variant of TrickBot Being Spread by Word Document
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Variant of TrickBot Being Spread by Word Document
-
Uncovering DRBControl: Inside the Cyberespionage Campaign Targeting Gambling Operations
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Uncovering DRBControl: Inside the Cyberespionage Campaign Targeting Gambling Operations
-
Uncovering DRBControl- Inside the Cyberespionage Campaign Targeting Gambling Operations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Uncovering DRBControl- Inside the Cyberespionage Campaign Targeting Gambling Operations
-
Actors Still Exploiting SharePoint Vulnerability to Attack Middle East Government Organizations
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Actors Still Exploiting SharePoint Vulnerability to Attack Middle East Government Organizations
-
APT27 ZXShell RootKit module updates
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT27 ZXShell RootKit module updates
-
APT27 ZxShell RootKit module updates
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT27 ZxShell RootKit module updates
-
cybersecurity-threatscape-2019-q3-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor cybersecurity-threatscape-2019-q3-eng
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor APT Trends Report Q2 2018
-
The original link failed its last check. Original publisher Detailsfor Analytics
-
BLOG SERIES_Huge Fan of Your Work
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor BLOG SERIES_Huge Fan of Your Work
-
Emissary Panda APT- Recent infrastructure and RAT analysis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Emissary Panda APT- Recent infrastructure and RAT analysis
-
A Peek into BRONZE UNION's Toolbox
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor A Peek into BRONZE UNION's Toolbox
-
Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers
-
The original link failed its last check. Original publisher Detailsfor Analytics
-
Operation-Taskmasters-2019-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation-Taskmasters-2019-eng
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Emissary Panda DLL Backdoor
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Multiple Chinese Threat Groups Exploiting CVE-2018-0798 Equation Editor Vulnerability Since Late 2018
-
OPERATION SOFT CELL- A WORLDWIDE CAMPAIGN AGAINST TELECOMMUNICATIONS PROVIDERS
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OPERATION SOFT CELL- A WORLDWIDE CAMPAIGN AGAINST TELECOMMUNICATIONS PROVIDERS
-
Operation Soft Cell_ A Worldwide Campaign Against Telecommunications Providers
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Soft Cell_ A Worldwide Campaign Against Telecommunications Providers
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Possible Turla HTTP Listener
-
Into the Fog - The Return of ICEFOG APT
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Into the Fog - The Return of ICEFOG APT
-
Emissary Panda Attacks Middle East Government Sharepoint Servers
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Emissary Panda Attacks Middle East Government Sharepoint Servers
-
Emissary Panda Attacks Middle East Government Sharepoint Servers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Emissary Panda Attacks Middle East Government Sharepoint Servers
-
APT_trends_report_Q1_2019_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q1_2019_Securelist
-
The original link failed its last check. Original publisher Detailsfor 중국 기반 해커, 국내 에너지 기관 공격
-
A Peek into BRONZE UNION’s Toolbox
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Peek into BRONZE UNION’s Toolbox
-
A Peek into BRONZE UNION’s Toolbox
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor A Peek into BRONZE UNION’s Toolbox
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2018 Master Table
-
ENISA Threat Landscape Report 2018
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ENISA Threat Landscape Report 2018
-
ChinaZ Revelations- Revealing ChinaZ Relationships with other Chinese Threat Actor Groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ChinaZ Revelations- Revealing ChinaZ Relationships with other Chinese Threat Actor Groups
-
CTA Adversary Playbook- Goblin Panda
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CTA Adversary Playbook- Goblin Panda
-
LuckyMouse signs malicious NDISProxy driver with certificate of Chinese IT company
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor LuckyMouse signs malicious NDISProxy driver with certificate of Chinese IT company
-
LuckyMouse signs malicious NDISProxy driver with certificate of Chinese IT company
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor LuckyMouse signs malicious NDISProxy driver with certificate of Chinese IT company
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Trends Report Q2 2018
-
LuckyMouse hits national data center to organize country-level waterholing campaign - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor LuckyMouse hits national data center to organize country-level waterholing campaign - Securelist
