APT41
Also reported as Brass Typhoon, BARIUM, TG-2633, Leopard Typhoon, Double Dragon and 30 other names. Linked to China by four sources.
Reports per quarter
Techniques seen in the last two years
- T1057 11 reports reports only
- T1059.001 11 reports in ATT&CK
- T1071.001 11 reports in ATT&CK
- T1082 11 reports in ATT&CK
- T1053.005 10 reports in ATT&CK
- T1105 9 reports in ATT&CK
- T1059.003 8 reports in ATT&CK
- T1140 8 reports reports only
- T1204.002 8 reports reports only
- T1566.001 8 reports in ATT&CK
Show all 290 techniques Show fewer
- T1016 6 reports in ATT&CK
- T1027 6 reports in ATT&CK
- T1041 6 reports reports only
- T1055 6 reports in ATT&CK
- T1190 6 reports in ATT&CK
- T1543.003 6 reports in ATT&CK
- T1547.001 6 reports in ATT&CK
- T1003.001 5 reports in ATT&CK
- T1003.002 5 reports in ATT&CK
- T1005 5 reports in ATT&CK
- T1018 5 reports in ATT&CK
- T1068 5 reports reports only
- T1083 5 reports in ATT&CK
- T1087.001 5 reports in ATT&CK
- T1087.002 5 reports in ATT&CK
- T1132.001 5 reports reports only
- T1189 5 reports reports only
- T1482 5 reports reports only
- T1570 5 reports in ATT&CK
- T1572 5 reports reports only
- T1573.001 5 reports reports only
- T1574.001 5 reports in ATT&CK
- T1007 4 reports reports only
- T1012 4 reports in ATT&CK
- T1033 4 reports in ATT&CK
- T1036 4 reports reports only
- T1036.005 4 reports in ATT&CK
- T1046 4 reports in ATT&CK
- T1047 4 reports in ATT&CK
- T1059.005 4 reports reports only
- T1069.002 4 reports reports only
- T1070.004 4 reports in ATT&CK
- T1071 4 reports reports only
- T1090.001 4 reports reports only
- T1095 4 reports reports only
- T1133 4 reports in ATT&CK
- T1135 4 reports in ATT&CK
- T1505.003 4 reports reports only
- T1518.001 4 reports reports only
- T1555.003 4 reports in ATT&CK
- T1560.001 4 reports in ATT&CK
- T1021.001 3 reports in ATT&CK
- T1021.002 3 reports in ATT&CK
- T1027.009 3 reports reports only
- T1049 3 reports in ATT&CK
- T1055.002 3 reports reports only
- T1056.001 3 reports in ATT&CK
- T1059 3 reports reports only
- T1059.007 3 reports reports only
- T1071.004 3 reports in ATT&CK
- T1078 3 reports in ATT&CK
- T1124 3 reports reports only
- T1129 3 reports reports only
- T1136.001 3 reports in ATT&CK
- T1219 3 reports reports only
- T1497.001 3 reports reports only
- T1566 3 reports reports only
- T1566.002 3 reports reports only
- T1569.002 3 reports in ATT&CK
- T1583.001 3 reports reports only
- T1583.003 3 reports reports only
- T1587.001 3 reports reports only
- T1608.001 3 reports reports only
- T1008 2 reports in ATT&CK
- T1037 2 reports in ATT&CK
- T1048 2 reports reports only
- T1053 2 reports reports only
- T1055.004 2 reports reports only
- T1055.009 2 reports reports only
- T1055.012 2 reports reports only
- T1059.006 2 reports reports only
- T1069 2 reports in ATT&CK
- T1069.001 2 reports reports only
- T1072 2 reports reports only
- T1074.001 2 reports reports only
- T1078.002 2 reports reports only
- T1078.003 2 reports reports only
- T1087 2 reports reports only
- T1090 2 reports in ATT&CK
- T1098 2 reports reports only
- T1098.007 2 reports in ATT&CK
- T1102 2 reports reports only
- T1104 2 reports in ATT&CK
- T1113 2 reports reports only
- T1119 2 reports reports only
- T1132 2 reports reports only
- T1134.001 2 reports reports only
- T1136 2 reports reports only
- T1195.001 2 reports reports only
- T1204 2 reports reports only
- T1210 2 reports reports only
- T1217 2 reports reports only
- T1218.007 2 reports reports only
- T1496 2 reports reports only
- T1497 2 reports reports only
- T1505.004 2 reports reports only
- T1548 2 reports reports only
- T1550.002 2 reports in ATT&CK
- T1552.001 2 reports reports only
- T1555 2 reports in ATT&CK
- T1559 2 reports reports only
- T1560 2 reports reports only
- T1564.004 2 reports reports only
- T1566.004 2 reports reports only
- T1567 2 reports reports only
- T1571 2 reports reports only
- T1574 2 reports reports only
- T1583 2 reports reports only
- T1583.004 2 reports reports only
- T1588.002 2 reports in ATT&CK
- T1590 2 reports reports only
- T1595 2 reports reports only
- T1595.002 2 reports in ATT&CK
- T1602 2 reports reports only
- T1608 2 reports reports only
- T1608.002 2 reports reports only
- T1608.006 2 reports reports only
- T1620 2 reports reports only
- T1622 2 reports reports only
- T1649 2 reports reports only
- T1001.003 1 report reports only
- T1003 1 report reports only
- T1003.003 1 report in ATT&CK
- T1010 1 report reports only
- T1014 1 report in ATT&CK
- T1016.001 1 report reports only
- T1020 1 report reports only
- T1021 1 report reports only
- T1021.004 1 report reports only
- T1021.005 1 report reports only
- T1021.006 1 report reports only
- T1027.002 1 report in ATT&CK
- T1036.003 1 report reports only
- T1036.007 1 report reports only
- T1037.001 1 report reports only
- T1039 1 report reports only
- T1040 1 report reports only
- T1053.002 1 report reports only
- T1053.003 1 report reports only
- T1055.001 1 report reports only
- T1055.003 1 report reports only
- T1056 1 report reports only
- T1059.002 1 report reports only
- T1059.004 1 report in ATT&CK
- T1059.009 1 report reports only
- T1059.010 1 report reports only
- T1059.011 1 report reports only
- T1069.003 1 report reports only
- T1070 1 report reports only
- T1070.003 1 report in ATT&CK
- T1074 1 report reports only
- T1074.002 1 report reports only
- T1078.004 1 report reports only
- T1087.004 1 report reports only
- T1090.003 1 report reports only
- T1091 1 report reports only
- T1098.001 1 report reports only
- T1098.003 1 report reports only
- T1098.004 1 report reports only
- T1098.005 1 report reports only
- T1098.006 1 report reports only
