Meta tags:
Headings (most frequently used words):
obfuscated, files, or, information, command, obfuscation, procedure, examples, mitigations, detection, strategy, references, other, sub, techniques, of, 18,
Text of the page (most frequently used words):
retrieved (111), and (81), the (59), has (53), used (38), 2018 (35), powershell (34), base64 (34), 2020 (33), 2019 (33), #obfuscated (31), 2025 (30), scripts (29), obfuscation (29), commands (29), march (27), encoded (27), may (26), threat (26), october (25), 2021 (23), june (22), command (21), t1027 (21), 2023 (19), with (19), group (19), obfuscate (18), november (17), july (17), september (17), 2022 (17), january (16), april (16), february (15), malware (15), encoding (15), 2017 (14), new (14), 2024 (14), code (14), december (13), detection (12), techniques (12), august (12), using (12), for (12), targets (11), campaign (11), analysis (11), att (10), all (10), operation (10), invoke (10), muddywater (9), actors (9), enterprise (8), execution (8), files (8), exploitation (8), ransomware (8), during (8), can (8), xor (8), also (8), malicious (7), from (7), actor (7), sharepoint (7), via (7), strings (7), 2026 (6), use (6), software (6), microsoft (6), attack (6), into (6), its (6), apt (6), research (6), attacks (6), fin8 (6), middle (6), cobalt (6), tools (6), powersploit (6), targeting (6), team (6), information (6), emotet (6), encryption (6), payloads (6), executed (6), variables (6), ics (5), mobile (5), none (5), backdoor (5), security (5), 2016 (5), east (5), powerstats (5), phishing (5), medusa (5), machete (5), panda (5), bohannon (5), variable (5), line (5), script (5), environment (5), mitre (4), data (4), sub (4), well (4), fin7 (4), sidewinder (4), global (4), toolshell (4), cve (4), falcone (4), government (4), qakbot (4), post (4), framework (4), targeted (4), netwalker (4), iranian (4), their (4), through (4), empire (4), north (4), korean (4), gamaredon (4), comrat (4), javascript (4), string (4), that (4), such (4), characters (4), windows (4), encrypted (4), including (4), technique (4), compressed (4), within (4), version (4), adversaries (4), reference (3), campaigns (3), groups (3), cti (3), mitigations (3), defenses (3), tactics (3), block (3), contagious (3), interview (3), loader (3), report (3), tricks (3), ursnif (3), dive (3), turla (3), tsundere (3), botnet (3), payload (3), ta505 (3), sqlrat (3), silence (3), sibot (3), analyzing (3), vulnerabilities (3), trend (3), micro (3), exploit (3), sardonic (3), redline (3), stealer (3), quadagent (3), uses (3), operations (3), compromised (3), poetrat (3), public (3), play (3), patchwork (3), wocao (3), cuckoobees (3), deep (3), fileless (3), organizations (3), expands (3), your (3), activity (3), magic (3), hound (3), loudminer (3), leafminer (3), lazyscripter (3), peck (3), iceapple (3), wirte (3), based (3), frankenstein (3), spider (3), carr (3), fin6 (3), havoc (3), after (3), darkwatchman (3), chimera (3), key (3), carrotbat (3), badhatch (3), backconfig (3), astaroth (3), aquatic (3), apt32 (3), patterns (3), description (3), name (3), analyze (3), execute (3), file (3), character (3), compression (3), zlib (3), encode (3), various (3), input (3), c0021 (3), c0018 (3), 010 (3), smuggling (3), corporation (2), are (2), domains (2), resources (2), components (2), analytics (2), strategies (2), assets (2), matrices (2), core (2), objects (2), surface (2), reduction (2), asr (2), rules (2), potentially (2), brumaghin (2), banking (2), trojan (2), search (2), faou (2), evolution (2), macro (2), salem (2), inside (2), forensic (2), active (2), updated (2), zero (2), day (2), wild (2), under (2), intelligence (2), rise (2), disruptive (2), novel (2), lee (2), service (2), agency (2), black (2), lunghi (2), multi (2), stage (2), clearsky (2), cyber (2), ventura (2), sector (2), daniel (2), vpn (2), cyberespionage (2), continues (2), exploits (2), arsenal (2), adamitis (2), associated (2), updates (2), spear (2), mstic (2), symantec (2), response (2), espionage (2), iuzvyk (2), tim (2), drive (2), platforms (2), way (2), ukraine (2), carbon (2), military (2), game (2), mac (2), alive (2), open (2), cisa (2), ahl (2), you (2), activities (2), developers (2), likely (2), multiple (2), asia (2), attackers (2), antivirus (2), obfuscator (2), vbscript (2), references (2), shell (2), unusual (2), tokens (2), substitution (2), excessive (2), escape (2), strategy (2), analytic (2), antimalware (2), being (2), obfuscates (2), zeus (2), xorindex (2), wizard (2), names (2), ta551 (2), insertion (2), making (2), sharpstats (2), rc4 (2), sandworm (2), was (2), compress (2), roguerobin (2), replacement (2), powerpunch (2), hosts (2), phasejam (2), which (2), were (2), been (2), other (2), randomized (2), leveraged (2), embedded (2), machine (2), interpreter (2), victim (2), batchencryption (2), tool (2), koctopus (2), kimsuky (2), ironwind (2), junk (2), hexane (2), gold (2), southfield (2), fruitfly (2), fox (2), kitten (2), standard (2), stdin (2), arguments (2), macros (2), delivered (2), ability (2), exe (2), denis (2), cookieminer (2), apt19 (2), binary (2), difficult (2), more (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, poisoning, google, results, kirill, boychenko, escalates, npm, packages, dfir, ryuk, return, goody, nasty, trick, credential, theft, business, disruption, holland, comfoolery, how, evades, dumont, usage, ubiedo, blockchain, node, abused, emerging, duncan, valak, beginnings, mass, distribution, vilkomir, preisman, servhelper, variant, employs, excel, drop, signed, financial, enterprises, lolbins, platt, reeves, revisited, astra, panel, skulkin, dissecting, chm, performing, rewterz, hegel, perspective, nafisi, lelli, goldmax, goldfinder, nobelium, layered, persistence, unit, brief, kenin, exploited, servers, proactive, insights, 53770, 53771, eye, siege, 49706, 49704, disrupting, premises, budaca, goes, agile, cherepanov, telebots, killdisk, darkhydrus, mohansundaram, neil, tyagi, approach, oilrig, technology, provider, kenefick, basta, gang, infiltrates, networks, brute, ratel, strike, cyberint, horejsi, resurfaces, lebanon, oman, israeli, domain, two, powershellmafia, 2012, mercer, rascagneres, private, azerbaijan, evolves, spotlight, john, wolfram, josh, murchie, matt, lin, ainsworth, robert, wallace, dimiter, andonov, dhanesh, kizhakkinan, jacob, thompson, ivanti, connect, secure, untangling, dantzig, schamper, shining, light, one, china, hidden, hacking, cybereason, nocturnus, stealthy, winnti, szappanos, brandt, give, insight, victor, injected, reflective, loading, malhortra, turkish, users, pdfs, executables, peretz, theck, earth, vetala, target, adds, recent, blackwater, shows, signs, anti, kaspersky, lab, singh, procedures, lancaster, muddying, water, anthony, galiette, doel, santos, turning, stone, cybersecurity, infrastructure, aa25, 071a, stopransomware, evolving, trends, presentation, cyberwarcon, saudi, eset, just, got, sharper, venezuelan, institutions, cylance, cut, latam, malik, cross, platform, mining, cracked, vst, eastern, regions, jazi, double, rat, den, observed, exploiting, trusted, crowdstrike, internet, services, iis, kayal, lyceum, reborn, counterintelligence, check, point, hamas, affiliated, moves, tetra, defense, cause, effect, sodinokibi, rusnák, toolset, spy, hunter, shuckworm, foreign, mission, center, actinium, ukrainian, boutin, grows, patrick, wardle, cobble, together, source, pieces, monstrous, iran, martin, zugec, investigation, elovitz, know, enemy, financially, motivated, loui, reynolds, embraces, big, hunting, part, hunt, pursuing, enigmatic, evasive, criminal, visa, cybercrime, ecommerce, merchants, schroeder, warner, nelson, github, powershellempire, perez, latest, propagation, özarslan, christmas, card, never, wanted, wave, back, wreak, exploring, emerges, holidays, smith, stafford, chen, steals, cryptocurrency, exchanges, cookies, seongsu, park, pyongyang, payroll, remote, workers, west, securonix, kolesnikov, dev, popper, ryan, sherstobitoff, devops, employees, matej, havranek, deceptivedevelopment, freelance, ar20, 303a, agent, btz, ten, year, journey, gorelik, svajcer, personality, disorder, cycraft, skeleton, taiwan, semiconductor, vendors, grunzweig, wilhoit, fractured, deliver, southeast, defender, cyberattack, think, tanks, non, profits, unidentified, dunwoody, not, cozy, uncomfortable, examination, suspected, apt29, costa, raas, avoslocker, incident, venere, neal, avos, vrabie, returns, improved, toolkit, hinchliffe, south, legitimate, processes, steal, passwords, personal, wiley, overwatch, exposes, possession, log4shell, hands, intrusion, attempt, dahan, kitty, corporations, privileges, credentials, phished, request, counsel, dosfuscation, ackroyd, twitter, lead, evasion, lefevre, bashfuscator, obfuscators, about_powershell_exe, encodedcommand, red, canary, bromiley, monday, vbe, katz, catch, osascript, applescript, interpreters, runtime, reconstruction, an1396, leverage, chaining, piping, token, indicative, an1395, exhibiting, syntactic, concatenation, outlier, length, entropy, an1394, det0505, enable, 