Sandworm Team
Also reported as IRIDIUM, Seashell Blizzard, Quedagh, FROZENBARENTS, APT44 and 39 other names. Sources disagree on the origin.
Reports per quarter
Techniques seen in the last two years
- T1059.001 6 reports in ATT&CK
- T1105 6 reports in ATT&CK
- T1190 6 reports in ATT&CK
- T1566.001 6 reports in ATT&CK
- T1053.005 5 reports in ATT&CK
- T1059.003 5 reports reports only
- T1082 5 reports in ATT&CK
- T1083 5 reports in ATT&CK
- T1529 5 reports reports only
- T1566.002 5 reports in ATT&CK
Show all 294 techniques Show fewer
- T1005 4 reports in ATT&CK
- T1016 4 reports reports only
- T1018 4 reports in ATT&CK
- T1033 4 reports in ATT&CK
- T1057 4 reports reports only
- T1070.004 4 reports in ATT&CK
- T1071.001 4 reports in ATT&CK
- T1091 4 reports reports only
- T1134 4 reports reports only
- T1189 4 reports reports only
- T1485 4 reports in ATT&CK
- T1569.002 4 reports reports only
- T1680 4 reports reports only
- T1041 3 reports in ATT&CK
- T1046 3 reports reports only
- T1049 3 reports in ATT&CK
- T1053 3 reports reports only
- T1069.002 3 reports reports only
- T1090 3 reports in ATT&CK
- T1090.003 3 reports reports only
- T1113 3 reports reports only
- T1124 3 reports reports only
- T1133 3 reports in ATT&CK
- T1135 3 reports reports only
- T1195 3 reports in ATT&CK
- T1195.002 3 reports in ATT&CK
- T1204.002 3 reports in ATT&CK
- T1219 3 reports in ATT&CK
- T1222 3 reports reports only
- T1484.001 3 reports reports only
- T1490 3 reports in ATT&CK
- T1566.003 3 reports reports only
- T1567 3 reports reports only
- T1595.002 3 reports in ATT&CK
- T1602.002 3 reports reports only
- T1608.004 3 reports reports only
- T1659 3 reports reports only
- T1003.003 2 reports in ATT&CK
- T1007 2 reports reports only
- T1012 2 reports reports only
- T1021 2 reports reports only
- T1021.001 2 reports reports only
- T1021.004 2 reports reports only
- T1027 2 reports in ATT&CK
- T1047 2 reports in ATT&CK
- T1055 2 reports reports only
- T1056.001 2 reports in ATT&CK
- T1059 2 reports reports only
- T1059.006 2 reports reports only
- T1074.001 2 reports reports only
- T1078 2 reports in ATT&CK
- T1078.003 2 reports reports only
- T1087 2 reports reports only
- T1087.002 2 reports in ATT&CK
- T1098.007 2 reports reports only
- T1114.002 2 reports reports only
- T1136.001 2 reports reports only
- T1203 2 reports in ATT&CK
- T1210 2 reports reports only
- T1212 2 reports reports only
- T1213 2 reports reports only
- T1219.002 2 reports reports only
- T1482 2 reports reports only
- T1505.003 2 reports in ATT&CK
- T1518.001 2 reports reports only
- T1547.001 2 reports reports only
- T1548.002 2 reports reports only
- T1555.003 2 reports in ATT&CK
- T1558 2 reports reports only
- T1560 2 reports reports only
- T1566 2 reports reports only
- T1567.002 2 reports reports only
- T1567.004 2 reports reports only
- T1583.003 2 reports reports only
- T1584.004 2 reports in ATT&CK
- T1598 2 reports reports only
- T1608.006 2 reports reports only
- T1665 2 reports reports only
- T0807 1 report in ATT&CK
- T0809 1 report reports only
- T0816 1 report reports only
- T0822 1 report reports only
- T0823 1 report reports only
- T0827 1 report reports only
- T0829 1 report reports only
- T0840 1 report reports only
- T0846 1 report reports only
- T0852 1 report reports only
- T0859 1 report reports only
- T0886 1 report reports only
- T0888 1 report reports only
- T0892 1 report reports only
- T1003 1 report reports only
- T1003.001 1 report in ATT&CK
- T1003.002 1 report reports only
- T1003.004 1 report reports only
- T1008 1 report reports only
- T1010 1 report reports only
- T1016.001 1 report reports only
- T1020 1 report reports only
- T1021.002 1 report in ATT&CK
- T1021.005 1 report reports only
- T1021.006 1 report reports only
- T1036.010 1 report reports only
- T1037 1 report reports only
- T1037.001 1 report reports only
- T1039 1 report reports only
- T1040 1 report in ATT&CK
- T1053.003 1 report reports only
- T1055.001 1 report reports only
- T1055.002 1 report reports only
- T1055.003 1 report reports only
- T1055.004 1 report reports only
- T1055.009 1 report reports only
- T1055.012 1 report reports only
- T1056 1 report reports only
- T1059.002 1 report reports only
- T1059.004 1 report reports only
- T1059.005 1 report in ATT&CK
- T1059.007 1 report reports only
- T1059.009 1 report reports only
- T1059.010 1 report reports only
- T1059.011 1 report reports only
- T1068 1 report reports only
- T1069 1 report reports only
- T1069.001 1 report reports only
- T1069.003 1 report reports only
- T1070 1 report reports only
- T1071 1 report reports only
- T1071.002 1 report reports only
- T1071.004 1 report reports only
- T1072 1 report in ATT&CK
- T1074 1 report reports only
- T1074.002 1 report reports only
- T1078.004 1 report reports only
- T1087.001 1 report reports only
- T1087.004 1 report reports only
- T1090.001 1 report reports only
- T1090.002 1 report reports only
- T1095 1 report reports only
- T1098 1 report reports only
- T1098.001 1 report reports only
- T1098.003 1 report reports only
- T1098.004 1 report reports only
- T1098.005 1 report reports only
- T1098.006 1 report reports only
- T1102 1 report reports only
- T1102.002 1 report in ATT&CK
- T1104 1 report reports only
- T1110 1 report reports only
- T1110.001 1 report reports only
