Wizard Spider
Also reported as Periwinkle Tempest, DEV-0193, UNC1878, TEMP.MixMaster, FIN12 and 15 other names. Linked to Russia by four sources.
Reports per quarter
Techniques seen in the last two years
- T1053.005 9 reports in ATT&CK
- T1057 8 reports reports only
- T1105 7 reports in ATT&CK
- T1059.001 6 reports in ATT&CK
- T1059.003 6 reports in ATT&CK
- T1082 6 reports in ATT&CK
- T1016 5 reports in ATT&CK
- T1071.001 5 reports in ATT&CK
- T1083 5 reports reports only
- T1204.002 5 reports in ATT&CK
Show all 276 techniques Show fewer
- T1566.001 5 reports in ATT&CK
- T1572 5 reports reports only
- T1005 4 reports in ATT&CK
- T1018 4 reports in ATT&CK
- T1027 4 reports reports only
- T1033 4 reports in ATT&CK
- T1041 4 reports in ATT&CK
- T1046 4 reports reports only
- T1047 4 reports in ATT&CK
- T1059 4 reports reports only
- T1140 4 reports reports only
- T1189 4 reports reports only
- T1190 4 reports reports only
- T1219 4 reports reports only
- T1482 4 reports reports only
- T1505.003 4 reports reports only
- T1003 3 reports reports only
- T1003.001 3 reports in ATT&CK
- T1003.002 3 reports in ATT&CK
- T1007 3 reports reports only
- T1021.001 3 reports in ATT&CK
- T1021.002 3 reports in ATT&CK
- T1036.005 3 reports reports only
- T1049 3 reports reports only
- T1055 3 reports in ATT&CK
- T1055.002 3 reports reports only
- T1059.005 3 reports reports only
- T1068 3 reports reports only
- T1069.002 3 reports reports only
- T1070.004 3 reports in ATT&CK
- T1071 3 reports reports only
- T1078 3 reports in ATT&CK
- T1087.001 3 reports reports only
- T1087.002 3 reports in ATT&CK
- T1132.001 3 reports reports only
- T1133 3 reports in ATT&CK
- T1135 3 reports in ATT&CK
- T1136.001 3 reports in ATT&CK
- T1486 3 reports reports only
- T1489 3 reports in ATT&CK
- T1490 3 reports in ATT&CK
- T1518.001 3 reports in ATT&CK
- T1566 3 reports reports only
- T1570 3 reports in ATT&CK
- T1574.001 3 reports reports only
- T1008 2 reports reports only
- T1021.004 2 reports reports only
- T1027.009 2 reports reports only
- T1036 2 reports reports only
- T1053 2 reports reports only
- T1055.004 2 reports reports only
- T1056 2 reports reports only
- T1056.001 2 reports reports only
- T1059.006 2 reports reports only
- T1059.007 2 reports reports only
- T1069.001 2 reports reports only
- T1071.004 2 reports reports only
- T1078.002 2 reports in ATT&CK
- T1090 2 reports reports only
- T1090.001 2 reports reports only
- T1095 2 reports reports only
- T1098 2 reports reports only
- T1098.007 2 reports reports only
- T1104 2 reports reports only
- T1119 2 reports reports only
- T1124 2 reports reports only
- T1129 2 reports reports only
- T1134 2 reports reports only
- T1136 2 reports reports only
- T1204 2 reports reports only
- T1217 2 reports reports only
- T1496 2 reports reports only
- T1505.004 2 reports reports only
- T1543.003 2 reports in ATT&CK
- T1547.001 2 reports in ATT&CK
- T1548 2 reports reports only
- T1555.003 2 reports reports only
- T1560 2 reports reports only
- T1560.001 2 reports in ATT&CK
- T1566.002 2 reports in ATT&CK
- T1566.004 2 reports reports only
- T1567 2 reports reports only
- T1571 2 reports reports only
- T1573.001 2 reports reports only
- T1583 2 reports reports only
- T1583.003 2 reports reports only
- T1587.001 2 reports reports only
- T1590 2 reports reports only
- T1595 2 reports reports only
- T1595.002 2 reports reports only
- T1608 2 reports reports only
- T1608.001 2 reports reports only
- T1608.002 2 reports reports only
- T1608.006 2 reports reports only
- T1620 2 reports reports only
- T1649 2 reports reports only
- T1010 1 report reports only
- T1012 1 report reports only
- T1016.001 1 report reports only
- T1020 1 report reports only
- T1021 1 report in ATT&CK
- T1021.005 1 report reports only
- T1021.006 1 report in ATT&CK
- T1036.003 1 report reports only
- T1037 1 report reports only
- T1037.001 1 report reports only
- T1039 1 report reports only
- T1040 1 report reports only
- T1048 1 report reports only
- T1053.003 1 report reports only
- T1055.001 1 report in ATT&CK
- T1055.003 1 report reports only
- T1055.009 1 report reports only
- T1055.012 1 report reports only
- T1056.003 1 report reports only
- T1059.002 1 report reports only
- T1059.004 1 report reports only
- T1059.009 1 report reports only
- T1059.010 1 report reports only
- T1059.011 1 report reports only
- T1069 1 report reports only
- T1069.003 1 report reports only
- T1070 1 report reports only
- T1070.006 1 report reports only
- T1072 1 report reports only
- T1074 1 report in ATT&CK
- T1074.001 1 report in ATT&CK
- T1074.002 1 report reports only
- T1078.003 1 report reports only
- T1078.004 1 report reports only
- T1087 1 report reports only
- T1087.004 1 report reports only
- T1090.003 1 report reports only
- T1091 1 report reports only
- T1098.001 1 report reports only
- T1098.003 1 report reports only
- T1098.004 1 report reports only
- T1098.005 1 report reports only
- T1098.006 1 report reports only
- T1102 1 report reports only
- T1102.002 1 report reports only
- T1106 1 report reports only
- T1110 1 report reports only
- T1112 1 report in ATT&CK
- T1113 1 report reports only
- T1114 1 report reports only
- T1114.001 1 report reports only
- T1114.002 1 report reports only
- T1114.003 1 report reports only
- T1115 1 report reports only
- T1120 1 report reports only
- T1123 1 report reports only
- T1125 1 report reports only
- T1132 1 report reports only
- T1134.001 1 report reports only
- T1136.002 1 report in ATT&CK
- T1137 1 report reports only
- T1137.006 1 report reports only
- T1195 1 report reports only
- T1195.001 1 report reports only
- T1195.002 1 report reports only
- T1199 1 report reports only
- T1200 1 report reports only
- T1201 1 report reports only
- T1203 1 report reports only
- T1204.001 1 report in ATT&CK