111, behavior, prevention, endpoint, m1040, consider, utilizing, scan, interface, amsi, processed, interpreted, m1049, mitigation, initial, 110, s0330, ascii, buffers, textdecoder, 109, s1248, 108, 107, g0102, conceal, chains, g0090, droppers, 106, s0386, salted, 3des, random, 105, out, encryptedscript, ps1, g0010, msi, installer, 104, s9034, configuration, 103, g0127, 102, 101, g0092, appear, contain, chinese, 100, s0390, g0091, g0121, s0589, s0450, c0058, gzip, s1085, rot13, aes, library, python, g0034, s0270, text, s1240, s0269, s0650, layer, blob, custom, s0223, contains, collection, scriptmodification, modules, s0194, s0685, pyminifier, s0428, g1040, s9014, crypto, g0040, c0014, c0012, layers, hexadecimal, functions, s0457, methods, vbscripts, g0069, dropped, kernel, drivers, known, safengine, shielden, mutations, then, virtual, g1051, g0059, pyobfuscate, some, visual, naming, combinations, letters, hinder, s0409, s0451, machines, g0077, perform, advanced, batch, g0140, s0669, g0094, s9029, s1022, g1001, utilized, 1900, s1229, g0115, g0047, executes, stores, perl, s0277, ran, c0001, avoid, g0117, g0061, fragmented, native, functionalities, g0046, g0037, s0363, documents, hide, urls, hosting, cmd, s0367, s0354, s0673, system, s0492, substitutions, g1052, orchestrator, registry, s0126, several, scriptlets, g0080, g0114, infected, host, s0462, s1081, decimal, vbs, s0475, parts, jscript, initiating, s0373, g0143, g0050, g0073, procedure, examples, live, permalink, last, modified, created, george, thomas, trukno, contributors, linux, macos, stealth, tactic, have, dosfucation, directory, traversals, invoked, voi, pcw, tei, system32, erool, wbem, wmic, shadowcopy, delete, example, abuse, syntax, utilizes, symbols, spacing, make, while, maintaining, same, intended, functionality, many, languages, support, built, form, url, manually, implement, splitting, order, casing, globing, involving, passing, streams, mkdir, tmp, nia, rev, dwssap, cte, tac, wor, application, content, impede, method, signature, this, type, included, interactively, scripting, compromise, invisible, unicode, 018, svg, 017, 016, 015, polymorphic, 014, 013, lnk, icon, 012, storage, 011, 009, stripped, 008, dynamic, api, resolution, 007, html, 006, indicator, removal, 005, compile, delivery, 004, steganography, 003, packing, 002, padding, 001, home, join, mclean, hotel, location, details, found, register, here, blog, contribute, benefactors, legal, branding, history, engage, advisory, council, learn, about, get, started, detections,
Text of the page (random words):
13 g0143 aquatic panda aquatic panda has encoded powershell commands in base64 14 s0373 astaroth astaroth has obfuscated and randomized parts of the jscript code it is initiating 15 s0475 backconfig backconfig has used compressed and decimal encoded vbs scripts 16 s1081 badhatch badhatch malicious powershell commands can be encoded with base64 17 c0018 c0018 during c0018 the threat actors used base64 to encode their powershell scripts 18 19 c0021 c0021 during c0021 the threat actors used encoded powershell commands 20 21 s0462 carrotbat carrotbat has the ability to execute obfuscated commands on the infected host 22 g0114 chimera chimera has encoded powershell commands 23 g0080 cobalt group cobalt group obfuscated several scriptlets and code used on the victim s machine including through use of xor and rc4 24 25 s0126 comrat comrat has used encryption and base64 to obfuscate its orchestrator code in the registry comrat has also used encoded powershell scripts 26 27 g1052 contagious interview contagious interview has obfuscated javascript code using base64 and variable substitutions 28 29 30 31 s0492 cookieminer cookieminer has used base64 encoding to obfuscate scripts on the system 32 s0673 darkwatchman darkwatchman has used base64 to encode powershell commands 33 s0354 denis denis has encoded its powershell commands in base64 13 s0367 emotet emotet has obfuscated macros within malicious documents to hide the urls hosting the malware cmd exe arguments and powershell scripts 34 35 36 37 s0363 empire empire has the ability to obfuscate commands using invoke obfuscation 38 g0037 fin6 fin6 has used encoded