Skip to content
Friday, June 26, 2026
  • Turla’s STOCKSTAY Backdoor Shows Why Espionage Defense Needs Egress Visibility
  • StrikeShark Shows Loader Malware Is an Edge-Exposure Problem
  • MuddyWater’s Chaos Masquerade Shows Ransomware Response Needs Attribution Discipline
  • SocGholish Takedown Shows Website Trust Is Malware Infrastructure
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
  • Turla’s STOCKSTAY Backdoor Shows Why Espionage Defense Needs Egress Visibility
  • StrikeShark Shows Loader Malware Is an Edge-Exposure Problem
  • MuddyWater’s Chaos Masquerade Shows Ransomware Response Needs Attribution Discipline
  • SocGholish Takedown Shows Website Trust Is Malware Infrastructure
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
  • Home
  • Malware
  • Page 2

Malware

Editorial cybersecurity illustration showing global phishing, remote access tooling, and defensive monitoring for TA4922-style campaigns.
  • Chinese Cyber Threat Intelligence
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

TA4922’s Global Expansion Shows HR and Tax Lures Are Initial Access Infrastructure

acint3 weeks ago04 mins

Proofpoint’s TA4922 reporting shows how localized HR, payroll, tax, and invoice lures can become full initial-access infrastructure through DLL sideloading, loaders, RATs, RMM tools, and browser credential theft.

Read More
Editorial cybersecurity illustration of an npm supply-chain compromise moving through CI/CD pipelines and cloud credentials.
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

Red Hat’s Miasma npm Compromise Shows Trusted Publishing Is Not a Control Boundary

acint3 weeks ago05 mins

A Red Hat Cloud Services npm compromise shows why signed releases and trusted publishing must be paired with install-time controls, CI/CD isolation, and fast credential rotation.

Read More
Editorial illustration of AI-assisted ransomware tooling testing EDR evasion and Active Directory discovery workflows.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

AI-Assisted Ransomware Tooling Shows EDR Evasion Is Now an Iteration Problem

acint3 weeks ago04 mins

Sophos observed ransomware-linked operators using AI-assisted development workflows to accelerate EDR evasion testing and Active Directory discovery. The defensive lesson: validate controls, harden identity, and monitor behavior before attackers iterate around your tooling.

Read More
Cyber threat intelligence illustration of macOS malvertising delivering a FlutterShell backdoor through fake desktop applications.
  • Cyber Security Blog
  • General CTI
  • Malware

FlutterBridge Shows Why macOS Malvertising Is Backdoor Delivery, Not Just Adware

acint3 weeks ago04 mins

Unit 42’s FlutterBridge research shows macOS malvertising evolving from adware into FlutterShell backdoor delivery. Here is what SMBs and government contractors should tighten first.

Read More
Editorial cybersecurity illustration of Mustang Panda PlugX fake browser updater intrusion chain
  • Chinese Cyber Threat Intelligence
  • Cyber Security Blog
  • General CTI
  • Malware

Mustang Panda’s Fake Browser Updater Shows Why LNK Files Still Matter

acint3 weeks ago04 mins

Mustang Panda’s fake browser updater chain shows why defenders still need to hunt LNK-to-PowerShell execution, DLL sideloading, user-context persistence, and suspicious HTTPS beaconing.

Read More
Editorial cybersecurity illustration of FortiClient EMS exploitation delivering an infostealer through endpoint management workflows.
  • Cyber Security Blog
  • General CTI
  • Malware

FortiClient EMS Exploitation Turns Endpoint Management Into an Infostealer Delivery System

acint3 weeks ago03 mins

Attackers are abusing CVE-2026-35616 in FortiClient EMS to push a credential stealer through trusted endpoint management workflows. Here is what defenders should check first.

Read More
Abstract cybersecurity illustration of an information stealer moving endpoint data through webhook infrastructure.
  • Cyber Security Blog
  • General CTI
  • Malware

SolyxImmortal Shows Why Python Infostealers Are a Business Risk, Not Just Malware Noise

acint3 weeks ago04 mins

SolyxImmortal combines persistence, browser credential theft, document collection, screenshots, keylogging, and webhook exfiltration. Here is what SMB and government-contractor defenders should do about it.

Read More
Editorial cybersecurity illustration of telecom network intrusion using Linux and Windows backdoors with defender tracing covert proxy tunnels.
  • Chinese Cyber Threat Intelligence
  • Cyber Security Blog
  • General CTI
  • Malware

Showboat and JFMBackdoor Show Telecom Intrusions Are Built for Pivoting

acint4 weeks ago04 mins

Lumen and PwC reporting on Showboat, Red Lamassu, and JFMBackdoor shows how China-linked telecom intrusions combine Linux footholds, proxying, and Windows backdoors. Here is what SMBs and government contractors should harden now.

Read More
Abstract cybersecurity illustration of spear phishing delivering XenoRAT malware against government finance networks.
  • Cyber Security Blog
  • General CTI
  • Malware

SideCopy’s XenoRAT Campaign Shows Why Localized Lures Beat Generic Phishing Defenses

acint4 weeks ago04 mins

SideCopy/APT36 targeted Afghanistan finance officials with Pashto-language lures and XenoRAT. Here is what SMBs and government contractors should take from the campaign.

Read More
Editorial cybersecurity illustration of npm dependency confusion targeting developer and CI/CD environments.
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

Dependency Confusion Campaign Shows Reconnaissance Is the First Supply-Chain Payload

acint4 weeks ago03 mins

Microsoft found 33 malicious npm packages abusing dependency confusion to profile developer and build environments. The defender lesson: treat package installation as code execution and lock down internal namespace hygiene before attackers do reconnaissance at scale.

Read More
  • 1
  • 2
  • 3
  • 4
  • …
  • 10

File Search

2
ThumbNameSizeDate
Thumb IOCs_YARA_TTPs_Posted_Articles/ IOCs_YARA_TTPs_Posted_Articles

IOCs_YARA_TTPs_Posted_Articles

Open 99.71 KB 2024-01-12 January 12, 2024 2024-03-22 March 22, 2024
21 Items
99.71 KB
March 22, 2024

0

e6ea770770

2026 Powered By BlazeThemes.