menuPass
Also reported as Red Apollo, Cicada, POTASSIUM, APT10, CVNX and 32 other names. Linked to China by four sources.
Reports per quarter
Techniques seen in the last two years
- T1059.001 14 reports in ATT&CK
- T1053.005 13 reports in ATT&CK
- T1057 12 reports reports only
- T1082 12 reports reports only
- T1059.003 11 reports in ATT&CK
- T1071.001 11 reports reports only
- T1140 11 reports in ATT&CK
- T1105 10 reports in ATT&CK
- T1204.002 10 reports in ATT&CK
- T1566.001 8 reports in ATT&CK
Show all 303 techniques Show fewer
- T1012 7 reports reports only
- T1016 7 reports in ATT&CK
- T1027 7 reports reports only
- T1041 7 reports reports only
- T1047 7 reports in ATT&CK
- T1190 7 reports in ATT&CK
- T1219 7 reports reports only
- T1055 6 reports reports only
- T1112 6 reports reports only
- T1132.001 6 reports reports only
- T1189 6 reports reports only
- T1543.003 6 reports reports only
- T1547.001 6 reports reports only
- T1566.002 6 reports reports only
- T1574.001 6 reports in ATT&CK
- T1003.001 5 reports reports only
- T1018 5 reports in ATT&CK
- T1033 5 reports reports only
- T1068 5 reports reports only
- T1070.004 5 reports in ATT&CK
- T1071 5 reports reports only
- T1136.001 5 reports reports only
- T1566 5 reports reports only
- T1573.001 5 reports reports only
- T1583.001 5 reports in ATT&CK
- T1005 4 reports in ATT&CK
- T1007 4 reports reports only
- T1021.001 4 reports in ATT&CK
- T1036 4 reports in ATT&CK
- T1036.005 4 reports in ATT&CK
- T1078 4 reports in ATT&CK
- T1083 4 reports in ATT&CK
- T1087.001 4 reports reports only
- T1087.002 4 reports in ATT&CK
- T1095 4 reports reports only
- T1136 4 reports reports only
- T1482 4 reports reports only
- T1572 4 reports reports only
- T1583.003 4 reports reports only
- T1587.001 4 reports reports only
- T1003.002 3 reports in ATT&CK
- T1021.002 3 reports reports only
- T1027.009 3 reports reports only
- T1046 3 reports in ATT&CK
- T1055.002 3 reports reports only
- T1059 3 reports reports only
- T1059.005 3 reports reports only
- T1069.002 3 reports reports only
- T1102 3 reports reports only
- T1124 3 reports reports only
- T1129 3 reports reports only
- T1133 3 reports reports only
- T1204 3 reports reports only
- T1486 3 reports reports only
- T1497.001 3 reports reports only
- T1505.003 3 reports reports only
- T1518.001 3 reports reports only
- T1555.003 3 reports reports only
- T1569.002 3 reports reports only
- T1570 3 reports reports only
- T1573 3 reports reports only
- T1583.004 3 reports reports only
- T1608.001 3 reports reports only
- T1620 3 reports reports only
- T1622 3 reports reports only
- T1003 2 reports reports only
- T1003.003 2 reports in ATT&CK
- T1008 2 reports reports only
- T1021 2 reports reports only
- T1036.007 2 reports reports only
- T1037.001 2 reports reports only
- T1049 2 reports in ATT&CK
- T1053 2 reports reports only
- T1055.004 2 reports reports only
- T1055.012 2 reports in ATT&CK
- T1056.001 2 reports in ATT&CK
- T1059.006 2 reports reports only
- T1059.007 2 reports reports only
- T1069.001 2 reports reports only
- T1070.006 2 reports reports only
- T1071.004 2 reports reports only
- T1072 2 reports reports only
- T1090 2 reports reports only
- T1090.001 2 reports reports only
- T1098 2 reports reports only
- T1098.007 2 reports reports only
- T1104 2 reports reports only
- T1113 2 reports reports only
- T1115 2 reports reports only
- T1119 2 reports in ATT&CK
- T1127.001 2 reports reports only
- T1132 2 reports reports only
- T1134.002 2 reports reports only
- T1135 2 reports reports only
- T1204.001 2 reports reports only
- T1210 2 reports in ATT&CK
- T1217 2 reports reports only
- T1218 2 reports reports only
- T1218.007 2 reports reports only
- T1496 2 reports reports only
- T1505.004 2 reports reports only
- T1546.003 2 reports reports only
- T1548 2 reports reports only
- T1560 2 reports in ATT&CK
- T1560.001 2 reports in ATT&CK
- T1566.004 2 reports reports only
- T1567 2 reports reports only
- T1568.002 2 reports reports only
- T1571 2 reports reports only
- T1573.002 2 reports reports only
- T1574 2 reports reports only
- T1583 2 reports reports only
- T1583.008 2 reports reports only
- T1584.004 2 reports reports only
- T1585.002 2 reports reports only
- T1588.002 2 reports in ATT&CK
- T1590 2 reports reports only
- T1595 2 reports reports only
- T1595.002 2 reports reports only
- T1598 2 reports reports only
- T1608 2 reports reports only
- T1608.002 2 reports reports only
- T1608.006 2 reports reports only
- T1649 2 reports reports only
- T1001.001 1 report reports only
- T1001.003 1 report reports only
- T1010 1 report reports only
- T1014 1 report reports only
- T1016.001 1 report reports only
- T1020 1 report reports only
- T1021.004 1 report in ATT&CK
- T1021.005 1 report reports only
- T1021.006 1 report reports only
- T1027.004 1 report reports only
- T1027.007 1 report reports only
- T1027.010 1 report reports only
- T1027.011 1 report reports only
- T1030 1 report reports only
- T1036.003 1 report in ATT&CK
- T1037 1 report reports only
- T1039 1 report in ATT&CK
- T1040 1 report reports only
- T1048 1 report reports only
- T1053.003 1 report reports only
- T1055.001 1 report reports only
- T1055.003 1 report reports only
- T1055.009 1 report reports only
- T1056 1 report reports only
- T1059.002 1 report reports only
- T1059.004 1 report reports only
- T1059.009 1 report reports only
- T1059.010 1 report reports only
- T1059.011 1 report reports only
- T1069 1 report reports only
- T1069.003 1 report reports only
- T1070 1 report reports only
- T1070.003 1 report in ATT&CK
- T1074 1 report reports only
- T1074.001 1 report in ATT&CK
- T1074.002 1 report in ATT&CK
- T1078.002 1 report reports only
- T1078.003 1 report reports only
