Malware Analysis Reports
BrazenBamboo Weaponizes FortiClient Vulnerability to Steal VPN Credentials via DEEPDATA
2024-11-15
Author: Callum Roxan, Charlie Gardner, Paul Rascagneres
Analysis of Evolving Evasion Tradecraft in Commodity Malware and Command-and-Control Frameworks
2024-09-05
StormBamboo Compromises ISP to Abuse Insecure Software Update Mechanisms
2024-08-02
Author: Ankur Saini, Paul Rascagneres, Steven Adair, Thomas Lancaster
MMD-0069-2024 - An old ELF Ransomware pivoted crypto (OpenSSL to PolarSSL) Linux/Encoder.1-2
2024-06-19
Author: unixfreaxjp
MMD-0068-2024 - "FHAPPI Campaign" (APT10) FreeHosting APT "PSploit" Poison Ivy
2024-06-19
Author: unixfreaxjp
Detecting Compromise of CVE-2024-3400 on Palo Alto Networks GlobalProtect Devices
2024-05-15
Author: Volexity Threat Research
Zero-Day Exploitation of Unauthenticated Remote Code Execution Vulnerability in GlobalProtect (CVE-2024-3400)
2024-04-12
Author: Volexity Threat Research
CharmingCypress: Innovating Persistence
2024-02-13
Author: Ankur Saini, Callum Roxan, Charlie Gardner, Damien Cash
Ivanti Connect Secure VPN Exploitation: New Observations
2024-01-18
Author: Matthew Meltzer, Sean Koessel, Steven Adair