Aquatic Panda
Also reported as RedHotel, Charcoal Typhoon, TAG-22, Earth Lusca, Red Dev 10 and 10 other names. Linked to China by four sources.
Reports per quarter
Techniques seen in the last two years
- T1053.005 8 reports reports only
- T1057 7 reports reports only
- T1059.001 7 reports in ATT&CK
- T1082 7 reports in ATT&CK
- T1105 7 reports in ATT&CK
- T1059.003 6 reports in ATT&CK
- T1071.001 6 reports reports only
- T1140 5 reports reports only
- T1204.002 5 reports reports only
- T1566.001 5 reports reports only
Show all 272 techniques Show fewer
- T1005 4 reports in ATT&CK
- T1007 4 reports in ATT&CK
- T1016 4 reports reports only
- T1027 4 reports reports only
- T1033 4 reports in ATT&CK
- T1041 4 reports reports only
- T1087.001 4 reports reports only
- T1189 4 reports reports only
- T1482 4 reports reports only
- T1572 4 reports reports only
- T1003.001 3 reports in ATT&CK
- T1003.002 3 reports reports only
- T1018 3 reports reports only
- T1021.002 3 reports in ATT&CK
- T1046 3 reports reports only
- T1047 3 reports in ATT&CK
- T1055.002 3 reports reports only
- T1059 3 reports reports only
- T1059.005 3 reports reports only
- T1068 3 reports reports only
- T1069.002 3 reports reports only
- T1070.004 3 reports in ATT&CK
- T1083 3 reports reports only
- T1087.002 3 reports reports only
- T1095 3 reports reports only
- T1132.001 3 reports reports only
- T1136.001 3 reports reports only
- T1190 3 reports reports only
- T1219 3 reports reports only
- T1505.003 3 reports reports only
- T1518.001 3 reports in ATT&CK
- T1543.003 3 reports in ATT&CK
- T1555.003 3 reports reports only
- T1566 3 reports reports only
- T1566.002 3 reports reports only
- T1570 3 reports reports only
- T1573.001 3 reports reports only
- T1574.001 3 reports in ATT&CK
- T1583.001 3 reports reports only
- T1583.003 3 reports reports only
- T1583.004 3 reports reports only
- T1008 2 reports reports only
- T1012 2 reports reports only
- T1021.001 2 reports in ATT&CK
- T1027.009 2 reports reports only
- T1036 2 reports reports only
- T1036.005 2 reports in ATT&CK
- T1049 2 reports reports only
- T1055 2 reports reports only
- T1055.004 2 reports reports only
- T1056.001 2 reports reports only
- T1059.006 2 reports reports only
- T1059.007 2 reports reports only
- T1069.001 2 reports reports only
- T1071 2 reports reports only
- T1071.004 2 reports reports only
- T1072 2 reports reports only
- T1078 2 reports reports only
- T1090 2 reports reports only
- T1090.001 2 reports reports only
- T1098 2 reports reports only
- T1098.007 2 reports reports only
- T1104 2 reports reports only
- T1119 2 reports reports only
- T1124 2 reports reports only
- T1129 2 reports reports only
- T1133 2 reports reports only
- T1135 2 reports reports only
- T1136 2 reports reports only
- T1204 2 reports reports only
- T1217 2 reports reports only
- T1496 2 reports reports only
- T1505.004 2 reports reports only
- T1547.001 2 reports reports only
- T1548 2 reports reports only
- T1560 2 reports reports only
- T1560.001 2 reports in ATT&CK
- T1566.004 2 reports reports only
- T1567 2 reports reports only
- T1571 2 reports reports only
- T1573.002 2 reports reports only
- T1583 2 reports reports only
- T1584.004 2 reports reports only
- T1587.001 2 reports reports only
- T1590 2 reports reports only
- T1595 2 reports reports only
- T1595.002 2 reports in ATT&CK
- T1608 2 reports reports only
- T1608.001 2 reports reports only
- T1608.002 2 reports reports only
- T1608.006 2 reports reports only
- T1620 2 reports reports only
- T1649 2 reports reports only
- T1003 1 report reports only
- T1010 1 report reports only
- T1016.001 1 report reports only
- T1020 1 report reports only
- T1021 1 report in ATT&CK
- T1021.004 1 report in ATT&CK
- T1021.005 1 report reports only
- T1021.006 1 report reports only
- T1036.003 1 report reports only
- T1037 1 report reports only
- T1037.001 1 report reports only
- T1039 1 report reports only
- T1040 1 report reports only
- T1048 1 report reports only