- T1078.004 1 report reports only
- T1087 1 report reports only
- T1087.004 1 report reports only
- T1090.003 1 report reports only
- T1091 1 report reports only
- T1098.001 1 report reports only
- T1098.003 1 report reports only
- T1098.004 1 report reports only
- T1098.005 1 report reports only
- T1098.006 1 report reports only
- T1102.002 1 report reports only
- T1106 1 report in ATT&CK
- T1114 1 report reports only
- T1114.001 1 report reports only
- T1114.002 1 report reports only
- T1114.003 1 report reports only
- T1120 1 report reports only
- T1123 1 report reports only
- T1125 1 report reports only
- T1132.002 1 report reports only
- T1134 1 report reports only
- T1134.001 1 report reports only
- T1136.002 1 report reports only
- T1137 1 report reports only
- T1137.006 1 report reports only
- T1195 1 report reports only
- T1195.001 1 report reports only
- T1195.002 1 report reports only
- T1199 1 report in ATT&CK
- T1200 1 report reports only
- T1201 1 report reports only
- T1203 1 report reports only
- T1204.004 1 report reports only
- T1213 1 report reports only
- T1213.001 1 report reports only
- T1213.002 1 report reports only
- T1213.003 1 report reports only
- T1218.014 1 report reports only
- T1221 1 report reports only
- T1484 1 report reports only
- T1484.001 1 report reports only
- T1485 1 report reports only
- T1489 1 report reports only
- T1490 1 report reports only
- T1491.002 1 report reports only
- T1497 1 report reports only
- T1497.003 1 report reports only
- T1498 1 report reports only
- T1505 1 report reports only
- T1518 1 report reports only
- T1526 1 report reports only
- T1528 1 report reports only
- T1529 1 report reports only
- T1530 1 report reports only
- T1534 1 report reports only
- T1537 1 report reports only
- T1538 1 report reports only
- T1543 1 report reports only
- T1543.002 1 report reports only
- T1543.004 1 report reports only
- T1546 1 report reports only
- T1546.004 1 report reports only
- T1546.008 1 report reports only
- T1546.012 1 report reports only
- T1546.015 1 report reports only
- T1547 1 report reports only
- T1547.002 1 report reports only
- T1547.005 1 report reports only
- T1547.009 1 report reports only
- T1548.002 1 report reports only
- T1550 1 report reports only
- T1550.001 1 report reports only
- T1550.002 1 report reports only
- T1552 1 report reports only
- T1553.002 1 report in ATT&CK
- T1554 1 report reports only
- T1555 1 report reports only
- T1556 1 report reports only
- T1556.002 1 report reports only
- T1556.006 1 report reports only
- T1556.009 1 report reports only
- T1558.003 1 report reports only
- T1559 1 report reports only
- T1560.002 1 report reports only
- T1563.002 1 report reports only
- T1564.001 1 report reports only
- T1564.003 1 report reports only
- T1564.004 1 report reports only
- T1564.006 1 report reports only
- T1565 1 report reports only
- T1565.001 1 report reports only
- T1566.003 1 report reports only
- T1567.001 1 report reports only
- T1567.002 1 report reports only
- T1569 1 report reports only
- T1574.011 1 report reports only
- T1578 1 report reports only
- T1580 1 report reports only
- T1583.006 1 report reports only
- T1584 1 report reports only
- T1585 1 report reports only
- T1585.003 1 report reports only
- T1586.002 1 report reports only
- T1587 1 report reports only
- T1587.003 1 report reports only
- T1588 1 report reports only
- T1588.001 1 report reports only
- T1588.003 1 report reports only
- T1588.004 1 report reports only
- T1588.007 1 report reports only
- T1589.002 1 report reports only
- T1590.005 1 report reports only
- T1592 1 report reports only
- T1593.002 1 report reports only
- T1595.001 1 report reports only
- T1602 1 report reports only
- T1602.001 1 report reports only
- T1602.002 1 report reports only
- T1608.003 1 report reports only
- T1608.004 1 report reports only
- T1608.005 1 report reports only
- T1613 1 report reports only
- T1614 1 report reports only
- T1614.001 1 report reports only
- T1615 1 report reports only
- T1619 1 report reports only
- T1621 1 report reports only
- T1627.001 1 report reports only
- T1652 1 report reports only
- T1654 1 report reports only
- T1657 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2007-5633
- CVE-2008-3431 KEV
- CVE-2008-5353
- CVE-2009-0556 KEV
- CVE-2009-0824
- CVE-2009-0927 KEV
- CVE-2009-3129 KEV
- CVE-2009-3867
- CVE-2009-4324 KEV
- CVE-2010-0188 KEV ransomware
- CVE-2010-0232 KEV
- CVE-2010-0249 KEV
Show all 458 CVEs Show fewer
- CVE-2010-1424
- CVE-2010-1592
- CVE-2010-2152
- CVE-2010-2883 KEV
- CVE-2010-3333 KEV
- CVE-2010-3915
- CVE-2010-3916
- CVE-2010-4398 KEV
- CVE-2011-0609 KEV
- CVE-2011-0611 KEV
- CVE-2011-1331
- CVE-2011-2005 KEV
- CVE-2011-2110
- CVE-2011-2462 KEV
- CVE-2011-3544 KEV
- CVE-2011-4369
- CVE-2012-0151 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-0422
- CVE-2012-0779
- CVE-2012-11882
- CVE-2012-1535 KEV
- CVE-2012-1723 KEV ransomware
- CVE-2012-1856 KEV
- CVE-2012-1875
- CVE-2012-1889 KEV
- CVE-2012-2543
- CVE-2012-4681 KEV ransomware
- CVE-2012-4792 KEV
- CVE-2012-5687
- CVE-2013-0422 KEV ransomware
- CVE-2013-0640 KEV
- CVE-2013-0707
- CVE-2013-0808
- CVE-2013-1331 KEV
- CVE-2013-1347 KEV
- CVE-2013-1493
- CVE-2013-2618
- CVE-2013-2729 KEV
- CVE-2013-3346 KEV
- CVE-2013-3644
- CVE-2013-3660 KEV
- CVE-2013-3893 KEV
- CVE-2013-3897 KEV
- CVE-2013-3900 KEV
- CVE-2013-3906 KEV
- CVE-2013-3918 KEV
- CVE-2013-4979
- CVE-2013-5065 KEV
- CVE-2013-5947
- CVE-2013-5990
- CVE-2013-7331 KEV
- CVE-2014-0160 KEV
- CVE-2014-0322 KEV
- CVE-2014-0497 KEV
- CVE-2014-0502 KEV
- CVE-2014-0515
- CVE-2014-0810
- CVE-2014-1225
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-1812 KEV ransomware
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-4076