- T1204.004 1 report reports only
- T1210 1 report in ATT&CK
- T1213 1 report reports only
- T1213.001 1 report reports only
- T1213.002 1 report reports only
- T1213.003 1 report reports only
- T1218 1 report reports only
- T1218.007 1 report reports only
- T1484 1 report reports only
- T1484.001 1 report reports only
- T1485 1 report reports only
- T1491.002 1 report reports only
- T1497 1 report reports only
- T1497.001 1 report reports only
- T1497.003 1 report reports only
- T1498 1 report reports only
- T1505 1 report reports only
- T1518 1 report reports only
- T1528 1 report reports only
- T1529 1 report reports only
- T1530 1 report reports only
- T1534 1 report reports only
- T1537 1 report reports only
- T1538 1 report reports only
- T1543 1 report reports only
- T1543.002 1 report reports only
- T1543.004 1 report reports only
- T1546 1 report reports only
- T1546.003 1 report reports only
- T1546.004 1 report reports only
- T1546.008 1 report reports only
- T1546.012 1 report reports only
- T1546.015 1 report reports only
- T1547 1 report reports only
- T1547.002 1 report reports only
- T1547.005 1 report reports only
- T1547.009 1 report reports only
- T1548.002 1 report reports only
- T1550 1 report reports only
- T1550.001 1 report reports only
- T1550.002 1 report in ATT&CK
- T1552 1 report reports only
- T1554 1 report reports only
- T1555 1 report reports only
- T1556 1 report reports only
- T1556.002 1 report reports only
- T1556.006 1 report reports only
- T1556.009 1 report reports only
- T1558.003 1 report in ATT&CK
- T1559 1 report reports only
- T1560.002 1 report reports only
- T1564.004 1 report reports only
- T1565 1 report reports only
- T1565.001 1 report reports only
- T1566.003 1 report reports only
- T1567.001 1 report reports only
- T1567.002 1 report in ATT&CK
- T1569 1 report reports only
- T1569.002 1 report in ATT&CK
- T1573 1 report reports only
- T1573.002 1 report reports only
- T1574 1 report reports only
- T1574.011 1 report reports only
- T1578 1 report reports only
- T1580 1 report reports only
- T1583.001 1 report reports only
- T1583.004 1 report reports only
- T1583.006 1 report reports only
- T1584 1 report reports only
- T1584.004 1 report reports only
- T1585 1 report reports only
- T1585.002 1 report in ATT&CK
- T1586.002 1 report reports only
- T1587 1 report reports only
- T1587.003 1 report reports only
- T1588 1 report reports only
- T1588.002 1 report in ATT&CK
- T1588.003 1 report in ATT&CK
- T1588.004 1 report reports only
- T1588.007 1 report reports only
- T1589.002 1 report reports only
- T1590.005 1 report reports only
- T1592 1 report reports only
- T1595.001 1 report reports only
- T1598 1 report reports only
- T1602 1 report reports only
- T1602.001 1 report reports only
- T1602.002 1 report reports only
- T1608.003 1 report reports only
- T1608.004 1 report reports only
- T1608.005 1 report reports only
- T1613 1 report reports only
- T1614 1 report reports only
- T1614.001 1 report reports only
- T1615 1 report reports only
- T1619 1 report reports only
- T1622 1 report reports only
- T1652 1 report reports only
- T1654 1 report reports only
- T1657 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2003-1138
- CVE-2005-1380
- CVE-2008-2463
- CVE-2008-3431 KEV
- CVE-2010-0738 KEV ransomware
- CVE-2010-0817
- CVE-2010-2568 KEV
- CVE-2010-3936
- CVE-2011-1255
- CVE-2011-1264
- CVE-2012-0151 KEV
- CVE-2012-0158 KEV ransomware
Show all 499 CVEs Show fewer
- CVE-2012-5687
- CVE-2013-0640 KEV
- CVE-2013-3660 KEV
- CVE-2013-3893 KEV
- CVE-2013-3900 KEV
- CVE-2013-5947
- CVE-2014-1225
- CVE-2014-1776 KEV
- CVE-2014-1812 KEV ransomware
- CVE-2014-2962
- CVE-2014-3567
- CVE-2014-4019
- CVE-2014-4113 KEV
- CVE-2014-4404 KEV
- CVE-2014-6271 KEV
- CVE-2014-6277
- CVE-2014-6278 KEV
- CVE-2014-6332 KEV
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0057
- CVE-2015-0554
- CVE-2015-1130 KEV
- CVE-2015-1635 KEV
- CVE-2015-1641 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-2051 KEV
- CVE-2015-2545 KEV
- CVE-2015-5119 KEV
- CVE-2015-7248
- CVE-2015-7254
- CVE-2015-8651 KEV
- CVE-2016-0147
- CVE-2016-0167 KEV ransomware
- CVE-2016-0189 KEV ransomware
- CVE-2016-0545
- CVE-2016-0984 KEV
- CVE-2016-1010 KEV
- CVE-2016-4117 KEV ransomware
- CVE-2016-4171 KEV
- CVE-2016-5195 KEV
- CVE-2016-7255 KEV ransomware
- CVE-2017-0068
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-10271 KEV ransomware
- CVE-2017-1099
- CVE-2017-11292 KEV
- CVE-2017-11774 KEV
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-12149 KEV ransomware
- CVE-2017-12824
- CVE-2017-14100
- CVE-2017-15399
- CVE-2017-15944 KEV
- CVE-2017-18368 KEV
- CVE-2017-3197
- CVE-2017-5638 KEV ransomware
- CVE-2017-6327 KEV
- CVE-2017-6328
- CVE-2017-8291 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2017-9805 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-0824 KEV
- CVE-2018-10562 KEV ransomware
- CVE-2018-1207
- CVE-2018-13374 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-14847 KEV
- CVE-2018-15961 KEV
- CVE-2018-15982 KEV ransomware
- CVE-2018-4878 KEV ransomware
- CVE-2018-7600 KEV ransomware
- CVE-2018-7602 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8405 KEV ransomware
- CVE-2018-8406 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2018-8581 KEV ransomware
- CVE-2018-8611 KEV
- CVE-2018-8639 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0803 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-1069 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-11539 KEV ransomware
- CVE-2019-11580 KEV ransomware
- CVE-2019-1181
- CVE-2019-1225
- CVE-2019-13720 KEV
- CVE-2019-1458 KEV ransomware
- CVE-2019-1579 KEV ransomware
- CVE-2019-16098
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-16920 KEV
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-2725 KEV ransomware