- T1053 1 report reports only
- T1053.003 1 report reports only
- T1055.001 1 report reports only
- T1055.003 1 report reports only
- T1055.009 1 report reports only
- T1055.012 1 report reports only
- T1056 1 report reports only
- T1059.002 1 report reports only
- T1059.004 1 report in ATT&CK
- T1059.009 1 report reports only
- T1059.010 1 report reports only
- T1059.011 1 report reports only
- T1069 1 report reports only
- T1069.003 1 report reports only
- T1070 1 report reports only
- T1074 1 report reports only
- T1074.001 1 report reports only
- T1074.002 1 report reports only
- T1078.002 1 report in ATT&CK
- T1078.003 1 report reports only
- T1078.004 1 report reports only
- T1087 1 report in ATT&CK
- T1087.004 1 report reports only
- T1090.003 1 report reports only
- T1091 1 report reports only
- T1098.001 1 report reports only
- T1098.003 1 report reports only
- T1098.004 1 report reports only
- T1098.005 1 report reports only
- T1098.006 1 report reports only
- T1102 1 report reports only
- T1102.002 1 report reports only
- T1112 1 report in ATT&CK
- T1113 1 report reports only
- T1114 1 report reports only
- T1114.001 1 report reports only
- T1114.002 1 report reports only
- T1114.003 1 report reports only
- T1115 1 report reports only
- T1120 1 report reports only
- T1123 1 report reports only
- T1125 1 report reports only
- T1132 1 report reports only
- T1134 1 report reports only
- T1134.001 1 report reports only
- T1136.002 1 report reports only
- T1137 1 report reports only
- T1137.006 1 report reports only
- T1195 1 report reports only
- T1195.001 1 report reports only
- T1195.002 1 report reports only
- T1199 1 report reports only
- T1200 1 report reports only
- T1201 1 report reports only
- T1203 1 report reports only
- T1204.001 1 report reports only
- T1204.004 1 report reports only
- T1210 1 report reports only
- T1213 1 report reports only
- T1213.001 1 report reports only
- T1213.002 1 report reports only
- T1213.003 1 report reports only
- T1218.007 1 report reports only
- T1484 1 report reports only
- T1484.001 1 report reports only
- T1485 1 report reports only
- T1486 1 report reports only
- T1489 1 report reports only
- T1490 1 report reports only
- T1491.002 1 report reports only
- T1497 1 report reports only
- T1497.001 1 report reports only
- T1497.003 1 report reports only
- T1498 1 report reports only
- T1505 1 report reports only
- T1518 1 report reports only
- T1528 1 report reports only
- T1529 1 report reports only
- T1530 1 report reports only
- T1534 1 report reports only
- T1537 1 report reports only
- T1538 1 report reports only
- T1543 1 report reports only
- T1543.002 1 report reports only
- T1543.004 1 report reports only
- T1546 1 report reports only
- T1546.003 1 report reports only
- T1546.004 1 report reports only
- T1546.008 1 report reports only
- T1546.012 1 report reports only
- T1546.015 1 report reports only
- T1547 1 report reports only
- T1547.002 1 report reports only
- T1547.005 1 report reports only
- T1547.009 1 report reports only
- T1548.002 1 report reports only
- T1550 1 report reports only
- T1550.001 1 report reports only
- T1550.002 1 report in ATT&CK
- T1552 1 report reports only
- T1554 1 report reports only
- T1555 1 report reports only
- T1556 1 report reports only
- T1556.002 1 report reports only
- T1556.006 1 report reports only
- T1556.009 1 report reports only
- T1558.003 1 report reports only
- T1559 1 report reports only
- T1560.002 1 report reports only
- T1564.004 1 report reports only
- T1565 1 report reports only
- T1565.001 1 report reports only
- T1566.003 1 report reports only
- T1567.001 1 report reports only
- T1567.002 1 report reports only
- T1569 1 report reports only
- T1569.002 1 report reports only
- T1573 1 report reports only
- T1574 1 report reports only
- T1574.011 1 report reports only
- T1578 1 report reports only
- T1580 1 report reports only
- T1583.006 1 report reports only
- T1583.008 1 report reports only
- T1584 1 report reports only