- CVE-2014-4113 KEV
- CVE-2014-4114 KEV
- CVE-2014-6324 KEV
- CVE-2014-6332 KEV
- CVE-2014-6352 KEV
- CVE-2014-7247
- CVE-2014-8361 KEV
- CVE-2014-8439 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-1635 KEV
- CVE-2015-1641 KEV
- CVE-2015-1642 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-1770 KEV
- CVE-2015-1805
- CVE-2015-2051 KEV
- CVE-2015-2291 KEV ransomware
- CVE-2015-2387 KEV
- CVE-2015-2419 KEV
- CVE-2015-2424 KEV
- CVE-2015-2545 KEV
- CVE-2015-2546 KEV ransomware
- CVE-2015-2590 KEV
- CVE-2015-3043 KEV
- CVE-2015-3105
- CVE-2015-4852 KEV
- CVE-2015-4902 KEV
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-6585
- CVE-2015-7248
- CVE-2015-7254
- CVE-2015-7645 KEV ransomware
- CVE-2015-7755 KEV
- CVE-2015-8651 KEV
- CVE-2016-0034 KEV ransomware
- CVE-2016-0167 KEV ransomware
- CVE-2016-0189 KEV ransomware
- CVE-2016-1019 KEV ransomware
- CVE-2016-10401
- CVE-2016-3353
- CVE-2016-4117 KEV ransomware
- CVE-2016-4119
- CVE-2016-4171 KEV
- CVE-2016-5195 KEV
- CVE-2016-7255 KEV ransomware
- CVE-2016-7836 KEV
- CVE-2016-7855 KEV
- CVE-2016-9192
- CVE-2017-0005 KEV
- CVE-2017-0143 KEV ransomware
- CVE-2017-0144 KEV ransomware
- CVE-2017-0146 KEV ransomware
- CVE-2017-0147 KEV ransomware
- CVE-2017-0176
- CVE-2017-0199 KEV ransomware
- CVE-2017-0213 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-1000353 KEV
- CVE-2017-10271 KEV ransomware
- CVE-2017-1099
- CVE-2017-11317 KEV
- CVE-2017-11357 KEV ransomware
- CVE-2017-11467
- CVE-2017-11774 KEV
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-12149 KEV ransomware
- CVE-2017-12629
- CVE-2017-12824
- CVE-2017-15399
- CVE-2017-15944 KEV
- CVE-2017-17215
- CVE-2017-18368 KEV
- CVE-2017-5638 KEV ransomware
- CVE-2017-5689 KEV
- CVE-2017-6327 KEV
- CVE-2017-6328
- CVE-2017-7269 KEV
- CVE-2017-8291 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2017-9248 KEV
- CVE-2017-9805 KEV
- CVE-2017-9822 KEV ransomware
- CVE-2018-0101
- CVE-2018-0171 KEV
- CVE-2018-0296 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-0824 KEV
- CVE-2018-10088
- CVE-2018-10561 KEV
- CVE-2018-10562 KEV ransomware
- CVE-2018-11776 KEV
- CVE-2018-1207
- CVE-2018-13379 KEV ransomware
- CVE-2018-15454
- CVE-2018-15961 KEV
- CVE-2018-15982 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-2025036
- CVE-2018-2628 KEV
- CVE-2018-2893
- CVE-2018-4878 KEV ransomware
- CVE-2018-4939 KEV
- CVE-2018-5002 KEV
- CVE-2018-6789 KEV ransomware
- CVE-2018-7600 KEV ransomware
- CVE-2018-7602 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8373 KEV
- CVE-2018-8453 KEV ransomware
- CVE-2018-8477
- CVE-2018-8514
- CVE-2018-8580
- CVE-2018-8581 KEV ransomware
- CVE-2018-8589 KEV
- CVE-2018-8595
- CVE-2018-8596
- CVE-2018-8598
- CVE-2018-8611 KEV
- CVE-2018-8616
- CVE-2018-8621
- CVE-2018-8622
- CVE-2018-8627
- CVE-2018-8637
- CVE-2018-8638
- CVE-2018-8639 KEV ransomware
- CVE-2018-9866
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0797 KEV
- CVE-2019-0803 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-1040
- CVE-2019-11510 KEV ransomware
- CVE-2019-11580 KEV ransomware
- CVE-2019-1322 KEV ransomware
- CVE-2019-1367 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-1405 KEV ransomware
- CVE-2019-1458 KEV ransomware
- CVE-2019-1579 KEV ransomware
- CVE-2019-16098
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-16759 KEV
- CVE-2019-16920 KEV
- CVE-2019-17026 KEV
- CVE-2019-17100
- CVE-2019-18187 KEV
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-2215 KEV
- CVE-2019-2725 KEV ransomware
- CVE-2019-3369
- CVE-2019-3396 KEV ransomware
- CVE-2019-3398 KEV
- CVE-2019-5591 KEV ransomware
- CVE-2019-7609 KEV
- CVE-2019-8394 KEV
- CVE-2019-9489
- CVE-2019-9621 KEV
- CVE-2019-9670 KEV
- CVE-2020-0601 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0787 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-10198
- CVE-2020-1040 KEV
- CVE-2020-116511
- CVE-2020-11652 KEV
- CVE-2020-11899 KEV
- CVE-2020-12641 KEV
- CVE-2020-1350 KEV
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-14750 KEV
- CVE-2020-14882 KEV
- CVE-2020-15505 KEV
- CVE-2020-1599
- CVE-2020-1664
- CVE-2020-17144 KEV
- CVE-2020-17530 KEV
- CVE-2020-2021 KEV ransomware
- CVE-2020-2551 KEV
- CVE-2020-2555 KEV
- CVE-2020-3118 KEV
- CVE-2020-3125
- CVE-2020-3529
- CVE-2020-35730 KEV
- CVE-2020-4006 KEV
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-6789
- CVE-2020-7961 KEV
- CVE-2020-8193 KEV
- CVE-2020-8195 KEV
- CVE-2020-8196 KEV
- CVE-2020-8243 KEV
- CVE-2020-8260 KEV
- CVE-2020-8468 KEV
- CVE-2020-8515 KEV
- CVE-2021-1472
- CVE-2021-1473
- CVE-2021-1636
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-1844
- CVE-2021-1879 KEV
- CVE-2021-20016 KEV ransomware
- CVE-2021-20837
- CVE-2021-21166 KEV
- CVE-2021-2135
- CVE-2021-21972 KEV ransomware
- CVE-2021-21975 KEV ransomware
- CVE-2021-21983
- CVE-2021-22555 KEV
- CVE-2021-22894 KEV
- CVE-2021-22899 KEV
- CVE-2021-22900 KEV
- CVE-2021-26084 KEV ransomware
- CVE-2021-26334
- CVE-2021-26411 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-26868
- CVE-2021-27065 KEV ransomware
- CVE-2021-27857
- CVE-2021-27876 KEV ransomware
- CVE-2021-27877 KEV ransomware
- CVE-2021-27878 KEV ransomware
- CVE-2021-28149
- CVE-2021-28152
- CVE-2021-28482
- CVE-2021-29855
- CVE-2021-30116 KEV ransomware
- CVE-2021-3019
- CVE-2021-30551 KEV
- CVE-2021-31195
- CVE-2021-31196 KEV
- CVE-2021-31206
- CVE-2021-31207 KEV ransomware
- CVE-2021-3156 KEV
- CVE-2021-31805
- CVE-2021-33742 KEV
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-35394 KEV
- CVE-2021-35464 KEV ransomware
- CVE-2021-36798
- CVE-2021-36934 KEV
- CVE-2021-36942 KEV ransomware
- CVE-2021-38001
- CVE-2021-3970
- CVE-2021-3971
- CVE-2021-3972
- CVE-2021-4034 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-40449 KEV ransomware