- T1102.002 1 report reports only
- T1106 1 report reports only
- T1114 1 report reports only
- T1114.001 1 report reports only
- T1114.002 1 report reports only
- T1114.003 1 report reports only
- T1115 1 report reports only
- T1120 1 report reports only
- T1123 1 report reports only
- T1125 1 report reports only
- T1132.002 1 report reports only
- T1134 1 report reports only
- T1136.002 1 report reports only
- T1137 1 report reports only
- T1137.006 1 report reports only
- T1195 1 report reports only
- T1195.002 1 report in ATT&CK
- T1197 1 report in ATT&CK
- T1199 1 report reports only
- T1200 1 report reports only
- T1201 1 report reports only
- T1203 1 report in ATT&CK
- T1204.001 1 report reports only
- T1204.004 1 report reports only
- T1213 1 report reports only
- T1213.001 1 report reports only
- T1213.002 1 report reports only
- T1213.003 1 report in ATT&CK
- T1218 1 report reports only
- T1218.014 1 report reports only
- T1222 1 report reports only
- T1480.002 1 report reports only
- T1484 1 report reports only
- T1484.001 1 report in ATT&CK
- T1485 1 report reports only
- T1486 1 report in ATT&CK
- T1489 1 report reports only
- T1490 1 report reports only
- T1491.002 1 report reports only
- T1497.003 1 report reports only
- T1498 1 report reports only
- T1505 1 report reports only
- T1518 1 report reports only
- T1528 1 report reports only
- T1529 1 report reports only
- T1530 1 report reports only
- T1534 1 report reports only
- T1537 1 report reports only
- T1538 1 report reports only
- T1543 1 report reports only
- T1543.002 1 report reports only
- T1543.004 1 report reports only
- T1546 1 report reports only
- T1546.003 1 report reports only
- T1546.004 1 report reports only
- T1546.008 1 report in ATT&CK
- T1546.012 1 report reports only
- T1546.015 1 report reports only
- T1547 1 report reports only
- T1547.002 1 report reports only
- T1547.005 1 report reports only
- T1547.009 1 report reports only
- T1548.002 1 report reports only
- T1550 1 report reports only
- T1550.001 1 report reports only
- T1552 1 report reports only
- T1553.002 1 report in ATT&CK
- T1554 1 report reports only
- T1556 1 report reports only
- T1556.002 1 report reports only
- T1556.006 1 report reports only
- T1556.009 1 report reports only
- T1558.003 1 report reports only
- T1560.002 1 report reports only
- T1564.001 1 report reports only
- T1564.010 1 report reports only
- T1565 1 report reports only
- T1565.001 1 report reports only
- T1566.003 1 report reports only
- T1567.001 1 report reports only
- T1567.002 1 report reports only
- T1569 1 report reports only
- T1573 1 report reports only
- T1573.002 1 report reports only
- T1574.011 1 report reports only
- T1578 1 report reports only
- T1580 1 report reports only
- T1583.006 1 report reports only
- T1584 1 report reports only
- T1584.004 1 report reports only
- T1585 1 report reports only
- T1585.002 1 report reports only
- T1586.002 1 report reports only
- T1587 1 report reports only
- T1587.003 1 report reports only
- T1588 1 report reports only
- T1588.003 1 report reports only
- T1588.004 1 report reports only
- T1588.007 1 report reports only
- T1589.002 1 report reports only
- T1590.005 1 report reports only
- T1592 1 report reports only
- T1595.001 1 report reports only
- T1596.005 1 report in ATT&CK
- T1598 1 report reports only
- T1602.001 1 report reports only
- T1602.002 1 report reports only
- T1608.003 1 report reports only
- T1608.004 1 report reports only
- T1608.005 1 report reports only
- T1613 1 report reports only
- T1614 1 report reports only
- T1614.001 1 report reports only
- T1615 1 report reports only
- T1619 1 report reports only
- T1627.001 1 report reports only
- T1652 1 report reports only
- T1654 1 report reports only
- T1657 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2008-2463
- CVE-2008-3431 KEV
- CVE-2010-1424
- CVE-2010-2152
- CVE-2010-3333 KEV
- CVE-2010-3915
- CVE-2010-3916
- CVE-2011-1331
- CVE-2011-2462 KEV
- CVE-2011-3544 KEV
- CVE-2011-4369
- CVE-2012-0151 KEV
Show all 353 CVEs Show fewer
- CVE-2012-0158 KEV ransomware
- CVE-2012-5687
- CVE-2013-0707
- CVE-2013-3163 KEV
- CVE-2013-3644
- CVE-2013-3893 KEV
- CVE-2013-3900 KEV
- CVE-2013-3918 KEV
- CVE-2013-5947
- CVE-2013-5990
- CVE-2014-0322 KEV
- CVE-2014-0515
- CVE-2014-0810
- CVE-2014-1225
- CVE-2014-1812 KEV ransomware
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-4113 KEV
- CVE-2014-4114 KEV
- CVE-2014-4404 KEV
- CVE-2014-6352 KEV
- CVE-2014-7247
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0062
- CVE-2015-0554
- CVE-2015-1130 KEV
- CVE-2015-1635 KEV
- CVE-2015-1641 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-2051 KEV
- CVE-2015-2291 KEV ransomware
- CVE-2015-2545 KEV
- CVE-2015-4852 KEV
- CVE-2015-5119 KEV
- CVE-2015-7248
- CVE-2015-7254
- CVE-2016-0099 KEV ransomware
- CVE-2016-0167 KEV ransomware
- CVE-2016-0545
- CVE-2016-5195 KEV
- CVE-2016-7836 KEV
- CVE-2016-9299
- CVE-2017-0005 KEV
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0213 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-10271 KEV ransomware
- CVE-2017-1099
- CVE-2017-11292 KEV
- CVE-2017-11774 KEV
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-12149 KEV ransomware
- CVE-2017-12824
- CVE-2017-15399
- CVE-2017-15944 KEV
- CVE-2017-18368 KEV
- CVE-2017-5638 KEV ransomware
- CVE-2017-6190
- CVE-2017-6327 KEV
- CVE-2017-6328
- CVE-2017-7269 KEV
- CVE-2017-8291 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2017-9805 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-0824 KEV
- CVE-2018-10562 KEV ransomware
- CVE-2018-11776 KEV
- CVE-2018-1207
- CVE-2018-13379 KEV ransomware
- CVE-2018-13382 KEV ransomware
- CVE-2018-13383 KEV ransomware