- T1585 1 report reports only
- T1585.002 1 report reports only
- T1586.002 1 report reports only
- T1587 1 report reports only
- T1587.003 1 report reports only
- T1588 1 report reports only
- T1588.002 1 report in ATT&CK
- T1588.003 1 report reports only
- T1588.004 1 report reports only
- T1588.007 1 report reports only
- T1589.002 1 report reports only
- T1590.005 1 report reports only
- T1592 1 report reports only
- T1595.001 1 report reports only
- T1598 1 report reports only
- T1602 1 report reports only
- T1602.001 1 report reports only
- T1602.002 1 report reports only
- T1608.003 1 report reports only
- T1608.004 1 report reports only
- T1608.005 1 report reports only
- T1613 1 report reports only
- T1614 1 report reports only
- T1614.001 1 report reports only
- T1615 1 report reports only
- T1619 1 report reports only
- T1622 1 report reports only
- T1652 1 report reports only
- T1654 1 report in ATT&CK
- T1657 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2008-3431 KEV
- CVE-2012-0151 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-5469
- CVE-2012-5687
- CVE-2013-3900 KEV
- CVE-2013-5947
- CVE-2014-0160 KEV
- CVE-2014-0346
- CVE-2014-1225
- CVE-2014-1812 KEV ransomware
- CVE-2014-2962
Show all 222 CVEs Show fewer
- CVE-2014-4019
- CVE-2014-4113 KEV
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-2051 KEV
- CVE-2015-7248
- CVE-2015-7254
- CVE-2016-0167 KEV ransomware
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-10271 KEV ransomware
- CVE-2017-1099
- CVE-2017-11774 KEV
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-12149 KEV ransomware
- CVE-2017-12824
- CVE-2017-15399
- CVE-2017-15944 KEV
- CVE-2017-5638 KEV ransomware
- CVE-2017-6327 KEV
- CVE-2017-6328
- CVE-2017-8291 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2017-9805 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-0824 KEV
- CVE-2018-10561 KEV
- CVE-2018-1207
- CVE-2018-13379 KEV ransomware
- CVE-2018-15961 KEV
- CVE-2018-15982 KEV ransomware
- CVE-2018-4878 KEV ransomware
- CVE-2018-7600 KEV ransomware
- CVE-2018-7602 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8581 KEV ransomware
- CVE-2018-8611 KEV
- CVE-2018-8639 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0803 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-11580 KEV ransomware
- CVE-2019-1458 KEV ransomware
- CVE-2019-16098
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-16920 KEV
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-3396 KEV ransomware
- CVE-2019-3398 KEV
- CVE-2019-8394 KEV
- CVE-2019-9489
- CVE-2019-948919
- CVE-2019-9621 KEV
- CVE-2020-0601 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0787 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-10198
- CVE-2020-1040 KEV
- CVE-2020-10826
- CVE-2020-10827
- CVE-2020-116511
- CVE-2020-11652 KEV
- CVE-2020-11899 KEV
- CVE-2020-1350 KEV
- CVE-2020-13756
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-14750 KEV
- CVE-2020-14882 KEV
- CVE-2020-1599
- CVE-2020-2021 KEV ransomware
- CVE-2020-3125
- CVE-2020-3529
- CVE-2020-35730 KEV
- CVE-2020-5902 KEV ransomware
- CVE-2020-6789
- CVE-2020-7961 KEV
- CVE-2020-8243 KEV
- CVE-2020-8260 KEV
- CVE-2020-8468 KEV
- CVE-2020-846820
- CVE-2020-8515 KEV
- CVE-2021-1636
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-1844
- CVE-2021-1879 KEV
- CVE-2021-20016 KEV ransomware
- CVE-2021-21166 KEV
- CVE-2021-21972 KEV ransomware
- CVE-2021-22205 KEV ransomware
- CVE-2021-22893 KEV ransomware
- CVE-2021-22894 KEV
- CVE-2021-22899 KEV
- CVE-2021-22900 KEV
- CVE-2021-26084 KEV ransomware
- CVE-2021-26411 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-28310 KEV
- CVE-2021-30116 KEV ransomware
- CVE-2021-30551 KEV
- CVE-2021-31195
- CVE-2021-31196 KEV
- CVE-2021-31206
- CVE-2021-31207 KEV ransomware
- CVE-2021-3120710
- CVE-2021-3156 KEV
- CVE-2021-31955 KEV
- CVE-2021-31956 KEV
- CVE-2021-33742 KEV
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-345239
- CVE-2021-34527 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-36798