- CVE-2021-40539 KEV ransomware
- CVE-2021-4104
- CVE-2021-41379 KEV ransomware
- CVE-2021-44026 KEV
- CVE-2021-44077 KEV
- CVE-2021-44207 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-44515 KEV
- CVE-2021-44832
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-0847 KEV
- CVE-2022-1040 KEV
- CVE-2022-21587 KEV ransomware
- CVE-2022-21882 KEV ransomware
- CVE-2022-22954 KEV ransomware
- CVE-2022-22957
- CVE-2022-22958
- CVE-2022-22963 KEV
- CVE-2022-22965 KEV
- CVE-2022-24500
- CVE-2022-24521 KEV ransomware
- CVE-2022-24682 KEV ransomware
- CVE-2022-24934
- CVE-2022-26134 KEV ransomware
- CVE-2022-26138 KEV
- CVE-2022-26809
- CVE-2022-26923 KEV
- CVE-2022-27924 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-30333 KEV ransomware
- CVE-2022-31199 KEV ransomware
- CVE-2022-3236 KEV
- CVE-2022-34305
- CVE-2022-37042 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41080 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-41328 KEV
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2022-49475
- CVE-2023-0669 KEV ransomware
- CVE-2023-20198 KEV
- CVE-2023-20273 KEV
- CVE-2023-21746
- CVE-2023-22518 KEV ransomware
- CVE-2023-22527 KEV ransomware
- CVE-2023-23397 KEV
- CVE-2023-24880 KEV ransomware
- CVE-2023-26360 KEV
- CVE-2023-27350 KEV ransomware
- CVE-2023-27532 KEV ransomware
- CVE-2023-27997 KEV ransomware
- CVE-2023-28461 KEV ransomware
- CVE-2023-2868 KEV
- CVE-2023-29324
- CVE-2023-29360 KEV
- CVE-2023-32315 KEV
- CVE-2023-3466
- CVE-2023-3467
- CVE-2023-3519 KEV ransomware
- CVE-2023-35384
- CVE-2023-36033 KEV
- CVE-2023-36802 KEV
- CVE-2023-38831 KEV ransomware
- CVE-2023-45727 KEV
- CVE-2023-46805 KEV ransomware
- CVE-2023-48788 KEV ransomware
- CVE-2023-4966 KEV ransomware
- CVE-2023-7101 KEV
- CVE-2023-7102
- CVE-2024-0012 KEV ransomware
- CVE-2024-20953 KEV
- CVE-2024-21287 KEV
- CVE-2024-21887 KEV ransomware
- CVE-2024-21893 KEV ransomware
- CVE-2024-21983
- CVE-2024-23204
- CVE-2024-24919 KEV ransomware
- CVE-2024-27956
- CVE-2024-30051 KEV ransomware
- CVE-2024-32113 KEV
- CVE-2024-3400 KEV ransomware
- CVE-2024-35250 KEV
- CVE-2024-36104
- CVE-2024-36401 KEV
- CVE-2024-38245
- CVE-2024-38856 KEV
- CVE-2024-42009 KEV
- CVE-2024-43451 KEV
- CVE-2024-43554
- CVE-2024-45195 KEV
- CVE-2024-4577 KEV ransomware
- CVE-2024-47575 KEV
- CVE-2024-5910 KEV
- CVE-2024-6473
- CVE-2024-9463 KEV
- CVE-2024-9464
- CVE-2024-9465 KEV
- CVE-2024-9466
- CVE-2024-9467
- CVE-2024-9474 KEV ransomware
- CVE-2025-2783 KEV
- CVE-2025-31324 KEV ransomware
- CVE-2025-55182 KEV ransomware
- CVE-2025-6218 KEV
- CVE-2025-8088 KEV ransomware
- CVE-2026-21236
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Bankshot (Malware Family)
Show all 1,159 reports Show fewer
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor StoneDrill (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Stone Panda, APT 10, menuPass
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Oblique RAT (Malware Family)
-
CrowdCasts Monthly: You Have an Adversary Problem
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CrowdCasts Monthly: You Have an Adversary Problem
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor METALJACK (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor elf.wellmess (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor SUNBURST (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Poison Ivy (Malware Family)
-
Nightshade Panda, APT 9, Group 27
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Nightshade Panda, APT 9, Group 27
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Red Apollo
-
The original link failed its last check. Original publisher Detailsfor Council on Foreign Relations
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor MimiKatz (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PlugX (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PowGoop (Malware Family)
-
EvilGrab Malware Family Used In Targeted Attacks
The original link failed its last check. Original publisher Detailsfor EvilGrab Malware Family Used In Targeted Attacks
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
China Chopper - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor China Chopper - Threat Group Cards: A Threat Actor Encyclopedia
-
Cobalt Strike (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Cobalt Strike (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Quasar RAT (Malware Family)
-
Team46 and TaxOff: two sides of the same coin
The original link failed its last check. Original publisher Detailsfor Team46 and TaxOff: two sides of the same coin
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor hodur_recon2024.pdf
-
Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausge…
The title opens archive.today, not the publisher’s page. Archived copy on ORKL Detailsfor Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausge…
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Endless Struggle Against APT10_ Insights from LODEINFO v0.6.6 - v0.7.3 Analysis - Researcher Blog - ITOCHU Cyber & Intelligence Inc_
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Modern Asia APT groups TTPs
-
Invitation to a Secret Event- Uncovering Earth Yako’s Campaigns
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Invitation to a Secret Event- Uncovering Earth Yako’s Campaigns
-
Gootkit Loader Actively Targets Australian Healthcare Industry
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Gootkit Loader Actively Targets Australian Healthcare Industry
-
Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
The original link failed its last check. Original publisher Detailsfor Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
-
APT10- Tracking down LODEINFO 2022, part II
