Leviathan
Also reported as TEMP.Periscope, Gingham Typhoon, TEMP.Jumper, APT40, MUDCARP and 18 other names. Linked to China by four sources.
Reports per quarter
Techniques seen in the last two years
- T1082 11 reports reports only
- T1053.005 10 reports reports only
- T1059.001 9 reports in ATT&CK
- T1071.001 9 reports reports only
- T1204.002 9 reports in ATT&CK
- T1057 8 reports reports only
- T1059.003 8 reports reports only
- T1105 8 reports in ATT&CK
- T1140 8 reports in ATT&CK
- T1566.001 8 reports in ATT&CK
Show all 322 techniques Show fewer
- T1027 7 reports reports only
- T1041 7 reports in ATT&CK
- T1189 7 reports in ATT&CK
- T1083 6 reports reports only
- T1547.001 6 reports in ATT&CK
- T1572 6 reports in ATT&CK
- T1005 5 reports reports only
- T1018 5 reports reports only
- T1033 5 reports reports only
- T1036.005 5 reports reports only
- T1059.005 5 reports in ATT&CK
- T1087.002 5 reports reports only
- T1132.001 5 reports reports only
- T1190 5 reports in ATT&CK
- T1482 5 reports reports only
- T1505.003 5 reports in ATT&CK
- T1566.002 5 reports in ATT&CK
- T1570 5 reports reports only
- T1574.001 5 reports reports only
- T1007 4 reports reports only
- T1016 4 reports reports only
- T1021.001 4 reports in ATT&CK
- T1046 4 reports reports only
- T1047 4 reports in ATT&CK
- T1055 4 reports reports only
- T1059 4 reports reports only
- T1059.007 4 reports reports only
- T1068 4 reports reports only
- T1069.002 4 reports reports only
- T1070.004 4 reports reports only
- T1087.001 4 reports reports only
- T1090.001 4 reports reports only
- T1135 4 reports reports only
- T1566 4 reports reports only
- T1573.001 4 reports reports only
- T1587.001 4 reports reports only
- T1003.001 3 reports in ATT&CK
- T1003.002 3 reports reports only
- T1012 3 reports reports only
- T1021.002 3 reports reports only
- T1027.009 3 reports reports only
- T1036 3 reports reports only
- T1048 3 reports reports only
- T1049 3 reports reports only
- T1055.002 3 reports reports only
- T1055.012 3 reports reports only
- T1056.001 3 reports reports only
- T1059.006 3 reports reports only
- T1074.001 3 reports in ATT&CK
- T1078 3 reports in ATT&CK
- T1078.002 3 reports reports only
- T1078.003 3 reports reports only
- T1090 3 reports reports only
- T1095 3 reports reports only
- T1098 3 reports reports only
- T1102 3 reports reports only
- T1119 3 reports reports only
- T1124 3 reports reports only
- T1129 3 reports reports only
- T1133 3 reports in ATT&CK
- T1134.001 3 reports reports only
- T1136.001 3 reports reports only
- T1219 3 reports reports only
- T1496 3 reports reports only
- T1497.001 3 reports reports only
- T1518.001 3 reports reports only
- T1543.003 3 reports reports only
- T1555.003 3 reports reports only
- T1560 3 reports in ATT&CK
- T1560.001 3 reports reports only
- T1571 3 reports reports only
- T1583 3 reports reports only
- T1583.001 3 reports in ATT&CK
- T1583.003 3 reports reports only
- T1595.002 3 reports in ATT&CK
- T1608.001 3 reports reports only
- T1620 3 reports reports only
- T1001.003 2 reports reports only
- T1003 2 reports in ATT&CK
- T1008 2 reports reports only
- T1010 2 reports reports only
- T1016.001 2 reports reports only
- T1021 2 reports reports only
- T1021.006 2 reports reports only
- T1039 2 reports reports only
- T1040 2 reports reports only
- T1053.003 2 reports reports only
- T1055.001 2 reports in ATT&CK
- T1055.003 2 reports reports only
- T1055.004 2 reports reports only
- T1059.002 2 reports reports only
- T1059.004 2 reports reports only
- T1069.001 2 reports reports only
- T1070 2 reports reports only
- T1071 2 reports reports only
- T1071.004 2 reports reports only
- T1072 2 reports reports only
- T1074.002 2 reports in ATT&CK
- T1078.004 2 reports reports only