- CVE-2018-1579
- CVE-2018-15961 KEV
- CVE-2018-15982 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-4878 KEV ransomware
- CVE-2018-4939 KEV
- CVE-2018-5407
- CVE-2018-5713
- CVE-2018-6789 KEV ransomware
- CVE-2018-7600 KEV ransomware
- CVE-2018-7602 KEV ransomware
- CVE-2018-8120 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8405 KEV ransomware
- CVE-2018-8406 KEV ransomware
- CVE-2018-8440 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2018-8581 KEV ransomware
- CVE-2018-8611 KEV
- CVE-2018-8639 KEV ransomware
- CVE-2018-8872
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0803 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-1040
- CVE-2019-11510 KEV ransomware
- CVE-2019-11539 KEV ransomware
- CVE-2019-11580 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-1458 KEV ransomware
- CVE-2019-15126
- CVE-2019-16098
- CVE-2019-16278 KEV
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-16759 KEV
- CVE-2019-16920 KEV
- CVE-2019-17100
- CVE-2019-18211
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-3369
- CVE-2019-3396 KEV ransomware
- CVE-2019-3398 KEV
- CVE-2019-5591 KEV ransomware
- CVE-2019-8394 KEV
- CVE-2019-9489
- CVE-2019-948919
- CVE-2019-9621 KEV
- CVE-2019-9670 KEV
- CVE-2020-0601 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0787 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10148 KEV
- CVE-2020-10189 KEV
- CVE-2020-10198
- CVE-2020-1040 KEV
- CVE-2020-116511
- CVE-2020-11652 KEV
- CVE-2020-11899 KEV
- CVE-2020-12641 KEV
- CVE-2020-12812 KEV ransomware
- CVE-2020-1350 KEV
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-14750 KEV
- CVE-2020-14882 KEV
- CVE-2020-15505 KEV
- CVE-2020-15782
- CVE-2020-1599
- CVE-2020-1664
- CVE-2020-17530 KEV
- CVE-2020-2021 KEV ransomware
- CVE-2020-2551 KEV
- CVE-2020-2555 KEV
- CVE-2020-3118 KEV
- CVE-2020-3125
- CVE-2020-3529
- CVE-2020-35730 KEV
- CVE-2020-36239
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-6789
- CVE-2020-7961 KEV
- CVE-2020-8193 KEV
- CVE-2020-8195 KEV
- CVE-2020-8196 KEV
- CVE-2020-8243 KEV
- CVE-2020-8260 KEV
- CVE-2020-8468 KEV
- CVE-2020-846820
- CVE-2020-8515 KEV
- CVE-2021-1636
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-1844
- CVE-2021-1879 KEV
- CVE-2021-20016 KEV ransomware
- CVE-2021-20021 KEV ransomware
- CVE-2021-20022 KEV ransomware
- CVE-2021-20023 KEV ransomware
- CVE-2021-21166 KEV
- CVE-2021-21551 KEV
- CVE-2021-21974
- CVE-2021-21985 KEV ransomware
- CVE-2021-22555 KEV
- CVE-2021-22893 KEV ransomware
- CVE-2021-22894 KEV
- CVE-2021-22899 KEV
- CVE-2021-22900 KEV
- CVE-2021-22941 KEV ransomware
- CVE-2021-26084 KEV ransomware
- CVE-2021-26411 KEV ransomware
- CVE-2021-26605
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-26868
- CVE-2021-27065 KEV ransomware
- CVE-2021-27101 KEV ransomware
- CVE-2021-27102 KEV ransomware
- CVE-2021-27103 KEV ransomware
- CVE-2021-27104 KEV ransomware
- CVE-2021-27857
- CVE-2021-28310 KEV
- CVE-2021-28474
- CVE-2021-29855
- CVE-2021-30116 KEV ransomware
- CVE-2021-30551 KEV
- CVE-2021-31195
- CVE-2021-31196 KEV
- CVE-2021-31206
- CVE-2021-31207 KEV ransomware
- CVE-2021-3156 KEV
- CVE-2021-31805
- CVE-2021-33742 KEV
- CVE-2021-33766 KEV
- CVE-2021-34473 KEV ransomware
- CVE-2021-34481
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-35394 KEV
- CVE-2021-36798
- CVE-2021-36934 KEV
- CVE-2021-36942 KEV ransomware
- CVE-2021-36958
- CVE-2021-38001
- CVE-2021-38647 KEV ransomware
- CVE-2021-4034 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-40449 KEV ransomware
- CVE-2021-40539 KEV ransomware
- CVE-2021-4104
- CVE-2021-41379 KEV ransomware
- CVE-2021-42321 KEV ransomware
- CVE-2021-44026 KEV
- CVE-2021-44077 KEV
- CVE-2021-44207 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-44515 KEV
- CVE-2021-44832
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-1040 KEV
- CVE-2022-1388 KEV ransomware
- CVE-2022-21587 KEV ransomware
- CVE-2022-21882 KEV ransomware
- CVE-2022-21919 KEV
- CVE-2022-22948 KEV
- CVE-2022-22954 KEV ransomware
- CVE-2022-22957
- CVE-2022-22958
- CVE-2022-22960 KEV
- CVE-2022-22963 KEV
- CVE-2022-22965 KEV
- CVE-2022-22972
- CVE-2022-24500
- CVE-2022-24521 KEV ransomware
- CVE-2022-24682 KEV ransomware
- CVE-2022-24934
- CVE-2022-26134 KEV ransomware
- CVE-2022-26138 KEV
- CVE-2022-26352 KEV ransomware
- CVE-2022-26809
- CVE-2022-26923 KEV
- CVE-2022-27518 KEV
- CVE-2022-27924 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-29464 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-30333 KEV ransomware
- CVE-2022-31199 KEV ransomware
- CVE-2022-34305
- CVE-2022-37042 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41080 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-41328 KEV
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2022-49475
- CVE-2023-0669 KEV ransomware
- CVE-2023-20198 KEV
- CVE-2023-20867 KEV
- CVE-2023-21746
- CVE-2023-23397 KEV
- CVE-2023-27350 KEV ransomware
- CVE-2023-27532 KEV ransomware
- CVE-2023-27997 KEV ransomware
- CVE-2023-28461 KEV ransomware
- CVE-2023-2868 KEV
- CVE-2023-32315 KEV
- CVE-2023-34048 KEV
- CVE-2023-34362 KEV ransomware
- CVE-2023-3466
- CVE-2023-3467
- CVE-2023-3519 KEV ransomware
- CVE-2023-36033 KEV
- CVE-2023-38831 KEV ransomware
- CVE-2023-42793 KEV ransomware
- CVE-2023-45727 KEV
- CVE-2023-46747 KEV ransomware
- CVE-2023-46805 KEV ransomware
- CVE-2023-48788 KEV ransomware
- CVE-2023-4966 KEV ransomware
- CVE-2024-0012 KEV ransomware
- CVE-2024-1709 KEV ransomware
- CVE-2024-21887 KEV ransomware
- CVE-2024-21893 KEV ransomware
- CVE-2024-21983
- CVE-2024-23108
- CVE-2024-23109
- CVE-2024-24919 KEV ransomware
- CVE-2024-27956
- CVE-2024-30051 KEV ransomware
- CVE-2024-3400 KEV ransomware
- CVE-2024-36401 KEV
