TA505
Also reported as Spandex Tempest, Hive0065, DEV-0950, Lace Tempest, CHIMBORAZO and 21 other names. Linked to Russia by three sources.
Reports per quarter
Techniques seen in the last two years
- T1041 2 reports reports only
- T1059.001 2 reports in ATT&CK
- T1071.001 2 reports in ATT&CK
- T1082 2 reports reports only
- T1218.011 2 reports in ATT&CK
- T1005 1 report reports only
- T1012 1 report reports only
- T1018 1 report reports only
- T1021.002 1 report reports only
- T1027.013 1 report in ATT&CK
Show all 46 techniques Show fewer
- T1036 1 report reports only
- T1036.007 1 report reports only
- T1053.005 1 report reports only
- T1055 1 report reports only
- T1059 1 report reports only
- T1059.003 1 report in ATT&CK
- T1068 1 report reports only
- T1070 1 report reports only
- T1071 1 report reports only
- T1102 1 report reports only
- T1105 1 report in ATT&CK
- T1113 1 report reports only
- T1114 1 report reports only
- T1129 1 report reports only
- T1190 1 report reports only
- T1204 1 report reports only
- T1204.002 1 report in ATT&CK
- T1218.010 1 report reports only
- T1219 1 report reports only
- T1482 1 report reports only
- T1505.003 1 report reports only
- T1518 1 report reports only
- T1537 1 report reports only
- T1539 1 report reports only
- T1546 1 report reports only
- T1546.011 1 report reports only
- T1547.001 1 report reports only
- T1552 1 report reports only
- T1553 1 report reports only
- T1555 1 report reports only
- T1560.001 1 report reports only
- T1563.002 1 report reports only
- T1566 1 report reports only
- T1566.001 1 report in ATT&CK
- T1566.002 1 report in ATT&CK
- T1574.001 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2007-5633
- CVE-2008-2463
- CVE-2009-0824
- CVE-2009-0927 KEV
- CVE-2009-3129 KEV
- CVE-2010-0188 KEV ransomware
- CVE-2010-0232 KEV
- CVE-2010-0249 KEV
- CVE-2010-0738 KEV ransomware
- CVE-2010-1592
- CVE-2010-3333 KEV
- CVE-2010-4398 KEV
Show all 490 CVEs Show fewer
- CVE-2011-0609 KEV
- CVE-2011-0611 KEV
- CVE-2011-1255
- CVE-2011-2005 KEV
- CVE-2011-2110
- CVE-2011-3544 KEV
- CVE-2011-4369
- CVE-2012-0158 KEV ransomware
- CVE-2012-0422
- CVE-2012-0507 KEV ransomware
- CVE-2012-0779
- CVE-2012-1535 KEV
- CVE-2012-1723 KEV ransomware
- CVE-2012-1856 KEV
- CVE-2012-1875
- CVE-2012-1889 KEV
- CVE-2012-4681 KEV ransomware
- CVE-2012-4792 KEV
- CVE-2012-5687
- CVE-2013-0074 KEV ransomware
- CVE-2013-0422 KEV ransomware
- CVE-2013-0640 KEV
- CVE-2013-0808
- CVE-2013-1331 KEV
- CVE-2013-1347 KEV
- CVE-2013-1493
- CVE-2013-2551 KEV ransomware
- CVE-2013-2618
- CVE-2013-2729 KEV
- CVE-2013-3346 KEV
- CVE-2013-3660 KEV
- CVE-2013-3893 KEV
- CVE-2013-3897 KEV
- CVE-2013-3906 KEV
- CVE-2013-4979
- CVE-2013-5065 KEV
- CVE-2013-5947
- CVE-2013-7331 KEV
- CVE-2014-0322 KEV
- CVE-2014-0497 KEV
- CVE-2014-0515
- CVE-2014-1225
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-4076
- CVE-2014-4113 KEV
- CVE-2014-4114 KEV
- CVE-2014-6332 KEV
- CVE-2014-6352 KEV
- CVE-2014-8361 KEV
- CVE-2014-8439 KEV
- CVE-2014-9583
- CVE-2015-0057
- CVE-2015-0313 KEV
- CVE-2015-0554
- CVE-2015-1641 KEV
- CVE-2015-1642 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-1805
- CVE-2015-2387 KEV
- CVE-2015-2419 KEV
- CVE-2015-2424 KEV
- CVE-2015-2545 KEV
- CVE-2015-2546 KEV ransomware
- CVE-2015-2590 KEV
- CVE-2015-3043 KEV
- CVE-2015-3105
- CVE-2015-4902 KEV
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-6585
- CVE-2015-7248
- CVE-2015-7254
- CVE-2015-7645 KEV ransomware
- CVE-2015-7755 KEV
- CVE-2015-8651 KEV
- CVE-2016-0034 KEV ransomware
- CVE-2016-0099 KEV ransomware
- CVE-2016-0147
- CVE-2016-0167 KEV ransomware
- CVE-2016-0189 KEV ransomware
- CVE-2016-0984 KEV
- CVE-2016-1010 KEV
- CVE-2016-1019 KEV ransomware
- CVE-2016-10401
- CVE-2016-3353
- CVE-2016-4117 KEV ransomware
- CVE-2016-4119
- CVE-2016-4171 KEV
- CVE-2016-7255 KEV ransomware
- CVE-2016-7855 KEV
- CVE-2017-0143 KEV ransomware
- CVE-2017-0144 KEV ransomware
- CVE-2017-0146 KEV ransomware
- CVE-2017-0147 KEV ransomware
- CVE-2017-0176
- CVE-2017-0199 KEV ransomware
- CVE-2017-01992
- CVE-2017-01996
- CVE-2017-0213 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-1000353 KEV
- CVE-2017-10271 KEV ransomware
- CVE-2017-11292 KEV
- CVE-2017-11317 KEV
- CVE-2017-11357 KEV ransomware
- CVE-2017-11467
- CVE-2017-11774 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2017-118827
- CVE-2017-12629
- CVE-2017-12824
- CVE-2017-15399
- CVE-2017-17215
- CVE-2017-3197
- CVE-2017-5638 KEV ransomware
- CVE-2017-7269 KEV
- CVE-2017-8291 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2017-9248 KEV
- CVE-2017-9822 KEV ransomware
- CVE-2018-0101
- CVE-2018-0171 KEV
- CVE-2018-0296 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-10088
- CVE-2018-10561 KEV
- CVE-2018-10562 KEV ransomware
- CVE-2018-11776 KEV
- CVE-2018-13374 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-14847 KEV