- T1090.003 2 reports in ATT&CK
- T1098.007 2 reports reports only
- T1102.002 2 reports reports only
- T1104 2 reports reports only
- T1106 2 reports reports only
- T1114 2 reports reports only
- T1114.002 2 reports reports only
- T1115 2 reports reports only
- T1136 2 reports reports only
- T1203 2 reports in ATT&CK
- T1204 2 reports reports only
- T1213 2 reports reports only
- T1217 2 reports reports only
- T1218.007 2 reports reports only
- T1489 2 reports reports only
- T1505.004 2 reports reports only
- T1518 2 reports reports only
- T1528 2 reports reports only
- T1529 2 reports reports only
- T1543 2 reports reports only
- T1546.004 2 reports reports only
- T1547.009 2 reports in ATT&CK
- T1548 2 reports reports only
- T1552.001 2 reports reports only
- T1553.002 2 reports in ATT&CK
- T1555 2 reports reports only
- T1558.003 2 reports reports only
- T1559 2 reports reports only
- T1560.002 2 reports reports only
- T1566.004 2 reports reports only
- T1567 2 reports reports only
- T1567.002 2 reports in ATT&CK
- T1569.002 2 reports reports only
- T1573 2 reports reports only
- T1573.002 2 reports reports only
- T1574 2 reports reports only
- T1584 2 reports reports only
- T1587.003 2 reports reports only
- T1588.003 2 reports reports only
- T1588.004 2 reports reports only
- T1589.002 2 reports reports only
- T1590 2 reports reports only
- T1592 2 reports reports only
- T1593.002 2 reports reports only
- T1595 2 reports reports only
- T1608 2 reports reports only
- T1608.002 2 reports reports only
- T1608.006 2 reports reports only
- T1649 2 reports reports only
- T1003.003 1 report reports only
- T1003.006 1 report reports only
- T1014 1 report reports only
- T1020 1 report reports only
- T1021.004 1 report in ATT&CK
- T1021.005 1 report reports only
- T1027.002 1 report reports only
- T1027.003 1 report in ATT&CK
- T1027.004 1 report reports only
- T1036.003 1 report reports only
- T1036.004 1 report reports only
- T1036.007 1 report reports only
- T1037 1 report reports only
- T1037.001 1 report reports only
- T1048.002 1 report reports only
- T1053 1 report reports only
- T1053.002 1 report reports only
- T1055.009 1 report reports only
- T1056 1 report reports only
- T1056.003 1 report reports only
- T1059.009 1 report reports only
- T1059.010 1 report reports only
- T1059.011 1 report reports only
- T1069 1 report reports only
- T1069.003 1 report reports only
- T1070.006 1 report reports only
- T1071.002 1 report reports only
- T1074 1 report reports only
- T1078.001 1 report reports only
- T1087 1 report reports only
- T1087.003 1 report reports only
- T1087.004 1 report reports only
- T1090.002 1 report reports only
- T1091 1 report reports only
- T1098.001 1 report reports only
- T1098.003 1 report reports only
- T1098.004 1 report reports only
- T1098.005 1 report reports only
- T1098.006 1 report reports only
- T1102.001 1 report reports only
- T1102.003 1 report in ATT&CK
- T1110.001 1 report reports only
- T1110.002 1 report reports only
- T1111 1 report reports only
- T1112 1 report reports only
- T1113 1 report reports only
- T1114.001 1 report reports only
- T1114.003 1 report reports only
- T1120 1 report reports only
- T1123 1 report reports only
- T1125 1 report reports only
- T1132 1 report reports only
- T1134 1 report reports only
- T1136.002 1 report reports only
- T1137 1 report reports only
- T1137.001 1 report reports only
- T1137.006 1 report reports only
- T1187 1 report reports only
- T1195 1 report reports only
- T1195.001 1 report reports only
- T1195.002 1 report reports only
- T1199 1 report reports only
- T1200 1 report reports only
- T1201 1 report reports only
- T1202 1 report reports only
- T1204.001 1 report in ATT&CK
- T1204.004 1 report reports only
