Cybervolk V2 Ftr

CyberVolk | A Deep Dive into the Hacktivists, Tools and Ransomware Fueling Pro-Russian Cyber Attacks

A loose collective of mostly low-skilled actors, CyberVolk absorbs and adapts a wide array of destructive malware for use against political targets.

Read More
DPRK Front V3 Ftr

DPRK IT Workers | A Network of Active Front Companies and Their Links to China

SentinelLabs has identified multiple deceptive websites linked to businesses in China fronting for North Korea's fake IT workers scheme.

Read More
BNThief Feature

BlueNoroff Hidden Risk | Threat Actor Targets Macs with Fake Crypto News and Novel Persistence

SentinelLabs has observed a suspected DPRK threat actor targeting Crypto-related businesses with novel multi-stage malware.

Read More
Cloud Workshop Blue Ftr

Cloud Malware | A Threat Hunter’s Guide to Analysis, Techniques and Delivery

Learn about cloud threats, how to hunt for them and how to analyze them in this post based on Alex Delamotte's recent LABScon workshop.

Read More
China Influence Feature

China’s Influence Ops | Twisting Tales of Volt Typhoon at Home and Abroad

China's CVERC attempts to attribute Volt Typhoon activities to the U.S., but the fact-free claims reveal much about the PRC's real agenda.

Read More
Kryptina Desert Ftr

Kryptina RaaS | From Unsellable Cast-Off to Enterprise Ransomware

Kryptina's adoption by Mallox affiliates complicates malware tracking as ransomware operators blend different codebases into new variants.

Read More
Zuzana Labscon23

LABScon23 Replay | They Spilled Oil in My Health-Boosting Smoothie

Zuzana Hromcová explores how Iran-aligned APT OilRig targets healthcare and local governments with a stream of updated and newly developed tools.

Read More
Exploring  VT Bus Ftr

Exploring the VirusTotal Dataset | An Analyst’s Guide to Effective Threat Research

Aleksandar Milenkoski & Jose Luis Sánchez Martínez (VirusTotal) /

We teamed up with VirusTotal to take a deep dive into the platform's extensive query capabilities through both the web and API interfaces.

Read More
Martin Wendiggensen LC23 Ftr

LABScon23 Replay | Black Magic – Influence Operations in the Open and At-Scale in Hungary

As electorates across the US and Europe go to the polls in 2024, this must-see talk on large-scale state influence operations could hardly be more timely or relevant.

Read More
Xeon Dive Bg

Xeon Sender | SMS Spam Shipping Multi-Tool Targeting SaaS Credentials

Cloud attack tool has been repurposed by multiple threat actors to push SMS spam and smishing campaigns through major SaaS providers.

Read More