- T1110.002 1 report reports only
- T1110.003 1 report reports only
- T1112 1 report reports only
- T1114 1 report reports only
- T1114.001 1 report reports only
- T1114.003 1 report reports only
- T1115 1 report reports only
- T1119 1 report reports only
- T1120 1 report reports only
- T1123 1 report reports only
- T1125 1 report reports only
- T1129 1 report reports only
- T1132 1 report reports only
- T1132.001 1 report in ATT&CK
- T1134.001 1 report reports only
- T1136 1 report reports only
- T1136.002 1 report reports only
- T1137 1 report reports only
- T1137.006 1 report reports only
- T1140 1 report in ATT&CK
- T1187 1 report reports only
- T1199 1 report in ATT&CK
- T1200 1 report reports only
- T1201 1 report reports only
- T1204 1 report reports only
- T1204.001 1 report in ATT&CK
- T1204.004 1 report reports only
- T1213.001 1 report reports only
- T1213.002 1 report reports only
- T1213.003 1 report reports only
- T1217 1 report reports only
- T1218 1 report reports only
- T1218.007 1 report reports only
- T1218.011 1 report in ATT&CK
- T1221 1 report reports only
- T1222.001 1 report reports only
- T1484 1 report reports only
- T1486 1 report in ATT&CK
- T1489 1 report in ATT&CK
- T1491.002 1 report in ATT&CK
- T1496 1 report reports only
- T1497 1 report reports only
- T1497.001 1 report reports only
- T1505 1 report reports only
- T1505.004 1 report reports only
- T1518 1 report reports only
- T1530 1 report reports only
- T1534 1 report reports only
- T1537 1 report reports only
- T1538 1 report reports only
- T1543 1 report reports only
- T1543.002 1 report reports only
- T1543.003 1 report reports only
- T1543.004 1 report reports only
- T1546 1 report reports only
- T1546.003 1 report reports only
- T1546.004 1 report reports only
- T1546.008 1 report reports only
- T1546.012 1 report reports only
- T1546.015 1 report reports only
- T1547 1 report reports only
- T1547.002 1 report reports only
- T1547.005 1 report reports only
- T1547.009 1 report reports only
- T1548 1 report reports only
- T1550 1 report reports only
- T1550.001 1 report reports only
- T1550.002 1 report reports only
- T1552.004 1 report reports only
- T1554 1 report reports only
- T1555 1 report reports only
- T1556 1 report reports only
- T1556.006 1 report reports only
- T1556.009 1 report reports only
- T1557 1 report reports only
- T1558.003 1 report reports only
- T1559 1 report reports only
- T1560.001 1 report reports only
- T1560.002 1 report reports only
- T1561.001 1 report reports only
- T1561.002 1 report in ATT&CK
- T1564.002 1 report reports only
- T1565 1 report reports only
- T1565.001 1 report reports only
- T1566.004 1 report reports only
- T1567.001 1 report reports only
- T1569 1 report reports only
- T1570 1 report in ATT&CK
- T1571 1 report in ATT&CK
- T1572 1 report reports only
- T1573 1 report reports only
- T1573.001 1 report reports only
- T1573.002 1 report reports only
- T1574 1 report reports only
- T1574.001 1 report reports only
- T1574.011 1 report reports only
- T1578 1 report reports only
- T1580 1 report reports only
- T1583 1 report in ATT&CK
- T1583.001 1 report in ATT&CK
- T1584 1 report reports only
- T1585 1 report reports only
- T1585.002 1 report in ATT&CK
- T1586.002 1 report reports only
- T1587 1 report reports only
- T1587.001 1 report in ATT&CK
- T1587.003 1 report reports only
- T1588 1 report reports only
- T1588.002 1 report in ATT&CK
- T1588.003 1 report reports only
- T1588.004 1 report reports only
- T1588.007 1 report reports only
- T1589.002 1 report in ATT&CK
- T1591.002 1 report in ATT&CK
- T1595 1 report reports only
- T1598.002 1 report reports only
- T1598.003 1 report in ATT&CK
- T1602 1 report reports only
- T1602.001 1 report reports only
- T1608 1 report reports only
- T1608.001 1 report in ATT&CK
- T1608.002 1 report reports only
- T1608.003 1 report reports only
- T1608.005 1 report reports only
- T1613 1 report reports only
- T1614 1 report reports only
- T1614.001 1 report reports only
- T1615 1 report reports only
- T1619 1 report reports only
- T1622 1 report reports only
- T1652 1 report reports only
- T1654 1 report reports only
- T1657 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-1999-0191
- CVE-1999-0262
- CVE-2008-3431 KEV
- CVE-2009-3129 KEV
- CVE-2010-0232 KEV
- CVE-2010-2861 KEV ransomware
- CVE-2010-3333 KEV
- CVE-2010-4398 KEV
- CVE-2011-0611 KEV
- CVE-2011-3402 KEV
- CVE-2011-4041
- CVE-2012-0158 KEV ransomware
Show all 185 CVEs Show fewer
- CVE-2012-1856 KEV
- CVE-2012-5687
- CVE-2013-2729 KEV
- CVE-2013-3906 KEV
- CVE-2013-5947
- CVE-2014-0751
- CVE-2014-1225
- CVE-2014-1761 KEV
- CVE-2014-2962
- CVE-2014-3828
- CVE-2014-4019
- CVE-2014-4114 KEV
- CVE-2014-4404 KEV
- CVE-2014-6271 KEV
- CVE-2014-6277
- CVE-2014-6278 KEV
- CVE-2014-6352 KEV
- CVE-2014-7186
- CVE-2014-7187
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-1130 KEV
- CVE-2015-1635 KEV
- CVE-2015-1641 KEV
- CVE-2015-1770 KEV
- CVE-2015-2051 KEV
- CVE-2015-2360 KEV
- CVE-2015-2424 KEV
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-5374
- CVE-2015-6585
- CVE-2015-7248
- CVE-2015-7254
- CVE-2016-4117 KEV ransomware
- CVE-2016-5195 KEV
- CVE-2016-7255 KEV ransomware
- CVE-2016-7855 KEV
- CVE-2017-0144 KEV ransomware
- CVE-2017-0147 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-10271 KEV ransomware
