APT19
Also reported as Codoso, Sunshop Group, JerseyMikes, Taffeta Typhoon, Checkered Typhoon and 37 other names. Linked to China by four sources.
Reports per quarter
Techniques seen in the last two years
- T1053.005 8 reports reports only
- T1082 8 reports in ATT&CK
- T1057 7 reports reports only
- T1059.001 7 reports in ATT&CK
- T1105 7 reports reports only
- T1204.002 7 reports in ATT&CK
- T1566.001 7 reports in ATT&CK
- T1071.001 6 reports in ATT&CK
- T1140 6 reports in ATT&CK
- T1027 5 reports reports only
Show all 276 techniques Show fewer
- T1041 5 reports reports only
- T1059.003 5 reports reports only
- T1132.001 5 reports in ATT&CK
- T1189 5 reports in ATT&CK
- T1005 4 reports reports only
- T1033 4 reports in ATT&CK
- T1036.005 4 reports reports only
- T1083 4 reports reports only
- T1482 4 reports reports only
- T1547.001 4 reports in ATT&CK
- T1572 4 reports reports only
- T1573.001 4 reports reports only
- T1574.001 4 reports in ATT&CK
- T1007 3 reports reports only
- T1016 3 reports in ATT&CK
- T1018 3 reports reports only
- T1027.009 3 reports reports only
- T1046 3 reports reports only
- T1047 3 reports reports only
- T1055 3 reports reports only
- T1055.002 3 reports reports only
- T1059 3 reports in ATT&CK
- T1059.005 3 reports reports only
- T1068 3 reports reports only
- T1069.002 3 reports reports only
- T1070.004 3 reports reports only
- T1087.001 3 reports reports only
- T1087.002 3 reports reports only
- T1129 3 reports reports only
- T1136.001 3 reports reports only
- T1190 3 reports reports only
- T1219 3 reports reports only
- T1505.003 3 reports reports only
- T1518.001 3 reports reports only
- T1566 3 reports reports only
- T1566.002 3 reports reports only
- T1570 3 reports reports only
- T1583.003 3 reports reports only
- T1587.001 3 reports reports only
- T1608.001 3 reports reports only
- T1003.001 2 reports reports only
- T1003.002 2 reports reports only
- T1008 2 reports reports only
- T1012 2 reports reports only
- T1021.001 2 reports reports only
- T1021.002 2 reports reports only
- T1036 2 reports reports only
- T1049 2 reports reports only
- T1055.004 2 reports reports only
- T1055.012 2 reports reports only
- T1056.001 2 reports reports only
- T1059.006 2 reports reports only
- T1059.007 2 reports reports only
- T1069.001 2 reports reports only
- T1071 2 reports reports only
- T1071.004 2 reports reports only
- T1078 2 reports reports only
- T1090 2 reports reports only
- T1090.001 2 reports reports only
- T1095 2 reports reports only
- T1098 2 reports reports only
- T1098.007 2 reports reports only
- T1102 2 reports reports only
- T1104 2 reports reports only
- T1119 2 reports reports only
- T1124 2 reports reports only
- T1133 2 reports reports only
- T1135 2 reports reports only
- T1136 2 reports reports only
- T1204 2 reports reports only
- T1217 2 reports reports only
- T1218.007 2 reports reports only
- T1496 2 reports reports only
- T1497.001 2 reports reports only
- T1505.004 2 reports reports only
- T1543.003 2 reports in ATT&CK
- T1548 2 reports reports only
- T1555.003 2 reports reports only
- T1560 2 reports reports only
- T1560.001 2 reports reports only
- T1566.004 2 reports reports only
- T1567 2 reports reports only
- T1571 2 reports reports only
- T1574 2 reports reports only
- T1583 2 reports reports only
- T1583.001 2 reports reports only
- T1590 2 reports reports only
- T1595 2 reports reports only
- T1595.002 2 reports reports only
- T1608 2 reports reports only
- T1608.002 2 reports reports only
- T1608.006 2 reports reports only
- T1620 2 reports reports only
- T1649 2 reports reports only
- T1001.003 1 report reports only
- T1003 1 report reports only
- T1010 1 report reports only
- T1016.001 1 report reports only
- T1020 1 report reports only
- T1021 1 report reports only
- T1021.004 1 report reports only
- T1021.005 1 report reports only
- T1021.006 1 report reports only
- T1036.003 1 report reports only
- T1036.007 1 report reports only
- T1037 1 report reports only
- T1037.001 1 report reports only
- T1039 1 report reports only