- CVE-2019-3396 KEV ransomware
- CVE-2019-3398 KEV
- CVE-2019-6225
- CVE-2019-8394 KEV
- CVE-2019-9621 KEV
- CVE-2020-0601 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0787 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-10198
- CVE-2020-1040 KEV
- CVE-2020-116511
- CVE-2020-11652 KEV
- CVE-2020-11899 KEV
- CVE-2020-12061
- CVE-2020-1350 KEV
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-14750 KEV
- CVE-2020-14871 KEV
- CVE-2020-14882 KEV
- CVE-2020-1599
- CVE-2020-1664
- CVE-2020-2021 KEV ransomware
- CVE-2020-3125
- CVE-2020-3529
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-6789
- CVE-2020-7961 KEV
- CVE-2020-8243 KEV
- CVE-2020-8260 KEV
- CVE-2020-8515 KEV
- CVE-2021-1636
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-1844
- CVE-2021-1879 KEV
- CVE-2021-20016 KEV ransomware
- CVE-2021-21166 KEV
- CVE-2021-21972 KEV ransomware
- CVE-2021-21974
- CVE-2021-22205 KEV ransomware
- CVE-2021-22893 KEV ransomware
- CVE-2021-22894 KEV
- CVE-2021-22899 KEV
- CVE-2021-22900 KEV
- CVE-2021-22941 KEV ransomware
- CVE-2021-22986 KEV ransomware
- CVE-2021-26084 KEV ransomware
- CVE-2021-26334
- CVE-2021-26411 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-26868
- CVE-2021-27065 KEV ransomware
- CVE-2021-27101 KEV ransomware
- CVE-2021-27102 KEV ransomware
- CVE-2021-27103 KEV ransomware
- CVE-2021-27104 KEV ransomware
- CVE-2021-30116 KEV ransomware
- CVE-2021-30551 KEV
- CVE-2021-31195
- CVE-2021-31196 KEV
- CVE-2021-31206
- CVE-2021-31207 KEV ransomware
- CVE-2021-3120710
- CVE-2021-3156 KEV
- CVE-2021-33742 KEV
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-345239
- CVE-2021-34527 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-36798
- CVE-2021-36934 KEV
- CVE-2021-36942 KEV ransomware
- CVE-2021-36958
- CVE-2021-38647 KEV ransomware
- CVE-2021-3970
- CVE-2021-3971
- CVE-2021-3972
- CVE-2021-4044
- CVE-2021-40444 KEV ransomware
- CVE-2021-40449 KEV ransomware
- CVE-2021-40539 KEV ransomware
- CVE-2021-4104
- CVE-2021-41379 KEV ransomware
- CVE-2021-42278 KEV ransomware
- CVE-2021-42287 KEV ransomware
- CVE-2021-440077
- CVE-2021-44077 KEV
- CVE-2021-44207 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-44515 KEV
- CVE-2021-44832
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-0609 KEV
- CVE-2022-0847 KEV
- CVE-2022-1388 KEV ransomware
- CVE-2022-21587 KEV ransomware
- CVE-2022-21882 KEV ransomware
- CVE-2022-21919 KEV
- CVE-2022-2294 KEV ransomware
- CVE-2022-22954 KEV ransomware
- CVE-2022-22957
- CVE-2022-22958
- CVE-2022-22960 KEV
- CVE-2022-22963 KEV
- CVE-2022-22965 KEV
- CVE-2022-22972
- CVE-2022-24500
- CVE-2022-24521 KEV ransomware
- CVE-2022-24682 KEV ransomware
- CVE-2022-24934
- CVE-2022-26134 KEV ransomware
- CVE-2022-26766
- CVE-2022-26809
- CVE-2022-26923 KEV
- CVE-2022-27924 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-30333 KEV ransomware
- CVE-2022-31199 KEV ransomware
- CVE-2022-35420
- CVE-2022-37042 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41080 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2022-4980
- CVE-2023-0669 KEV ransomware
- CVE-2023-20198 KEV
- CVE-2023-21746
- CVE-2023-22518 KEV ransomware
- CVE-2023-23397 KEV
- CVE-2023-27350 KEV ransomware
- CVE-2023-27532 KEV ransomware
- CVE-2023-27997 KEV ransomware
- CVE-2023-28461 KEV ransomware
- CVE-2023-2868 KEV
- CVE-2023-32315 KEV
- CVE-2023-34362 KEV ransomware
- CVE-2023-3466
- CVE-2023-3467
- CVE-2023-3519 KEV ransomware
- CVE-2023-36033 KEV
- CVE-2023-38831 KEV ransomware
- CVE-2023-38950 KEV
- CVE-2023-3895037
- CVE-2023-38951
- CVE-2023-3895138
- CVE-2023-38952
- CVE-2023-3895239
- CVE-2023-42793 KEV ransomware
- CVE-2023-45727 KEV
- CVE-2023-46604 KEV ransomware
- CVE-2023-46805 KEV ransomware
- CVE-2023-47246 KEV ransomware
- CVE-2023-48788 KEV ransomware
- CVE-2023-4966 KEV ransomware
- CVE-2024-0012 KEV ransomware
- CVE-2024-13789
- CVE-2024-14007
- CVE-2024-21887 KEV ransomware
- CVE-2024-21893 KEV ransomware
- CVE-2024-21983
- CVE-2024-24919 KEV ransomware
- CVE-2024-27956
- CVE-2024-30051 KEV ransomware
- CVE-2024-3400 KEV ransomware
- CVE-2024-36401 KEV
- CVE-2024-40890 KEV
- CVE-2024-40891 KEV
- CVE-2024-42009 KEV
- CVE-2024-4577 KEV ransomware
- CVE-2024-47575 KEV
- CVE-2024-50664
- CVE-2024-55591 KEV ransomware
- CVE-2024-56196
- CVE-2024-57811
- CVE-2024-58274
- CVE-2024-6473
- CVE-2024-8266
- CVE-2024-8420
- CVE-2024-9474 KEV ransomware
- CVE-2025-0108 KEV
- CVE-2025-10035 KEV ransomware
- CVE-2025-10159
- CVE-2025-11833
- CVE-2025-11953 KEV
- CVE-2025-12686
- CVE-2025-1393
- CVE-2025-14087
- CVE-2025-14174 KEV
- CVE-2025-14847 KEV
- CVE-2025-1496
- CVE-2025-1539
- CVE-2025-1974
- CVE-2025-1980
- CVE-2025-2000
- CVE-2025-20156
- CVE-2025-20188
- CVE-2025-20289
- CVE-2025-20333 KEV
- CVE-2025-20354
- CVE-2025-20363
- CVE-2025-20674
- CVE-2025-2071
- CVE-2025-21218
- CVE-2025-21355
- CVE-2025-22224 KEV
- CVE-2025-22372
- CVE-2025-22455
- CVE-2025-22457 KEV ransomware
- CVE-2025-23006 KEV ransomware
- CVE-2025-24085 KEV
- CVE-2025-24201 KEV
- CVE-2025-24288
- CVE-2025-24472 KEV ransomware
- CVE-2025-24522
- CVE-2025-24990 KEV
- CVE-2025-25181 KEV
- CVE-2025-25256
- CVE-2025-26613
- CVE-2025-27007
- CVE-2025-27135
- CVE-2025-27140
- CVE-2025-27223
- CVE-2025-27224
- CVE-2025-27363 KEV
- CVE-2025-27364
- CVE-2025-2746 KEV
- CVE-2025-27554
- CVE-2025-27636
- CVE-2025-27690
- CVE-2025-27781
- CVE-2025-27797
- CVE-2025-27819
- CVE-2025-2783 KEV
- CVE-2025-2787
- CVE-2025-29891
- CVE-2025-29913
- CVE-2025-29927
- CVE-2025-29972
- CVE-2025-3015
- CVE-2025-30216
- CVE-2025-30259
- CVE-2025-30356
- CVE-2025-31129
- CVE-2025-31201 KEV
- CVE-2025-31324 KEV ransomware
- CVE-2025-32068
- CVE-2025-32375
- CVE-2025-32432 KEV
- CVE-2025-32433 KEV
- CVE-2025-32444
- CVE-2025-32445
- CVE-2025-3248 KEV ransomware
- CVE-2025-32819
- CVE-2025-32992
- CVE-2025-33053 KEV