- CVE-2017-11774 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2017-18368 KEV
- CVE-2017-5638 KEV ransomware
- CVE-2017-6190
- CVE-2017-9805 KEV
- CVE-2018-10562 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-2025036
- CVE-2018-4878 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8405 KEV ransomware
- CVE-2018-8406 KEV ransomware
- CVE-2018-8611 KEV
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0803 KEV ransomware
- CVE-2019-0859 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-15126
- CVE-2019-1579 KEV ransomware
- CVE-2019-1653 KEV
- CVE-2019-19781 KEV ransomware
- CVE-2019-2725 KEV ransomware
- CVE-2019-6820
- CVE-2019-7609 KEV
- CVE-2019-9670 KEV
- CVE-2020-0601 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0968 KEV ransomware
- CVE-2020-11901
- CVE-2020-1472 KEV ransomware
- CVE-2020-14882 KEV
- CVE-2020-15368
- CVE-2020-3529
- CVE-2020-35730 KEV
- CVE-2020-4006 KEV
- CVE-2020-5902 KEV ransomware
- CVE-2021-1636
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-21551 KEV
- CVE-2021-25748
- CVE-2021-26084 KEV ransomware
- CVE-2021-26334
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-31207 KEV ransomware
- CVE-2021-3156 KEV
- CVE-2021-32648 KEV
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-36934 KEV
- CVE-2021-38647 KEV ransomware
- CVE-2021-3970
- CVE-2021-3971
- CVE-2021-3972
- CVE-2021-4034 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2021-45105
- CVE-2022-0847 KEV
- CVE-2022-22963 KEV
- CVE-2022-22965 KEV
- CVE-2022-23176 KEV
- CVE-2022-26134 KEV ransomware
- CVE-2022-26352 KEV ransomware
- CVE-2022-27926 KEV
- CVE-2022-30190 KEV ransomware
- CVE-2022-3802
- CVE-2022-38028 KEV
- CVE-2022-40300
- CVE-2022-41040 KEV ransomware
- CVE-2022-41091 KEV ransomware
- CVE-2022-4135 KEV
- CVE-2022-41352 KEV ransomware
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2023-23397 KEV
- CVE-2023-27532 KEV ransomware
- CVE-2023-2868 KEV
- CVE-2023-28771 KEV
- CVE-2023-32315 KEV
- CVE-2023-33009 KEV
- CVE-2023-33010 KEV
- CVE-2023-34362 KEV ransomware
- CVE-2023-36025 KEV
- CVE-2023-36884 KEV ransomware
- CVE-2023-3883
- CVE-2023-38831 KEV ransomware
- CVE-2023-42793 KEV ransomware
- CVE-2023-46805 KEV ransomware
- CVE-2023-48788 KEV ransomware
- CVE-2023-4966 KEV ransomware
- CVE-2023-5631 KEV
- CVE-2024-0012 KEV ransomware
- CVE-2024-11182 KEV
- CVE-2024-1709 KEV ransomware
- CVE-2024-21412 KEV ransomware
- CVE-2024-21413 KEV
- CVE-2024-21887 KEV ransomware
- CVE-2024-21893 KEV ransomware
- CVE-2024-21983
- CVE-2024-2617
- CVE-2024-26229
- CVE-2024-3400 KEV ransomware
- CVE-2024-42009 KEV
- CVE-2024-47575 KEV
- CVE-2024-49039 KEV ransomware
- CVE-2024-7262 KEV
- CVE-2024-7263
- CVE-2024-9474 KEV ransomware
- CVE-2024-9680 KEV ransomware
- CVE-2025-0282 KEV ransomware
- CVE-2025-26633 KEV ransomware
- CVE-2025-55182 KEV ransomware
- CVE-2025-6218 KEV
- CVE-2025-66478
- CVE-2025-8088 KEV ransomware
- CVE-2026-1281 KEV
- CVE-2026-1340 KEV
- CVE-2026-21509 KEV
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor DCRat (Malware Family)
Show all 528 reports Show fewer
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CyclopsBlink (Malware Family)
-
HermeticWiper (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor HermeticWiper (Malware Family)
-
Olympic Destroyer (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Olympic Destroyer (Malware Family)
-
Sandworm Team, Iron Viking, Voodoo Bear
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Sandworm Team, Iron Viking, Voodoo Bear
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BlackEnergy (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor EternalPetya (Malware Family)
-
Sandworm Zero Day Vulnerability | iSIGHT Partners
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Sandworm Zero Day Vulnerability | iSIGHT Partners
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BlackEnergy
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor VPNFilter (Malware Family)
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PartyTicket (Malware Family)
-
RU APT targeting Energy Infrastructure (Unknown unknowns, part 3)
The original link failed its last check. Original publisher Detailsfor RU APT targeting Energy Infrastructure (Unknown unknowns, part 3)
-
The original link failed its last check. Original publisher Detailsfor APT44 Report
-
CVE-2024-21412_ Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CVE-2024-21412_ Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day
-
Ukraine remains Russia’s biggest cyber focus in 2023
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ukraine remains Russia’s biggest cyber focus in 2023
-
Dissecting Npm Malware- Five Packages And Their Evil Install Scripts
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Dissecting Npm Malware- Five Packages And Their Evil Install Scripts
-
Contracts Identify Cyber Operations Projects from Russian Company NTC Vulkan
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Contracts Identify Cyber Operations Projects from Russian Company NTC Vulkan
-
Microsoft Security Compliance and Identity
The original link failed its last check. Original publisher Detailsfor Microsoft Security Compliance and Identity
-
SwiftSlicer- New destructive wiper malware strikes Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SwiftSlicer- New destructive wiper malware strikes Ukraine
