Archive


Publications

Rootkit evolution

Malware reports

Malware Miscellany, July 2008


Malware descriptions

New Gpcode – mostly hot air

Incidents

Gpcode – here we go again

Incidents

Antivirus Fraudware Goes Mobile?


Incidents

Taking down botnets

Spam and phishing reports

Spam report: July 2008

Incidents

Social engineering on Twitter

Authors Categories Tags
  • Subscribe

  • Reports

    Focus on DroxiDat/SystemBC

    An unknown actor targeted an electric utility in southern Africa with Cobalt Strike beacons and DroxiDat, a new variant of the SystemBC payload. We speculate that this incident was in the initial stages of a ransomware attack.

    APT trends report Q2 2023

    This is our latest summary of the significant events and findings, focusing on activities that we observed during Q2 2023.

    Meet the GoldenJackal APT group. Don’t expect any howls

    GoldenJackal is an APT group, active since 2019, that usually targets government and diplomatic entities in the Middle East and South Asia. The main feature of this group is a specific toolset of .NET malware, JackalControl, JackalWorm, JackalSteal, JackalPerInfo and JackalScreenWatcher.

    Subscribe to our weekly e-mails

    The hottest research right in your inbox