- CVE-2025-33222
- CVE-2025-33223
- CVE-2025-34027
- CVE-2025-34036
- CVE-2025-34044
- CVE-2025-34046
- CVE-2025-34143
- CVE-2025-34153
- CVE-2025-34159
- CVE-2025-34222
- CVE-2025-34224
- CVE-2025-3495
- CVE-2025-36250
- CVE-2025-3699
- CVE-2025-39247
- CVE-2025-40765
- CVE-2025-41244 KEV
- CVE-2025-41430
- CVE-2025-41651
- CVE-2025-41680
- CVE-2025-41723
- CVE-2025-42599 KEV
- CVE-2025-43200 KEV
- CVE-2025-43300 KEV
- CVE-2025-43529 KEV
- CVE-2025-43858
- CVE-2025-43995
- CVE-2025-46348
- CVE-2025-46811
- CVE-2025-47277
- CVE-2025-47282
- CVE-2025-47646
- CVE-2025-48054
- CVE-2025-48148
- CVE-2025-48926
- CVE-2025-49125
- CVE-2025-49132
- CVE-2025-49136
- CVE-2025-49844
- CVE-2025-50201
- CVE-2025-50454
- CVE-2025-51495
- CVE-2025-52166
- CVE-2025-52452
- CVE-2025-52906
- CVE-2025-5353
- CVE-2025-53770 KEV ransomware
- CVE-2025-53771
- CVE-2025-53942
- CVE-2025-54122
- CVE-2025-5419 KEV
- CVE-2025-54309 KEV
- CVE-2025-54347
- CVE-2025-54875
- CVE-2025-54964
- CVE-2025-55150
- CVE-2025-55182 KEV ransomware
- CVE-2025-55190
- CVE-2025-55727
- CVE-2025-55728
- CVE-2025-55796
- CVE-2025-5597
- CVE-2025-5622
- CVE-2025-57819 KEV
- CVE-2025-57870
- CVE-2025-58048
- CVE-2025-58159
- CVE-2025-58321
- CVE-2025-58366
- CVE-2025-58367
- CVE-2025-58371
- CVE-2025-59118
- CVE-2025-59230 KEV
- CVE-2025-59346
- CVE-2025-59366
- CVE-2025-59503
- CVE-2025-59718 KEV
- CVE-2025-59719
- CVE-2025-60854
- CVE-2025-61882 KEV ransomware
- CVE-2025-61884 KEV ransomware
- CVE-2025-61928
- CVE-2025-61932 KEV
- CVE-2025-62168
- CVE-2025-6222
- CVE-2025-62221 KEV
- CVE-2025-62645
- CVE-2025-62703
- CVE-2025-62713
- CVE-2025-64095
- CVE-2025-64400
- CVE-2025-64428
- CVE-2025-64446 KEV
- CVE-2025-65018
- CVE-2025-6543 KEV
- CVE-2025-6558 KEV
- CVE-2025-66399
- CVE-2025-66516
- CVE-2025-68613 KEV
- CVE-2025-7426
- CVE-2025-7503
- CVE-2025-7775 KEV
- CVE-2025-8110 KEV
- CVE-2025-8424
- CVE-2025-8857
- CVE-2025-8875 KEV
- CVE-2025-8876 KEV
- CVE-2025-9900
- CVE-2026-1731 KEV ransomware
- CVE-2026-20127 KEV
- CVE-2026-21236
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Monty Spider - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Monty Spider - Threat Group Cards: A Threat Actor Encyclopedia
-
Mummy Spider, TA542 - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Mummy Spider, TA542 - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor ISFB (Malware Family)
Show all 1,158 reports Show fewer
-
Smoky Spider - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Smoky Spider - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor RiskIQ Threat Intelligence Roundup: Campaigns Targeting Ukraine and Global Malware Infrastructure | RiskIQ
-
BazarBackdoor (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BazarBackdoor (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Conti (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor IcedID (Malware Family)
-
Wizard Spider, Gold Blackburn - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Wizard Spider, Gold Blackburn - Threat Group Cards: A Threat Actor Encyclopedia
-
Cobalt Strike (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Cobalt Strike (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ryuk (Malware Family)
-
Scully Spider, TA547 - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Scully Spider, TA547 - Threat Group Cards: A Threat Actor Encyclopedia
-
Team46 and TaxOff: two sides of the same coin
The original link failed its last check. Original publisher Detailsfor Team46 and TaxOff: two sides of the same coin
-
The original link failed its last check. Original publisher Detailsfor Hive0137 on AI journey
-
Spam trends campaigns senior superlatives 2023
The original link failed its last check. Original publisher Detailsfor Spam trends campaigns senior superlatives 2023
-
Ex-Conti and FIN7 Actors Collaborate with New Domino Backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ex-Conti and FIN7 Actors Collaborate with New Domino Backdoor
-
The DPRK delicate sound of cyber
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The DPRK delicate sound of cyber
-
Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
The original link failed its last check. Original publisher Detailsfor Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
-
BlackCat Ransomware- Tactics and Techniques From a Targeted Attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BlackCat Ransomware- Tactics and Techniques From a Targeted Attack
-
Bumblebee Malware Loader- Threat Analysis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Bumblebee Malware Loader- Threat Analysis
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Conti vs. Monti- A Reinvention or Just a Simple Rebranding-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Conti vs. Monti- A Reinvention or Just a Simple Rebranding-
-
Initial access broker repurposing techniques in targeted attacks against Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Initial access broker repurposing techniques in targeted attacks against Ukraine
-
Looking for the ‘Sliver’ lining- Hunting for emerging command-and-control frameworks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Looking for the ‘Sliver’ lining- Hunting for emerging command-and-control frameworks
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor From Ramnit To Bumblebee (via NeverQuest)- Similarities and Code Overlap Shed Light On Relationships Between Malware Developers
-
BumbleBee Roasts Its Way to Domain Admin
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BumbleBee Roasts Its Way to Domain Admin
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Russian Ransomware C2 Network Discovered in Censys Data
The original link failed its last check. Original publisher Detailsfor Russian Ransomware C2 Network Discovered in Censys Data
-