- CVE-2018-15454
- CVE-2018-15961 KEV
- CVE-2018-20250 KEV ransomware
- CVE-2018-2025036
- CVE-2018-2628 KEV
- CVE-2018-2893
- CVE-2018-4878 KEV ransomware
- CVE-2018-5002 KEV
- CVE-2018-6055
- CVE-2018-7600 KEV ransomware
- CVE-2018-7602 KEV ransomware
- CVE-2018-8120 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8373 KEV
- CVE-2018-8453 KEV ransomware
- CVE-2018-8589 KEV
- CVE-2018-8611 KEV
- CVE-2018-9866
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0752 KEV ransomware
- CVE-2019-0797 KEV
- CVE-2019-0808 KEV
- CVE-2019-0859 KEV ransomware
- CVE-2019-11043 KEV ransomware
- CVE-2019-1132 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-11707 KEV
- CVE-2019-11708 KEV
- CVE-2019-1181
- CVE-2019-1182
- CVE-2019-1367 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-1458 KEV ransomware
- CVE-2019-1653 KEV
- CVE-2019-16759 KEV
- CVE-2019-17026 KEV
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-2215 KEV
- CVE-2019-2725 KEV ransomware
- CVE-2019-3568 KEV
- CVE-2019-5786 KEV
- CVE-2019-5840
- CVE-2019-6225
- CVE-2019-7286 KEV
- CVE-2019-7287 KEV
- CVE-2019-7609 KEV
- CVE-2019-8518
- CVE-2019-9670 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-11899 KEV
- CVE-2020-12061
- CVE-2020-14002
- CVE-2020-1472 KEV ransomware
- CVE-2020-14871 KEV
- CVE-2020-14882 KEV
- CVE-2020-15505 KEV
- CVE-2020-1631 KEV
- CVE-2020-1664
- CVE-2020-17144 KEV
- CVE-2020-2021 KEV ransomware
- CVE-2020-4006 KEV
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-7961 KEV
- CVE-2020-8243 KEV
- CVE-2020-8260 KEV
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-20016 KEV ransomware
- CVE-2021-207103
- CVE-2021-21972 KEV ransomware
- CVE-2021-21974
- CVE-2021-22894 KEV
- CVE-2021-22899 KEV
- CVE-2021-22900 KEV
- CVE-2021-22986 KEV ransomware
- CVE-2021-26411 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-2710
- CVE-2021-27101 KEV ransomware
- CVE-2021-27102 KEV ransomware
- CVE-2021-27103 KEV ransomware
- CVE-2021-27104 KEV ransomware
- CVE-2021-30116 KEV ransomware
- CVE-2021-31207 KEV ransomware
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-36934 KEV
- CVE-2021-40444 KEV ransomware
- CVE-2021-40449 KEV ransomware
- CVE-2021-41379 KEV ransomware
- CVE-2021-41773 KEV ransomware
- CVE-2021-42278 KEV ransomware
- CVE-2021-42287 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-1388 KEV ransomware
- CVE-2022-21587 KEV ransomware
- CVE-2022-21919 KEV
- CVE-2022-22954 KEV ransomware
- CVE-2022-22960 KEV
- CVE-2022-22972
- CVE-2022-27924 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-31199 KEV ransomware
- CVE-2022-35420
- CVE-2022-47986 KEV ransomware
- CVE-2022-4980
- CVE-2023-0669 KEV ransomware
- CVE-2023-20198 KEV
- CVE-2023-22518 KEV ransomware
- CVE-2023-23397 KEV
- CVE-2023-24362
- CVE-2023-27350 KEV ransomware
- CVE-2023-27351 KEV ransomware
- CVE-2023-2868 KEV
- CVE-2023-34362 KEV ransomware
- CVE-2023-35036
- CVE-2023-3519 KEV ransomware
- CVE-2023-36033 KEV
- CVE-2023-42793 KEV ransomware
- CVE-2023-46604 KEV ransomware
- CVE-2023-46805 KEV ransomware
- CVE-2023-47246 KEV ransomware
- CVE-2023-4966 KEV ransomware
- CVE-2024-13789
- CVE-2024-14007
- CVE-2024-1708 KEV ransomware
- CVE-2024-1709 KEV ransomware
- CVE-2024-21887 KEV ransomware
- CVE-2024-26169 KEV ransomware
- CVE-2024-27198 KEV ransomware
- CVE-2024-40890 KEV
- CVE-2024-40891 KEV
- CVE-2024-4577 KEV ransomware
- CVE-2024-50664
- CVE-2024-55591 KEV ransomware
- CVE-2024-56196
- CVE-2024-57811
- CVE-2024-58274
- CVE-2024-8266
- CVE-2024-8420
- CVE-2025-0108 KEV
- CVE-2025-10035 KEV ransomware
- CVE-2025-10159
- CVE-2025-11833
- CVE-2025-11953 KEV
- CVE-2025-12686
- CVE-2025-1393
- CVE-2025-14087
- CVE-2025-14174 KEV
- CVE-2025-14847 KEV
- CVE-2025-1496
- CVE-2025-1539
- CVE-2025-1974
- CVE-2025-1980
- CVE-2025-2000
- CVE-2025-20156
- CVE-2025-20188
- CVE-2025-20289
- CVE-2025-20333 KEV
- CVE-2025-20354
- CVE-2025-20363
- CVE-2025-20674
- CVE-2025-2071
- CVE-2025-21218
- CVE-2025-21355
- CVE-2025-22224 KEV
- CVE-2025-22372
- CVE-2025-22455
- CVE-2025-22457 KEV ransomware
- CVE-2025-23006 KEV ransomware
- CVE-2025-24085 KEV
- CVE-2025-24201 KEV
- CVE-2025-24288
- CVE-2025-24472 KEV ransomware
- CVE-2025-24522
- CVE-2025-24990 KEV
- CVE-2025-25181 KEV
- CVE-2025-25256
- CVE-2025-26613
- CVE-2025-27007
- CVE-2025-27135
- CVE-2025-27140
- CVE-2025-27223
- CVE-2025-27224
- CVE-2025-27363 KEV
- CVE-2025-27364
- CVE-2025-2746 KEV
- CVE-2025-27554
- CVE-2025-27636
- CVE-2025-27690
- CVE-2025-27781
- CVE-2025-27797
- CVE-2025-27819
- CVE-2025-2783 KEV
- CVE-2025-2787
- CVE-2025-29891
- CVE-2025-29913
- CVE-2025-29927
- CVE-2025-29972
- CVE-2025-3015
- CVE-2025-30216
- CVE-2025-30259
- CVE-2025-30356
- CVE-2025-31129
- CVE-2025-31201 KEV
- CVE-2025-31324 KEV ransomware
- CVE-2025-32068
- CVE-2025-32375
- CVE-2025-32432 KEV
- CVE-2025-32433 KEV
- CVE-2025-32444
- CVE-2025-32445
- CVE-2025-3248 KEV ransomware