- CVE-2024-42009 KEV
- CVE-2024-4577 KEV ransomware
- CVE-2024-47575 KEV
- CVE-2024-6473
- CVE-2024-8190 KEV
- CVE-2024-8963 KEV
- CVE-2024-9379 KEV
- CVE-2024-9380 KEV
- CVE-2024-9381
- CVE-2024-9474 KEV ransomware
- CVE-2025-2783 KEV
- CVE-2025-31324 KEV ransomware
- CVE-2025-49704 KEV ransomware
- CVE-2025-49706 KEV ransomware
- CVE-2025-53770 KEV ransomware
- CVE-2025-53771
- CVE-2025-55182 KEV ransomware
- CVE-2025-8088 KEV ransomware
- CVE-2026-21236
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Bankshot (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor StoneDrill (Malware Family)
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor ShadowPad (Malware Family)
Show all 1,151 reports Show fewer
-
Earth Lusca - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Earth Lusca - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Crimson RAT (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ghost RAT (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Oblique RAT (Malware Family)
-
ShadowPad: new activity from the Winnti group
The original link failed its last check. Original publisher Detailsfor ShadowPad: new activity from the Winnti group
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor METALJACK (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor elf.wellmess (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor SUNBURST (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CHINACHOPPER (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor QakBot (Malware Family)
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor REvil (Malware Family)
-
APT 41 - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor APT 41 - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor MimiKatz (Malware Family)
-
Axiom, Group 72 - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Axiom, Group 72 - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor ZXShell (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PlugX (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PowGoop (Malware Family)
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor NjRAT (Malware Family)
-
Cobalt Strike (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Cobalt Strike (Malware Family)
-
Winnti Group, Wicked Panda - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Winnti Group, Wicked Panda - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ryuk (Malware Family)
-
Team46 and TaxOff: two sides of the same coin
The original link failed its last check. Original publisher Detailsfor Team46 and TaxOff: two sides of the same coin
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor MoonWalk | ThreatLabz
-
APT41 Has Arisen From the DUST | Google Cloud Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT41 Has Arisen From the DUST | Google Cloud Blog
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor DodgeBox | ThreatLabz
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor i-soon-data-leaks-jp
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor i-soon-data-leaks-en
-
Uncovering an undetected KeyPlug implant attacking industries in Italy - Yoroi
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Uncovering an undetected KeyPlug implant attacking industries in Italy - Yoroi
-
Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausge…
The title opens archive.today, not the publisher’s page. Archived copy on ORKL Detailsfor Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausge…
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Dark Pink APT unleashes malware for deeper and more sinister intrusions in the Asia-Pacific and Europe _ Group-IB Blog
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Modern Asia APT groups TTPs
-
Lancefly- Group Uses Custom Backdoor to Target Orgs in Government, Aviation, Other Sectors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Lancefly- Group Uses Custom Backdoor to Target Orgs in Government, Aviation, Other Sectors
-
Attack on Security Titans- Earth Longzhi Returns With New Tricks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attack on Security Titans- Earth Longzhi Returns With New Tricks
-
Daggerfly- APT Actor Targets Telecoms Company in Africa
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Daggerfly- APT Actor Targets Telecoms Company in Africa
-
How Microsoft names threat actors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How Microsoft names threat actors
-
Mélofée- a new alien malware in the Panda's toolset targeting Linux hosts
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Mélofée- a new alien malware in the Panda's toolset targeting Linux hosts
-
Operation Tainted Love - Chinese APTs Target Telcos in New Attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Tainted Love - Chinese APTs Target Telcos in New Attacks
-
PlugX Malware Being Distributed via Vulnerability Exploitation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor PlugX Malware Being Distributed via Vulnerability Exploitation
-
Blackfly: Espionage Group Targets Materials Technology
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Blackfly: Espionage Group Targets Materials Technology
-
Dark Pink - New APT hitting Asia-Pacific, Europe that goes deeper and darker
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Dark Pink - New APT hitting Asia-Pacific, Europe that goes deeper and darker
-
Dark Pink: New APT hitting Asia-Pacific, Europe that goes deeper and darker
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Dark Pink: New APT hitting Asia-Pacific, Europe that goes deeper and darker
-
Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
The original link failed its last check. Original publisher Detailsfor Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