Unprecedented Shift- The Trickbot Group is Systematically Attacking Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Unprecedented Shift- The Trickbot Group is Systematically Attacking Ukraine
-
Hive ransomware gets upgrades in Rust
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hive ransomware gets upgrades in Rust
-
The many lives of BlackCat ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The many lives of BlackCat ransomware
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t12022
-
Bablosoft; Lowering the Barrier of Entry for Malicious Actors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Bablosoft; Lowering the Barrier of Entry for Malicious Actors
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware Analysis- Trickbot
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
ITG23 Crypters Highlight Cooperation Between Cybercriminal Groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ITG23 Crypters Highlight Cooperation Between Cybercriminal Groups
-
ITG23 crypters cooperation between cybercriminal groups
The original link failed its last check. Original publisher Detailsfor ITG23 crypters cooperation between cybercriminal groups
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Network Footprints of Gamaredon Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Network Footprints of Gamaredon Group
-
Ransomware-as-a-service- Understanding the cybercrime gig economy and how to protect yourself
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware-as-a-service- Understanding the cybercrime gig economy and how to protect yourself
-
Russian Cyber Attack campaigns and actors - NOBELIUM has struck again.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian Cyber Attack campaigns and actors - NOBELIUM has struck again.pdf
-
Russian cyber attack campaigns and actors.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian cyber attack campaigns and actors.pdf
-
ransomware-chats.pdf?1651576098
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor ransomware-chats.pdf?1651576098
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
GOLD ULRICK Continues Conti Operations Despite Public Disclosures
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor GOLD ULRICK Continues Conti Operations Despite Public Disclosures
-
Russian State-Sponsored and Criminal Cyber .pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian State-Sponsored and Criminal Cyber .pdf
-
Alert (AA22-110A)- Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (AA22-110A)- Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
ConversingLabs Ep. 2- Conti pivots as ransomware as a service struggles
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ConversingLabs Ep. 2- Conti pivots as ransomware as a service struggles
-
TRM Analysis Corroborates Suspected Ties Between Conti and Ryuk Ransomware Groups and Wizard Spider
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TRM Analysis Corroborates Suspected Ties Between Conti and Ryuk Ransomware Groups and Wizard Spider
-
FIN7 Power Hour Adversary Archaeology and the Evolution of FIN7
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FIN7 Power Hour Adversary Archaeology and the Evolution of FIN7
-
FIN7 Power Hour- Adversary Archaeology and the Evolution of FIN7
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FIN7 Power Hour- Adversary Archaeology and the Evolution of FIN7
-
GOLD ULRICK Leaks Reveal Organizational Structure and Relationships
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor GOLD ULRICK Leaks Reveal Organizational Structure and Relationships
-
Sandworm- A tale of disruption told anew
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sandworm- A tale of disruption told anew
-
Conti Affiliate Exposed- New Domain Names, IP Addresses and Email Addresses Uncovered
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Conti Affiliate Exposed- New Domain Names, IP Addresses and Email Addresses Uncovered
-
Exposing initial access broker with ties to Conti
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Exposing initial access broker with ties to Conti
-
The Ransomware Threat Landscape: What to Expect in 2022
The original link failed its last check. Original publisher Detailsfor The Ransomware Threat Landscape: What to Expect in 2022
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor What Wicked Webs We Un-weave
-
BazarLoader Actors Initiate Contact via Website Contact Forms
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BazarLoader Actors Initiate Contact via Website Contact Forms
-
Legitimate Sites used as Cobalt Strike C2s against Indian Government
The original link failed its last check. Original publisher Detailsfor Legitimate Sites used as Cobalt Strike C2s against Indian Government
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor 2021trends.pdf
-
New malware TrickBot AnchorDNS backdoor upgrades AnchorMail
The original link failed its last check. Original publisher Detailsfor New malware TrickBot AnchorDNS backdoor upgrades AnchorMail
-
Trickbot Group’s AnchorDNS Backdoor Upgrades to AnchorMail
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Trickbot Group’s AnchorDNS Backdoor Upgrades to AnchorMail
-
Notorious TrickBot Malware Gang Shuts Down its Botnet Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Notorious TrickBot Malware Gang Shuts Down its Botnet Infrastructure
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
An Empirically Comparative Analysis of Ransomware Binaries
The original link failed its last check. Original publisher Detailsfor An Empirically Comparative Analysis of Ransomware Binaries
-
Cybercrime Moves- Conti Ransomware Absorbs TrickBot Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cybercrime Moves- Conti Ransomware Absorbs TrickBot Malware
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2022GTR
-