-
Chinese Cyber-Espionage Group Hacked Government Data Center
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Cyber-Espionage Group Hacked Government Data Center
-
LuckyMouse hits national data center to organize country-level waterholing campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor LuckyMouse hits national data center to organize country-level waterholing campaign
-
LuckyMouse hits national data center to organize country-level waterholing campaign
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor LuckyMouse hits national data center to organize country-level waterholing campaign
-
Decoding network data from a Gh0st RAT variant
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Decoding network data from a Gh0st RAT variant
-
Decoding network data from a Gh0st RAT variant
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Decoding network data from a Gh0st RAT variant
-
Operation PZChao- a possible return of the Iron Tiger APT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation PZChao- a possible return of the Iron Tiger APT
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor MacProStorage02:_2018ROW:Bitdefender-Business-2017-WhitePaper-PZCHAO-crea2452-en_EN:Bitdefender-Business-2017-WhitePaper-PZCHAO-crea2452-en_EN.indd
-
Advanced Persistent Threat Groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threat Groups
-
BRONZE UNION Cyberespionage Persists Despite Disclosures
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BRONZE UNION Cyberespionage Persists Despite Disclosures
-
DragonOK Updates Toolset and Targets Multiple Geographic Regions
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DragonOK Updates Toolset and Targets Multiple Geographic Regions
-
DragonOK Updates Toolset and Targets Multiple Geographic Regions
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor DragonOK Updates Toolset and Targets Multiple Geographic Regions
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Tale of Two Targets
-
threatconnect-discovers-chinese-apt-activity-in-europe
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor threatconnect-discovers-chinese-apt-activity-in-europe
-
The original link failed its last check. Original publisher Detailsfor security_report_20160613.pdf
-
Zscaler Research: Malicious Office files dropping Kasidet and Dridex
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Zscaler Research: Malicious Office files dropping Kasidet and Dridex
-
Threat Group-3390 Targets Organizations For Cyberespionage
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Threat Group-3390 Targets Organizations For Cyberespionage
-
Threat Group-3390 Targets Organizations for Cyberespionage | Dell SecureWorks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group-3390 Targets Organizations for Cyberespionage | Dell SecureWorks
-
Reversing the C2C HTTP Emmental communication
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Reversing the C2C HTTP Emmental communication
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Iron Tiger Appendix
-
Operation Iron Tiger: Exploring Chinese Cyber-Espionage Attacks on United States Defense Contractors
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Iron Tiger: Exploring Chinese Cyber-Espionage Attacks on United States Defense Contractors
-
Operation Iron Tiger- Attackers Shift from East Asia to the United States
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Iron Tiger- Attackers Shift from East Asia to the United States
-
Threat Group 3390 Cyberespionage
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group 3390 Cyberespionage
-
Uncovering the Seven Pointed Dagger
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Uncovering the Seven Pointed Dagger
-
Disect Android APKs like a Pro - Static code analysis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Disect Android APKs like a Pro - Static code analysis
-
Iran and Russia blamed for state-sponsored espionage
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iran and Russia blamed for state-sponsored espionage
-
Iran and Russia blamed for statesponsored espionage
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Iran and Russia blamed for statesponsored espionage
-
Iran and Russia blamed for state-sponsored espionage
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Iran and Russia blamed for state-sponsored espionage
-
BKDR_RARSTONE: New RAT to Watch Out For - TrendLabs Security Intelligence Blog
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor BKDR_RARSTONE: New RAT to Watch Out For - TrendLabs Security Intelligence Blog
-
Alleged Apt Intrusion Set: 1.Php Group
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Alleged Apt Intrusion Set: 1.Php Group
-
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Inside a Back Door Attack
Newest first. Details opens the report in Explore.