-
Russia’s Wartime Cyber Operations in Ukraine- Military Impacts, Influences, and Implications
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russia’s Wartime Cyber Operations in Ukraine- Military Impacts, Influences, and Implications
-
Preparing for a Russian cyber offensive against Ukraine this winter
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Preparing for a Russian cyber offensive against Ukraine this winter
-
Unpacking Colibri Loader- A Russian APT linked Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Unpacking Colibri Loader- A Russian APT linked Campaign
-
Inside the Mind of a ‘Rat’ - Agent Tesla Detection and Analysis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Inside the Mind of a ‘Rat’ - Agent Tesla Detection and Analysis
-
Conceptualizing a Continuum of Cyber Threat Attribution
The original link failed its last check. Original publisher Detailsfor Conceptualizing a Continuum of Cyber Threat Attribution
-
Overview of the Cyber Weapons Used in the Ukraine - Russia War
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Overview of the Cyber Weapons Used in the Ukraine - Russia War
-
Space Invaders- Cyber Threats That Are Out Of This World
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Space Invaders- Cyber Threats That Are Out Of This World
-
Continued cyber activity in Eastern Europe observed by TAG
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Continued cyber activity in Eastern Europe observed by TAG
-
Industroyer2 and INCONTROLLER In-depth Technical Analysis of the Most Recent ICS-specific Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Industroyer2 and INCONTROLLER In-depth Technical Analysis of the Most Recent ICS-specific Malware
-
Deep Analysis of Snake Keylogger
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Deep Analysis of Snake Keylogger
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t12022
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor UNC1151 Assessed with High Confidence to have Links to Belarus, Ghostwriter Campaign Aligned with Belarusian Government Interests _ Mandiant
-
Threat Thursday- Malware Rebooted - How Industroyer2 Takes Aim at Ukraine Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Thursday- Malware Rebooted - How Industroyer2 Takes Aim at Ukraine Infrastructure
-
Network Footprints of Gamaredon Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Network Footprints of Gamaredon Group
-
Threat Thursday_ Malware Rebooted - How Industroyer2 Takes Aim at Ukraine Infrastructure
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Thursday_ Malware Rebooted - How Industroyer2 Takes Aim at Ukraine Infrastructure
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attackers Deploy New ICS Attack Framework - TRITON - and Cause Operational Disruption to Critical Infrastructure.pdf
-
Russian Cyber Attack campaigns and actors - NOBELIUM has struck again.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian Cyber Attack campaigns and actors - NOBELIUM has struck again.pdf
-
BE2 custom plugins, router abuse, and target profiles.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BE2 custom plugins, router abuse, and target profiles.pdf
-
Russian cyber attack campaigns and actors.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian cyber attack campaigns and actors.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Black Energy – Analysis.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Industroyer2 in Perspective
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Industroyer2 in Perspective
-
Russian State-Sponsored and Criminal Cyber .pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian State-Sponsored and Criminal Cyber .pdf
-
Alert (AA22-110A)- Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (AA22-110A)- Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure
-
Industroyer2- Industroyer reloaded
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Industroyer2- Industroyer reloaded
-
Industroyer2 Industroyer Reloaded
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Industroyer2 Industroyer Reloaded
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Cyberattack by Sandworm Group (UAC-0082) on energy facilities of Ukraine using malicious programs INDUSTROYER2 and CADDYWIPER
-
Industroyer2- Industroyer reloaded
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Industroyer2- Industroyer reloaded
-
CISA warns orgs of WatchGuard bug exploited by Russian state hackers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CISA warns orgs of WatchGuard bug exploited by Russian state hackers
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ukraine CyberWar Overview
-
US disrupts Russian Cyclops Blink botnet before being used in attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor US disrupts Russian Cyclops Blink botnet before being used in attacks
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Justice Department Announces Court-Authorized Disruption of Botnet Controlled by the Russian Federation’s Main Intelligence Directorate (GRU)
-
Viasat confirms satellite modems were wiped with AcidRain malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Viasat confirms satellite modems were wiped with AcidRain malware
-
AcidRain: A Modem Wiper Rains Down on Europe
