SWEED
Also reported as Sweed.
Reports per quarter
Techniques seen in the last two years
- T1059.001 3 reports
- T1566.001 3 reports
- T1005 2 reports
- T1027 2 reports
- T1027.002 2 reports
- T1036 2 reports
- T1048.003 2 reports
- T1055.012 2 reports
- T1059.007 2 reports
- T1071 2 reports
Show all 46 techniques Show fewer
- T1082 2 reports
- T1555.003 2 reports
- T1003 1 report
- T1016 1 report
- T1027.010 1 report
- T1041 1 report
- T1055 1 report
- T1055.002 1 report
- T1057 1 report
- T1059.003 1 report
- T1106 1 report
- T1112 1 report
- T1114 1 report
- T1204.001 1 report
- T1204.002 1 report
- T1485 1 report
- T1489 1 report
- T1491 1 report
- T1497.001 1 report
- T1539 1 report
- T1543 1 report
- T1546.015 1 report
- T1552 1 report
- T1566.002 1 report
- T1573 1 report
- T1574.001 1 report
- T1583.001 1 report
- T1583.003 1 report
- T1583.004 1 report
- T1584.001 1 report
- T1588.001 1 report
- T1591 1 report
- T1591.002 1 report
- T1608.001 1 report
- T1620 1 report
- T1657 1 report
Counts come from technique IDs in the actor's report text.
CVEs named in reports
- CVE-2012-0158 KEV ransomware
- CVE-2012-5469
- CVE-2012-5687
- CVE-2013-5947
- CVE-2014-0160 KEV
- CVE-2014-0346
- CVE-2014-1225
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
Show all 61 CVEs Show fewer
- CVE-2015-2051 KEV
- CVE-2015-7036
- CVE-2015-7248
- CVE-2015-7254
- CVE-2016-0189 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-11822
- CVE-2017-11882 KEV ransomware
- CVE-2017-12824
- CVE-2017-15399
- CVE-2017-8291 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-10561 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-8457
- CVE-2019-8577
- CVE-2019-8598
- CVE-2019-8600
- CVE-2019-8602
- CVE-2020-0688 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-10786
- CVE-2020-10787
- CVE-2020-10826
- CVE-2020-10827
- CVE-2020-13756
- CVE-2020-1472 KEV ransomware
- CVE-2020-1664
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2021-26411 KEV ransomware
- CVE-2021-31207 KEV ransomware
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-4044
- CVE-2021-40444 KEV ransomware
- CVE-2021-43936
- CVE-2021-44228 KEV ransomware
- CVE-2022-1096 KEV
- CVE-2022-24086 KEV
- CVE-2022-30190 KEV ransomware
- CVE-2023-38331
- CVE-2023-38831 KEV ransomware
- CVE-2025-55182 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Loki Password Stealer (PWS) (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Loki Password Stealer (PWS) (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Formbook (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Agent Tesla (Malware Family)
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
Show all 199 reports Show fewer
-
logpoint-etpr-a-comprehensive-overview-on-stealer-malware-families.pdf
The original link failed its last check. Original publisher Detailsfor logpoint-etpr-a-comprehensive-overview-on-stealer-malware-families.pdf
-
Spam trends campaigns senior superlatives 2023
The original link failed its last check. Original publisher Detailsfor Spam trends campaigns senior superlatives 2023
-
TLP-CLEAR-20230912-EN-GuLoader-Information-report.pdf
The original link failed its last check. Original publisher Detailsfor TLP-CLEAR-20230912-EN-GuLoader-Information-report.pdf
-
The original link failed its last check. Original publisher Detailsfor https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/trojanized-onenote-document-leads-to-formbook-malware/
-
2020-q2-spamhaus-botnet-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor 2020-q2-spamhaus-botnet-threat-report.pdf
-
CTNT_Q1_2020_COVID-Report_Final.pdf
The original link failed its last check. Original publisher Detailsfor CTNT_Q1_2020_COVID-Report_Final.pdf
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor [CB19] Cyber Threat Landscape in Japan – Revealing Threat in the Shadow by Chi En Shen (Ashley) Oleg Bondarenko
-
SWEED Targeting Precision Engineering Companies in Italy
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor SWEED Targeting Precision Engineering Companies in Italy
-
SWEED Targeting Precision Engineering Companies in Italy
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SWEED Targeting Precision Engineering Companies in Italy
-
SWEED- Exposing years of Agent Tesla campaigns
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SWEED- Exposing years of Agent Tesla campaigns
-
Comprehensive Threat Intelligence_ SWEED_ Exposing years of Agent Tesla campaigns
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Comprehensive Threat Intelligence_ SWEED_ Exposing years of Agent Tesla campaigns
-
The Formidable FormBook Form Grabber | NETSCOUT
The original link failed its last check. Original publisher Detailsfor The Formidable FormBook Form Grabber | NETSCOUT
-
The original link failed its last check. Original publisher Detailsfor GitHub - R3MRUM/loki-parse: A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security researchers who want to know what data is being exfiltrated to the C2, bot tracking, etc...
Newest first. Details opens the report in Explore.