2023-03-30 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
The 3CX VoIP Desktop Application has been compromised to deliver malware via legitimate 3CX updates. Huntress has been investigating this incident and working to validate and assess the current supply chain threat to the security community.
P0
2023-02-20 09:52 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Mobile banking users are being manipulated by attackers to authorize fraudulent transactions. Learn what financial service providers can do to render these organized crimes powerless.
P0
2023-02-17 07:57 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
What happens when you combine ransomware with information stealers, remote access Trojans, and other malware in one easy-to-download package?
P15
2022-12-21 13:38 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB discovers banking Trojan targeting users of more than 400 apps in 16 countries
P0
2022-10-24 07:31 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Analysis of months-long MajikPOS and Treasure Hunter campaign that infected dozens of terminals
P0
2022-08-11 15:39 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Detecting MaliBot, a fresh Android banking trojan, with a Fraud Protection solution
P0
2022-06-24 15:42 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Hunting the latest TTPs used for delivering the Trojan
P0
2022-04-26 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Sometimes hackers can be overly confident in their malware. Take a journey with us through a malware sample that contains no obfuscation whatsoever.
P0
2022-04-25 12:00 UTC
Government
UK NCSC Threat Reports · indexed 2026-08-15 18:50 UTC
A technical analysis of a new variant of the SparrowDoor malware.
P0
2022-03-08 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Unit 42 researchers disclosed several vulnerabilities and attack techniques in GKE Autopilot to Google, the root cause being insufficient verification of allowlisted workload image names. An attacker with permissions to create a pod could have abused these vulnerabilities to (1) escape their pod and compromise the underlying node, (2) escalate privileges and become full cluster administrators, and (3) covertly persist administrative access through backdoors that are completely invisible to clus…
P0
2022-03-01 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
We discovered malicious, targeted advanced persistent threat (APT) activity on a partner's system. Here, we dive into the BABYSHARK malware strain.
P0
2021-09-10 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Allows an attacker with privileges in the account to share resources outside of the account even when an org policy restricts this, thus enabling them to backdoor their access.
P0
2021-09-07 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In this blog, read along as we investigate a malicious foothold and decode the payload step by step.
P0
2021-08-17 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Join us on a threat analysis journey as we discover a very shady Python—and a very friendly RAT.
P0
2021-07-02 07:51 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
The reversing tale of GrimAgent malware used by Ryuk
P0
2021-06-15 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Dive into a threat analysis with us as we dissect a PowerShell command with an environmentally keyed malware payload.
P0
2021-05-25 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Join us for a threat hunting adventure as we analyze a suspicious run key that leads us to Cobalt Strike malware hidden across nearly 700 registry values.
P0
2021-05-04 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In this blog, we look at some malicious PowerShell code breadcrumbs that one hacker left behind to unravel how they maintained access during a cyberattack.
P0
2021-03-31 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A recap of hack_it 2021, a virtual security training event packed with interactive exercises, malware analysis, hacking workshops and more.
P0
2021-03-09 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Hackers always try to cover up their tracks. In this blog, we step through layers of obfuscation to uncover the real intent of a .NET malware sample.
P0
2021-02-09 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
To avoid detection, hackers often turn a system’s own tools against itself. Here, we examine a malicious payload that was executed using PowerShell.
P0
2021-01-12 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn manual malware analysis techniques used by threat researchers. Explore static & dynamic analysis, reverse engineering tools, and real-world investigation methods.
P0
2020-12-14 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress covers the breaking news about Solarwinds’ Orion platform being exploited as part of a coordinated attack to distribute malware.
P0
2020-12-07 09:23 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
A story about operators of JS-sniffer FakeSecurity distributing Raccoon stealer
P0
2020-11-24 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In this blog, we dissect a sample of malware that makes clever use of batch scripting obfuscation—turns out it was a launcher for TrickBot!
P0
2020-10-22 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A recap of hack_it 2020, a virtual security training event packed with interactive exercises, malware research and analysis, and more.
P0
2020-08-20 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
As a follow-up to our previous post, we recently uncovered a really peculiar piece of malware that works through a lot of different layers of abstraction.
P0
2020-07-05 13:51 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Top 11 books on digital forensics, incident response, and malware analysis
P0
2020-05-29 13:54 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
When ice burns through bank accounts
P0
2019-05-24 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
For 6 years, it was not possible to see what hosted zones an attacker may have created in an account. This issue could be viewed as a business decision that adding the ability to viewing this data was not worthwhile, but the delay is significant and would allow someone that had compromised an environment to maintain a backdoor.
P0