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor AcidRain: A Modem Wiper Rains Down on Europe
-
AcidRain - A Modem Wiper Rains Down on Europe
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor AcidRain - A Modem Wiper Rains Down on Europe
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who is EMBER BEAR-
-
New Sandworm Malware Cyclops Blink Replaces VPNFilter
The link to Mirror on Box failed its last check. Detailsfor New Sandworm Malware Cyclops Blink Replaces VPNFilter
-
Sandworm- A tale of disruption told anew
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sandworm- A tale of disruption told anew
-
Cyclops Blink malware sets up shop in ASUS routers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyclops Blink malware sets up shop in ASUS routers
-
Cyclops Blink Sets Sights on Asus Routers
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cyclops Blink Sets Sights on Asus Routers
-
Cyclops Blink Sets Sights on Asus Routers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyclops Blink Sets Sights on Asus Routers
-
ASUS warns of Cyclops Blink malware attacks targeting routers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ASUS warns of Cyclops Blink malware attacks targeting routers
-
China’s Government Is Learning From Russia’s Cyberattacks Against Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor China’s Government Is Learning From Russia’s Cyberattacks Against Ukraine
-
New CaddyWiper data wiping malware hits Ukrainian networks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New CaddyWiper data wiping malware hits Ukrainian networks
-
Responses to Russia's Invasion of Ukraine Likely to Spur Retaliation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Responses to Russia's Invasion of Ukraine Likely to Spur Retaliation
-
HermeticWiper and PartyTicket Targeting Computers in Ukraine
The link to Mirror on Box failed its last check. Detailsfor HermeticWiper and PartyTicket Targeting Computers in Ukraine
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor What is HermeticWiper – An Analysis of the Malware and Larger Threat Landscape in the Russian Ukrainian War
-
Cyber threat activity in Ukraine- analysis and resources
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber threat activity in Ukraine- analysis and resources
-
Russia or Ukraine- Hacking groups take sides
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russia or Ukraine- Hacking groups take sides
-
What You Need to Know About Russian Cyber Escalation in Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor What You Need to Know About Russian Cyber Escalation in Ukraine
-
Threat Update – Ukraine & Russia conflict
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Update – Ukraine & Russia conflict
-
Report-OSINT-Russia-Ukraine-Conflict-Cyberaspect.pdf
The original link failed its last check. Original publisher Detailsfor Report-OSINT-Russia-Ukraine-Conflict-Cyberaspect.pdf
-
Shadowserver Special Reports – Cyclops Blink
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shadowserver Special Reports – Cyclops Blink
-
Security warning- Hackers are using this new malware to target firewall appliances
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Security warning- Hackers are using this new malware to target firewall appliances
-
New Sandworm malware Cyclops Blink replaces VPNFilter
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Sandworm malware Cyclops Blink replaces VPNFilter
-
Alert (AA22-054A) New Sandworm Malware Cyclops Blink Replaces VPNFilter
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (AA22-054A) New Sandworm Malware Cyclops Blink Replaces VPNFilter
-
Var tæt på at slukke tusindvis af vindmøller- Nu fortæller Vestas om cyberangreb
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Var tæt på at slukke tusindvis af vindmøller- Nu fortæller Vestas om cyberangreb
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t32021
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Lessons Learned From Successive Use of Offensive Cyber Operations Against Ukraine and What May Be Next
-
Deep Analysis Agent Tesla Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Deep Analysis Agent Tesla Malware
-
Anticipating Cyber Threats as the Ukraine Crisis Escalates
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Anticipating Cyber Threats as the Ukraine Crisis Escalates
-
Anticipating and Preparing for Russian Cyber Activity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Anticipating and Preparing for Russian Cyber Activity
-
Technical Analysis of the WhisperGate Malicious Bootloader
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Technical Analysis of the WhisperGate Malicious Bootloader
-
Deep analysis agent tesla malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Deep analysis agent tesla malware
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor UNC1151 Assessed with High Confidence to have Links to Belarus, Ghostwriter Campaign Aligned with Belarusian Government Interests
-
UNC1151_Assessed-with-High-Confidence-to-have-Links-to-Belarus_Mandiant
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor UNC1151_Assessed-with-High-Confidence-to-have-Links-to-Belarus_Mandiant
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t22021
-
