Malware Analysis Reports
Phishing for Codes: Russian Threat Actors Target Microsoft 365 OAuth Workflows
2025-04-22
Author: Charlie Gardner, Josh Duke, Matthew Meltzer, Sean Koessel, Steven Adair, Tom Lancaster
Multiple Russian Threat Actors Targeting Microsoft Device Code Authentication
2025-02-13
Author: Charlie Gardner, Steven Adair, Tom Lancaster
MMD-0068-2024 - "FHAPPI Campaign" (APT10) FreeHosting APT "PSploit" Poison Ivy
2024-06-19
Author: unixfreaxjp
CharmingCypress: Innovating Persistence
2024-02-13
Author: Ankur Saini, Callum Roxan, Charlie Gardner, Damien Cash
Charming Kitten Updates POWERSTAR with an InterPlanetary Twist
2023-06-28
Author: Ankur Saini, Charlie Gardner
Operation EmailThief: Active Exploitation of Zero-day XSS Vulnerability in Zimbra
2022-02-03
Author: Steven Adair, Thomas Lancaster
Suspected APT29 Operation Launches Election Fraud Themed Phishing Campaigns
2021-05-27
Author: Damien Cash, Josh Grunzweig, Matthew Meltzer, Sean Koessel, Steven Adair, Thomas Lancaster
Escaping the Microsoft Office Sandbox
2018-08-15
New Attack, Old Tricks
2017-02-06
PowerDuke: Widespread Post-Election Spear Phishing Campaigns Targeting Think Tanks and NGOs
2016-11-09
Author: Steven Adair
AVTOKYO 2013.5 - Threats of Kelihos, CookieBomb, RedKit's and its Bad Actor
2014-02-18
Author: unixfreaxjp