-
Conceptualizing a Continuum of Cyber Threat Attribution
The original link failed its last check. Original publisher Detailsfor Conceptualizing a Continuum of Cyber Threat Attribution
-
The Rise of Earth Aughisky: Tracking the Campaigns Taidoor Started
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Rise of Earth Aughisky: Tracking the Campaigns Taidoor Started
-
More Than Meets the Eye- Exposing a Polyglot File That Delivers IcedID
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor More Than Meets the Eye- Exposing a Polyglot File That Delivers IcedID
-
You never walk alone- The SideWalk backdoor gets a Linux variant
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor You never walk alone- The SideWalk backdoor gets a Linux variant
-
New Wave of Espionage Activity Targets Asian Governments
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Wave of Espionage Activity Targets Asian Governments
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
MustangPanda%20-%20Enemy%20at%20the%20gate_final.pdf
The original link failed its last check. Original publisher Detailsfor MustangPanda%20-%20Enemy%20at%20the%20gate_final.pdf
-
What to Expect When You’re Electing- Preparing for Cyber Threats to the 2022 U.S. Midterm Elections
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor What to Expect When You’re Electing- Preparing for Cyber Threats to the 2022 U.S. Midterm Elections
-
APT41 World Tour 2021 on a tight schedule
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT41 World Tour 2021 on a tight schedule
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT41- A Case Sudy
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Russian Ransomware C2 Network Discovered in Censys Data
The original link failed its last check. Original publisher Detailsfor Russian Ransomware C2 Network Discovered in Censys Data
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Operation CuckooBees- Deep-Dive into Stealthy Winnti Techniques
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation CuckooBees- Deep-Dive into Stealthy Winnti Techniques
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Gamer Cheater Hacker Spy
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
yir-cyber-threats-report-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-report-download.pdf
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Continued Targeting of Indian Power Grid Assets by Chinese State-Sponsored Activity Group
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Continued Targeting of Indian Power Grid Assets by Chinese State-Sponsored Activity Group
-
APT41 (Double Dragon)- A Dual Espionage and Cyber Crime Operation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT41 (Double Dragon)- A Dual Espionage and Cyber Crime Operation
-
A Summary of APT41 Targeting U.S. State Governments
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor A Summary of APT41 Targeting U.S. State Governments
-
Does This Look Infected- A Summary of APT41 Targeting U.S. State Governments
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Does This Look Infected- A Summary of APT41 Targeting U.S. State Governments
-
Legitimate Sites used as Cobalt Strike C2s against Indian Government
The original link failed its last check. Original publisher Detailsfor Legitimate Sites used as Cobalt Strike C2s against Indian Government
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor 2021trends.pdf
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ShadowPad Malware Analysis
-
Researchers Link ShadowPad Malware Attacks to Chinese Ministry and PLA
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Researchers Link ShadowPad Malware Attacks to Chinese Ministry and PLA
-
ShadowPad Malware Analysis _ Secureworks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ShadowPad Malware Analysis _ Secureworks
-
VMware Exposing Malware In Linux Based Multi Cloud Environments
The original link failed its last check. Original publisher Detailsfor VMware Exposing Malware In Linux Based Multi Cloud Environments
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t32021
-
MoonBounce_ the dark side of UEFI firmware _ Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor MoonBounce_ the dark side of UEFI firmware _ Securelist
-
MoonBounce- the dark side of UEFI firmware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MoonBounce- the dark side of UEFI firmware
-
Delving Deep: An Analysis of Earth Lusca's Operations
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Delving Deep: An Analysis of Earth Lusca's Operations
-
Winnti is Coming - Evolution after Prosecution@HITCON2021
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Winnti is Coming - Evolution after Prosecution@HITCON2021
-
Winnti is Coming - Evolution after Prosecution
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Winnti is Coming - Evolution after Prosecution
-
PseudoManuscrypt- a mass-scale spyware attack campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor PseudoManuscrypt- a mass-scale spyware attack campaign
-
Now You Serial, Now You Don’t — Systematically Hunting for Deserialization Exploits
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Now You Serial, Now You Don’t — Systematically Hunting for Deserialization Exploits
-
Chasing Shadows- A deep dive into the latest obfuscation methods being used by ShadowPad
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chasing Shadows- A deep dive into the latest obfuscation methods being used by ShadowPad
-
It’s a BEE! It’s a… no, it’s ShadowPad.
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor It’s a BEE! It’s a… no, it’s ShadowPad.