The Ghostwriter Scenario (UNC1151)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Ghostwriter Scenario (UNC1151)
-
Ghosts on the Wire- Expanding Conceptions of Network Anomalies
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ghosts on the Wire- Expanding Conceptions of Network Anomalies
-
report-old-dogs-new-tricks.pdf
The original link failed its last check. Original publisher Detailsfor report-old-dogs-new-tricks.pdf
-
Technical report of AgentTesla
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Technical report of AgentTesla
-
Centreon to Exim and Back- On the Trail of Sandworm
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Centreon to Exim and Back- On the Trail of Sandworm
-
France Ties Russia's Sandworm to a Multiyear Hacking Spree
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor France Ties Russia's Sandworm to a Multiyear Hacking Spree
-
What Is the Point of These Nation-State Indictments-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor What Is the Point of These Nation-State Indictments-
-
Auf Tätersuche- Herausforderungen bei der Analyse von Cyber-Angriffen
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Auf Tätersuche- Herausforderungen bei der Analyse von Cyber-Angriffen
-
The Devil’s in the Details- SUNBURST Attribution
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Devil’s in the Details- SUNBURST Attribution
-
Russian cyber attack campaigns and actors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian cyber attack campaigns and actors
-
Russian APT Uses COVID-19 Lures to Deliver Zebrocy - Intezer
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Russian APT Uses COVID-19 Lures to Deliver Zebrocy - Intezer
-
A Zebra in Gopher's Clothing- Russian APT Uses COVID-19 Lures to Deliver Zebrocy
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Zebra in Gopher's Clothing- Russian APT Uses COVID-19 Lures to Deliver Zebrocy
-
Ukraine’s Top Cyber Cop on Defending Against Disinformation and Russian Hackers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ukraine’s Top Cyber Cop on Defending Against Disinformation and Russian Hackers
-
Extrapolating Adversary Intent Through Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Extrapolating Adversary Intent Through Infrastructure
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Enigmatic Energetic Bear
-
The Russian Hackers (BERSERK BEAR) Playing 'Chekhov's Gun' With US Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Russian Hackers (BERSERK BEAR) Playing 'Chekhov's Gun' With US Infrastructure
-
Revisited- Fancy Bear's New Faces...and Sandworms' too
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Revisited- Fancy Bear's New Faces...and Sandworms' too
-
US charges Russian GRU officers for NotPetya, other major hacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor US charges Russian GRU officers for NotPetya, other major hacks
-
US Indicts Sandworm, Russia's Most Destructive Cyberwar Unit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor US Indicts Sandworm, Russia's Most Destructive Cyberwar Unit
-
UK exposes series of Russian cyber attacks against Olympic and Paralympic Games
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor UK exposes series of Russian cyber attacks against Olympic and Paralympic Games
-
2020.10.15_Operation_Quicksand_MuddyWater’s_Offensive_Attack_Against_Israeli
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2020.10.15_Operation_Quicksand_MuddyWater’s_Offensive_Attack_Against_Israeli
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attribution- A Puzzle
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q22020
-
Russia's GRU Hackers Hit US Government and Energy Targets
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russia's GRU Hackers Hit US Government and Energy Targets
-
Probable Sandworm Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Probable Sandworm Infrastructure
-
Russian Cyber Attack Campaigns and Actors - Threat Research
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Russian Cyber Attack Campaigns and Actors - Threat Research
-
NSA- Russia's Sandworm Hackers Have Hijacked Mail Servers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor NSA- Russia's Sandworm Hackers Have Hijacked Mail Servers
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Silos of Excellence
-
CSA Sandworm Actors Exploiting Vulnerability in Exim Transfer Agent
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CSA Sandworm Actors Exploiting Vulnerability in Exim Transfer Agent
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Turla_ComRAT
-
Mikroceen_ Spying backdoor leveraged in high‑profile networks in Central Asia _ WeLiveSecurity
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Mikroceen_ Spying backdoor leveraged in high‑profile networks in Central Asia _ WeLiveSecurity
-
Mikroceen- Spying backdoor leveraged in high‑profile networks in Central Asia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Mikroceen- Spying backdoor leveraged in high‑profile networks in Central Asia
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q12020
-
Spyware-Stealer-Locker-Wiper-LockerGoga-Revisited.pdf
The original link failed its last check. Original publisher Detailsfor Spyware-Stealer-Locker-Wiper-LockerGoga-Revisited.pdf
-
The ICS Threat Landscape and Activity Groups
