|
You are here |
www.welivesecurity.com | ||
| | | | |
www.cybereason.com
|
|
| | | | | Cybereason GSOC observed distribution of the Bumblebee Loader and post-exploitation activities including privilege escalation, reconnaissance and credential theft. Bumblebee operators use the Cobalt Strike framework throughout the attack and abuse credentials for privilege escalation to access Active Directory, as well as abusing a domain administrator account to move laterally, create local user accounts and exfiltrate data... | |
| | | | |
lab52.io
|
|
| | | | | [AI summary] This post details the analysis of malware used by the Mustang Panda APT group, highlighting changes in encryption algorithms and command-and-control communication tactics. | |
| | | | |
synacktiv.com
|
|
| | | | | LinkPro: eBPF rootkit analysis | |
| | | | |
www.dragos.com
|
|
| | | Explore Dragos' Q1 2025 ransomware analysis for ICS/OT environments. Discover key trends, threat actors, and mitigation strategies for industrial networks. | ||