- T1210 1 report reports only
- T1212 1 report reports only
- T1213.001 1 report reports only
- T1213.002 1 report reports only
- T1213.003 1 report reports only
- T1218 1 report reports only
- T1218.005 1 report reports only
- T1218.010 1 report in ATT&CK
- T1218.014 1 report reports only
- T1222.002 1 report reports only
- T1484 1 report reports only
- T1484.001 1 report reports only
- T1485 1 report reports only
- T1486 1 report reports only
- T1490 1 report reports only
- T1491.002 1 report reports only
- T1497 1 report reports only
- T1497.003 1 report reports only
- T1498 1 report reports only
- T1505 1 report reports only
- T1505.001 1 report reports only
- T1530 1 report reports only
- T1534 1 report in ATT&CK
- T1537 1 report reports only
- T1538 1 report reports only
- T1539 1 report reports only
- T1543.002 1 report reports only
- T1543.004 1 report reports only
- T1546 1 report reports only
- T1546.003 1 report in ATT&CK
- T1546.008 1 report reports only
- T1546.012 1 report reports only
- T1546.015 1 report reports only
- T1547 1 report reports only
- T1547.002 1 report reports only
- T1547.005 1 report reports only
- T1548.002 1 report reports only
- T1550 1 report reports only
- T1550.001 1 report reports only
- T1550.002 1 report reports only
- T1550.003 1 report reports only
- T1552 1 report reports only
- T1554 1 report reports only
- T1555.001 1 report reports only
- T1556 1 report reports only
- T1556.006 1 report reports only
- T1556.009 1 report reports only
- T1561 1 report reports only
- T1563.002 1 report reports only
- T1564.001 1 report reports only
- T1564.003 1 report reports only
- T1564.004 1 report reports only
- T1565 1 report reports only
- T1565.001 1 report reports only
- T1566.003 1 report reports only
- T1567.001 1 report reports only
- T1569 1 report reports only
- T1574.011 1 report reports only
- T1578 1 report reports only
- T1580 1 report reports only
- T1583.002 1 report reports only
- T1583.004 1 report reports only
- T1583.006 1 report reports only
- T1584.004 1 report in ATT&CK
- T1584.008 1 report in ATT&CK
- T1585 1 report reports only
- T1585.002 1 report in ATT&CK
- T1585.003 1 report reports only
- T1586 1 report reports only
- T1586.002 1 report in ATT&CK
- T1587 1 report reports only
- T1587.002 1 report reports only
- T1588 1 report reports only
- T1588.002 1 report reports only
- T1588.007 1 report reports only
- T1589.001 1 report in ATT&CK
- T1590.001 1 report reports only
- T1590.005 1 report reports only
- T1594 1 report reports only
- T1595.001 1 report reports only
- T1598 1 report reports only
- T1602 1 report reports only
- T1602.001 1 report reports only
- T1602.002 1 report reports only
- T1608.003 1 report reports only
- T1608.004 1 report reports only
- T1608.005 1 report reports only
- T1613 1 report reports only
- T1614 1 report reports only
- T1614.001 1 report reports only
- T1615 1 report reports only
- T1619 1 report reports only
- T1622 1 report reports only
- T1627.001 1 report reports only
- T1652 1 report reports only
- T1654 1 report reports only
- T1657 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2007-5633
- CVE-2008-3431 KEV
- CVE-2009-0824
- CVE-2010-1256
- CVE-2010-1424
- CVE-2010-1592
- CVE-2010-1899
- CVE-2010-2152
- CVE-2010-2730
- CVE-2010-3915
- CVE-2010-3916
- CVE-2010-3972
Show all 323 CVEs Show fewer
- CVE-2011-1331
- CVE-2011-2462 KEV
- CVE-2011-3544 KEV
- CVE-2012-0151 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-2531
- CVE-2012-2532
- CVE-2012-5687
- CVE-2013-0707
- CVE-2013-2618
- CVE-2013-3163 KEV
- CVE-2013-3644
- CVE-2013-3893 KEV
- CVE-2013-3900 KEV
- CVE-2013-3918 KEV
- CVE-2013-5947
- CVE-2013-5990
- CVE-2014-0322 KEV
- CVE-2014-0810
- CVE-2014-1225