powershell commands 39 g0046 fin7 fin7 has used fragmented strings environment variables standard input stdin and native character replacement functionalities to obfuscate commands 6 40 41 g0061 fin8 fin8 has used environment variables and standard input stdin to obfuscate command line arguments fin8 also obfuscates malicious macros delivered as payloads 6 42 43 g0117 fox kitten fox kitten has base64 encoded scripts to avoid detection 44 c0001 frankenstein during frankenstein the threat actors ran encoded commands from the command line 45 s0277 fruitfly fruitfly executes and stores obfuscated perl scripts 46 g0047 gamaredon group gamaredon group has used obfuscated or encrypted scripts 47 48 49 50 g0115 gold southfield gold southfield has executed base64 encoded powershell scripts on compromised hosts 51 s1229 havoc havoc has utilized xor encryption with the key 01 01 1900 to obfuscate command strings 52 g1001 hexane hexane has used base64 encoded scripts 53 s1022 iceapple iceapple can use base64 and junk javascript code to obfuscate information 54 s9029 ironwind ironwind has used base64 encoding and xor encryption with the key 53 to obfuscate command strings 52 g0094 kimsuky kimsuky has encoded malicious powershell scripts using base64 55 s0669 koctopus koctopus has obfuscated scripts with the batchencryption tool 56 g0140 lazyscripter lazyscripter has leveraged the batchencryption tool to perform advanced batch script obfuscation and encoding techniques 56 g0077 leafminer leafminer obfuscated scripts that were used on victim machines 57 s0451 loudminer loudminer has obfuscated various scripts 58 s0409 machete machete has used pyobfuscate zlib compression and base64 encoding for obfuscation machete has also used some visual obfuscation techniques by naming variables as combinations of letters to hinder analysis 59 60 g0059 magic hound magic hound has used base64 encoded commands 61 62 g1051 medusa group medusa group has obfuscated powershell scripts with base64 encoding 63 medusa group has also obfuscated the code of dropped kernel drivers using a software known as safengine shielden which randomized the code through code mutations and then leveraged an embedded virtual machine interpreter to execute the code 64 g0069 muddywater muddywater has used daniel bohannon s invoke obfuscation framework and obfuscated powershell scripts 65 12 the group has also used other obfuscation methods including base64 obfuscation of vbscripts and powershell commands 65 66 67 68 69 70 71 s0457 netwalker netwalker s powershell script has been obfuscated with multiple layers including base64 and hexadecimal encoding and xor encryption as well as obfuscated powershell functions and variables 72 73 c0012 operation cuckoobees during operation cuckoobees the threat actors executed an encoded vbscript file 74 c0014 operation wocao during operation wocao threat actors executed powershell commands which were encoded or compressed using base64 zlib and xor 75 g0040 patchwork patchwork has obfuscated a script with crypto obfuscator 76 s9014 phasejam phasejam has encoded commands with base64 77 g1040 play play has used base64 encoded powershell scripts for post exploit activities on compromised hosts 78 s0428 poetrat poetrat has pyminifier to obfuscate scripts 79 s0685 powerpunch powerpunch can use base64 encoded scripts 48 s0194 powersploit powersploit contains a collection of scriptmodification modules that compress and encode scripts and payloads 80 81 s0223 powerstats powerstats uses character replacement powershell environment variables and xor encoding to obfuscate code powerstats s backdoor code is a multi layer obfuscated encoded and compressed blob 66 82 powerstats has used powershell code with custom string obfuscation 83 s0650 qakbot qakbot can use obfuscated and encoded scripts 84 85 s0269 quadagent quadagent was likely obfuscated using invoke obfuscation 86 12 s1240 redline stealer redline stealer has obfuscated scripts within text files used in execution 87 s0270 roguerobin the powershell script with the roguerobin payload was obfuscated using the compress technique in invoke obfuscation 88 12 g0034 sandworm team sandworm team has used rot13 encoding aes encryption and compression with the zlib library for their python based backdoor 89 s1085 sardonic sardonic powershell scripts can be encrypted with rc4 and compressed using gzip 90 c0058 sharepoint toolshell exploitation during sharepoint