- T1040 1 report reports only
- T1048 1 report reports only
- T1053 1 report reports only
- T1053.003 1 report reports only
- T1055.001 1 report reports only
- T1055.003 1 report reports only
- T1055.009 1 report reports only
- T1056 1 report reports only
- T1059.002 1 report reports only
- T1059.004 1 report reports only
- T1059.009 1 report reports only
- T1059.010 1 report reports only
- T1059.011 1 report reports only
- T1069 1 report reports only
- T1069.003 1 report reports only
- T1070 1 report reports only
- T1072 1 report reports only
- T1074 1 report reports only
- T1074.001 1 report reports only
- T1074.002 1 report reports only
- T1078.002 1 report reports only
- T1078.003 1 report reports only
- T1078.004 1 report reports only
- T1087 1 report reports only
- T1087.004 1 report reports only
- T1090.003 1 report reports only
- T1091 1 report reports only
- T1098.001 1 report reports only
- T1098.003 1 report reports only
- T1098.004 1 report reports only
- T1098.005 1 report reports only
- T1098.006 1 report reports only
- T1102.002 1 report reports only
- T1106 1 report reports only
- T1113 1 report reports only
- T1114 1 report reports only
- T1114.001 1 report reports only
- T1114.002 1 report reports only
- T1114.003 1 report reports only
- T1115 1 report reports only
- T1120 1 report reports only
- T1123 1 report reports only
- T1125 1 report reports only
- T1132 1 report reports only
- T1134 1 report reports only
- T1134.001 1 report reports only
- T1136.002 1 report reports only
- T1137 1 report reports only
- T1137.006 1 report reports only
- T1195 1 report reports only
- T1195.001 1 report reports only
- T1195.002 1 report reports only
- T1199 1 report reports only
- T1200 1 report reports only
- T1201 1 report reports only
- T1203 1 report reports only
- T1204.001 1 report reports only
- T1204.004 1 report reports only
- T1210 1 report reports only
- T1213 1 report reports only
- T1213.001 1 report reports only
- T1213.002 1 report reports only
- T1213.003 1 report reports only
- T1218 1 report reports only
- T1218.014 1 report reports only
- T1484 1 report reports only
- T1484.001 1 report reports only
- T1485 1 report reports only
- T1486 1 report reports only
- T1489 1 report reports only
- T1490 1 report reports only
- T1491.002 1 report reports only
- T1497 1 report reports only
- T1497.003 1 report reports only
- T1498 1 report reports only
- T1505 1 report reports only
- T1518 1 report reports only
- T1528 1 report reports only
- T1529 1 report reports only
- T1530 1 report reports only
- T1534 1 report reports only
- T1537 1 report reports only
- T1538 1 report reports only
- T1543 1 report reports only
- T1543.002 1 report reports only
- T1543.004 1 report reports only
- T1546 1 report reports only
- T1546.003 1 report reports only
- T1546.004 1 report reports only
- T1546.008 1 report reports only
- T1546.012 1 report reports only
- T1546.015 1 report reports only
- T1547 1 report reports only
- T1547.002 1 report reports only
- T1547.005 1 report reports only
- T1547.009 1 report reports only
- T1548.002 1 report reports only
- T1550 1 report reports only
- T1550.001 1 report reports only
- T1550.002 1 report reports only
- T1552 1 report reports only
- T1553.002 1 report reports only
- T1554 1 report reports only
- T1555 1 report reports only
- T1556 1 report reports only
- T1556.006 1 report reports only
- T1556.009 1 report reports only
- T1558.003 1 report reports only
- T1559 1 report reports only
- T1560.002 1 report reports only
- T1564.004 1 report reports only
- T1565 1 report reports only
- T1565.001 1 report reports only
- T1566.003 1 report reports only
- T1567.001 1 report reports only
- T1567.002 1 report reports only
- T1569 1 report reports only
- T1569.002 1 report reports only
- T1573 1 report reports only
- T1573.002 1 report reports only
- T1574.011 1 report reports only
- T1578 1 report reports only
- T1580 1 report reports only
- T1583.004 1 report reports only
- T1583.006 1 report reports only
- T1584 1 report reports only