- CVE-2014-1761 KEV
- CVE-2014-1812 KEV ransomware
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-4113 KEV
- CVE-2014-4114 KEV
- CVE-2014-6352 KEV
- CVE-2014-7247
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0062
- CVE-2015-0235
- CVE-2015-0554
- CVE-2015-1641 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-1805
- CVE-2015-5119 KEV
- CVE-2015-7248
- CVE-2015-7254
- CVE-2015-7547
- CVE-2015-7645 KEV ransomware
- CVE-2015-7755 KEV
- CVE-2016-0099 KEV ransomware
- CVE-2016-0167 KEV ransomware
- CVE-2016-0189 KEV ransomware
- CVE-2016-1019 KEV ransomware
- CVE-2016-10401
- CVE-2016-3353
- CVE-2016-4117 KEV ransomware
- CVE-2016-5195 KEV
- CVE-2016-7836 KEV
- CVE-2017-0143 KEV ransomware
- CVE-2017-0144 KEV ransomware
- CVE-2017-0176
- CVE-2017-0199 KEV ransomware
- CVE-2017-0213 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-1000353 KEV
- CVE-2017-10271 KEV ransomware
- CVE-2017-1099
- CVE-2017-11292 KEV
- CVE-2017-11467
- CVE-2017-11774 KEV
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-12149 KEV ransomware
- CVE-2017-12629
- CVE-2017-12824
- CVE-2017-15399
- CVE-2017-15906
- CVE-2017-15944 KEV
- CVE-2017-17215
- CVE-2017-5638 KEV ransomware
- CVE-2017-6327 KEV
- CVE-2017-6328
- CVE-2017-7269 KEV
- CVE-2017-8291 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2017-9805 KEV
- CVE-2017-9822 KEV ransomware
- CVE-2018-0101
- CVE-2018-0171 KEV
- CVE-2018-0296 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-0824 KEV
- CVE-2018-10088
- CVE-2018-10561 KEV
- CVE-2018-10562 KEV ransomware
- CVE-2018-11776 KEV
- CVE-2018-1207
- CVE-2018-13379 KEV ransomware
- CVE-2018-15454
- CVE-2018-15961 KEV
- CVE-2018-15982 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-2628 KEV
- CVE-2018-2893
- CVE-2018-4878 KEV ransomware
- CVE-2018-5002 KEV
- CVE-2018-7600 KEV ransomware
- CVE-2018-7602 KEV ransomware
- CVE-2018-8120 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8373 KEV
- CVE-2018-8440 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2018-8570
- CVE-2018-8581 KEV ransomware
- CVE-2018-8589 KEV
- CVE-2018-8611 KEV
- CVE-2018-8639 KEV ransomware
- CVE-2018-9866
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0797 KEV
- CVE-2019-0803 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-11043 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-11539 KEV ransomware
- CVE-2019-11580 KEV ransomware
- CVE-2019-1367 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-1458 KEV ransomware
- CVE-2019-16098
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-16920 KEV
- CVE-2019-17026 KEV
- CVE-2019-17100
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-2215 KEV
- CVE-2019-2725 KEV ransomware
- CVE-2019-3369
- CVE-2019-3396 KEV ransomware
- CVE-2019-3398 KEV
- CVE-2019-6225
- CVE-2019-8394 KEV
- CVE-2019-9489
- CVE-2019-9621 KEV
- CVE-2020-0601 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0787 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-10198
- CVE-2020-1040 KEV
- CVE-2020-116511
- CVE-2020-11652 KEV
- CVE-2020-11899 KEV
- CVE-2020-1350 KEV
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-1472122
- CVE-2020-14750 KEV
- CVE-2020-14882 KEV
- CVE-2020-1599
- CVE-2020-1664
- CVE-2020-2021 KEV ransomware
- CVE-2020-3125
- CVE-2020-3529
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-6789
- CVE-2020-7961 KEV
- CVE-2020-8243 KEV
- CVE-2020-8260 KEV
- CVE-2020-8468 KEV
- CVE-2020-8515 KEV
- CVE-2021-1472
- CVE-2021-1473
- CVE-2021-1636
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-1844
- CVE-2021-1879 KEV
- CVE-2021-20016 KEV ransomware
- CVE-2021-21166 KEV
- CVE-2021-2135
- CVE-2021-21551 KEV
- CVE-2021-21975 KEV ransomware
- CVE-2021-21983
- CVE-2021-22555 KEV
- CVE-2021-22893 KEV ransomware
- CVE-2021-22894 KEV
