Hacking Team
Linked to Italy by one source.
Reports per quarter
CVEs named in reports
- CVE-2008-2551
- CVE-2009-3129 KEV
- CVE-2010-0188 KEV ransomware
- CVE-2010-0840 KEV
- CVE-2010-1297 KEV
- CVE-2010-1424
- CVE-2010-2152
- CVE-2010-2568 KEV
- CVE-2010-2568224
- CVE-2010-3301
- CVE-2010-3333 KEV
- CVE-2010-3336
Show all 126 CVEs Show fewer
- CVE-2010-3653
- CVE-2010-3915
- CVE-2010-3916
- CVE-2011-0097
- CVE-2011-0611 KEV
- CVE-2011-1255
- CVE-2011-1331
- CVE-2011-1823 KEV
- CVE-2011-2462 KEV
- CVE-2011-3544 KEV
- CVE-2012-0056
- CVE-2012-0158 KEV ransomware
- CVE-2012-0507 KEV ransomware
- CVE-2012-1723 KEV ransomware
- CVE-2012-1889 KEV
- CVE-2012-6422
- CVE-2013-0074 KEV ransomware
- CVE-2013-0422 KEV ransomware
- CVE-2013-0640 KEV
- CVE-2013-0707
- CVE-2013-1331 KEV
- CVE-2013-1347 KEV
- CVE-2013-1493
- CVE-2013-2423 KEV
- CVE-2013-2460
- CVE-2013-2551 KEV ransomware
- CVE-2013-2729 KEV
- CVE-2013-3644
- CVE-2013-3893 KEV
- CVE-2013-3896 KEV
- CVE-2013-3897 KEV
- CVE-2013-3918 KEV
- CVE-2013-5330
- CVE-2013-5990
- CVE-2014-0497 KEV
- CVE-2014-0503
- CVE-2014-0751
- CVE-2014-0810
- CVE-2014-1510
- CVE-2014-1511
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-3393
- CVE-2014-3566
- CVE-2014-4076
- CVE-2014-4113 KEV
- CVE-2014-4114 KEV
- CVE-2014-6324 KEV
- CVE-2014-6332 KEV
- CVE-2014-7247
- CVE-2014-8730
- CVE-2015-0072
- CVE-2015-0096
- CVE-2015-0310 KEV
- CVE-2015-0311 KEV
- CVE-2015-0311222
- CVE-2015-0313 KEV
- CVE-2015-1641 KEV
- CVE-2015-1671 KEV
- CVE-2015-1692
- CVE-2015-1701 KEV ransomware
- CVE-2015-1770 KEV
- CVE-2015-2331
- CVE-2015-2387 KEV
- CVE-2015-2419 KEV
- CVE-2015-2424 KEV
- CVE-2015-2426 KEV
- CVE-2015-2545 KEV
- CVE-2015-2590 KEV
- CVE-2015-3043 KEV
- CVE-2015-3113 KEV
- CVE-2015-4902 KEV
- CVE-2015-5097
- CVE-2015-5119 KEV
- CVE-2015-5119220
- CVE-2015-5122 KEV
- CVE-2015-5122221
- CVE-2015-6585
- CVE-2015-7645 KEV ransomware
- CVE-2015-8651 KEV
- CVE-2016-0034 KEV ransomware
- CVE-2016-0147
- CVE-2016-0165 KEV
- CVE-2016-0167 KEV ransomware
- CVE-2016-0189 KEV ransomware
- CVE-2016-0984 KEV
- CVE-2016-1010 KEV
- CVE-2016-1019 KEV ransomware
- CVE-2016-4117 KEV ransomware
- CVE-2016-4171 KEV
- CVE-2016-4655 KEV
- CVE-2016-4656 KEV
- CVE-2016-4657 KEV
- CVE-2016-7836 KEV
- CVE-2017-0199 KEV ransomware
- CVE-2017-11774 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2017-12824
- CVE-2017-3197
- CVE-2017-8759 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-15982 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-2025036
- CVE-2018-8174 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2018-8611 KEV
- CVE-2019-3568 KEV
- CVE-2021-30860 KEV
- CVE-2021-31979 KEV
- CVE-2021-33771 KEV
- CVE-2022-0609 KEV
- CVE-2023-42793 KEV ransomware
- CVE-2025-2783 KEV
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
Show all 150 reports Show fewer
-
Lazarus Group, Hidden Cobra, Labyrinth Chollima
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Lazarus Group, Hidden Cobra, Labyrinth Chollima
-
Advanced Threat Research | Intel Security
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Threat Research | Intel Security
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Demonstrating_Hustle
-
APT Group Wekby Leveraging Adobe Flash Exploit (CVE-2015-5119) _ Volexity Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT Group Wekby Leveraging Adobe Flash Exploit (CVE-2015-5119) _ Volexity Blog
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Moisha Ransomware
-
CatalanGate Extensive Mercenary Spyware Operation against Catalans Using Pegasus and Candiru
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CatalanGate Extensive Mercenary Spyware Operation against Catalans Using Pegasus and Candiru
-
Karakurt Hacking Team Indicators of Compromise (IOC)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Karakurt Hacking Team Indicators of Compromise (IOC)
-
The hacker-for-hire industry is now too big to fail
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The hacker-for-hire industry is now too big to fail
-
Wir enthüllen den Staatstrojaner „Subzero“ aus Österreich
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Wir enthüllen den Staatstrojaner „Subzero“ aus Österreich
-
Pegasus vs. Predator- Dissident's Doubly-Infected iPhone Reveals Cytrox Mercenary Spyware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Pegasus vs. Predator- Dissident's Doubly-Infected iPhone Reveals Cytrox Mercenary Spyware
-
Sorveglianza- l’azienda italiana che vuole sfidare i colossi NSO e Palantir
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sorveglianza- l’azienda italiana che vuole sfidare i colossi NSO e Palantir
-