- T1584.004 1 report reports only
- T1585 1 report reports only
- T1585.002 1 report reports only
- T1586.002 1 report reports only
- T1587 1 report reports only
- T1587.003 1 report reports only
- T1588 1 report reports only
- T1588.002 1 report in ATT&CK
- T1588.003 1 report reports only
- T1588.004 1 report reports only
- T1588.007 1 report reports only
- T1589.002 1 report reports only
- T1590.005 1 report reports only
- T1592 1 report reports only
- T1595.001 1 report reports only
- T1598 1 report reports only
- T1602 1 report reports only
- T1602.001 1 report reports only
- T1602.002 1 report reports only
- T1608.003 1 report reports only
- T1608.004 1 report reports only
- T1608.005 1 report reports only
- T1613 1 report reports only
- T1614 1 report reports only
- T1614.001 1 report reports only
- T1615 1 report reports only
- T1619 1 report reports only
- T1622 1 report reports only
- T1627.001 1 report reports only
- T1652 1 report reports only
- T1654 1 report reports only
- T1657 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2008-3431 KEV
- CVE-2009-4324 KEV
- CVE-2010-1424
- CVE-2010-2152
- CVE-2010-2883 KEV
- CVE-2010-3915
- CVE-2010-3916
- CVE-2011-1331
- CVE-2011-2462 KEV
- CVE-2011-3544 KEV
- CVE-2012-0151 KEV
- CVE-2012-0158 KEV ransomware
Show all 267 CVEs Show fewer
- CVE-2012-4792 KEV
- CVE-2012-4969 KEV
- CVE-2012-5687
- CVE-2013-0707
- CVE-2013-1347 KEV
- CVE-2013-1493
- CVE-2013-2423 KEV
- CVE-2013-3644
- CVE-2013-3893 KEV
- CVE-2013-3900 KEV
- CVE-2013-3918 KEV
- CVE-2013-5947
- CVE-2013-5990
- CVE-2014-0322 KEV
- CVE-2014-0502 KEV
- CVE-2014-0810
- CVE-2014-1225
- CVE-2014-1812 KEV ransomware
- CVE-2014-2962
- CVE-2014-3393
- CVE-2014-4019
- CVE-2014-4113 KEV
- CVE-2014-4114 KEV
- CVE-2014-6332 KEV
- CVE-2014-6352 KEV
- CVE-2014-7247
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-1641 KEV
- CVE-2015-2424 KEV
- CVE-2015-2545 KEV
- CVE-2015-4852 KEV
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-6585
- CVE-2015-7248
- CVE-2015-7254
- CVE-2015-7501
- CVE-2016-0167 KEV ransomware
- CVE-2016-5195 KEV
- CVE-2016-7836 KEV
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0213 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-10271 KEV ransomware
- CVE-2017-1099
- CVE-2017-11774 KEV
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-12149 KEV ransomware
- CVE-2017-12824
- CVE-2017-15399
- CVE-2017-15944 KEV
- CVE-2017-18368 KEV
- CVE-2017-5638 KEV ransomware
- CVE-2017-6327 KEV
- CVE-2017-6328
- CVE-2017-7269 KEV
- CVE-2017-8291 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2017-9805 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-0824 KEV
- CVE-2018-11776 KEV
- CVE-2018-1207
- CVE-2018-13379 KEV ransomware
- CVE-2018-15961 KEV
- CVE-2018-15982 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-4878 KEV ransomware
- CVE-2018-4939 KEV
- CVE-2018-6789 KEV ransomware
- CVE-2018-7600 KEV ransomware
- CVE-2018-7602 KEV ransomware
- CVE-2018-8120 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8581 KEV ransomware
- CVE-2018-8611 KEV
- CVE-2018-8639 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0803 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-1040
- CVE-2019-11510 KEV ransomware
- CVE-2019-11580 KEV ransomware
- CVE-2019-1458 KEV ransomware
- CVE-2019-16098
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-16759 KEV
- CVE-2019-16920 KEV
- CVE-2019-17100
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-3369
- CVE-2019-3396 KEV ransomware
- CVE-2019-3398 KEV
- CVE-2019-8394 KEV
- CVE-2019-9489
- CVE-2019-9621 KEV
- CVE-2020-0601 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0787 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-10198
- CVE-2020-1040 KEV
- CVE-2020-116511
- CVE-2020-11652 KEV
- CVE-2020-11899 KEV
- CVE-2020-1350 KEV
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-14750 KEV
- CVE-2020-14882 KEV
- CVE-2020-15505 KEV
- CVE-2020-1599
- CVE-2020-1664
- CVE-2020-17530 KEV
- CVE-2020-2021 KEV ransomware
- CVE-2020-2551 KEV
- CVE-2020-2555 KEV
- CVE-2020-3118 KEV
- CVE-2020-3125
- CVE-2020-3529
