The SessionManager IIS backdoor: a possibly overlooked GELSEMIUM artefactKaspersky Securelist·Jun 30, 08:00 UTC · Jun 30, 2022Malware42
CloudSorcerer APT uses cloud services and GitHub as C2Kaspersky Securelist·Jul 8, 07:00 UTC · Jul 8, 2024Malware142
PipeMagic in 2025: How the backdoor operators’ tactics have changedKaspersky Securelist·Aug 18, 09:00 UTC · Aug 18, 2025MalwareCVE-2025-29824CVE-2017-014447
CRAT wants to plunder your endpointsCisco Talos·Nov 12, 13:18 UTC · Nov 12, 2020MalwareCVE-2017-829147
“Red October”. Detailed Malware Description 4. Second Stage of AttackKaspersky Securelist·Jan 17, 16:06 UTC · Jan 17, 2013Malware42
GALLIUM Expands Targeting Across Telecommunications, Government and Finance Sectors With New PingPull ToolPalo Alto Unit 42·Jun 5, 20:24 UTC · Jun 5, 2024Malware42
Operation AppleJeus: Lazarus hits cryptocurrency exchange with fake installer and macOS malwareKaspersky Securelist·Aug 23, 08:00 UTC · Aug 23, 2018Malware42
HoneyMyte updates CoolClient backdoor, uses new data stealing toolsKaspersky Securelist·Jan 26, 19:27 UTC · Jan 26, 2026Malware42
RATs Spread Via Fake Skype, Zoom, Google Meet SitesInfosecurity Magazine·Mar 7, 17:00 UTC · Mar 7, 2024Malware55
OilRig Uses ISMDoor Variant; Possibly Linked to Greenbug Threat GroupPalo Alto Unit 42·Jan 10, 16:52 UTC · Jan 10, 2020Malware30
Nation-state actor uses new LookBack RAT to target US utilitiesSecurity Affairs·Aug 2, 16:50 UTC · Aug 2, 2019Malware42
MagicRAT: Lazarus’ latest gateway into victim networksCisco Talos·Sep 7, 12:01 UTC · Sep 7, 2022Malware42
LimeRAT malware delivered using 8-yearSecurity Affairs·Apr 1, 08:00 UTC · Apr 1, 2020MalwareCVE-2012-015835
ObliqueRAT returns with new campaign using hijacked websitesCisco Talos·Mar 2, 13:04 UTC · Mar 2, 2021Malware42
“Red October”. Detailed Malware Description 3. Second Stage of AttackKaspersky Securelist·Jan 17, 16:07 UTC · Jan 17, 2013Malware130
Aveo Malware Family Targets Japanese Speaking UsersPalo Alto Unit 42·Apr 27, 08:51 UTC · Apr 27, 2020Malware30
New version of MysterySnail RAT and lightweight MysteryMonoSnail backdoorKaspersky Securelist·Apr 17, 08:00 UTC · Apr 17, 2025MalwareCVE-2021-4044960
Chinese APT CL-STA-1062 Expands Attacks on Southeast Asian Critical Infrastructure With Custom MalwareSecurity Affairs·Jun 26, 17:16 UTC · Jun 26, 2026Malware55
FIN7 hacking group is switched to new techniques to evade detectionSecurity Affairs·Oct 10, 05:41 UTC · Oct 10, 2017Malware42
Google Stops Collecting Location Data from MapsSchneier on Security·Dec 26, 12:03 UTC · Dec 26, 2023Malware30
⚡ Weekly Recap: Double-Tap Skimmers, PromptSpy AI, 30Tbps DDoS, Docker Malware & MoreThe Hacker News·Feb 26, 11:25 UTC · Feb 26, 2026MalwareCVE-2026-22769CVE-2026-25926CVE-2026-26119+32 CVEs60
“Red October”. Detailed Malware Description 2. Second Stage of AttackKaspersky Securelist·Jan 17, 16:08 UTC · Jan 17, 2013Malware42
GhostContainer backdoor for Exchange serversKaspersky Securelist·Jul 17, 08:00 UTC · Jul 17, 2025MalwareCVE-2020-068847
Experts attribute NukeSped RAT to North KoreaSecurity Affairs·Oct 25, 06:49 UTC · Oct 25, 2019Malware42
T9000: Advanced Modular Backdoor Uses Complex AntiPalo Alto Unit 42·Nov 1, 10:04 UTC · Nov 1, 2018MalwareCVE-2012-1856CVE-2015-164160
Analyzing a variant of the GM Bot Android malwareSecurity Affairs·Jan 6, 21:22 UTC · Jan 6, 2017Malware30
OilRig uses RGDoor IIS Backdoor on Targets in the Middle EastPalo Alto Unit 42·Nov 1, 11:00 UTC · Nov 1, 2018Malware42
BBSRAT Attacks Targeting Russian Organizations Linked to Roaming TigerPalo Alto Unit 42·Nov 1, 09:59 UTC · Nov 1, 2018MalwareCVE-2012-015835
SIEM agent being used in SilentCryptoMiner attacksKaspersky Securelist·Oct 4, 08:00 UTC · Oct 4, 2024Malware30
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.jsThe Hacker News·Aug 4, 05:21 UTC · Aug 4, 2026Malware142
The EAGERBEE backdoor may be related to the CoughingDown actorKaspersky Securelist·Jan 6, 08:02 UTC · Jan 6, 2025Malware42
LilacSquid: The stealthy trilogy of PurpleInk, InkBox and InkLoaderCisco Talos·May 30, 12:01 UTC · May 30, 2024Malware42