UEFI threats moving to the ESP- Introducing ESPecter bootkit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor UEFI threats moving to the ESP- Introducing ESPecter bootkit
-
UEFI threats moving to the ESP_ Introducing ESPecter bootkit _ WeLiveSecurity
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor UEFI threats moving to the ESP_ Introducing ESPecter bootkit _ WeLiveSecurity
-
From Pearl to Pegasus Bahraini Government Hacks Activists with NSO Group Zero-Click iPhone Exploits
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor From Pearl to Pegasus Bahraini Government Hacks Activists with NSO Group Zero-Click iPhone Exploits
-
Pegasus- The new global weapon for silencing journalists
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Pegasus- The new global weapon for silencing journalists
-
VisualDoor- SonicWall SSL-VPN Exploit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor VisualDoor- SonicWall SSL-VPN Exploit
-
Running in Circles Uncovering the Clients of Cyberespionage Firm Circles
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Running in Circles Uncovering the Clients of Cyberespionage Firm Circles
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor report-spark-bahamut
-
2020.10.05_-_MosaicRegressor_Lurking_in_the_Shadows_of_UEFI_Securelist_2020
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2020.10.05_-_MosaicRegressor_Lurking_in_the_Shadows_of_UEFI_Securelist_2020
-
MosaicRegressor- Lurking in the Shadows of UEFI
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MosaicRegressor- Lurking in the Shadows of UEFI
-
'World's Most Wanted Man' Involved in Bizarre Attempt to Buy Hacking Tools
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 'World's Most Wanted Man' Involved in Bizarre Attempt to Buy Hacking Tools
-
Molerats Delivers Spark Backdoor to Government and Telecommunications Organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Molerats Delivers Spark Backdoor to Government and Telecommunications Organizations
-
Rich Headers- leveraging this mysterious artifact of the PE format
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Rich Headers- leveraging this mysterious artifact of the PE format
-
APT cases exploiting vulnerabilities in region‑specific software
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT cases exploiting vulnerabilities in region‑specific software
-
Wikipedia Entry on Equation Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Wikipedia Entry on Equation Group
-
Researchers Say They Uncovered Uzbekistan Hacking Operations Due to Spectacularly Bad OPSEC
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Researchers Say They Uncovered Uzbekistan Hacking Operations Due to Spectacularly Bad OPSEC
-
Threat Group Cards: A Threat Actor Encyclopedia
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
From Hacking Team to hacked team to...-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor From Hacking Team to hacked team to...-
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET-LoJax
-
Hide and Seek- Tracking NSO Group’s Pegasus Spyware to Operations in 45 Countries
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hide and Seek- Tracking NSO Group’s Pegasus Spyware to Operations in 45 Countries
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor North Korean Regime-Backed Programmer Charged With Conspiracy to Conduct Multiple Cyber Attacks and Intrusions
-
Dissecting Operation Troy: Cyberespionage in South Korea White Paper
The original link failed its last check. Original publisher Detailsfor Dissecting Operation Troy: Cyberespionage in South Korea White Paper
-
New traces of Hacking Team in the wild
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New traces of Hacking Team in the wild
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sandvine’s PacketLogic Devices Used to Deploy Government Spyware in Turkey and Redirect Egyptian Users to Affiliate Ads-
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor BAD TRAFFIC_ Sandvine’s PacketLogic Devices Used to Deploy Government Spyware in Turkey and Redirect Egyptian Users to Affiliate Ads_
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor new-traces-hacking-team-wild
-
Champing at the Cyberbit Ethiopian Dissidents Targeted with New Commercial Spyware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Champing at the Cyberbit Ethiopian Dissidents Targeted with New Commercial Spyware
-
'DarkHotel' APT Uses New Methods to Target Politicians
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 'DarkHotel' APT Uses New Methods to Target Politicians
-
Open Source Malware - Sharing is caring?
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Open Source Malware - Sharing is caring?