- CVE-2025-32819
- CVE-2025-32992
- CVE-2025-33053 KEV
- CVE-2025-33222
- CVE-2025-33223
- CVE-2025-34027
- CVE-2025-34036
- CVE-2025-34044
- CVE-2025-34046
- CVE-2025-34143
- CVE-2025-34153
- CVE-2025-34159
- CVE-2025-34222
- CVE-2025-34224
- CVE-2025-3495
- CVE-2025-36250
- CVE-2025-3699
- CVE-2025-39247
- CVE-2025-40765
- CVE-2025-41244 KEV
- CVE-2025-41430
- CVE-2025-41651
- CVE-2025-41680
- CVE-2025-41723
- CVE-2025-42599 KEV
- CVE-2025-43200 KEV
- CVE-2025-43300 KEV
- CVE-2025-43529 KEV
- CVE-2025-43858
- CVE-2025-43995
- CVE-2025-46348
- CVE-2025-46811
- CVE-2025-47277
- CVE-2025-47282
- CVE-2025-47646
- CVE-2025-48054
- CVE-2025-48148
- CVE-2025-48926
- CVE-2025-49125
- CVE-2025-49132
- CVE-2025-49136
- CVE-2025-49844
- CVE-2025-50201
- CVE-2025-50454
- CVE-2025-51495
- CVE-2025-52166
- CVE-2025-52452
- CVE-2025-52906
- CVE-2025-5353
- CVE-2025-53770 KEV ransomware
- CVE-2025-53771
- CVE-2025-53942
- CVE-2025-54122
- CVE-2025-5419 KEV
- CVE-2025-54309 KEV
- CVE-2025-54347
- CVE-2025-54875
- CVE-2025-54964
- CVE-2025-55150
- CVE-2025-55182 KEV ransomware
- CVE-2025-55190
- CVE-2025-55727
- CVE-2025-55728
- CVE-2025-55796
- CVE-2025-5597
- CVE-2025-5622
- CVE-2025-57819 KEV
- CVE-2025-57870
- CVE-2025-58048
- CVE-2025-58159
- CVE-2025-58321
- CVE-2025-58366
- CVE-2025-58367
- CVE-2025-58371
- CVE-2025-59118
- CVE-2025-59230 KEV
- CVE-2025-59346
- CVE-2025-59366
- CVE-2025-59503
- CVE-2025-59718 KEV
- CVE-2025-59719
- CVE-2025-60854
- CVE-2025-61882 KEV ransomware
- CVE-2025-61884 KEV ransomware
- CVE-2025-61928
- CVE-2025-61932 KEV
- CVE-2025-62168
- CVE-2025-6222
- CVE-2025-62221 KEV
- CVE-2025-62645
- CVE-2025-62703
- CVE-2025-62713
- CVE-2025-64095
- CVE-2025-64400
- CVE-2025-64428
- CVE-2025-64446 KEV
- CVE-2025-65018
- CVE-2025-6543 KEV
- CVE-2025-6558 KEV
- CVE-2025-66399
- CVE-2025-66516
- CVE-2025-68613 KEV
- CVE-2025-7426
- CVE-2025-7503
- CVE-2025-7775 KEV
- CVE-2025-8110 KEV
- CVE-2025-8424
- CVE-2025-8857
- CVE-2025-8875 KEV
- CVE-2025-8876 KEV
- CVE-2025-9900
- CVE-2026-1731 KEV ransomware
- CVE-2026-20127 KEV
- CVE-2026-21236
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
TA505 Continues to Infect Networks With SDBbot RAT
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor TA505 Continues to Infect Networks With SDBbot RAT
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Amadey (Malware Family)
Show all 639 reports Show fewer
-
Monty Spider - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Monty Spider - Threat Group Cards: A Threat Actor Encyclopedia
-
GraceWire / FlawedGrace malware adventure
The original link failed its last check. Original publisher Detailsfor GraceWire / FlawedGrace malware adventure
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Gandcrab (Malware Family)
-
The original link failed its last check. Original publisher Detailsfor Binary Defense
-
Indrik Spider - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Indrik Spider - Threat Group Cards: A Threat Actor Encyclopedia
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
Silence, Contract Crew - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Silence, Contract Crew - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor FlawedAmmyy (Malware Family)
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Clop (Malware Family)
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Buhtrap, Ratopak Spider - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Buhtrap, Ratopak Spider - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Dridex (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Triton (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Zeus (Malware Family)
-
Wizard Spider, Gold Blackburn - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Wizard Spider, Gold Blackburn - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Locky (Malware Family)
-
TA505, Graceful Spider, Gold Evergreen
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor TA505, Graceful Spider, Gold Evergreen
-
artik.blue is for sale! Check it out on ExpiredDomains.com
The original link failed its last check. Original publisher Detailsfor artik.blue is for sale! Check it out on ExpiredDomains.com
-
TA505 Uses HTML, RATs, Other Techniques in Campaigns
The original link failed its last check. Original publisher Detailsfor TA505 Uses HTML, RATs, Other Techniques in Campaigns
-
Taming the Storm- Understanding and Mitigating the Consequences of CVE-2023-27350
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Taming the Storm- Understanding and Mitigating the Consequences of CVE-2023-27350
-
Elastic Security Labs discovers the LOBSHOT malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Elastic Security Labs discovers the LOBSHOT malware
-
How Microsoft names threat actors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How Microsoft names threat actors
-