- CVE-2021-22899 KEV
- CVE-2021-22900 KEV
- CVE-2021-26084 KEV ransomware
- CVE-2021-26411 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-27857
- CVE-2021-28149
- CVE-2021-28152
- CVE-2021-28482
- CVE-2021-29855
- CVE-2021-30116 KEV ransomware
- CVE-2021-3019
- CVE-2021-30551 KEV
- CVE-2021-31195
- CVE-2021-31196 KEV
- CVE-2021-31206
- CVE-2021-31207 KEV ransomware
- CVE-2021-3156 KEV
- CVE-2021-31979 KEV
- CVE-2021-3197961
- CVE-2021-33742 KEV
- CVE-2021-33771 KEV
- CVE-2021-3377162
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-36798
- CVE-2021-36934 KEV
- CVE-2021-36942 KEV ransomware
- CVE-2021-4034 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-40449 KEV ransomware
- CVE-2021-40539 KEV ransomware
- CVE-2021-4104
- CVE-2021-41379 KEV ransomware
- CVE-2021-44077 KEV
- CVE-2021-44207 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-44515 KEV
- CVE-2021-44832
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-1388 KEV ransomware
- CVE-2022-21587 KEV ransomware
- CVE-2022-21882 KEV ransomware
- CVE-2022-21919 KEV
- CVE-2022-2294 KEV ransomware
- CVE-2022-22954 KEV ransomware
- CVE-2022-22957
- CVE-2022-22958
- CVE-2022-22960 KEV
- CVE-2022-22972
- CVE-2022-24500
- CVE-2022-24521 KEV ransomware
- CVE-2022-24682 KEV ransomware
- CVE-2022-24934
- CVE-2022-26134 KEV ransomware
- CVE-2022-26352 KEV ransomware
- CVE-2022-26766
- CVE-2022-26809
- CVE-2022-26923 KEV
- CVE-2022-27924 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-30333 KEV ransomware
- CVE-2022-31199 KEV ransomware
- CVE-2022-37042 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41080 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-41328 KEV
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2022-49475
- CVE-2023-0669 KEV ransomware
- CVE-2023-21746
- CVE-2023-23397 KEV
- CVE-2023-27350 KEV ransomware
- CVE-2023-27532 KEV ransomware
- CVE-2023-27997 KEV ransomware
- CVE-2023-28461 KEV ransomware
- CVE-2023-32315 KEV
- CVE-2023-3466
- CVE-2023-3467
- CVE-2023-3519 KEV ransomware
- CVE-2023-36025 KEV
- CVE-2023-36033 KEV
- CVE-2023-3883
- CVE-2023-38831 KEV ransomware
- CVE-2023-45727 KEV
- CVE-2023-46805 KEV ransomware
- CVE-2023-48788 KEV ransomware
- CVE-2024-0012 KEV ransomware
- CVE-2024-21412 KEV ransomware
- CVE-2024-21887 KEV ransomware
- CVE-2024-21893 KEV ransomware
- CVE-2024-21983
- CVE-2024-23204
- CVE-2024-24919 KEV ransomware
- CVE-2024-27956
- CVE-2024-30051 KEV ransomware
- CVE-2024-3400 KEV ransomware
- CVE-2024-36401 KEV
- CVE-2024-36991
- CVE-2024-38080 KEV
- CVE-2024-38112 KEV
- CVE-2024-42009 KEV
- CVE-2024-4577 KEV ransomware
- CVE-2024-47575 KEV
- CVE-2024-4885 KEV
- CVE-2024-6473
- CVE-2024-9474 KEV ransomware
- CVE-2025-2783 KEV
- CVE-2025-31324 KEV ransomware
- CVE-2025-55182 KEV ransomware
- CVE-2026-21236
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Leviathan, APT 40, TEMP.Periscope - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Leviathan, APT 40, TEMP.Periscope - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CHINACHOPPER (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor FlawedAmmyy (Malware Family)
Show all 923 reports Show fewer
-
China Chopper - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor China Chopper - Threat Group Cards: A Threat Actor Encyclopedia
-
Team46 and TaxOff: two sides of the same coin
The original link failed its last check. Original publisher Detailsfor Team46 and TaxOff: two sides of the same coin
-
Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausge…
The title opens archive.today, not the publisher’s page. Archived copy on ORKL Detailsfor Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausge…
-
CVE-2024-21412_ Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CVE-2024-21412_ Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day