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT10- Tracking down LODEINFO 2022, part II
-
APT10- Tracking down LODEINFO 2022, part I
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT10- Tracking down LODEINFO 2022, part I
-
Conceptualizing a Continuum of Cyber Threat Attribution
The original link failed its last check. Original publisher Detailsfor Conceptualizing a Continuum of Cyber Threat Attribution
-
Witchetty- Group Uses Updated Toolset in Attacks on Governments in Middle East
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Witchetty- Group Uses Updated Toolset in Attacks on Governments in Middle East
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
MustangPanda%20-%20Enemy%20at%20the%20gate_final.pdf
The original link failed its last check. Original publisher Detailsfor MustangPanda%20-%20Enemy%20at%20the%20gate_final.pdf
-
Rising Tide- Chasing the Currents of Espionage in the South China Sea
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Rising Tide- Chasing the Currents of Espionage in the South China Sea
-
Malicious Cookie Stuffing Chrome Extensions with 1.4 Million Users
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malicious Cookie Stuffing Chrome Extensions with 1.4 Million Users
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
Space Invaders- Cyber Threats That Are Out Of This World
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Space Invaders- Cyber Threats That Are Out Of This World
-
New Qualys Research Report- Evolution of Quasar RAT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Qualys Research Report- Evolution of Quasar RAT
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Russian Ransomware C2 Network Discovered in Censys Data
The original link failed its last check. Original publisher Detailsfor Russian Ransomware C2 Network Discovered in Censys Data
-
CB_941_Canhbao_APT_36c5a857fa.pdf
The original link failed its last check. Original publisher Detailsfor CB_941_Canhbao_APT_36c5a857fa.pdf
-
BRONZE STARLIGHT Ransomware Operations Use HUI Loader
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BRONZE STARLIGHT Ransomware Operations Use HUI Loader
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Phishing Campaigns featuring Ursnif Trojan on the Rise
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Phishing Campaigns featuring Ursnif Trojan on the Rise
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Twisted Panda_ Chinese APT espionage operation against Russian’s state-owned defense institutes - Check Point Research
-
Threat Actors Prey on Eager Travelers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Actors Prey on Eager Travelers
-
THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
The original link failed its last check. Original publisher Detailsfor THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t12022
-
Twisted Panda- Chinese APT Launch Spy Operation Against Russian Defence Institutes
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Twisted Panda- Chinese APT Launch Spy Operation Against Russian Defence Institutes
-
APT_trends_report_Q2_2022_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2022_Securelist
-
Chinese Naikon Group Back with New Espionage Attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Naikon Group Back with New Espionage Attack
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
A lookback under the TA410 umbrella- Its cyberespionage TTPs and activity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A lookback under the TA410 umbrella- Its cyberespionage TTPs and activity
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Chinese hackers abuse VLC Media Player to launch malware loader
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese hackers abuse VLC Media Player to launch malware loader
-
Cicada- Chinese APT Group Widens Targeting in Recent Espionage Activity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cicada- Chinese APT Group Widens Targeting in Recent Espionage Activity
-
Unmasking China’s State Hackers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Unmasking China’s State Hackers
-
Legitimate Sites used as Cobalt Strike C2s against Indian Government
The original link failed its last check. Original publisher Detailsfor Legitimate Sites used as Cobalt Strike C2s against Indian Government
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor 2021trends.pdf
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
China Implicated in Prolonged Supply Chain Attack Targeting Taiwan Financial Sector
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor China Implicated in Prolonged Supply Chain Attack Targeting Taiwan Financial Sector
-
Chinese hackers linked to months-long attack on Taiwanese financial sector
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese hackers linked to months-long attack on Taiwanese financial sector
-
VMware Exposing Malware In Linux Based Multi Cloud Environments
The original link failed its last check. Original publisher Detailsfor VMware Exposing Malware In Linux Based Multi Cloud Environments
-
Winnti is Coming - Evolution after Prosecution@HITCON2021
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Winnti is Coming - Evolution after Prosecution@HITCON2021
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor EP 103- Cloud Hopper
-
sneak-peek-ch1-2-finding-beacons-in-the-dark.pdf
The original link failed its last check. Original publisher Detailsfor sneak-peek-ch1-2-finding-beacons-in-the-dark.pdf
-
Masters of Mimicry: new APT group ChamelGang and its arsenal
The original link failed its last check. Original publisher Detailsfor Masters of Mimicry: new APT group ChamelGang and its arsenal
-
Masters of Mimicry: new APT group ChamelGang and its arsenal