-
APT41 Perfects Code Signing Abuse to Escalate Supply Chain Attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT41 Perfects Code Signing Abuse to Escalate Supply Chain Attacks
-
FINDING BEACONS IN THE DARK 1650728751599
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor FINDING BEACONS IN THE DARK 1650728751599
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q3 2021
-
sneak-peek-ch1-2-finding-beacons-in-the-dark.pdf
The original link failed its last check. Original publisher Detailsfor sneak-peek-ch1-2-finding-beacons-in-the-dark.pdf
-
Drawing a Dragon- Connecting the Dots to Find APT41
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Drawing a Dragon- Connecting the Dots to Find APT41
-
Masters of Mimicry: new APT group ChamelGang and its arsenal
The original link failed its last check. Original publisher Detailsfor Masters of Mimicry: new APT group ChamelGang and its arsenal
-
Masters of Mimicry: new APT group ChamelGang and its arsenal
The original link failed its last check. Original publisher Detailsfor Masters of Mimicry: new APT group ChamelGang and its arsenal
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
4 Chinese APT Groups Identified Targeting Mail Server of Afghan Telecommunications Firm Roshan
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 4 Chinese APT Groups Identified Targeting Mail Server of Afghan Telecommunications Firm Roshan
-
FamousSparrow_ A suspicious hotel guest _ WeLiveSecurity
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor FamousSparrow_ A suspicious hotel guest _ WeLiveSecurity
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t22021
-
FamousSparrow- A suspicious hotel guest
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FamousSparrow- A suspicious hotel guest
-
Grayfly- Chinese Threat Actor Uses Newly-discovered Sidewalk Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Grayfly- Chinese Threat Actor Uses Newly-discovered Sidewalk Malware
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2021ThreatHunting
-
This Is Not a Test: APT41 Initiates Global Intrusion Campaign Using Multiple Exploits
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor This Is Not a Test: APT41 Initiates Global Intrusion Campaign Using Multiple Exploits
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
Earth Baku: An APT Group Targeting Indo-Pacific Countries With New Stealth Loaders and Backdoor
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Earth Baku: An APT Group Targeting Indo-Pacific Countries With New Stealth Loaders and Backdoor
-
The SideWalk may be as dangerous as the CROSSWALK
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The SideWalk may be as dangerous as the CROSSWALK
-
ShadowPad - A Masterpiece of Privately Sold Malware in Chinese Espionage
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ShadowPad - A Masterpiece of Privately Sold Malware in Chinese Espionage
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Shadowpad
-
DeadRinger_ Exposing Chinese Threat Actors Targeting Major Telcos
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor DeadRinger_ Exposing Chinese Threat Actors Targeting Major Telcos
-
DeadRinger- Exposing Chinese Threat Actors Targeting Major Telcos
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DeadRinger- Exposing Chinese Threat Actors Targeting Major Telcos
-
Top Routinely Exploited Vulnerabilities
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Top Routinely Exploited Vulnerabilities
-
report-old-dogs-new-tricks.pdf
The original link failed its last check. Original publisher Detailsfor report-old-dogs-new-tricks.pdf
-
BIOPASS RAT New Malware Sniffs Victims via Live Streaming
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor BIOPASS RAT New Malware Sniffs Victims via Live Streaming
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese State-Sponsored Activity Group TAG-22 Targets Nepal, the Philippines, and Taiwan Using Winnti and Other Tooling
-
The original link failed its last check. Original publisher Detailsfor Презентация PowerPoint
-
Ryuk Ransomware Now Targeting Webservers
The original link failed its last check. Original publisher Detailsfor Ryuk Ransomware Now Targeting Webservers
-
Geopolitical nation-state threat actor overview June 2021
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Geopolitical nation-state threat actor overview June 2021
-
Cobalt Strike- Favorite Tool from APT to Crimeware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cobalt Strike- Favorite Tool from APT to Crimeware
-
Big airline heist APT41 likely behind massive supply chain attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Big airline heist APT41 likely behind massive supply chain attack
-
Big airline heist_ APT41 likely behind massive supply chain attack
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Big airline heist_ APT41 likely behind massive supply chain attack
-
Looks like the page you're looking for doesn't exist or has moved.
The original link failed its last check. Original publisher Detailsfor Looks like the page you're looking for doesn't exist or has moved.
-
Hacker Lexicon- What Is a Supply Chain Attack-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hacker Lexicon- What Is a Supply Chain Attack-
-
Mustang Panda PlugX - 45.251.240.55 Pivot
The original link failed its last check. Original publisher Detailsfor Mustang Panda PlugX - 45.251.240.55 Pivot
-
APT Threat Landscape of Taiwan in 2020
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Threat Landscape of Taiwan in 2020
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CTIR_casestudy_2.pdf
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CTIR_casestudy_1.pdf
-
China’s PLA Unit 61419 Purchasing Foreign Antivirus Products, Likely for Exploitation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor China’s PLA Unit 61419 Purchasing Foreign Antivirus Products, Likely for Exploitation
-
the-operations-of-winnti-group.pdf
The original link failed its last check. Original publisher Detailsfor the-operations-of-winnti-group.pdf
-
APT35 ‘Charming Kitten' discovered in a pre-infected environment _ Blog _ Darktrace
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT35 ‘Charming Kitten' discovered in a pre-infected environment _ Blog _ Darktrace
-
APT35 ‘Charming Kitten' discovered in a pre-infected environment
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT35 ‘Charming Kitten' discovered in a pre-infected environment
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor mtrends-2021
-
APT10_ sophisticated multi-layered loader Ecipekac discovered in A41APT campaign _ Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT10_ sophisticated multi-layered loader Ecipekac discovered in A41APT campaign _ Securelist
-
report-bb-2021-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor report-bb-2021-threat-report.pdf
-
Technical Analysis of Operation Diànxùn
The original link failed its last check. Original publisher Detailsfor Technical Analysis of Operation Diànxùn
-
Linux Backdoor RedXOR Likely Operated by Chinese Nation-State
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Linux Backdoor RedXOR Likely Operated by Chinese Nation-State
-