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-6789
- CVE-2020-7961 KEV
- CVE-2020-8193 KEV
- CVE-2020-8195 KEV
- CVE-2020-8196 KEV
- CVE-2020-8243 KEV
- CVE-2020-8260 KEV
- CVE-2020-8468 KEV
- CVE-2020-8515 KEV
- CVE-2021-1636
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-1844
- CVE-2021-1879 KEV
- CVE-2021-20016 KEV ransomware
- CVE-2021-21166 KEV
- CVE-2021-22555 KEV
- CVE-2021-22894 KEV
- CVE-2021-22899 KEV
- CVE-2021-22900 KEV
- CVE-2021-26084 KEV ransomware
- CVE-2021-26411 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-26868
- CVE-2021-27065 KEV ransomware
- CVE-2021-30116 KEV ransomware
- CVE-2021-30551 KEV
- CVE-2021-31195
- CVE-2021-31196 KEV
- CVE-2021-31206
- CVE-2021-31207 KEV ransomware
- CVE-2021-3156 KEV
- CVE-2021-31805
- CVE-2021-33742 KEV
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-35394 KEV
- CVE-2021-36798
- CVE-2021-36934 KEV
- CVE-2021-36942 KEV ransomware
- CVE-2021-4034 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-40449 KEV ransomware
- CVE-2021-40539 KEV ransomware
- CVE-2021-4104
- CVE-2021-41379 KEV ransomware
- CVE-2021-44077 KEV
- CVE-2021-44207 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-44515 KEV
- CVE-2021-44832
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-21587 KEV ransomware
- CVE-2022-21882 KEV ransomware
- CVE-2022-22954 KEV ransomware
- CVE-2022-22957
- CVE-2022-22958
- CVE-2022-22963 KEV
- CVE-2022-22965 KEV
- CVE-2022-24500
- CVE-2022-24521 KEV ransomware
- CVE-2022-24682 KEV ransomware
- CVE-2022-24934
- CVE-2022-26134 KEV ransomware
- CVE-2022-26138 KEV
- CVE-2022-26809
- CVE-2022-26923 KEV
- CVE-2022-27924 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-30333 KEV ransomware
- CVE-2022-31199 KEV ransomware
- CVE-2022-34305
- CVE-2022-37042 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41080 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-41328 KEV
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2022-49475
- CVE-2023-0669 KEV ransomware
- CVE-2023-21746
- CVE-2023-23397 KEV
- CVE-2023-27350 KEV ransomware
- CVE-2023-27532 KEV ransomware
- CVE-2023-27997 KEV ransomware
- CVE-2023-28461 KEV ransomware
- CVE-2023-32315 KEV
- CVE-2023-3466
- CVE-2023-3467
- CVE-2023-3519 KEV ransomware
- CVE-2023-36033 KEV
- CVE-2023-38831 KEV ransomware
- CVE-2023-45727 KEV
- CVE-2023-46805 KEV ransomware
- CVE-2023-48788 KEV ransomware
- CVE-2024-0012 KEV ransomware
- CVE-2024-21887 KEV ransomware
- CVE-2024-21893 KEV ransomware
- CVE-2024-21983
- CVE-2024-24919 KEV ransomware
- CVE-2024-27956
- CVE-2024-30051 KEV ransomware
- CVE-2024-3400 KEV ransomware
- CVE-2024-36401 KEV
- CVE-2024-42009 KEV
- CVE-2024-4577 KEV ransomware
- CVE-2024-47575 KEV
- CVE-2024-6473
- CVE-2024-9474 KEV ransomware
- CVE-2025-2783 KEV
- CVE-2025-31324 KEV ransomware
- CVE-2025-55182 KEV ransomware
- CVE-2026-21236
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
CrowdCasts Monthly: You Have an Adversary Problem
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CrowdCasts Monthly: You Have an Adversary Problem
-
Emissary Panda, APT 27, LuckyMouse, Bronze Union
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Emissary Panda, APT 27, LuckyMouse, Bronze Union
Show all 821 reports Show fewer
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Poison Ivy (Malware Family)
-
Nightshade Panda, APT 9, Group 27
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Nightshade Panda, APT 9, Group 27
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor APT 19, Deep Panda, C0d0so0
-
Turbine Panda, APT 26, Shell Crew, WebMasters, KungFu Kittens
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Turbine Panda, APT 26, Shell Crew, WebMasters, KungFu Kittens
-
Cobalt Strike (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Cobalt Strike (Malware Family)
-
Ready for Summer: The Sunshop Campaign
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Ready for Summer: The Sunshop Campaign
-
ICIT Brief – China’s Espionage Dynasty: Economic Death by a Thousand Cuts