The original link failed its last check. Original publisher Detailsfor Masters of Mimicry: new APT group ChamelGang and its arsenal
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
report-old-dogs-new-tricks.pdf
The original link failed its last check. Original publisher Detailsfor report-old-dogs-new-tricks.pdf
-
Ryuk Ransomware Now Targeting Webservers
The original link failed its last check. Original publisher Detailsfor Ryuk Ransomware Now Targeting Webservers
-
Looks like the page you're looking for doesn't exist or has moved.
The original link failed its last check. Original publisher Detailsfor Looks like the page you're looking for doesn't exist or has moved.
-
The original link failed its last check. Original publisher Detailsfor mtrends-2018.pdf
-
Mustang Panda PlugX - 45.251.240.55 Pivot
The original link failed its last check. Original publisher Detailsfor Mustang Panda PlugX - 45.251.240.55 Pivot
-
Threat Thursday- SombRAT — Always Leave Yourself a Backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Thursday- SombRAT — Always Leave Yourself a Backdoor
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CTIR_casestudy_2.pdf
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CTIR_casestudy_1.pdf
-
the-operations-of-winnti-group.pdf
The original link failed its last check. Original publisher Detailsfor the-operations-of-winnti-group.pdf
-
New ICS Threat Activity Group- TALONITE
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New ICS Threat Activity Group- TALONITE
-
APT10_ sophisticated multi-layered loader Ecipekac discovered in A41APT campaign _ Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT10_ sophisticated multi-layered loader Ecipekac discovered in A41APT campaign _ Securelist
-
report-bb-2021-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor report-bb-2021-threat-report.pdf
-
Technical Analysis of Operation Diànxùn
The original link failed its last check. Original publisher Detailsfor Technical Analysis of Operation Diànxùn
-
Intezer-2020-Go-Malware-Round-Up.pdf
The original link failed its last check. Original publisher Detailsfor Intezer-2020-Go-Malware-Round-Up.pdf
-
APT10: Tracking down the stealth activity of the A41APT campaign
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT10: Tracking down the stealth activity of the A41APT campaign
-
A41APT case ~Analysis of the Stealth APT Campaign Threatening Japan
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor A41APT case ~Analysis of the Stealth APT Campaign Threatening Japan
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
China cyber attacks- the current threat landscape
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor China cyber attacks- the current threat landscape
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Active Directory 侵害と推奨対策
-
From ThreatHunting to Campaign Tracking
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor From ThreatHunting to Campaign Tracking
-
[HITCON 2020 CTI Village] Threat Hunting and Campaign Tracking Workshop.pptx
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor [HITCON 2020 CTI Village] Threat Hunting and Campaign Tracking Workshop.pptx
-
Attack Activities by Quasar Family
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attack Activities by Quasar Family
-
Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Japan-Linked Organizations Targeted in Long-Running and Sophisticated Attack Campaign _ Symantec Blogs
-
Japan-Linked Organizations Targeted in Long-Running and Sophisticated Attack Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Japan-Linked Organizations Targeted in Long-Running and Sophisticated Attack Campaign
-
Incident readiness: preparing a proactive response to attacks
The original link failed its last check. Original publisher Detailsfor Incident readiness: preparing a proactive response to attacks
-
Alert (AA20-275A)- Potential for China Cyber Response to Heightened U.S.-China Tensions
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (AA20-275A)- Potential for China Cyber Response to Heightened U.S.-China Tensions
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor TA410
-
In-Memory shellcode decoding to evade AVs/EDRs
The original link failed its last check. Original publisher Detailsfor In-Memory shellcode decoding to evade AVs/EDRs
-
BRONZE VINEWOOD Targets Supply Chains _ Secureworks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor BRONZE VINEWOOD Targets Supply Chains _ Secureworks
-
BRONZE VINEWOOD Targets Supply Chains
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BRONZE VINEWOOD Targets Supply Chains
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor P01_P10_eng
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor TA410_ The Group Behind LookBack Attacks Against U.S. Utilities Sector Returns with New Malware _ Proofpoint US
-
TA410- The Group Behind LookBack Attacks Against U.S. Utilities Sector Returns with New Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA410- The Group Behind LookBack Attacks Against U.S. Utilities Sector Returns with New Malware
-
mpressioncss_ta_report_2019_4.pdf
The original link failed its last check. Original publisher Detailsfor mpressioncss_ta_report_2019_4.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor mpressioncss_ta_report_2019_4
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The energy reserves in the Eastern Mediterranean Sea and a malicious campaign of APT10 against Turkey
-
Operation Cloud Hopper & RedLeaves
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Cloud Hopper & RedLeaves
-
Catching APT41 exploiting a zero-day vulnerability
The original link failed its last check. Detailsfor Catching APT41 exploiting a zero-day vulnerability
-
Is APT 27 Abusing COVID-19 To Attack People !