Recent TZW Campaigns Revealed As Part of GlobeImposter Malware Family
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Recent TZW Campaigns Revealed As Part of GlobeImposter Malware Family
-
TrueBot Analysis Part I - A short glimpse into packed TrueBot samples
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TrueBot Analysis Part I - A short glimpse into packed TrueBot samples
-
Investigating Intrusions From Intriguing Exploits
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Investigating Intrusions From Intriguing Exploits
-
Breaking the silence - Recent Truebot activity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Breaking the silence - Recent Truebot activity
-
Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
The original link failed its last check. Original publisher Detailsfor Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
-
GraceWire / FlawedGrace malware adventure
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor GraceWire / FlawedGrace malware adventure
-
LockBit 3.0 Being Distributed via Amadey Bot
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor LockBit 3.0 Being Distributed via Amadey Bot
-
Black Basta Ransomware - Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Black Basta Ransomware - Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor
-
Microsoft links Raspberry Robin worm to Clop ransomware attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft links Raspberry Robin worm to Clop ransomware attacks
-
Raspberry Robin worm part of larger ecosystem facilitating pre-ransomware activity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Raspberry Robin worm part of larger ecosystem facilitating pre-ransomware activity
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Mandiant Red Team Emulates FIN11 Tactics To Control Operational Technology Servers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Mandiant Red Team Emulates FIN11 Tactics To Control Operational Technology Servers
-
Amadey Bot Being Distributed Through SmokeLoader
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Amadey Bot Being Distributed Through SmokeLoader
-
Malware analysis with IDA/Radare2 - Basic Unpacking (Dridex first stage)
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Malware analysis with IDA/Radare2 - Basic Unpacking (Dridex first stage)
-
The hateful eight- Kaspersky’s guide to modern ransomware groups’ TTPs (Download Form)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The hateful eight- Kaspersky’s guide to modern ransomware groups’ TTPs (Download Form)
-
THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
The original link failed its last check. Original publisher Detailsfor THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
-
SocGholish Campaigns and Initial Access Kit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SocGholish Campaigns and Initial Access Kit
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor 2021trends.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware Spotlight- Clop
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Annual Threat trends 2021
-
TrickBot gang template-based metaprogramming Bazar malware
The original link failed its last check. Original publisher Detailsfor TrickBot gang template-based metaprogramming Bazar malware
-
Log4j Exploit Hits Again- Vulnerable Unifi Network Application (Ubiquiti) at Risk
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Log4j Exploit Hits Again- Vulnerable Unifi Network Application (Ubiquiti) at Risk
-
Microsoft Word - DiavolFLASH Approved FINAL 01192022
The original link failed its last check. Original publisher Detailsfor Microsoft Word - DiavolFLASH Approved FINAL 01192022
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware Headliners- Dridex
-
Tracking a P2P network related to TA505
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tracking a P2P network related to TA505
-
Dridex Trojan - Defeating Anti-Analysis - Strings Decryption - C&C Extraction
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Dridex Trojan - Defeating Anti-Analysis - Strings Decryption - C&C Extraction
-
FINDING BEACONS IN THE DARK 1650728751599
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor FINDING BEACONS IN THE DARK 1650728751599
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor TA505 exploits SolarWinds Serv-U vulnerability (CVE-2021-35211) for initial access – NCC Group Research
-
TA505 exploits SolarWinds Serv-U vulnerability (CVE-2021-35211) for initial access
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA505 exploits SolarWinds Serv-U vulnerability (CVE-2021-35211) for initial access
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Stopping GRACEFUL SPIDER- Falcon Complete’s Fast Response to Recent SolarWinds Serv-U Exploit Campaign
-
Whatta TA_ TA505 Ramps Up Activity, Delivers New FlawedGrace Variant _ Proofpoint US