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor ICIT Brief – China’s Espionage Dynasty: Economic Death by a Thousand Cuts
-
Emissary Panda, APT 27, LuckyMouse, Bronze Union
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Emissary Panda, APT 27, LuckyMouse, Bronze Union
-
Team46 and TaxOff: two sides of the same coin
The original link failed its last check. Original publisher Detailsfor Team46 and TaxOff: two sides of the same coin
-
Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausge…
The title opens archive.today, not the publisher’s page. Archived copy on ORKL Detailsfor Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausge…
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Dark Pink APT unleashes malware for deeper and more sinister intrusions in the Asia-Pacific and Europe _ Group-IB Blog
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Modern Asia APT groups TTPs
-
Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
The original link failed its last check. Original publisher Detailsfor Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
MustangPanda%20-%20Enemy%20at%20the%20gate_final.pdf
The original link failed its last check. Original publisher Detailsfor MustangPanda%20-%20Enemy%20at%20the%20gate_final.pdf
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Continued cyber activity in Eastern Europe observed by TAG
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Continued cyber activity in Eastern Europe observed by TAG
-
Russian Ransomware C2 Network Discovered in Censys Data
The original link failed its last check. Original publisher Detailsfor Russian Ransomware C2 Network Discovered in Censys Data
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Chinese Hackers Target VMware Horizon Servers with Log4Shell to Deploy Rootkit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Hackers Target VMware Horizon Servers with Log4Shell to Deploy Rootkit
-
Legitimate Sites used as Cobalt Strike C2s against Indian Government
The original link failed its last check. Original publisher Detailsfor Legitimate Sites used as Cobalt Strike C2s against Indian Government
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor 2021trends.pdf
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
VMware Exposing Malware In Linux Based Multi Cloud Environments
The original link failed its last check. Original publisher Detailsfor VMware Exposing Malware In Linux Based Multi Cloud Environments
-
Patchwork_Patchwork-APT-caught-in-its-own-web_MalwarebytesLabs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Patchwork_Patchwork-APT-caught-in-its-own-web_MalwarebytesLabs
-
Winnti is Coming - Evolution after Prosecution@HITCON2021
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Winnti is Coming - Evolution after Prosecution@HITCON2021
-
sneak-peek-ch1-2-finding-beacons-in-the-dark.pdf
The original link failed its last check. Original publisher Detailsfor sneak-peek-ch1-2-finding-beacons-in-the-dark.pdf
-
Masters of Mimicry: new APT group ChamelGang and its arsenal
The original link failed its last check. Original publisher Detailsfor Masters of Mimicry: new APT group ChamelGang and its arsenal
-
Masters of Mimicry: new APT group ChamelGang and its arsenal
The original link failed its last check. Original publisher Detailsfor Masters of Mimicry: new APT group ChamelGang and its arsenal
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
IISerpent- Malware‑driven SEO fraud as a service
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor IISerpent- Malware‑driven SEO fraud as a service
-
APT Cobalt Strike Campaign targeting Slovakia (DEF CON talk)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Cobalt Strike Campaign targeting Slovakia (DEF CON talk)
-
report-old-dogs-new-tricks.pdf
The original link failed its last check. Original publisher Detailsfor report-old-dogs-new-tricks.pdf
-
Ryuk Ransomware Now Targeting Webservers
The original link failed its last check. Original publisher Detailsfor Ryuk Ransomware Now Targeting Webservers
-
Looks like the page you're looking for doesn't exist or has moved.