-
Open Source Malware - Sharing is caring-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Open Source Malware - Sharing is caring-
-
McAfee Labs Quarterly Threat Report June 2017
The original link failed its last check. Original publisher Detailsfor McAfee Labs Quarterly Threat Report June 2017
-
The Deception Project: A New Japanese-Centric Threat
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor The Deception Project: A New Japanese-Centric Threat
-
The Deception Project- A New Japanese-Centric Threat
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Deception Project- A New Japanese-Centric Threat
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OurMine
-
Microsoft_Security_Intelligence_Report_Volume_21_English
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft_Security_Intelligence_Report_Volume_21_English
-
DHS-NCCIC - Malware Trends.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DHS-NCCIC - Malware Trends.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Million Dollar Dissident: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender - The Citizen Lab
-
lookout-pegasus-technical-analysis
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor lookout-pegasus-technical-analysis
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Shadow Brokers
-
us-16-Guarnieri-Anderson-Iran-And-The-Soft-War-For-Internet-Dominance-paper
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor us-16-Guarnieri-Anderson-Iran-And-The-Soft-War-For-Internet-Dominance-paper
-
En Route with Sednit Part 1: Approaching the Target
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor En Route with Sednit Part 1: Approaching the Target
-
Reverse-engineering DUBNIUM's Flash-targeting exploit
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Reverse-engineering DUBNIUM's Flash-targeting exploit
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor PowerPoint Presentation
-
Keep Calm and (Don’t) Enable Macros- A New Threat Actor Targets UAE Dissidents
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Keep Calm and (Don’t) Enable Macros- A New Threat Actor Targets UAE Dissidents
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Stealth Falcon
-
Operation C-Major Actors Also Used Android BlackBerry Mobile Spyware Against Targets
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Operation C-Major Actors Also Used Android BlackBerry Mobile Spyware Against Targets
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ghosts in the Endpoint
-
The original link failed its last check. Original publisher Detailsfor rpt-mtrends-2016.pdf
-
HPE - Cyber Risk Report - 2016.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor HPE - Cyber Risk Report - 2016.pdf
-
Cisco - Annual Security Report - 2016.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cisco - Annual Security Report - 2016.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Black Atlas Endangers In-Store Card Payments and SMBs Worldwide; Switches between BlackPOS and Other Tools
-
Operation Black Atlas: How Cybercriminals Used Gorynych Botnet, BlackPOS, and other Malware
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Black Atlas: How Cybercriminals Used Gorynych Botnet, BlackPOS, and other Malware
-
Packrat: Seven Years of a South American Threat Actor
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Packrat: Seven Years of a South American Threat Actor
-
Packrat_ Seven Years of a South American Threat Actor
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Packrat_ Seven Years of a South American Threat Actor
-
Packrat- Seven Years of a South American Threat Actor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Packrat- Seven Years of a South American Threat Actor
-
TDrop2 Attacks Suggest Dark Seoul Attackers Return - Palo Alto Networks BlogPalo Alto Networks Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor TDrop2 Attacks Suggest Dark Seoul Attackers Return - Palo Alto Networks BlogPalo Alto Networks Blog
-
Mapping FinFisher’s Continuing Proliferation
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Mapping FinFisher’s Continuing Proliferation
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Carbanak is packing new guns
-
Carbanak gang is back and packing new guns
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Carbanak gang is back and packing new guns
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Fancy Bear
-
New activity of The Blue Termite APT - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor New activity of The Blue Termite APT - Securelist
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Darkhotel's attacks in 2015
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor HTExploitTelemetry
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Darkhotel’s attacks in 2015
-
UPS- Observations on CVE-2015-3113, Prior Zero-Days and the Pirpi Payload
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor UPS- Observations on CVE-2015-3113, Prior Zero-Days and the Pirpi Payload
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Watering Hole Attack on Aerospace Firm Exploits CVE-2015-5122 to Install IsSpace Backdoor - Palo Alto Networks BlogPalo Alto Networks Blog
-
China Hacks the Peace Palace: All Your EEZ’s Are Belong to Us
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor China Hacks the Peace Palace: All Your EEZ’s Are Belong to Us
-
Watering Hole Attack on Aerospace Firm Exploits CVE-2015-5122 to Install IsSpace Backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Watering Hole Attack on Aerospace Firm Exploits CVE-2015-5122 to Install IsSpace Backdoor
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT Group UPS Targets US Government with Hacking Team Flash Exploit - Palo Alto Networks BlogPalo Alto Networks Blog
-
Sednit APT Group Meets Hacking Team
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sednit APT Group Meets Hacking Team
-
Spy Tech Company 'Hacking Team' Gets Hacked
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Spy Tech Company 'Hacking Team' Gets Hacked
-
When Governments Hack Opponents: A Look At Actors And Technology
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor When Governments Hack Opponents: A Look At Actors And Technology
-
Targeted Threat Index: Characterizing And Quantifying Politically-Motivated Targeted Malware
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Targeted Threat Index: Characterizing And Quantifying Politically-Motivated Targeted Malware
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor HackingTeam
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hacking Team
-
Dissecting Operation Troy: Cyberespionage In South Korea
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Dissecting Operation Troy: Cyberespionage In South Korea
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Syrian Electronic Army
Newest first. Details opens the report in Explore.