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Whatta TA_ TA505 Ramps Up Activity, Delivers New FlawedGrace Variant _ Proofpoint US
-
Whatta TA- TA505 Ramps Up Activity, Delivers New FlawedGrace Variant
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Whatta TA- TA505 Ramps Up Activity, Delivers New FlawedGrace Variant
-
Explosive New MirrorBlast Campaign Targets Financial Companies
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Explosive New MirrorBlast Campaign Targets Financial Companies
-
TrickBot gang doubles down enterprise infection
The original link failed its last check. Original publisher Detailsfor TrickBot gang doubles down enterprise infection
-
MirrorBlast and TA505- Examining Similarities in Tactics, Techniques and Procedures
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MirrorBlast and TA505- Examining Similarities in Tactics, Techniques and Procedures
-
Big Game Hunting TTPs Continue to Shift After DarkSide Pipeline Attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Big Game Hunting TTPs Continue to Shift After DarkSide Pipeline Attack
-
Signed MSI files, Raccoon and Amadey are used for installing ServHelper RAT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Signed MSI files, Raccoon and Amadey are used for installing ServHelper RAT
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ASEC_REPORT_vol.103_ENG
-
Morgan Stanley reports data breach after vendor Accellion hack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Morgan Stanley reports data breach after vendor Accellion hack
-
TA505 adds GoLang crypter for delivering miners and ServHelper
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA505 adds GoLang crypter for delivering miners and ServHelper
-
Malware Masquerades as Privacy Tool
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware Masquerades as Privacy Tool
-
filedownload.do?attach_file_seq=2808&attach_file_id=EpF2808.pdf
The original link failed its last check. Original publisher Detailsfor filedownload.do?attach_file_seq=2808&attach_file_id=EpF2808.pdf
-
Ukrainian police arrest Clop ransomware members, seize server infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ukrainian police arrest Clop ransomware members, seize server infrastructure
-
The original link failed its last check. Original publisher Detailsfor Intel 471
-
Meet The Ransomware Gang Behind One of the Biggest Supply Chain Hacks Ever
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Meet The Ransomware Gang Behind One of the Biggest Supply Chain Hacks Ever
-
Threat Assessment- Clop Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Assessment- Clop Ransomware
-
PaaS, or how hackers evade antivirus software
The original link failed its last check. Original publisher Detailsfor PaaS, or how hackers evade antivirus software
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor mtrends-2021
-
report-bb-2021-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor report-bb-2021-threat-report.pdf
-
MineBridge Is on the Rise, With a Sophisticated Delivery Mechanism
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MineBridge Is on the Rise, With a Sophisticated Delivery Mechanism
-
The_CrowdStrike_2021_Global_Threat_Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The_CrowdStrike_2021_Global_Threat_Report
-
Return of the MINEBRIDGE RAT With New TTPs and Social Engineering Lures
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Return of the MINEBRIDGE RAT With New TTPs and Social Engineering Lures
-
Cyber Criminals Exploit Accellion FTA for Data Theft and Extortion
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber Criminals Exploit Accellion FTA for Data Theft and Extortion
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Probable Iranian Cyber Actors, Static Kitten, Conducting Cyberespionage Campaign Targeting UAE and Kuwait Government Agencies
-
De ataque con Malware a incidente de Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor De ataque con Malware a incidente de Ransomware
-
research.checkpoint.com-Stopping Serial Killer Catching the Next Strike
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor research.checkpoint.com-Stopping Serial Killer Catching the Next Strike
-
DRIDEX Stopping Serial Killer- Catching the Next Strike
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DRIDEX Stopping Serial Killer- Catching the Next Strike
-
TA505s modified loader means new attack campaign could be coming
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA505s modified loader means new attack campaign could be coming
-
DebUNCing Attribution How Mandiant Tracks Uncategorized Threat Actors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DebUNCing Attribution How Mandiant Tracks Uncategorized Threat Actors
-
Using Qiling Framework to Unpack TA505 packed samples
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Using Qiling Framework to Unpack TA505 packed samples