The original link failed its last check. Detailsfor Is APT 27 Abusing COVID-19 To Attack People !
-
Cyber Threat Landscape in Japan – Revealing Threat in the Shadow
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber Threat Landscape in Japan – Revealing Threat in the Shadow
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor [CB19] Cyber Threat Landscape in Japan – Revealing Threat in the Shadow by Chi En Shen (Ashley) Oleg Bondarenko
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020
-
The original link failed its last check. Original publisher Detailsfor Aarhus_miniseminar_291118.pdf
-
cds19-executive-s08-achievement-unlocked.pdf
The original link failed its last check. Original publisher Detailsfor cds19-executive-s08-achievement-unlocked.pdf
-
APT cases exploiting vulnerabilities in region‑specific software
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT cases exploiting vulnerabilities in region‑specific software
-
The original link failed its last check. Original publisher Detailsfor Analytics
-
Context Identifies new AVIVORE threat group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Context Identifies new AVIVORE threat group
-
New threat group behind Airbus cyber attacks, claim researchers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New threat group behind Airbus cyber attacks, claim researchers
-
AVIVORE – Hunting Global Aerospace through the Supply Chain | Context Information Security
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor AVIVORE – Hunting Global Aerospace through the Supply Chain | Context Information Security
-
AVIVORE – Hunting Global Aerospace through the Supply Chain
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor AVIVORE – Hunting Global Aerospace through the Supply Chain
-
AVIVORE - Hunting Global Aerospace through the Supply Chain
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor AVIVORE - Hunting Global Aerospace through the Supply Chain
-
Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Two Birds, One STONE PANDA
-
APT41: A Dual Espionage and Cyber Crime Operation
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor APT41: A Dual Espionage and Cyber Crime Operation
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor report_APT41
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Is there a pattern-
-
OPERATION SOFT CELL- A WORLDWIDE CAMPAIGN AGAINST TELECOMMUNICATIONS PROVIDERS
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OPERATION SOFT CELL- A WORLDWIDE CAMPAIGN AGAINST TELECOMMUNICATIONS PROVIDERS
-
Operation Soft Cell_ A Worldwide Campaign Against Telecommunications Providers
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Soft Cell_ A Worldwide Campaign Against Telecommunications Providers
-
Threat Spotlight_ MenuPass_QuasarRAT Backdoor
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Spotlight_ MenuPass_QuasarRAT Backdoor
-
Threat Spotlight- MenuPass-QuasarRAT Backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Spotlight- MenuPass-QuasarRAT Backdoor
-
Into the Fog - The Return of ICEFOG APT
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Into the Fog - The Return of ICEFOG APT
-
Uncovering new Activity by APT10
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Uncovering new Activity by APT10
-
Uncovering New Activity By APT10
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Uncovering New Activity By APT10
-
APT_trends_report_Q1_2019_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q1_2019_Securelist
-
The original link failed its last check. Original publisher Detailsfor 중국 기반 해커, 국내 에너지 기관 공격
-
The original link failed its last check. Original publisher Detailsfor rpt-mtrends-2019.pdf
-
mpressioncss_ta_report_2019.pdf
The original link failed its last check. Original publisher Detailsfor mpressioncss_ta_report_2019.pdf
-
Attacker Tracking Users Seeking Pakistani Passport
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attacker Tracking Users Seeking Pakistani Passport
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor rpt-mtrends-2019
-
Defeating Compiler-Level Obfuscations Used in APT10 Malware
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Defeating Compiler-Level Obfuscations Used in APT10 Malware
-
APT Groups Moving Down the Supply Chain
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Groups Moving Down the Supply Chain
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2018 Master Table
-
APT10 Targeted Norwegian MSP and US Companies in Sustained Campaign
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT10 Targeted Norwegian MSP and US Companies in Sustained Campaign
-
APT10 Targeted Norwegian MSP and US Companies in Sustained Campaign
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT10 Targeted Norwegian MSP and US Companies in Sustained Campaign
-
2018_ A Year of Cyber Attacks – HACKMAGEDDON
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2018_ A Year of Cyber Attacks – HACKMAGEDDON
-
The APT Chronicles_December 2018 edition
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The APT Chronicles_December 2018 edition
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Hackers Indicted - Members of APT 10 Group Targeted Intellectual Property and Confidential Business Information
-
Cyber-Espionage Campaign Targeting the Naval Industry (“MartyMcFly”)
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber-Espionage Campaign Targeting the Naval Industry (“MartyMcFly”)
-
VB2018 - Who Was Not Responsible for Olympic Destroyer
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor VB2018 - Who Was Not Responsible for Olympic Destroyer
-
APT10 Targeting Japanese Corporations Using Updated TTPs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT10 Targeting Japanese Corporations Using Updated TTPs
-
APT10 Targeting Japanese Corporations Using Updated TTPs
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT10 Targeting Japanese Corporations Using Updated TTPs
-
Who is Mr An, and was he working for APT10-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who is Mr An, and was he working for APT10-
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Two Birds, One STONE PANDA
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Two Birds, One STONE PANDA
-
Chinese Cyberespionage Originating From Tsinghua University Infrastructure
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Cyberespionage Originating From Tsinghua University Infrastructure
-
Chinese Cyberespionage Originating From Tsinghua University Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Cyberespionage Originating From Tsinghua University Infrastructure
-
APT10 was managed by the Tianjin bureau of the Chinese Ministry of State Security
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT10 was managed by the Tianjin bureau of the Chinese Ministry of State Security
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor More on Huaying Haitai and Laoying Baichaun, the companies associated with APT10. Is there a state connection-
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who is Mr Zhang-
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who is Mr Gao-
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who is Mr Zheng-
-
Who was behind this unprecedented Cyber attack on Western infrastructure-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who was behind this unprecedented Cyber attack on Western infrastructure-
-
BSides IR in Heterogeneous Environment
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BSides IR in Heterogeneous Environment