-
PwC Cyber Threats 2022: A Year in Retrospect.pdf
The original link failed its last check. Original publisher Detailsfor PwC Cyber Threats 2022: A Year in Retrospect.pdf
-
Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
The original link failed its last check. Original publisher Detailsfor Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
-
Conceptualizing a Continuum of Cyber Threat Attribution
The original link failed its last check. Original publisher Detailsfor Conceptualizing a Continuum of Cyber Threat Attribution
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
MustangPanda%20-%20Enemy%20at%20the%20gate_final.pdf
The original link failed its last check. Original publisher Detailsfor MustangPanda%20-%20Enemy%20at%20the%20gate_final.pdf
-
Rising Tide- Chasing the Currents of Espionage in the South China Sea
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Rising Tide- Chasing the Currents of Espionage in the South China Sea
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Russian Ransomware C2 Network Discovered in Censys Data
The original link failed its last check. Original publisher Detailsfor Russian Ransomware C2 Network Discovered in Censys Data
-
Burrowing your way into VPNs, Proxies, and Tunnels
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Burrowing your way into VPNs, Proxies, and Tunnels
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Unmasking China’s State Hackers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Unmasking China’s State Hackers
-
Legitimate Sites used as Cobalt Strike C2s against Indian Government
The original link failed its last check. Original publisher Detailsfor Legitimate Sites used as Cobalt Strike C2s against Indian Government
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor 2021trends.pdf
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
VMware Exposing Malware In Linux Based Multi Cloud Environments
The original link failed its last check. Original publisher Detailsfor VMware Exposing Malware In Linux Based Multi Cloud Environments
-
Winnti is Coming - Evolution after Prosecution@HITCON2021
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Winnti is Coming - Evolution after Prosecution@HITCON2021
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Injection is the New Black- Novel RTF Template Inject Technique Poised for Widespread Adoption Beyond APT Actors
-
sneak-peek-ch1-2-finding-beacons-in-the-dark.pdf
The original link failed its last check. Original publisher Detailsfor sneak-peek-ch1-2-finding-beacons-in-the-dark.pdf
-
Masters of Mimicry: new APT group ChamelGang and its arsenal
The original link failed its last check. Original publisher Detailsfor Masters of Mimicry: new APT group ChamelGang and its arsenal
-
Masters of Mimicry: new APT group ChamelGang and its arsenal
The original link failed its last check. Original publisher Detailsfor Masters of Mimicry: new APT group ChamelGang and its arsenal
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Microsoft Digital Defense Report OCTOBER 2021
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Digital Defense Report OCTOBER 2021
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
report-old-dogs-new-tricks.pdf
The original link failed its last check. Original publisher Detailsfor report-old-dogs-new-tricks.pdf
-
Government points finger at China over cyber attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Government points finger at China over cyber attacks
-
CSA_TTPs-of-Indicted-APT40-Actors-Associated-with-China-MSS-Hainan-State-Security-Department
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CSA_TTPs-of-Indicted-APT40-Actors-Associated-with-China-MSS-Hainan-State-Security-Department