-
TA505- A Brief History Of Their Time
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA505- A Brief History Of Their Time
-
TA505_ A Brief History Of Their Time – Fox-IT International blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor TA505_ A Brief History Of Their Time – Fox-IT International blog
-
TinyPOS and ProLocker- An Odd Relationship
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TinyPOS and ProLocker- An Odd Relationship
-
FIN11- A Widespread Ransomware and Extortion Operation (Webinar)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FIN11- A Widespread Ransomware and Extortion Operation (Webinar)
-
Leakware-Ransomware-Hybrid Attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Leakware-Ransomware-Hybrid Attacks
-
FIN11- Widespread Email Campaigns as Precursor for Ransomware and Data Theft
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FIN11- Widespread Email Campaigns as Precursor for Ransomware and Data Theft
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Trickbot disrupted
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CVE-2020-1472- Advanced Persistent Threat Actors Use Zerologon Vulnerability In Exploit Chain with Unpatched Vulnerabilities
-
Eager Beaver: A Short Overview of the Restless Threat Actor TA505
The original link failed its last check. Original publisher Detailsfor Eager Beaver: A Short Overview of the Restless Threat Actor TA505
-
TA505 targets the Americas in a new campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA505 targets the Americas in a new campaign
-
Eager Beaver- A Short Overview of the Restless Threat Actor TA505
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Eager Beaver- A Short Overview of the Restless Threat Actor TA505
-
TA505 targets the Americas in a new campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA505 targets the Americas in a new campaign
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Maksim Yakubets
-
What's behind the increase in ransomware attacks this year?
The original link failed its last check. Original publisher Detailsfor What's behind the increase in ransomware attacks this year?
-
Reverse Engineering Dridex and Automating IOC Extraction
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Reverse Engineering Dridex and Automating IOC Extraction
-
Reverse Engineering Dridex and Automating IOC Extraction
The original link failed its last check. Original publisher Detailsfor Reverse Engineering Dridex and Automating IOC Extraction
-
Partners in crime North Koreans and elite Russian-speaking cybercriminals
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Partners in crime North Koreans and elite Russian-speaking cybercriminals
-
Partners in crime_ North Koreans and elite Russian-speaking cybercriminals - Intel 471
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Partners in crime_ North Koreans and elite Russian-speaking cybercriminals - Intel 471
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CERTFR-2020-CTI-009
-
Dridex – From Word to Domain Dominance
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Dridex – From Word to Domain Dominance
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CERTFR-2020-CTI-008
-
Flowspec - TA505s bulletproof hoster of choice
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Flowspec - TA505s bulletproof hoster of choice
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ServHelper- Hidden Miners
-
Clop, Clop! It’s a TA505 HTML malspam analysis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Clop, Clop! It’s a TA505 HTML malspam analysis
-
WastedLocker- A New Ransomware Variant Developed By The Evil Corp Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor WastedLocker- A New Ransomware Variant Developed By The Evil Corp Group
-
WastedLocker_ A New Ransomware Variant Developed By The Evil Corp Group – NCC Group Research
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor WastedLocker_ A New Ransomware Variant Developed By The Evil Corp Group – NCC Group Research
-
TA505 returns with a new bag of tricks
The original link failed its last check. Original publisher Detailsfor TA505 returns with a new bag of tricks
-
TA505 returns with a new bag of tricks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA505 returns with a new bag of tricks
-
Operation TA505- network infrastructure. Part 3.
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation TA505- network infrastructure. Part 3.
-
Operation TA505: network infrastructure. Part 3
The original link failed its last check. Original publisher Detailsfor Operation TA505: network infrastructure. Part 3
-
Operation TA505- investigating the ServHelper backdoor with NetSupport RAT. Part 2.
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation TA505- investigating the ServHelper backdoor with NetSupport RAT. Part 2.