The original link failed its last check. Original publisher Detailsfor Looks like the page you're looking for doesn't exist or has moved.
-
Mustang Panda PlugX - 45.251.240.55 Pivot
The original link failed its last check. Original publisher Detailsfor Mustang Panda PlugX - 45.251.240.55 Pivot
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CTIR_casestudy_2.pdf
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CTIR_casestudy_1.pdf
-
the-operations-of-winnti-group.pdf
The original link failed its last check. Original publisher Detailsfor the-operations-of-winnti-group.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor mtrends-2021
-
report-bb-2021-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor report-bb-2021-threat-report.pdf
-
Technical Analysis of Operation Diànxùn
The original link failed its last check. Original publisher Detailsfor Technical Analysis of Operation Diànxùn
-
How China’s Devastating Microsoft Hack Puts Us All at Risk
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How China’s Devastating Microsoft Hack Puts Us All at Risk
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
Analyzing APT19 malware using a step-by-step method
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analyzing APT19 malware using a step-by-step method
-
Chimera, APT19 under the radar -
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chimera, APT19 under the radar -
-
Alert (AA20-275A)- Potential for China Cyber Response to Heightened U.S.-China Tensions
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (AA20-275A)- Potential for China Cyber Response to Heightened U.S.-China Tensions
-
In-Memory shellcode decoding to evade AVs/EDRs
The original link failed its last check. Original publisher Detailsfor In-Memory shellcode decoding to evade AVs/EDRs
-
SCYTHE Library: #ThreatThursday - Buhtrap
The original link failed its last check. Original publisher Detailsfor SCYTHE Library: #ThreatThursday - Buhtrap
-
Catching APT41 exploiting a zero-day vulnerability
The original link failed its last check. Detailsfor Catching APT41 exploiting a zero-day vulnerability
-
Is APT 27 Abusing COVID-19 To Attack People !
The original link failed its last check. Detailsfor Is APT 27 Abusing COVID-19 To Attack People !
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor mtrends-2020
-
Reviving MuddyC3 Used by MuddyWater (IRAN) APT
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Reviving MuddyC3 Used by MuddyWater (IRAN) APT
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor [CB19] Cyber Threat Landscape in Japan – Revealing Threat in the Shadow by Chi En Shen (Ashley) Oleg Bondarenko
-
The original link failed its last check. Original publisher Detailsfor Aarhus_miniseminar_291118.pdf
-
cds19-executive-s08-achievement-unlocked.pdf
The original link failed its last check. Original publisher Detailsfor cds19-executive-s08-achievement-unlocked.pdf
-
TA2101 plays government imposter to distribute malware to German, Italian, and US organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA2101 plays government imposter to distribute malware to German, Italian, and US organizations
-
The original link failed its last check. Original publisher Detailsfor Analytics
-
BLOG SERIES_Huge Fan of Your Work
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor BLOG SERIES_Huge Fan of Your Work
-
APT41: A Dual Espionage and Cyber Crime Operation
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor APT41: A Dual Espionage and Cyber Crime Operation
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor report_APT41
-
Hunting and detecting Cobalt Strike
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hunting and detecting Cobalt Strike
-
Into the Fog - The Return of ICEFOG APT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Into the Fog - The Return of ICEFOG APT
-
Into the Fog - The Return of ICEFOG APT
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Into the Fog - The Return of ICEFOG APT
-
mpressioncss_ta_report_2019.pdf
The original link failed its last check. Original publisher Detailsfor mpressioncss_ta_report_2019.pdf
-
Operation Red Signature Targets South Korean Companies
The original link failed its last check. Original publisher Detailsfor Operation Red Signature Targets South Korean Companies
-
BSides IR in Heterogeneous Environment
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BSides IR in Heterogeneous Environment
-
