Detecting evolving threats: NetSupport RAT campaignCisco Talos·Aug 1, 10:00 UTC · Aug 1, 2024Malware30
Gamaredon campaign abuses LNK files to distribute Remcos backdoorCisco Talos·Mar 28, 10:00 UTC · Mar 28, 2025Malware42
CloudZ RAT potentially steals OTP messages using Pheno pluginCisco Talos·May 5, 10:00 UTC · May 5, 2026Malware55
Newly identified wiper malware “PathWiper” targets critical infrastructure in UkraineCisco Talos·Jun 5, 10:00 UTC · Jun 5, 2025Malware55
Old certificate, new signature: Open-source tools forge signature timestamps on Windows driversCisco Talos·Jul 11, 17:04 UTC · Jul 11, 2023Malware55
DarkGate switches up its tactics with new payload, email templatesCisco Talos·Jun 5, 12:00 UTC · Jun 5, 2024Malware30
Rhadamanthys Stealer Adds Innovative AI Feature in Version 0.7.0Recorded Future·Aug 22, 00:00 UTC · Aug 22, 2025Malware55
Fake AV Investigation Unearths KevDroid, New Android MalwareCisco Talos·Apr 2, 15:48 UTC · Apr 2, 2018MalwareCVE-2015-3636CVE-2017-1188235
Some Snort discussion about Murofet, Kazy, or whatever we're calling it..Cisco Talos·Mar 7, 21:51 UTC · Mar 7, 2012Malware30
Gauss & FinFisher: The latest targeted malware everyone cares about.Cisco Talos·Aug 10, 20:29 UTC · Aug 10, 2012Malware30
Triggering Miniflame's C&C Communication to Create a PcapCisco Talos·Dec 11, 21:29 UTC · Dec 11, 2012Malware30
New VPNFilter malware targets at least 500K networking devices worldwideCisco Talos·May 23, 13:00 UTC · May 23, 2018Malware55
Threat Spotlight: AsyncRAT campaigns feature new version of 3LOSH crypterCisco Talos·Apr 5, 12:00 UTC · Apr 5, 2022Malware30
From CastleLoader to CastleRAT: TAG-150 Advances Operations with MultiRecorded Future·Jun 22, 00:00 UTC · Jun 22, 2025Malware30
IcedID Banking Trojan Teams up with Ursnif/Dreambot for DistributionCisco Talos·Apr 10, 20:12 UTC · Apr 10, 2018Malware42
GrayBravo’s CastleLoader Activity Clusters Target Multiple IndustriesRecorded Future·Oct 9, 00:00 UTC · Oct 9, 2025Malware30
MagicRAT: Lazarus’ latest gateway into victim networksCisco Talos·Sep 7, 12:01 UTC · Sep 7, 2022Malware42
Writing a BugSleep C2 server and detecting its traffic with SnortCisco Talos·Oct 30, 10:00 UTC · Oct 30, 2024Malware130
Threat Spotlight: PoSeidon, A Deep Dive Into Point of Sale MalwareCisco Talos·Mar 20, 11:57 UTC · Mar 20, 2015Malware30
Threat actors use copyright infringement phishing lure to deploy infostealersCisco Talos·Oct 31, 13:37 UTC · Oct 31, 2024Malware30
Famous Chollima deploying Python version of GolangGhost RATCisco Talos·Jun 18, 10:00 UTC · Jun 18, 2025Malware130
MaaS operation using Emmenhtal and Amadey linked to threats against Ukrainian entitiesCisco Talos·Jul 17, 10:00 UTC · Jul 17, 2025Malware30
Fake Cisco Job Posting Targets Korean CandidatesCisco Talos·Jan 30, 19:19 UTC · Jan 30, 2019Malware30
Operation Celestial Force employs mobile and desktop malware to target Indian entitiesCisco Talos·Jun 13, 10:00 UTC · Jun 13, 2024Malware42
UAT-7810 continues building ORB networks using new malwareCisco Talos·Jul 7, 10:00 UTC · Jul 7, 2026MalwareCVE-2020-22653CVE-2020-22658CVE-2023-25717+1 CVEs47
New open-source infostealer, and reflections on 2023 so farCisco Talos·Aug 31, 18:00 UTC · Aug 31, 2023Malware55
What you can learn from Cisco Talos’ new oil pumpjack workshopCisco Talos·Feb 11, 16:02 UTC · Feb 11, 2019Malware55
Mozilla's Guide to Privacy-Aware Christmas ShoppingSchneier on Security·Jan 27, 14:30 UTC · Jan 27, 2020Malware30