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A brief history of TA505
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation TA505- how we analyzed new tools from the creators of the Dridex trojan, Locky ransomware, and Neutrino botnet
-
The original link failed its last check. Original publisher Detailsfor Operation TA505: how we analyzed new tools from the creators of the Dridex trojan, Locky ransomware, and Neutrino botnet
-
Cybersecurity_ Tool leaks are very interesting occurrences in cyber security. _ Deutsche Telekom
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cybersecurity_ Tool leaks are very interesting occurrences in cyber security. _ Deutsche Telekom
-
TA505 Continues to Infect Networks With SDBbot RAT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA505 Continues to Infect Networks With SDBbot RAT
-
GuLoader delivers RATs and Spies in Disguise
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor GuLoader delivers RATs and Spies in Disguise
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SDBbot Unpacker
-
200407-MWB-COVID-White-Paper_Final
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 200407-MWB-COVID-White-Paper_Final
-
TA505's Box of Chocolate - On Hidden Gems packed with the TA505 Packer
The original link failed its last check. Original publisher Detailsfor TA505's Box of Chocolate - On Hidden Gems packed with the TA505 Packer
-
TA505's Box of Chocolate - On Hidden Gems packed with the TA505 Packer
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA505's Box of Chocolate - On Hidden Gems packed with the TA505 Packer
-
Coronavirus Threat Landscape Update
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Coronavirus Threat Landscape Update
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA505 and Others Launch New Coronavirus Campaigns; Now the Largest Collection of Attack Types in Years
-
cybersecurity-threatscape-2019-q4-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor cybersecurity-threatscape-2019-q4-eng
-
Breaking TA505’s Crypter with an SMT Solver
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Breaking TA505’s Crypter with an SMT Solver
-
Report2020CrowdStrikeGlobalThreatReport
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2020CrowdStrikeGlobalThreatReport
-
Lexfo-WhitePaper-The_Lazarus_Constellation
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Lexfo-WhitePaper-The_Lazarus_Constellation
-
2020.02.22_APT_threat_report_2019_CN_version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2020.02.22_APT_threat_report_2019_CN_version
-
2020_State-of-Malware-Report.pdf
The original link failed its last check. Original publisher Detailsfor 2020_State-of-Malware-Report.pdf
-
TA505 Hackers Behind Maastricht University Ransomware Attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA505 Hackers Behind Maastricht University Ransomware Attack
-
STOMP 2 DIS- Brilliance in the (Visual) Basics
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor STOMP 2 DIS- Brilliance in the (Visual) Basics
-
The original link failed its last check. Original publisher Detailsfor Forensics Report True Hedge
-
BayWorld event, Cyber Attack Against Foreign Trade Industry
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BayWorld event, Cyber Attack Against Foreign Trade Industry
-
Inside of CL0P’s ransomware operation
The original link failed its last check. Original publisher Detailsfor Inside of CL0P’s ransomware operation
-
Inside of CL0P’s ransomware operation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Inside of CL0P’s ransomware operation
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TAFOF Unpacker
-
Threat Spotlight- Amadey Bot Targets Non-Russian Users
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Spotlight- Amadey Bot Targets Non-Russian Users
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Clop ransomware Notes
-
The original link failed its last check. Original publisher Detailsfor Binary Defense
-
An Updated ServHelper Tunnel Variant
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor An Updated ServHelper Tunnel Variant
-
TA505 evolves ServHelper, uses Predator The Thief and Team Viewer Hijacking
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA505 evolves ServHelper, uses Predator The Thief and Team Viewer Hijacking
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor [CB19] Cyber Threat Landscape in Japan – Revealing Threat in the Shadow by Chi En Shen (Ashley) Oleg Bondarenko
-
cybersecurity-threatscape-2019-q3-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor cybersecurity-threatscape-2019-q3-eng
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA505 Get2 Analysis
-
TA-505 Cybercrime on System Integrator Companies
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor TA-505 Cybercrime on System Integrator Companies
-
Shikata Ga Nai Encoder Still Going Strong
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shikata Ga Nai Encoder Still Going Strong
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA505 Timeline
-
TA505 Distributes New SDBbot Remote Access Trojan with Get2 Downloader
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA505 Distributes New SDBbot Remote Access Trojan with Get2 Downloader
-
Analysis of the new TA505 campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis of the new TA505 campaign
-
SectorJ04 Group’s Increased Activity in 2019
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SectorJ04 Group’s Increased Activity in 2019
-
SectorJ04 Group’s Increased Activity in 2019
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor SectorJ04 Group’s Increased Activity in 2019
-
TA505 At It Again_ Variety is the Spice of ServHelper and FlawedAmmyy
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor TA505 At It Again_ Variety is the Spice of ServHelper and FlawedAmmyy
-
TA505: Variety in Use of ServHelper and FlawedAmmyy
The original link failed its last check. Original publisher Detailsfor TA505: Variety in Use of ServHelper and FlawedAmmyy
-
TA505 At It Again- Variety is the Spice of ServHelper and FlawedAmmyy
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA505 At It Again- Variety is the Spice of ServHelper and FlawedAmmyy
-
Trickbot Delivered via Highly Obfuscated JS File
The original link failed its last check. Original publisher Detailsfor Trickbot Delivered via Highly Obfuscated JS File
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Silence 2.0: Going Global
-
The 2019 Resurgence of Smokeloader
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The 2019 Resurgence of Smokeloader