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cases of cyberattacks including those by a group known as APT40 which the Chinese government is behind (Statement by Press Secretary YOSHIDA Tomoyuki)
-
Statement on China’s cyber campaigns
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Statement on China’s cyber campaigns
-
UK and allies hold Chinese state responsible for a pervasive pattern of hacking
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor UK and allies hold Chinese state responsible for a pervasive pattern of hacking
-
Ryuk Ransomware Now Targeting Webservers
The original link failed its last check. Original publisher Detailsfor Ryuk Ransomware Now Targeting Webservers
-
Cobalt Strike- Favorite Tool from APT to Crimeware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cobalt Strike- Favorite Tool from APT to Crimeware
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (AA21-200A)- Tactics, Techniques, and Procedures of Indicted APT40 Actors Associated with China’s MSS Hainan State Security Department
-
Looks like the page you're looking for doesn't exist or has moved.
The original link failed its last check. Original publisher Detailsfor Looks like the page you're looking for doesn't exist or has moved.
-
Mustang Panda PlugX - 45.251.240.55 Pivot
The original link failed its last check. Original publisher Detailsfor Mustang Panda PlugX - 45.251.240.55 Pivot
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CTIR_casestudy_2.pdf
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CTIR_casestudy_1.pdf
-
the-operations-of-winnti-group.pdf
The original link failed its last check. Original publisher Detailsfor the-operations-of-winnti-group.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor mtrends-2021
-
report-bb-2021-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor report-bb-2021-threat-report.pdf
-
Technical Analysis of Operation Diànxùn
The original link failed its last check. Original publisher Detailsfor Technical Analysis of Operation Diànxùn
-
CSET - Academics, AI, and APTs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CSET - Academics, AI, and APTs
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor nao-sec.org-Royal Road ReDive
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Royal Road! Re-Dive
-
China cyber attacks- the current threat landscape
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor China cyber attacks- the current threat landscape
-
Microsoft Security—detecting empires in the cloud
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Security—detecting empires in the cloud
-
Microsoft Security—detecting empires in the cloud - Microsoft Security
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Security—detecting empires in the cloud - Microsoft Security
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 調查局 08-19 公布中國對台灣政府機關駭侵事件說明
-
In-Memory shellcode decoding to evade AVs/EDRs
The original link failed its last check. Original publisher Detailsfor In-Memory shellcode decoding to evade AVs/EDRs
-
Leviathan APT campaign in 2020 Malaysian political crisis _ Elastic Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Leviathan APT campaign in 2020 Malaysian political crisis _ Elastic Blog
-
A close look at the advanced techniques used in a Malaysian-focused APT campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A close look at the advanced techniques used in a Malaysian-focused APT campaign
-
Catching APT41 exploiting a zero-day vulnerability
The original link failed its last check. Detailsfor Catching APT41 exploiting a zero-day vulnerability
-
Is APT 27 Abusing COVID-19 To Attack People !
The original link failed its last check. Detailsfor Is APT 27 Abusing COVID-19 To Attack People !