Advanced Persistent Threat Groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threat Groups
-
US Arrests Chinese Man Involved With Sakula Malware Used in OPM and Anthem Hacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor US Arrests Chinese Man Involved With Sakula Malware Used in OPM and Anthem Hacks
-
Privileges and Credentials: Phished at the Request of Counsel
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Privileges and Credentials: Phished at the Request of Counsel
-
Privileges and Credentials- Phished at the Request of Counsel
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Privileges and Credentials- Phished at the Request of Counsel
-
Writing PCRE's for applied passive network defense [Emotet]
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Writing PCRE's for applied passive network defense [Emotet]
-
KingSlayer A Supply chain attack
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor KingSlayer A Supply chain attack
-
ICIT-Brief-China-Espionage-Dynasty
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ICIT-Brief-China-Espionage-Dynasty
-
The original link failed its last check. Original publisher Detailsfor security_report_20160613.pdf
-
Turbo Twist: Two 64-bit Derusbi Strains Converge
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Turbo Twist: Two 64-bit Derusbi Strains Converge
-
Ever Present Persistence - Established Footholds Seen in the Wild
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ever Present Persistence - Established Footholds Seen in the Wild
-
Ever Present Persistence - Established Footholds Seen in the Wild
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ever Present Persistence - Established Footholds Seen in the Wild
-
The original link failed its last check. Original publisher Detailsfor rpt-mtrends-2016.pdf
-
New Attacks Linked to C0d0so0 Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Attacks Linked to C0d0so0 Group
-
Trochilus RAT Evades Antivirus Detection, Used for Cyber-Espionage in South-East Asia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Trochilus RAT Evades Antivirus Detection, Used for Cyber-Espionage in South-East Asia
-
Cyber war in perspective: Russian aggression against Ukraine
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Cyber war in perspective: Russian aggression against Ukraine
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Без названия
-
Uncovering the Seven Pointed Dagger
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Uncovering the Seven Pointed Dagger
-
Hammertoss: Stealthy Tactics Define A Russian Cyber Threat Group
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Hammertoss: Stealthy Tactics Define A Russian Cyber Threat Group
-
The original link failed its last check. Original publisher Detailsfor rpt-apt29-hammertoss.pdf
-
Microsoft Word - 2015-02-XX -Scanbox II - TLPWHITE.docx
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Word - 2015-02-XX -Scanbox II - TLPWHITE.docx
-
Aided Frame, Aided Direction (Because it’s a redirect) | FireEye Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Aided Frame, Aided Direction (Because it’s a redirect) | FireEye Blog
-
Supply Chain Analysis: From Quartermaster To Sunshopfireeye
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Supply Chain Analysis: From Quartermaster To Sunshopfireeye
-
SonicALERT: CVE 2014-0322 Malware - Sakurel (Feb 21, 2014)
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor SonicALERT: CVE 2014-0322 Malware - Sakurel (Feb 21, 2014)
-
The Chinese Malware Complexes: The Maudi Surveillance Operation
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Chinese Malware Complexes: The Maudi Surveillance Operation
-
CrowdCasts Monthly- You Have an Adversary Problem
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CrowdCasts Monthly- You Have an Adversary Problem
-
CrowdCasts Monthly: You Have an Adversary Problem
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CrowdCasts Monthly: You Have an Adversary Problem
-
BKDR_RARSTONE: New RAT to Watch Out For - TrendLabs Security Intelligence Blog
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor BKDR_RARSTONE: New RAT to Watch Out For - TrendLabs Security Intelligence Blog
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iexpl0Re Rat
-
Alleged Apt Intrusion Set: 1.Php Group
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Alleged Apt Intrusion Set: 1.Php Group
Newest first. Details opens the report in Explore.