toolshell exploitation threat actors executed base64 encoded powershell commands 91 92 93 94 95 s0450 sharpstats sharpstats has used base64 encoding and xor to obfuscate powershell scripts 83 s0589 sibot sibot has obfuscated scripts used in execution 96 g0121 sidewinder sidewinder has used base64 encoding for scripts 97 98 g0091 silence silence has used environment variable string substitution for obfuscation 99 s0390 sqlrat sqlrat has used a character insertion obfuscation technique making the script appear to contain chinese characters 100 g0092 ta505 ta505 has used base64 encoded powershell commands 101 102 g0127 ta551 ta551 has used obfuscated variable names in a javascript configuration file 103 s9034 tsundere botnet tsundere botnet s msi installer has base64 encoded command execution 104 g0010 turla turla has used encryption including salted 3des via powersploit s out encryptedscript ps1 random variable names and base64 encoding to obfuscate powershell commands and payloads 105 s0386 ursnif ursnif droppers execute base64 encoded powershell commands 106 g0090 wirte wirte has xor encrypted command line strings to conceal malware execution chains 52 g0102 wizard spider wizard spider used base64 encoding to obfuscate an empire service and powershell commands 107 108 s1248 xorindex loader xorindex loader has obfuscated strings using ascii buffers and textdecoder 109 s0330 zeus panda zeus panda obfuscates the macro commands in its initial payload 110 mitigations id mitigation description m1049 antivirus antimalware consider utilizing the antimalware scan interface amsi on windows 10 to analyze commands after being processed interpreted m1040 behavior prevention on endpoint on windows 10 enable attack surface reduction asr rules to block execution of potentially obfuscated scripts 111 detection strategy id name analytic id analytic description det0505 detection strategy for command obfuscation an1394 detection of command line activity exhibiting syntactic obfuscation patterns such as excessive escape characters base64 encoding command concatenation or outlier command length and entropy an1395 detection of shell commands that leverage encoded execution command chaining excessive piping or unusual token patterns indicative of obfuscation an1396 detection of obfuscated commands via shell osascript or applescript interpreters using unusual tokens encoding variable substitution or runtime string reconstruction references katz o 2020 october 26 catch me if you can javascript obfuscation retrieved march 17 2023 bromiley m 2016 december 27 malware monday vbscript and vbe files retrieved march 17 2023 red canary n d 2022 threat detection report powershell retrieved march 17 2023 microsoft 2023 february 8 about_powershell_exe encodedcommand retrieved march 17 2023 lefevre a n d bashfuscator command obfuscators retrieved march 17 2023 bohannon d carr n 2017 june 30 obfuscation in the wild targeted attackers lead the way in evasion techniques retrieved february 12 2018 ackroyd r 2023 march 24 twitter retrieved september 12 2024 bohannon d 2018 march 19 invoke dosfuscation retrieved march 17 2023 bohannon d 2016 september 24 invoke obfuscation retrieved march 17 2023 ahl i 2017 june 06 privileges and credentials phished at the request of counsel retrieved may 17 2018 carr n 2017 may 14 cyber espionage is alive and well apt32 and the threat to global corporations retrieved june 18 2017 bohannon d 2017 march 13 invoke obfuscation powershell obfuscator retrieved june 18 2017 dahan a 2017 operation cobalt kitty retrieved december 27 2018 wiley b et al 2021 december 29 overwatch exposes aquatic panda in possession of log4shell exploit tools during hands on intrusion attempt retrieved january 18 2022 salem e 2019 february 13 astaroth malware uses legitimate os and antivirus processes to steal passwords and personal data retrieved april 17 2019 hinchliffe a and falcone r 2020 may 11 updated backconfig malware targeting government and military organizations in south asia retrieved june 17 2020 vrabie v et al 2021 march 10 fin8 returns with improved badhatch toolkit retrieved september 8 2021 venere g neal c 2022 june 21 avos ransomware group expands with new attack arsenal retrieved january 11 2023 costa f 2022 may 1 raas avoslocker incident response analysis retrieved january 11 2023 dunwoody m et al 2018 november 19 not so cozy an uncomfortable examination of a suspected apt29 phishing campaign