Exchange servers under siege from at least 10 APT groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Exchange servers under siege from at least 10 APT groups
-
China-linked Group RedEcho Targets the Indian Power Sector Amid Heightened Border Tensions
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor China-linked Group RedEcho Targets the Indian Power Sector Amid Heightened Border Tensions
-
The_CrowdStrike_2021_Global_Threat_Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The_CrowdStrike_2021_Global_Threat_Report
-
operation-nightscout-supply-chain-attack-online-gaming-asia
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor operation-nightscout-supply-chain-attack-online-gaming-asia
-
ptsecurity.com-Higaisa or Winnti APT41 backdoors old and new
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ptsecurity.com-Higaisa or Winnti APT41 backdoors old and new
-
Researchers Disclose Undocumented Chinese Malware Used in Recent Attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Researchers Disclose Undocumented Chinese Malware Used in Recent Attacks
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
Higaisa or Winnti- APT41 backdoors, old and new
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Higaisa or Winnti- APT41 backdoors, old and new
-
Sunburst backdoor – code overlaps with Kazuar
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sunburst backdoor – code overlaps with Kazuar
-
securelist.com-Sunburst backdoor code overlaps with Kazuar
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor securelist.com-Sunburst backdoor code overlaps with Kazuar
-
China cyber attacks- the current threat landscape
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor China cyber attacks- the current threat landscape
-
Analyzing Cobalt Strike for Fun and Profit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analyzing Cobalt Strike for Fun and Profit
-
From ThreatHunting to Campaign Tracking
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor From ThreatHunting to Campaign Tracking
-
Analyzing Organizational Invasion Ransom Incidents Using Dtrack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analyzing Organizational Invasion Ransom Incidents Using Dtrack
-
Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
-
Hunting for Barium using Azure Sentinel
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hunting for Barium using Azure Sentinel
-
APT_trends_report_Q3_2020_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q3_2020_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q3 2020
-
Study of the ShadowPad APT backdoor and its relation to PlugX
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Study of the ShadowPad APT backdoor and its relation to PlugX
-
Alert (AA20-275A)- Potential for China Cyber Response to Heightened U.S.-China Tensions
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (AA20-275A)- Potential for China Cyber Response to Heightened U.S.-China Tensions
-
FY20 Microsoft Digital Defense Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor FY20 Microsoft Digital Defense Report
-
APT41- Indictments Put Chinese Espionage Group in the Spotlight
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT41- Indictments Put Chinese Espionage Group in the Spotlight
-
U.S. Justice Department Charges APT41 Hackers over Global Cyberattacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor U.S. Justice Department Charges APT41 Hackers over Global Cyberattacks
-
The original link failed its last check. Original publisher Detailsfor winnti-2020-rus.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Seven International Cyber Defendants, Including “Apt41” Actors, Charged In Connection With Computer Intrusion Campaigns Against More Than 100 Victims Globally
-
An overview of targeted attacks and APTs on Linux
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor An overview of targeted attacks and APTs on Linux
-
2020.09.29_ShadowPad - new activity from the Winnti group
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2020.09.29_ShadowPad - new activity from the Winnti group
-
In-Memory shellcode decoding to evade AVs/EDRs
The original link failed its last check. Original publisher Detailsfor In-Memory shellcode decoding to evade AVs/EDRs
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor What even is Winnti-
-
cybersecurity-threatscape-2020-q1-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor cybersecurity-threatscape-2020-q1-eng
-
BRONZE VINEWOOD Targets Supply Chains _ Secureworks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor BRONZE VINEWOOD Targets Supply Chains _ Secureworks
-
BRONZE VINEWOOD Targets Supply Chains
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BRONZE VINEWOOD Targets Supply Chains
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Multi-stage APT attack drops Cobalt Strike using Malleable C2 feature - Malwarebytes Labs _ Malwarebytes Labs
-
Multi-stage APT attack drops Cobalt Strike using Malleable C2 feature
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Multi-stage APT attack drops Cobalt Strike using Malleable C2 feature
-
Hacker Lexicon- What Is a Supply Chain Attack-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hacker Lexicon- What Is a Supply Chain Attack-
-
No “Game over” for the Winnti Group _ WeLiveSecurity
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor No “Game over” for the Winnti Group _ WeLiveSecurity
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor T1055 Process Injection
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q12020
-
WINNTI GROUP_ Insights From the Past
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor WINNTI GROUP_ Insights From the Past
-
WINNTI GROUP- Insights From the Past
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor WINNTI GROUP- Insights From the Past
-
APT41 Using New Speculoos Backdoor to Target Organizations Globally
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT41 Using New Speculoos Backdoor to Target Organizations Globally
-
Catching APT41 exploiting a zero-day vulnerability
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Catching APT41 exploiting a zero-day vulnerability
-
Catching APT41 exploiting a zero-day vulnerability
The original link failed its last check. Detailsfor Catching APT41 exploiting a zero-day vulnerability
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor report-bb-decade-of-the-rats
-
This Is Not a Test_ APT41 Initiates Global Intrusion Campaign Using Multiple Exploits _ FireEye Inc
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor This Is Not a Test_ APT41 Initiates Global Intrusion Campaign Using Multiple Exploits _ FireEye Inc
-
This Is Not a Test- APT41 Initiates Global Intrusion Campaign Using Multiple Exploits
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor This Is Not a Test- APT41 Initiates Global Intrusion Campaign Using Multiple Exploits
-
Analysis Of Exploitation- CVE-2020-10189 ( exploited by APT41)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis Of Exploitation- CVE-2020-10189 ( exploited by APT41)
-
Is APT 27 Abusing COVID-19 To Attack People !
The original link failed its last check. Detailsfor Is APT 27 Abusing COVID-19 To Attack People !