VMware Exposing Malware In Linux Based Multi Cloud Environments
The original link failed its last check. Original publisher Detailsfor VMware Exposing Malware In Linux Based Multi Cloud Environments
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t32021
-
TrickBot gang template-based metaprogramming Bazar malware
The original link failed its last check. Original publisher Detailsfor TrickBot gang template-based metaprogramming Bazar malware
-
ALPHV ransomware gang analysis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ALPHV ransomware gang analysis
-
FBI links Diavol ransomware to the TrickBot cybercrime group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FBI links Diavol ransomware to the TrickBot cybercrime group
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Kraken the Code on Prometheus
-
Microsoft Word - DiavolFLASH Approved FINAL 01192022
The original link failed its last check. Original publisher Detailsfor Microsoft Word - DiavolFLASH Approved FINAL 01192022
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Winnti is Coming - Evolution after Prosecution@HITCON2021
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Winnti is Coming - Evolution after Prosecution@HITCON2021
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Diavol Ransomware
-
The double extortion business- Conti Ransomware Gang finds new avenues of negotiation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The double extortion business- Conti Ransomware Gang finds new avenues of negotiation
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Mummy Spider’s Emotet Malware is Back After a Year Hiatus; Wizard Spider’s TrickBot Observed in Its Return
-
The original link failed its last check. Original publisher Detailsfor Conti Ransomware
-
Conti Ransomware Nets at Least $25.5 Million in Four Months
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Conti Ransomware Nets at Least $25.5 Million in Four Months
-
FINDING BEACONS IN THE DARK 1650728751599
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor FINDING BEACONS IN THE DARK 1650728751599
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor HTML smuggling surges- Highly evasive loader technique increasingly used in banking malware, targeted attacks
-
THREAT ANALYSIS REPORT- From Shatak Emails to the Conti Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor THREAT ANALYSIS REPORT- From Shatak Emails to the Conti Ransomware
-
Advanced IP Scanner- the preferred scanner in the A(P)T toolbox
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced IP Scanner- the preferred scanner in the A(P)T toolbox
-
Trickbot Rising — Gang Doubles Down on Infection Efforts to Amass Network Footholds
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Trickbot Rising — Gang Doubles Down on Infection Efforts to Amass Network Footholds
-
TrickBot gang doubles down enterprise infection
The original link failed its last check. Original publisher Detailsfor TrickBot gang doubles down enterprise infection
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FIN12- The Prolific Ransomware Intrusion Threat Actor That Has Aggressively Pursued Healthcare Targets
-
sneak-peek-ch1-2-finding-beacons-in-the-dark.pdf
The original link failed its last check. Original publisher Detailsfor sneak-peek-ch1-2-finding-beacons-in-the-dark.pdf
-
Masters of Mimicry: new APT group ChamelGang and its arsenal
The original link failed its last check. Original publisher Detailsfor Masters of Mimicry: new APT group ChamelGang and its arsenal
-
Masters of Mimicry: new APT group ChamelGang and its arsenal
The original link failed its last check. Original publisher Detailsfor Masters of Mimicry: new APT group ChamelGang and its arsenal
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t22021
-
Falcon OverWatch Hunts Down Adversaries Where They Hide
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Falcon OverWatch Hunts Down Adversaries Where They Hide
-
Analyzing attacks that exploit the CVE-2021-40444 MSHTML vulnerability
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analyzing attacks that exploit the CVE-2021-40444 MSHTML vulnerability
-
Big Game Hunting TTPs Continue to Shift After DarkSide Pipeline Attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Big Game Hunting TTPs Continue to Shift After DarkSide Pipeline Attack
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2021ThreatHunting
-
Sidoh- WIZARD SPIDER’s Mysterious Exfiltration Tool
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sidoh- WIZARD SPIDER’s Mysterious Exfiltration Tool
-
Cobalt Strike, a Defender’s Guide
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cobalt Strike, a Defender’s Guide
-
Analysis of Diavol Ransomware Reveals Possible Link to TrickBot Gang
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis of Diavol Ransomware Reveals Possible Link to TrickBot Gang
-
An insider insights into Conti operations – Part one
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor An insider insights into Conti operations – Part one
-
Nationstate_ransomware_with_consecutive_endnotes.pdf
The original link failed its last check. Original publisher Detailsfor Nationstate_ransomware_with_consecutive_endnotes.pdf
-
A Detailed Analysis of The Last Version of Conti Ransomware
The original link failed its last check. Original publisher Detailsfor A Detailed Analysis of The Last Version of Conti Ransomware
-
report-old-dogs-new-tricks.pdf
The original link failed its last check. Original publisher Detailsfor report-old-dogs-new-tricks.pdf
-
Detecting Trickbot with Splunk
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Detecting Trickbot with Splunk
-
Ryuk Ransomware Now Targeting Webservers
The original link failed its last check. Original publisher Detailsfor Ryuk Ransomware Now Targeting Webservers
-