- CVE-2021-36934 KEV
- CVE-2021-36942 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-40449 KEV ransomware
- CVE-2021-40539 KEV ransomware
- CVE-2021-4104
- CVE-2021-41379 KEV ransomware
- CVE-2021-43936
- CVE-2021-440077
- CVE-2021-44077 KEV
- CVE-2021-44207 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-44515 KEV
- CVE-2021-44832
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-1040 KEV
- CVE-2022-21587 KEV ransomware
- CVE-2022-21882 KEV ransomware
- CVE-2022-22954 KEV ransomware
- CVE-2022-22957
- CVE-2022-22958
- CVE-2022-24086 KEV
- CVE-2022-24500
- CVE-2022-24521 KEV ransomware
- CVE-2022-24682 KEV ransomware
- CVE-2022-24934
- CVE-2022-26134 KEV ransomware
- CVE-2022-26809
- CVE-2022-26923 KEV
- CVE-2022-27924 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-27926 KEV
- CVE-2022-30190 KEV ransomware
- CVE-2022-30333 KEV ransomware
- CVE-2022-31199 KEV ransomware
- CVE-2022-37042 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41080 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2023-0669 KEV ransomware
- CVE-2023-21746
- CVE-2023-23397 KEV
- CVE-2023-27350 KEV ransomware
- CVE-2023-27532 KEV ransomware
- CVE-2023-27997 KEV ransomware
- CVE-2023-28461 KEV ransomware
- CVE-2023-32315 KEV
- CVE-2023-3466
- CVE-2023-3467
- CVE-2023-3519 KEV ransomware
- CVE-2023-36033 KEV
- CVE-2023-38831 KEV ransomware
- CVE-2023-45727 KEV
- CVE-2023-46805 KEV ransomware
- CVE-2023-48788 KEV ransomware
- CVE-2023-5631 KEV
- CVE-2024-0012 KEV ransomware
- CVE-2024-21413 KEV
- CVE-2024-21887 KEV ransomware
- CVE-2024-21893 KEV ransomware
- CVE-2024-21983
- CVE-2024-24919 KEV ransomware
- CVE-2024-27956
- CVE-2024-30051 KEV ransomware
- CVE-2024-3400 KEV ransomware
- CVE-2024-36401 KEV
- CVE-2024-42009 KEV
- CVE-2024-43451 KEV
- CVE-2024-4577 KEV ransomware
- CVE-2024-47575 KEV
- CVE-2024-6473
- CVE-2024-9474 KEV ransomware
- CVE-2025-2783 KEV
- CVE-2025-31324 KEV ransomware
- CVE-2025-55182 KEV ransomware
- CVE-2026-21236
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Earth Lusca - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Earth Lusca - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor NjRAT (Malware Family)
Show all 674 reports Show fewer
-
Team46 and TaxOff: two sides of the same coin
The original link failed its last check. Original publisher Detailsfor Team46 and TaxOff: two sides of the same coin
-
Staying ahead of threat actors in the age of AI _ Microsoft Security Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Staying ahead of threat actors in the age of AI _ Microsoft Security Blog
-
PwC Cyber Threats 2022: A Year in Retrospect.pdf
The original link failed its last check. Original publisher Detailsfor PwC Cyber Threats 2022: A Year in Retrospect.pdf
-
Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
The original link failed its last check. Original publisher Detailsfor Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Russian Ransomware C2 Network Discovered in Censys Data
The original link failed its last check. Original publisher Detailsfor Russian Ransomware C2 Network Discovered in Censys Data
-
BRONZE STARLIGHT Ransomware Operations Use HUI Loader
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BRONZE STARLIGHT Ransomware Operations Use HUI Loader
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Legitimate Sites used as Cobalt Strike C2s against Indian Government
The original link failed its last check. Original publisher Detailsfor Legitimate Sites used as Cobalt Strike C2s against Indian Government
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor 2021trends.pdf
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ShadowPad Malware Analysis
-
ShadowPad Malware Analysis _ Secureworks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ShadowPad Malware Analysis _ Secureworks
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2022GTR
-
VMware Exposing Malware In Linux Based Multi Cloud Environments