-
Report2020CrowdStrikeGlobalThreatReport
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2020CrowdStrikeGlobalThreatReport
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor mtrends-2020
-
Winnti Group targeting universities in Hong Kong
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Winnti Group targeting universities in Hong Kong
-
Cyber Threat Landscape in Japan – Revealing Threat in the Shadow
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber Threat Landscape in Japan – Revealing Threat in the Shadow
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor [CB19] Cyber Threat Landscape in Japan – Revealing Threat in the Shadow by Chi En Shen (Ashley) Oleg Bondarenko
-
Operation ENDTRADE: Multi-Stage Backdoors that TICK
The original link failed its last check. Original publisher Detailsfor Operation ENDTRADE: Multi-Stage Backdoors that TICK
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data
-
The original link failed its last check. Original publisher Detailsfor Aarhus_miniseminar_291118.pdf
-
Operation ENDTRADE- Finding Multi-Stage Backdoors that TICK
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation ENDTRADE- Finding Multi-Stage Backdoors that TICK
-
cds19-executive-s08-achievement-unlocked.pdf
The original link failed its last check. Original publisher Detailsfor cds19-executive-s08-achievement-unlocked.pdf
-
MESSAGETAP- Who’s Reading Your Text Messages-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MESSAGETAP- Who’s Reading Your Text Messages-
-
The original link failed its last check. Original publisher Detailsfor Analytics
-
MESSAGETAP_ Who’s Reading Your Text Messages
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor MESSAGETAP_ Who’s Reading Your Text Messages
-
Shikata Ga Nai Encoder Still Going Strong
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shikata Ga Nai Encoder Still Going Strong
-
Winnti Group’s skip‑2.0_ A Microsoft SQL Server backdoor
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Winnti Group’s skip‑2.0_ A Microsoft SQL Server backdoor
-
LOWKEY_ Hunting for the Missing Volume Serial ID
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor LOWKEY_ Hunting for the Missing Volume Serial ID
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Winnti
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor HELO Winnti_ Attack or Scan
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor HELO Winnti- Attack or Scan-
-
APT41: A Dual Espionage and Cyber Crime Operation
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor APT41: A Dual Espionage and Cyber Crime Operation
-
GAME OVER: Detecting and Stopping an APT41 Operation
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor GAME OVER: Detecting and Stopping an APT41 Operation
-
APT41: A Dual Espionage and Cyber Crime Operation
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor APT41: A Dual Espionage and Cyber Crime Operation
-
GAME OVER- Detecting and Stopping an APT41 Operation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor GAME OVER- Detecting and Stopping an APT41 Operation
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor blog_APT41
-
2019 Cyber Threatscape Report I Accenture
The original link failed its last check. Original publisher Detailsfor 2019 Cyber Threatscape Report I Accenture
-
APT41- A Dual Espionage and Cyber Crime Operation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT41- A Dual Espionage and Cyber Crime Operation
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor report_APT41
-
TLP-WHITE-CERT-EU-MEMO-190725-1.pdf
The original link failed its last check. Original publisher Detailsfor TLP-WHITE-CERT-EU-MEMO-190725-1.pdf
-
Winnti_ Attacking the Heart of the German Industry
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Winnti_ Attacking the Heart of the German Industry
-
Hunting and detecting Cobalt Strike
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hunting and detecting Cobalt Strike
-
Into the Fog - The Return of ICEFOG APT
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Into the Fog - The Return of ICEFOG APT
-
TeamViewer Confirms Undisclosed Breach From 2016
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TeamViewer Confirms Undisclosed Breach From 2016
-
Bayer points finger at Wicked Panda in cyberattack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Bayer points finger at Wicked Panda in cyberattack
-
mpressioncss_ta_report_2019.pdf
The original link failed its last check. Original publisher Detailsfor mpressioncss_ta_report_2019.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation ShadowHammer
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation ShadowHammer
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2019GlobalThreatReport
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Gaming-Industry.Asia
-
The original link failed its last check. Original publisher Detailsfor CrowdStrike_GTR_2019.pdf
-
Accenture-Cyber-Threatscape-Report-2018.pdf
The original link failed its last check. Original publisher Detailsfor Accenture-Cyber-Threatscape-Report-2018.pdf
-
Meet CrowdStrike’s Adversary of the Month for July- WICKED SPIDER
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Meet CrowdStrike’s Adversary of the Month for July- WICKED SPIDER
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Burning Umbrella
-
Advanced Persistent Threat Groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threat Groups
-
Analysing a 10-Year-Old SNOWBALL
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysing a 10-Year-Old SNOWBALL
-
Recent Winnti Infrastructure and Samples _ ClearSky Cybersecurity
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Recent Winnti Infrastructure and Samples _ ClearSky Cybersecurity
-
Winnti Evolution - Going Open Source
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Winnti Evolution - Going Open Source
-
Winnti Abuses GitHub for C&C Communications
The original link failed its last check. Original publisher Detailsfor Winnti Abuses GitHub for C&C Communications
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Detecting threat actors in recent German industrial attacks with Windows Defender ATP – Microsoft Secure
-
Detecting threat actors in recent German industrial attacks with Windows Defender ATP
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Detecting threat actors in recent German industrial attacks with Windows Defender ATP
-
The original link failed its last check. Original publisher Detailsfor security_report_20160613.pdf
-
Newcomers in the Derusbi family
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Newcomers in the Derusbi family
-
Uncovering the Seven Pointed Dagger
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Uncovering the Seven Pointed Dagger
-
Animal Farm APT and the Shadow of French Intelligence
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Animal Farm APT and the Shadow of French Intelligence
-
Dino: The Latest Spying Malware From An Allegedly French Espionage Group Analyzed
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Dino: The Latest Spying Malware From An Allegedly French Espionage Group Analyzed
-
The original link failed its last check. Original publisher Detailsfor APT17_Report.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Animals in the APT Farm
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Animals in the APT Farm
-
casper-malware-babar-bunny-another-espionage-cartoon
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor casper-malware-babar-bunny-another-espionage-cartoon
-
Casper Malware- After Babar and Bunny, Another Espionage Cartoon
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Casper Malware- After Babar and Bunny, Another Espionage Cartoon
-
Babar: espionage software finally found and put under the microscope
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Babar: espionage software finally found and put under the microscope
-
Threat Group-3279 Targets the Video Game Industry | Secureworks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group-3279 Targets the Video Game Industry | Secureworks
-
BKDR_RARSTONE: New RAT to Watch Out For - TrendLabs Security Intelligence Blog
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor BKDR_RARSTONE: New RAT to Watch Out For - TrendLabs Security Intelligence Blog
Newest first. Details opens the report in Explore.