The original link failed its last check. Original publisher Detailsfor The ICS Threat Landscape and Activity Groups
-
UK condemns Russia's GRU over Georgia cyber-attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor UK condemns Russia's GRU over Georgia cyber-attacks
-
Rich Headers- leveraging this mysterious artifact of the PE format
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Rich Headers- leveraging this mysterious artifact of the PE format
-
North American Electric Cyber Threat Perspective
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor North American Electric Cyber Threat Perspective
-
The Untold Story of the 2018 Olympics Cyberattack, the Most Deceptive Hack in History
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Untold Story of the 2018 Olympics Cyberattack, the Most Deceptive Hack in History
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Ghost
-
Dragos - Global Oil and Gas Cyber Threat Perspctive
The original link failed its last check. Original publisher Detailsfor Dragos - Global Oil and Gas Cyber Threat Perspctive
-
Zebrocy Multilanguage Malware Salad
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Zebrocy Multilanguage Malware Salad
-
Zebrocy’s Multilanguage Malware Salad
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Zebrocy’s Multilanguage Malware Salad
-
Malware Against the C Monoculture
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware Against the C Monoculture
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET-LightNeuron
-
The original link failed its last check. Original publisher Detailsfor rpt-mtrends-2019.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2019GlobalThreatReport
-
Iranian-backed hackers stole data from major U.S. government contractor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian-backed hackers stole data from major U.S. government contractor
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor rpt-mtrends-2019
-
The original link failed its last check. Original publisher Detailsfor CrowdStrike_GTR_2019.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BLACK ENERGY – Analysis
-
GreyEnergy: Updated arsenal of one of the most dangerous threat actors
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor GreyEnergy: Updated arsenal of one of the most dangerous threat actors
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_GreyEnergy
-
GreyEnergy- Updated arsenal of one of the most dangerous threat actors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor GreyEnergy- Updated arsenal of one of the most dangerous threat actors
-
Microsoft Word - CRASHOVERRIDE_Dragos_Website_FINAL.docx
The original link failed its last check. Original publisher Detailsfor Microsoft Word - CRASHOVERRIDE_Dragos_Website_FINAL.docx
-
New TeleBots backdoor- First evidence linking Industroyer to NotPetya
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New TeleBots backdoor- First evidence linking Industroyer to NotPetya
-
The Untold Story of NotPetya, the Most Devastating Cyberattack in History
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Untold Story of NotPetya, the Most Devastating Cyberattack in History
-
The original link failed its last check. Original publisher Detailsfor BfV Cyber-Brief Nr. 02/2018
-
Industrial Control System Threats
The original link failed its last check. Original publisher Detailsfor Industrial Control System Threats
-
KillDisk Variant Hits Latin American Financial Groups
The original link failed its last check. Original publisher Detailsfor KillDisk Variant Hits Latin American Financial Groups
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor blog
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Attackers Deploy New ICS Attack Framework “TRITON” and Cause Operational Disruption to Critical Infrastructure « Attackers Deploy New ICS Attack Framework “TRITON” and Cause Operational Disruption to Critical Infrastructure | FireEye Inc
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attackers Deploy New ICS Attack Framework “TRITON” and Cause Operational Disruption to Critical Infrastructure
-
TeleBots are back_ supply-chain attacks against Ukraine
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor TeleBots are back_ supply-chain attacks against Ukraine
-
Cyberattacks Against Ukrainian ICS
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Cyberattacks Against Ukrainian ICS
-
Casting a Light on BlackEnergy
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Casting a Light on BlackEnergy
-
Analysis of TeleBots’ cunning backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis of TeleBots’ cunning backdoor
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Industroyer
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Industroyer
-
TeleBots are back: supply-chain attacks against Ukraine
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor TeleBots are back: supply-chain attacks against Ukraine
-
From BlackEnergy to ExPetr - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor From BlackEnergy to ExPetr - Securelist
-
TeleBots are back- Supply‑chain attacks against Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TeleBots are back- Supply‑chain attacks against Ukraine
-
The original link failed its last check. Original publisher Detailsfor CrashOverride_revised091118
-
Open Source Malware - Sharing is caring?