-
cybersecurity-threatscape-2019-q4-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor cybersecurity-threatscape-2019-q4-eng
-
Attribution is in the object- using RTF object dimensions to track APT phishing weaponizers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attribution is in the object- using RTF object dimensions to track APT phishing weaponizers
-
APT40 goes from Template Injections to OLE-Linkings for payload delivery
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT40 goes from Template Injections to OLE-Linkings for payload delivery
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT 40 in Malaysia
-
APT40 is run by the Hainan department of the Chinese Ministry of State Security
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT40 is run by the Hainan department of the Chinese Ministry of State Security
-
Hainan Xiandun Technology Company is APT40
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hainan Xiandun Technology Company is APT40
-
Cyber Threat Landscape in Japan – Revealing Threat in the Shadow
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber Threat Landscape in Japan – Revealing Threat in the Shadow
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor [CB19] Cyber Threat Landscape in Japan – Revealing Threat in the Shadow by Chi En Shen (Ashley) Oleg Bondarenko
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
-
The original link failed its last check. Original publisher Detailsfor Aarhus_miniseminar_291118.pdf
-
cds19-executive-s08-achievement-unlocked.pdf
The original link failed its last check. Original publisher Detailsfor cds19-executive-s08-achievement-unlocked.pdf
-
The original link failed its last check. Original publisher Detailsfor Analytics
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Two Birds, One STONE PANDA
-
APT41: A Dual Espionage and Cyber Crime Operation
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor APT41: A Dual Espionage and Cyber Crime Operation
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor report_APT41
-
The original link failed its last check. Original publisher Detailsfor APT-Attacks-eng.pdf
-
Into the Fog - The Return of ICEFOG APT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Into the Fog - The Return of ICEFOG APT
-
Into the Fog - The Return of ICEFOG APT
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Into the Fog - The Return of ICEFOG APT
-
APT_trends_report_Q1_2019_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q1_2019_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT 40
-
The original link failed its last check. Original publisher Detailsfor Council on Foreign Relations
-
The original link failed its last check. Original publisher Detailsfor 중국 기반 해커, 국내 에너지 기관 공격
-
The original link failed its last check. Original publisher Detailsfor rpt-mtrends-2019.pdf
-
mpressioncss_ta_report_2019.pdf
The original link failed its last check. Original publisher Detailsfor mpressioncss_ta_report_2019.pdf
-
The original link failed its last check. Original publisher Detailsfor https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/attacker-tracking-users-seeking-pakistani-passport/
-
The original link failed its last check. Original publisher Detailsfor Accenture Strategy Templates
-
APT40- Examining a China-Nexus Espionage Actor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT40- Examining a China-Nexus Espionage Actor
-
APT40: Examining a China-Nexus Espionage Actor « APT40: Examining a China-Nexus Espionage Actor
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT40: Examining a China-Nexus Espionage Actor « APT40: Examining a China-Nexus Espionage Actor
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor rpt-mtrends-2019
-
Analyzing Digital Quartermasters in Asia – Do Chinese and Indian APTs Have a Shared Supply Chain?
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Analyzing Digital Quartermasters in Asia – Do Chinese and Indian APTs Have a Shared Supply Chain?
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2018 Master Table
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Threat Actor TEMP.Periscope Targets UK-Based Engineering Company Using Russian APT Techniques
-
Goblin Panda targets Cambodia sharing capacities with another Chinese group hackers Temp Periscope
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Goblin Panda targets Cambodia sharing capacities with another Chinese group hackers Temp Periscope
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Two Birds, One STONE PANDA
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Two Birds, One STONE PANDA
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Espionage Group TEMP.Periscope Targets Cambodia Ahead of July 2018 Elections and Reveals Broad Operations Globally
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BADFLICK is not so bad!
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries
-
Advanced Persistent Threat Groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threat Groups
-
The original link failed its last check. Original publisher Detailsfor security_report_20160613.pdf
-
Russian Police Prevented Massive Banking Sector Cyber Attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian Police Prevented Massive Banking Sector Cyber Attack
-
Newcomers in the Derusbi family
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Newcomers in the Derusbi family
-
Uncovering the Seven Pointed Dagger
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Uncovering the Seven Pointed Dagger
-
The original link failed its last check. Original publisher Detailsfor APT17_Report.pdf
-
BKDR_RARSTONE: New RAT to Watch Out For - TrendLabs Security Intelligence Blog
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor BKDR_RARSTONE: New RAT to Watch Out For - TrendLabs Security Intelligence Blog
-
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Inside a Back Door Attack
Newest first. Details opens the report in Explore.