-
Latest Spam Campaigns from TA505 Now Using New Malware Tools Gelup and FlowerPippi
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Latest Spam Campaigns from TA505 Now Using New Malware Tools Gelup and FlowerPippi
-
Latest Spam Campaigns from TA505 Now Using New Malware Tools Gelup and FlowerPippi
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Latest Spam Campaigns from TA505 Now Using New Malware Tools Gelup and FlowerPippi
-
Latest Spam Campaigns from TA505 Now Using New Malware Tools Gelup and FlowerPippi
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Latest Spam Campaigns from TA505 Now Using New Malware Tools Gelup and FlowerPippi
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA505 begins summer campaigns with a new pet malware downloader, AndroMut, in the UAE, South Korea, Singapore, and the United States
-
Threat Group Cards: A Threat Actor Encyclopedia
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
URLZone top malware in Japan, while Emotet and LINE Phishing round out the landscape
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor URLZone top malware in Japan, while Emotet and LINE Phishing round out the landscape
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Inside Cybercrime Groups Harvesting Active Directory for Fun and Profit - Vitali Kremez
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Inside Cybercrime Groups Harvesting Active Directory for Fun and Profit - Vitali Kremez
-
TA505 is Expanding its Operations
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor TA505 is Expanding its Operations
-
TA505 is Expanding its Operations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA505 is Expanding its Operations
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FlawedAmmyy
-
The Stealthy Email Stealer in the TA505 Arsenal
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Stealthy Email Stealer in the TA505 Arsenal
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analyzing Amadey
-
Threat Actor TA505 Targets Financial Enterprises Using LOLBins and a New Backdoor Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Actor TA505 Targets Financial Enterprises Using LOLBins and a New Backdoor Malware
-
CyberInt_Legit Remote Access Tools Turn Into Threat Actors' Tools_Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CyberInt_Legit Remote Access Tools Turn Into Threat Actors' Tools_Report
-
OSINT Reporting Regarding DPRK and TA505 Overlap
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OSINT Reporting Regarding DPRK and TA505 Overlap
-
New ServHelper Variant Employs Excel 4.0 Macro to Drop Signed Payload
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New ServHelper Variant Employs Excel 4.0 Macro to Drop Signed Payload
-
Quick Analysis of a Trickbot Sample with NSA's Ghidra SRE Framework
The original link failed its last check. Original publisher Detailsfor Quick Analysis of a Trickbot Sample with NSA's Ghidra SRE Framework
-
Trickbot Adds Credential-Grabbing Capabilities
The original link failed its last check. Original publisher Detailsfor Trickbot Adds Credential-Grabbing Capabilities
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2018 Master Table
-
TA505 Crime Gang Debuts Brand-New ServHelper Backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA505 Crime Gang Debuts Brand-New ServHelper Backdoor
-
TA505 Group Adopts New ServHelper Backdoor and FlawedGrace RAT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA505 Group Adopts New ServHelper Backdoor and FlawedGrace RAT
-
ServHelper and FlawedGrace - New malware introduced by TA505
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ServHelper and FlawedGrace - New malware introduced by TA505
-
URSNIF, EMOTET, DRIDEX and BitPayme Linked by Loader
The original link failed its last check. Original publisher Detailsfor URSNIF, EMOTET, DRIDEX and BitPayme Linked by Loader
-
tRat- New modular RAT appears in multiple email campaigns
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor tRat- New modular RAT appears in multiple email campaigns
-
Trickbot Shows Off New Trick: Password Grabber Module
The original link failed its last check. Original publisher Detailsfor Trickbot Shows Off New Trick: Password Grabber Module
-
New modular downloaders fingerprint systems, prepare for more - Part 1- Marap
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New modular downloaders fingerprint systems, prepare for more - Part 1- Marap
-
ce44cbda9fdc061050c1d2a5dec0270874a9dc85.pdf
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor ce44cbda9fdc061050c1d2a5dec0270874a9dc85.pdf
-
TA505 Abusing SettingContent-ms within PDF files to Distribute FlawedAmmyy RAT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA505 Abusing SettingContent-ms within PDF files to Distribute FlawedAmmyy RAT
-
New Noteworthy Changes to Necurs’ Behaviors
The original link failed its last check. Original publisher Detailsfor New Noteworthy Changes to Necurs’ Behaviors
-
Necurs Evades Detection via Internet Shortcut File
The original link failed its last check. Original publisher Detailsfor Necurs Evades Detection via Internet Shortcut File
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor BlackTDS
-
Leaked Ammyy Admin Source Code Turned into Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Leaked Ammyy Admin Source Code Turned into Malware
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Holiday lull- Not so much
-
Threat Actor Profile- TA505, From Dridex to GlobeImposter
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Actor Profile- TA505, From Dridex to GlobeImposter
-
return of fake UPS cannot deliver malspam with an updated nemucod ransomware and Kovter payload
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor return of fake UPS cannot deliver malspam with an updated nemucod ransomware and Kovter payload
-
Informe_Evoluci%C3%B3n_Trickbot.pdf
The original link failed its last check. Original publisher Detailsfor Informe_Evoluci%C3%B3n_Trickbot.pdf
-
https://www.trustwave.com/Resources/SpiderLabs-Blog/Necurs-Recurs/
The original link failed its last check. Original publisher Detailsfor https://www.trustwave.com/Resources/SpiderLabs-Blog/Necurs-Recurs/
-
Evolution of the GOLD EVERGREEN Threat Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Evolution of the GOLD EVERGREEN Threat Group
-
TrickBot Banker Insights | NETSCOUT
The original link failed its last check. Original publisher Detailsfor TrickBot Banker Insights | NETSCOUT
Newest first. Details opens the report in Explore.