The original link failed its last check. Original publisher Detailsfor VMware Exposing Malware In Linux Based Multi Cloud Environments
-
Delving Deep: An Analysis of Earth Lusca's Operations
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Delving Deep: An Analysis of Earth Lusca's Operations
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt
-
Winnti is Coming - Evolution after Prosecution@HITCON2021
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Winnti is Coming - Evolution after Prosecution@HITCON2021
-
Chasing Shadows- A deep dive into the latest obfuscation methods being used by ShadowPad
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chasing Shadows- A deep dive into the latest obfuscation methods being used by ShadowPad
-
sneak-peek-ch1-2-finding-beacons-in-the-dark.pdf
The original link failed its last check. Original publisher Detailsfor sneak-peek-ch1-2-finding-beacons-in-the-dark.pdf
-
Masters of Mimicry: new APT group ChamelGang and its arsenal
The original link failed its last check. Original publisher Detailsfor Masters of Mimicry: new APT group ChamelGang and its arsenal
-
Masters of Mimicry: new APT group ChamelGang and its arsenal
The original link failed its last check. Original publisher Detailsfor Masters of Mimicry: new APT group ChamelGang and its arsenal
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
APT_trends_report_Q2_2021_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2021_Securelist
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Shadowpad
-
report-old-dogs-new-tricks.pdf
The original link failed its last check. Original publisher Detailsfor report-old-dogs-new-tricks.pdf
-
Ryuk Ransomware Now Targeting Webservers
The original link failed its last check. Original publisher Detailsfor Ryuk Ransomware Now Targeting Webservers
-
InSideCopy: How this APT continues to evolve its arsenal
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor InSideCopy: How this APT continues to evolve its arsenal
-
Looks like the page you're looking for doesn't exist or has moved.
The original link failed its last check. Original publisher Detailsfor Looks like the page you're looking for doesn't exist or has moved.
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CTIR_casestudy_2.pdf
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CTIR_casestudy_1.pdf
-
the-operations-of-winnti-group.pdf
The original link failed its last check. Original publisher Detailsfor the-operations-of-winnti-group.pdf
-
report-bb-2021-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor report-bb-2021-threat-report.pdf
-
Technical Analysis of Operation Diànxùn
The original link failed its last check. Original publisher Detailsfor Technical Analysis of Operation Diànxùn
-
Intezer-2020-Go-Malware-Round-Up.pdf
The original link failed its last check. Original publisher Detailsfor Intezer-2020-Go-Malware-Round-Up.pdf
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
2020-q2-spamhaus-botnet-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor 2020-q2-spamhaus-botnet-threat-report.pdf
-
In-Memory shellcode decoding to evade AVs/EDRs
The original link failed its last check. Original publisher Detailsfor In-Memory shellcode decoding to evade AVs/EDRs
-
Catching APT41 exploiting a zero-day vulnerability
The original link failed its last check. Detailsfor Catching APT41 exploiting a zero-day vulnerability
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor [CB19] Cyber Threat Landscape in Japan – Revealing Threat in the Shadow by Chi En Shen (Ashley) Oleg Bondarenko
-
The original link failed its last check. Original publisher Detailsfor Aarhus_miniseminar_291118.pdf
-
mpressioncss_ta_report_2019.pdf
The original link failed its last check. Original publisher Detailsfor mpressioncss_ta_report_2019.pdf
-
AutoIt-Compiled Worm Sends Fileless BLADABINDI/njRAT
The original link failed its last check. Original publisher Detailsfor AutoIt-Compiled Worm Sends Fileless BLADABINDI/njRAT
Newest first. Details opens the report in Explore.