Is Diavol Ransomware Connected to Wizard Spider-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Is Diavol Ransomware Connected to Wizard Spider-
-
TrickBot- New attacks see the botnet deploy new banking module, new ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TrickBot- New attacks see the botnet deploy new banking module, new ransomware
-
Diavol - A New Ransomware Used By Wizard Spider-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Diavol - A New Ransomware Used By Wizard Spider-
-
Shelob Moonlight – Spinning a Larger Web From IcedID to CONTI, a Trojan and Ransomware collaboration
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shelob Moonlight – Spinning a Larger Web From IcedID to CONTI, a Trojan and Ransomware collaboration
-
Response When Minutes Matter- Falcon Complete Disrupts WIZARD SPIDER eCrime Operators
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Response When Minutes Matter- Falcon Complete Disrupts WIZARD SPIDER eCrime Operators
-
Looks like the page you're looking for doesn't exist or has moved.
The original link failed its last check. Original publisher Detailsfor Looks like the page you're looking for doesn't exist or has moved.
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CTIR_casestudy_2.pdf
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CTIR_casestudy_1.pdf
-
The original link failed its last check. Original publisher Detailsfor Intel 471
-
the-operations-of-winnti-group.pdf
The original link failed its last check. Original publisher Detailsfor the-operations-of-winnti-group.pdf
-
Ransom Mafia - Analysis of the World's First Ransomware Cartel
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransom Mafia - Analysis of the World's First Ransomware Cartel
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2021-Threat-Detection-Report
-
report-bb-2021-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor report-bb-2021-threat-report.pdf
-
Technical Analysis of Operation Diànxùn
The original link failed its last check. Original publisher Detailsfor Technical Analysis of Operation Diànxùn
-
Nice to meet you too My name is Ryuk
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Nice to meet you too My name is Ryuk
-
The_CrowdStrike_2021_Global_Threat_Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The_CrowdStrike_2021_Global_Threat_Report
-
BazarLoader’s Elaborate Flower Shop Lure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BazarLoader’s Elaborate Flower Shop Lure
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Trickbot Still Alive and Well
-
blog.truesec.com-Collaboration between FIN7 and the RYUK group a Truesec Investigation
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor blog.truesec.com-Collaboration between FIN7 and the RYUK group a Truesec Investigation
-
Collaboration between FIN7 and the RYUK group, a Truesec Investigation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Collaboration between FIN7 and the RYUK group, a Truesec Investigation
-
Collaboration Between FIN7 and the RYUK Group
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Collaboration Between FIN7 and the RYUK Group
-
Russian cyber attack campaigns and actors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian cyber attack campaigns and actors
-
DebUNCing Attribution How Mandiant Tracks Uncategorized Threat Actors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DebUNCing Attribution How Mandiant Tracks Uncategorized Threat Actors
-
Analyzing Network Infrastructure as Composite Objects
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analyzing Network Infrastructure as Composite Objects
-
Zooming into Darknet Threats Targeting Japanese Organizations
The original link failed its last check. Original publisher Detailsfor Zooming into Darknet Threats Targeting Japanese Organizations
-
Ryuk Speed Run, 2 Hours to Ransom
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ryuk Speed Run, 2 Hours to Ransom
-
SCYTHE Library: #ThreatThursday - Ryuk
The original link failed its last check. Original publisher Detailsfor SCYTHE Library: #ThreatThursday - Ryuk
-
UNC 1878 Indicators from Threatconnect
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor UNC 1878 Indicators from Threatconnect
-
A Bazar start- How one hospital thwarted a Ryuk ransomware outbreak
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Bazar start- How one hospital thwarted a Ryuk ransomware outbreak
-
Building wave of ransomware attacks strike U.S. hospitals
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Building wave of ransomware attacks strike U.S. hospitals
-
Hacking group is targeting US hospitals with Ryuk ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hacking group is targeting US hospitals with Ryuk ransomware
-
Unhappy Hour Special- KEGTAP and SINGLEMALT With a Ransomware Chaser
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Unhappy Hour Special- KEGTAP and SINGLEMALT With a Ransomware Chaser
-
FBI, DHS, HHS Warn of Imminent, Credible Ransomware Threat Against U.S. Hospitals
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FBI, DHS, HHS Warn of Imminent, Credible Ransomware Threat Against U.S. Hospitals
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor UNC1878 Indicators
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor UNC1878 indicators
-
WIZARD SPIDER Update- Resilient, Reactive and Resolute
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor WIZARD SPIDER Update- Resilient, Reactive and Resolute
-
Tracing fresh Ryuk campaigns itw
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Tracing fresh Ryuk campaigns itw
-
Double Trouble- Ransomware with Data Leak Extortion, Part 2
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Double Trouble- Ransomware with Data Leak Extortion, Part 2
-
What's behind the increase in ransomware attacks this year?