retrieved november 27 2018 microsoft defender research team 2018 december 3 analysis of cyberattack on u s think tanks non profits public sector by unidentified attackers retrieved april 15 2019 grunzweig j and wilhoit k 2018 november 29 the fractured block campaign carrotbat used to deliver malware targeting southeast asia retrieved june 2 2020 cycraft 2020 april 15 apt group chimera apt operation skeleton key targets taiwan semiconductor vendors retrieved august 24 2020 svajcer v 2018 july 31 multiple cobalt personality disorder retrieved september 5 2018 gorelik m 2018 october 08 cobalt group 2 0 retrieved november 5 2018 faou m 2020 may from agent btz to comrat v4 a ten year journey retrieved june 15 2020 cisa 2020 october 29 malware analysis report ar20 303a retrieved december 9 2020 matej havranek 2025 february 20 deceptivedevelopment targets freelance developers retrieved october 17 2025 ryan sherstobitoff 2024 october 29 inside a north korean phishing operation targeting devops employees retrieved october 20 2025 securonix threat research d iuzvyk t peck o kolesnikov 2024 april 24 analysis of dev popper new attack campaign targeting software developers likely associated with north korean threat actors retrieved october 20 2025 seongsu park 2024 november 4 from pyongyang to your payroll the rise of north korean remote workers in the west retrieved october 17 2025 chen y et al 2019 january 31 mac malware steals cryptocurrency exchanges cookies retrieved july 22 2020 smith s stafford m 2021 december 14 darkwatchman a new evolution in fileless techniques retrieved january 10 2022 brumaghin e 2019 january 15 emotet re emerges after the holidays retrieved march 25 2019 trend micro 2019 january 16 exploring emotet s activities retrieved march 25 2019 özarslan s 2018 december 21 the christmas card you never wanted a new wave of emotet is back to wreak havoc retrieved march 25 2019 perez d 2018 december 28 analysis of the latest emotet propagation campaign retrieved april 16 2019 schroeder w warner j nelson m n d github powershellempire retrieved april 28 2016 visa public 2019 february fin6 cybercrime group expands threat to ecommerce merchants retrieved september 16 2019 carr n et al 2018 august 01 on the hunt for fin7 pursuing an enigmatic and evasive global criminal operation retrieved august 23 2018 loui e and reynolds j 2021 august 30 carbon spider embraces big game hunting part 1 retrieved september 20 2021 elovitz s ahl i 2016 august 18 know your enemy new financially motivated spear phishing group retrieved february 26 2018 martin zugec 2021 july 27 deep dive into a fin8 attack a forensic investigation retrieved september 1 2021 cisa 2020 september 15 iran based threat actor exploits vpn vulnerabilities retrieved december 21 2020 adamitis d et al 2019 june 4 it s alive threat actors cobble together open source pieces into monstrous frankenstein campaign retrieved may 11 2020 patrick wardle n d mac malware of 2017 retrieved september 21 2018 boutin j 2020 june 11 gamaredon group grows its game retrieved june 16 2020 microsoft threat intelligence center 2022 february 4 actinium targets ukrainian organizations retrieved february 18 2022 threat hunter team symantec and carbon black 2025 april 10 shuckworm targets foreign military mission based in ukraine retrieved july 23 2025 rusnák z 2024 september 26 cyberespionage the gamaredon way analysis of toolset used to spy on ukraine in 2022 and 2023 retrieved october 30 2024 tetra defense 2020 march cause and effect sodinokibi ransomware analysis retrieved november 17 2024 check point 2024 november 12 hamas affiliated threat actor wirte continues its middle east operations and moves to disruptive activity retrieved april 20 2026 kayal a et al 2021 october lyceum reborn counterintelligence in the middle east retrieved june 14 2022 crowdstrike 2022 may iceapple a novel internet information services iis post exploitation framework retrieved june 27 2022 den iuzvyk tim peck 2025 february 13 analyzing deep drive north korean threat actors observed exploiting trusted platforms for targeted attacks retrieved august 19 2025 jazi h 2021 february lazyscripter from empire to double rat retrieved november 17 2024 symantec security response 2018 july 25 leafminer new espionage campaigns targeting middle eastern regions retrieved august 28 2018 malik m 2019 june 20 loudminer cross platform mining in cracked vst software retrieved may 18 20...
|