-
Hogfish Redleaves Malware Threat Analysis I Accenture
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Hogfish Redleaves Malware Threat Analysis I Accenture
-
ChessMaster Adds Updated Tools to Its Arsenal
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ChessMaster Adds Updated Tools to Its Arsenal
-
ChessMaster Adds Updated Tools to Its Arsenal
The original link failed its last check. Original publisher Detailsfor ChessMaster Adds Updated Tools to Its Arsenal
-
ChessMaster Adds Updated Tools to Its Arsenal - TrendLabs Security Intelligence Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ChessMaster Adds Updated Tools to Its Arsenal - TrendLabs Security Intelligence Blog
-
Who Wasn’t Responsible for Olympic Destroyer-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who Wasn’t Responsible for Olympic Destroyer-
-
ChessMaster Makes its Move: A Look into the Campaign's Cyberespionage Arsenal
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor ChessMaster Makes its Move: A Look into the Campaign's Cyberespionage Arsenal
-
New method of macro malware disguised as defense-related files
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New method of macro malware disguised as defense-related files
-
Advanced Persistent Threat Groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threat Groups
-
Cyberespionage Group Turla Deploys Backdoor Ahead of G20 Task Force Summit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyberespionage Group Turla Deploys Backdoor Ahead of G20 Task Force Summit
-
ChessMaster Makes its Move- A Look into the Campaign’s Cyberespionage Arsenal
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ChessMaster Makes its Move- A Look into the Campaign’s Cyberespionage Arsenal
-
chessmaster-cyber-espionage-campaign
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor chessmaster-cyber-espionage-campaign
-
ChessMaster Makes its Move: A Look into its Arsenal
The original link failed its last check. Original publisher Detailsfor ChessMaster Makes its Move: A Look into its Arsenal
-
The original link failed its last check. Original publisher Detailsfor BfV Cyber-Brief Nr. 2/2017
-
Alert (TA17-117A)- Intrusions Affecting Multiple Victims Across Multiple Sectors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (TA17-117A)- Intrusions Affecting Multiple Victims Across Multiple Sectors
-
Researchers claim China trying to hack South Korea missile defense efforts
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Researchers claim China trying to hack South Korea missile defense efforts
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Coming Soon…
-
APT10 (MenuPass Group)- New Tools, Global Campaign Latest Manifestation of Longstanding Threat
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT10 (MenuPass Group)- New Tools, Global Campaign Latest Manifestation of Longstanding Threat
-
Chinese Nation-State Hackers Target U.S in Operation TradeSecret
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Nation-State Hackers Target U.S in Operation TradeSecret
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Cloud Hopper
-
cloud-hopper-report-final-upda_72977
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor cloud-hopper-report-final-upda_72977
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Operation Cloud Hopper
-
The Deception Project: A New Japanese-Centric Threat
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor The Deception Project: A New Japanese-Centric Threat
-
The Deception Project- A New Japanese-Centric Threat
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Deception Project- A New Japanese-Centric Threat
-
ChChes - Malware that Communicates with C&C Servers Using Cookie Headers
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor ChChes - Malware that Communicates with C&C Servers Using Cookie Headers
-
JPCERT/CC Blog: ChChes – Malware that Communicates with C&C Servers Using Cookie Headers
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor JPCERT/CC Blog: ChChes – Malware that Communicates with C&C Servers Using Cookie Headers
-
menuPass Returns with New Malware and New Attacks Against Japanese Academics and Organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor menuPass Returns with New Malware and New Attacks Against Japanese Academics and Organizations
-
Malware ChChes interacts with C & C server using Cookie header
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware ChChes interacts with C & C server using Cookie header
-
ICIT-Brief-China-Espionage-Dynasty
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ICIT-Brief-China-Espionage-Dynasty
-
The original link failed its last check. Original publisher Detailsfor security_report_20160613.pdf
-
The Four Element Sword Engagement
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor The Four Element Sword Engagement
-
Taiwan Presidential Election: A Case Study on Thematic Targeting - Cyber security updates
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Taiwan Presidential Election: A Case Study on Thematic Targeting - Cyber security updates
-
Taiwan Presidential Election: A Case Study on Thematic Targeting
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Taiwan Presidential Election: A Case Study on Thematic Targeting
-
Newcomers in the Derusbi family
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Newcomers in the Derusbi family
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Targeted Malware Attacks against NGO Linked to Attacks on Burmese Government Websites - The Citizen Lab
-
Chinese Actors Use ‘3102’ Malware in Attacks on US Government and EU Media
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Actors Use ‘3102’ Malware in Attacks on US Government and EU Media
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Microsoft Word - ASERT Threat Intelligence Brief 2015-05 PlugX Threat Activity in Myanmar.docx
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Word - ASERT Threat Intelligence Brief 2015-05 PlugX Threat Activity in Myanmar.docx
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor HTExploitTelemetry
-
Uncovering the Seven Pointed Dagger
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Uncovering the Seven Pointed Dagger
-
Microsoft Word - 2015-02-XX -Scanbox II - TLPWHITE.docx
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Word - 2015-02-XX -Scanbox II - TLPWHITE.docx
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor A Detailed Examination of the Siesta Campaign « A Detailed Examination of the Siesta Campaign | FireEye Inc
-
A Detailed Examination of the Siesta Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Detailed Examination of the Siesta Campaign
-
CrowdCasts Monthly- You Have an Adversary Problem
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CrowdCasts Monthly- You Have an Adversary Problem
-
CrowdCasts Monthly: You Have an Adversary Problem
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CrowdCasts Monthly: You Have an Adversary Problem
-
2Q Report on Targeted Attack Campaigns
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2Q Report on Targeted Attack Campaigns
-
BKDR_RARSTONE: New RAT to Watch Out For - TrendLabs Security Intelligence Blog
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor BKDR_RARSTONE: New RAT to Watch Out For - TrendLabs Security Intelligence Blog
-
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Inside a Back Door Attack
Newest first. Details opens the report in Explore.