The original link failed its last check. Original publisher Detailsfor What's behind the increase in ransomware attacks this year?
-
wp-spark-state-of-ransomware.pdf
The original link failed its last check. Original publisher Detailsfor wp-spark-state-of-ransomware.pdf
-
In-Memory shellcode decoding to evade AVs/EDRs
The original link failed its last check. Original publisher Detailsfor In-Memory shellcode decoding to evade AVs/EDRs
-
SCANdalous! (External Detection Using Network Scan Data and Automation)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SCANdalous! (External Detection Using Network Scan Data and Automation)
-
Russian Cyber Attack Campaigns and Actors - Threat Research
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Russian Cyber Attack Campaigns and Actors - Threat Research
-
DarkSide Pipeline Attack Shakes Up the Ransomware-as-a-Service Landscape
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DarkSide Pipeline Attack Shakes Up the Ransomware-as-a-Service Landscape
-
Catching APT41 exploiting a zero-day vulnerability
The original link failed its last check. Detailsfor Catching APT41 exploiting a zero-day vulnerability
-
It’s Your Money and They Want It Now - The Cycle of Adversary Pursuit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor It’s Your Money and They Want It Now - The Cycle of Adversary Pursuit
-
They Come in the Night- Ransomware Deployment Trends
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor They Come in the Night- Ransomware Deployment Trends
-
Report2020CrowdStrikeGlobalThreatReport
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2020CrowdStrikeGlobalThreatReport
-
2020_State-of-Malware-Report.pdf
The original link failed its last check. Original publisher Detailsfor 2020_State-of-Malware-Report.pdf
-
The original link failed its last check. Original publisher Detailsfor Forensics Report True Hedge
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hunting for Ransomware
-
Threat spotlight- the curious case of Ryuk ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat spotlight- the curious case of Ryuk ransomware
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor [CB19] Cyber Threat Landscape in Japan – Revealing Threat in the Shadow by Chi En Shen (Ashley) Oleg Bondarenko
-
The original link failed its last check. Original publisher Detailsfor Aarhus_miniseminar_291118.pdf
-
WIZARD SPIDER Adds New Features to Ryuk for Targeting Hosts on LAN
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor WIZARD SPIDER Adds New Features to Ryuk for Targeting Hosts on LAN
-
Deobfuscating Ostap- TrickBot’s 34,000 Line JavaScript Downloader
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Deobfuscating Ostap- TrickBot’s 34,000 Line JavaScript Downloader
-
TrickBot Modifications Target U.S. Mobile Users
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TrickBot Modifications Target U.S. Mobile Users
-
Trickbot Delivered via Highly Obfuscated JS File
The original link failed its last check. Original publisher Detailsfor Trickbot Delivered via Highly Obfuscated JS File
-
Threat Group Cards: A Threat Actor Encyclopedia
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Hunting and detecting Cobalt Strike
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hunting and detecting Cobalt Strike
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Inside Cybercrime Groups Harvesting Active Directory for Fun and Profit - Vitali Kremez
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Inside Cybercrime Groups Harvesting Active Directory for Fun and Profit - Vitali Kremez
-
mpressioncss_ta_report_2019.pdf
The original link failed its last check. Original publisher Detailsfor mpressioncss_ta_report_2019.pdf
-
Interception- Dissecting BokBot’s “Man in the Browser”
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Interception- Dissecting BokBot’s “Man in the Browser”
-
New Evidence Proves Ongoing WIZARD SPIDER - LUNAR SPIDER Collaboration
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Evidence Proves Ongoing WIZARD SPIDER - LUNAR SPIDER Collaboration
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2019GlobalThreatReport
-
PINCHY SPIDER Affiliates Adopt “Big Game Hunting” Tactics to Distribute GandCrab Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor PINCHY SPIDER Affiliates Adopt “Big Game Hunting” Tactics to Distribute GandCrab Ransomware
-
Quick Analysis of a Trickbot Sample with NSA's Ghidra SRE Framework
The original link failed its last check. Original publisher Detailsfor Quick Analysis of a Trickbot Sample with NSA's Ghidra SRE Framework
-
The original link failed its last check. Original publisher Detailsfor CrowdStrike_GTR_2019.pdf
-
“Sin”-ful SPIDERS- WIZARD SPIDER and LUNAR SPIDER Sharing the Same Web
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor “Sin”-ful SPIDERS- WIZARD SPIDER and LUNAR SPIDER Sharing the Same Web
-
Trickbot Adds Credential-Grabbing Capabilities
The original link failed its last check. Original publisher Detailsfor Trickbot Adds Credential-Grabbing Capabilities
-
A Nasty Trick- From Credential Theft Malware to Business Disruption
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Nasty Trick- From Credential Theft Malware to Business Disruption
-
Big Game Hunting with Ryuk- Another Lucrative Targeted Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Big Game Hunting with Ryuk- Another Lucrative Targeted Ransomware
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Big Game Hunting- The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware
-
Trickbot Shows Off New Trick: Password Grabber Module
The original link failed its last check. Original publisher Detailsfor Trickbot Shows Off New Trick: Password Grabber Module
-
Cutwail Spam Campaign Uses Steganography to Distribute URLZone
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cutwail Spam Campaign Uses Steganography to Distribute URLZone
-
Informe_Evoluci%C3%B3n_Trickbot.pdf
The original link failed its last check. Original publisher Detailsfor Informe_Evoluci%C3%B3n_Trickbot.pdf
-
TrickBot Banker Insights | NETSCOUT
The original link failed its last check. Original publisher Detailsfor TrickBot Banker Insights | NETSCOUT
Newest first. Details opens the report in Explore.