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Open Source Malware - Sharing is caring?
-
Open Source Malware - Sharing is caring-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Open Source Malware - Sharing is caring-
-
CRASHOVERRIDE: Analysis of the Threat to Electric Grid Operations
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CRASHOVERRIDE: Analysis of the Threat to Electric Grid Operations
-
Enhanced Analysis of GRIZZLY STEPPE Activity
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Enhanced Analysis of GRIZZLY STEPPE Activity
-
KillDisk now targeting Linux- Demands $250K ransom, but can’t decrypt
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor KillDisk now targeting Linux- Demands $250K ransom, but can’t decrypt
-
GRIZZLY STEPPE - Russian Malicious Cyber Activity
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor GRIZZLY STEPPE - Russian Malicious Cyber Activity
-
The rise of TeleBots- Analyzing disruptive KillDisk attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The rise of TeleBots- Analyzing disruptive KillDisk attacks
-
The rise of TeleBots: Analyzing disruptive KillDisk attacks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The rise of TeleBots: Analyzing disruptive KillDisk attacks
-
Android malware analysis with Radare- Dissecting the Triada Trojan
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Android malware analysis with Radare- Dissecting the Triada Trojan
-
It's Parliamentary: KeyBoy and the targeting of the Tibetan Community
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor It's Parliamentary: KeyBoy and the targeting of the Tibetan Community
-
It’s Parliamentary - KeyBoy and the targeting of the Tibetan Community
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor It’s Parliamentary - KeyBoy and the targeting of the Tibetan Community
-
Industrial Cybersecurity Threat Briefing
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Industrial Cybersecurity Threat Briefing
-
Fireeye - ICS Vulnerability Trend Report - 2016.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Fireeye - ICS Vulnerability Trend Report - 2016.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Unveiling Patchwork
-
Unveiling Patchwork the Copy Paste APT
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Unveiling Patchwork the Copy Paste APT
-
Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups
-
Ongoing Sophisticated Malware Campaign Compromising ICS (Update C) | ICS-CERT
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Ongoing Sophisticated Malware Campaign Compromising ICS (Update C) | ICS-CERT
-
BE2 Custom Plugins, Router Abuse, and Target Profiles - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor BE2 Custom Plugins, Router Abuse, and Target Profiles - Securelist
-
BlackEnergy APT Attacks in Ukraine employ spearphishing with Word documents
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor BlackEnergy APT Attacks in Ukraine employ spearphishing with Word documents
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor BlackEnergy3_WP_012716_1c
-
New wave of cyberattacks against Ukrainian power industry
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor New wave of cyberattacks against Ukrainian power industry
-
Back in BlackEnergy *: 2014 Targeted Attacks in Ukraine and Poland
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Back in BlackEnergy *: 2014 Targeted Attacks in Ukraine and Poland
-
BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry
-
BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry
-
BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry
-
Cyber war in perspective: Russian aggression against Ukraine
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Cyber war in perspective: Russian aggression against Ukraine
-
Operation Potao Express: Analysis Of A Cyber-Espionage Toolkit
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Potao Express: Analysis Of A Cyber-Espionage Toolkit
-
Operation Potao Express- Analysis of a cyber‑espionage toolkit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Potao Express- Analysis of a cyber‑espionage toolkit
-
FireEye Intelligence: Threat Landscape Overview
The original link failed its last check. Original publisher Detailsfor FireEye Intelligence: Threat Landscape Overview
-
The original link failed its last check. Original publisher Detailsfor rpt-m-trends-2015.pdf
-
Korplug military targeted attacks- Afghanistan & Tajikistan
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Korplug military targeted attacks- Afghanistan & Tajikistan
-
Korplug military targeted attacks: Afghanistan & Tajikistan
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Korplug military targeted attacks: Afghanistan & Tajikistan
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Timeline of Sandworm Attacks
-
Timeline of Sandworm Attacks | Security Intelligence Blog
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Timeline of Sandworm Attacks | Security Intelligence Blog
-
BE2 Custom Plugins, Router Abuse, and Target Profiles - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor BE2 Custom Plugins, Router Abuse, and Target Profiles - Securelist
-
BE2 custom plugins, router abuse, and target profiles
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BE2 custom plugins, router abuse, and target profiles
-
Sandworm Windows zero-day vulnerability being actively exploited in targeted attacks
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Sandworm Windows zero-day vulnerability being actively exploited in targeted attacks
-
Sandworm Windows zero-day vulnerability being actively exploited in targeted attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sandworm Windows zero-day vulnerability being actively exploited in targeted attacks
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Sandworm Briefing Deck
-
BlackEnergy & Quedagh: The convergence of crimeware and APT attacks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor BlackEnergy & Quedagh: The convergence of crimeware and APT attacks
-
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Black Energy Crypto
Newest first. Details opens the report in Explore.