Skip to content
Bulwark Black Bulwark Black LLC
Threat Intel
  • Latest reporting
  • Russian CTI
  • Chinese CTI
  • North Korean CTI
  • Iranian CTI
  • Global / Anomalous
  • Malware
  • IOC / YARA downloads
Software
  • Contractor Codex ↗
  • SAMscout AI ↗
  • VA Disability Calc & Track
  • What we build
  • All software
Services
  • Websites & Web Apps
  • Custom iOS Apps
  • AI & Automation
  • Small-Business IT & Cybersecurity
Company
  • About
  • Community
  • Contact
IOC Extractor Indicators Feeds The Brief Blog
Threat Intel → Work with us →
All Threat Intel → Latest reporting Russian CTI Chinese CTI North Korean CTI Iranian CTI Global / Anomalous Malware IOC / YARA downloads
All Software → Contractor Codex ↗ SAMscout AI ↗ VA Disability Calc & Track What we build All software
All Services → Websites & Web Apps Custom iOS Apps AI & Automation Small-Business IT & Cybersecurity
All Company → About Community Contact
IOC Extractor Indicators Feeds The Brief Blog Work with us →
RSS
Latest
BINDCLOAK Shows Why C2 Detection Needs Message-Level VisibilityPasskey Attacks Show Why Passwordless Still Needs Endpoint DefenseDPRK npm Compromises Show Why Dependency Trust Is Now Identity RiskN-able N-central Exploitation Shows Why MSP Tools Are Control-Plane RiskHOLLOWGRAPH Shows Why Microsoft 365 Is Now Part of the C2 BattlefieldFuyao Android TV Botnet Shows Why Cheap Streaming Sticks Are Business Network RiskSonicWall SMA Exploit Chain Shows Why VPN Appliances Need Incident Response, Not Just PatchingAdform Script Compromise Shows Why Third-Party Tags Need Supply-Chain ControlsCaptiveCrunch Shows Why Travel Wi-Fi Is Now an Identity Attack SurfaceXCSSET v40 Shows Why Developer Macs Are Supply-Chain Infrastructure84 4G/5G Core Flaws Show Why Telecom Trust Zones Need Zero TrustAstaroth WhatsApp Web Spambot Shows Browser Sessions Are Distribution InfrastructureTA488 Turns Outlook Web Access Into a Stealthy Persistence LayerOpen Source Supply Chain Compromise Needs Build-Pipeline Defense, Not Just Dependency ScanningBINDCLOAK Shows Why C2 Detection Needs Message-Level VisibilityPasskey Attacks Show Why Passwordless Still Needs Endpoint DefenseDPRK npm Compromises Show Why Dependency Trust Is Now Identity RiskN-able N-central Exploitation Shows Why MSP Tools Are Control-Plane RiskHOLLOWGRAPH Shows Why Microsoft 365 Is Now Part of the C2 BattlefieldFuyao Android TV Botnet Shows Why Cheap Streaming Sticks Are Business Network RiskSonicWall SMA Exploit Chain Shows Why VPN Appliances Need Incident Response, Not Just PatchingAdform Script Compromise Shows Why Third-Party Tags Need Supply-Chain ControlsCaptiveCrunch Shows Why Travel Wi-Fi Is Now an Identity Attack SurfaceXCSSET v40 Shows Why Developer Macs Are Supply-Chain Infrastructure84 4G/5G Core Flaws Show Why Telecom Trust Zones Need Zero TrustAstaroth WhatsApp Web Spambot Shows Browser Sessions Are Distribution InfrastructureTA488 Turns Outlook Web Access Into a Stealthy Persistence LayerOpen Source Supply Chain Compromise Needs Build-Pipeline Defense, Not Just Dependency Scanning

Threat Intel·Malware·Jan 8, 2024·By Albert LaScola

Alert: Carbanak Malware Strikes Again With Updated Tactics

Alert: Carbanak Malware Strikes Again With Updated Tactics
Alert: Carbanak Malware Strikes Again With Updated Tactics

#Carbanak#Spear Phishing

← Older report

From Akamai to F5 to NTLM… with love.

Newer report →

NoName on Rampage! Claims DDoS Attacks on Ukrainian Government Sites

Next step

Want this turned into detection for your environment?

We build the defenses we write about: detection rules, hardening, and incident response for small businesses and government contractors. Or take the indicators above and run them yourself, every report ships with machine-readable downloads.

Work With Us →Get the IOC Feeds →

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

readers get The Brief

Double opt-in. One-click unsubscribe on every issue. We never share your address.

Bulwark Black

Veteran-Owned · SDVOSB

Bulwark Black LLC
Cyber threat intelligence, custom software, and remote tech help.
Remote across the United States.

Registered agent address (mailing only):
522 W Riverside Ave, Ste N
Spokane, WA 99201

Two front doors

  • Cyber Threat Intelligence
  • Indicator Database
  • Threat Feeds
  • Shared Infrastructure
  • Threat Alerts
  • The Brief
  • Tech Services & Apps

Services

  • Websites & Web Apps
  • Custom iOS Apps
  • AI & Automation
  • IT + Cybersecurity

Company

  • About
  • Software
  • VA Disability Calc & Track
  • Community
  • Blog
  • How I Work
  • Contact
  • Privacy
  • Terms
  • VA Calc Privacy Policy

For agencies & primes

  • Capability statement
  • CAGE: 17UL6
  • UEI: DVNTWBJ2HMP8
  • SDVOSB · SAM Registered

support@bulwarkblack.com

Connect

  • LinkedIn
  • GitHub

© 2026 Bulwark Black LLC. All rights reserved.

Privacy · Terms · Cookie choices

We use Google Analytics to measure site traffic, which sets cookies. No ads and no cross-site tracking. See our privacy policy.