Skip to content
Thursday, June 4, 2026
  • Stock Exchange Mailbox Espionage Shows Executive Email Is Strategic Infrastructure
  • TA4922’s Global Expansion Shows HR and Tax Lures Are Initial Access Infrastructure
  • Red Hat’s Miasma npm Compromise Shows Trusted Publishing Is Not a Control Boundary
  • AI-Assisted Ransomware Tooling Shows EDR Evasion Is Now an Iteration Problem
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
  • Stock Exchange Mailbox Espionage Shows Executive Email Is Strategic Infrastructure
  • TA4922’s Global Expansion Shows HR and Tax Lures Are Initial Access Infrastructure
  • Red Hat’s Miasma npm Compromise Shows Trusted Publishing Is Not a Control Boundary
  • AI-Assisted Ransomware Tooling Shows EDR Evasion Is Now an Iteration Problem
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
Recent
  • Editorial cybersecurity illustration of executive mailbox espionage and cloud data exfiltration around a stock exchange.

    Stock Exchange Mailbox Espionage Shows Executive Email Is Strategic Infrastructure

    6 hours ago
  • Editorial cybersecurity illustration showing global phishing, remote access tooling, and defensive monitoring for TA4922-style campaigns.

    TA4922’s Global Expansion Shows HR and Tax Lures Are Initial Access Infrastructure

    11 hours ago
  • Editorial cybersecurity illustration of an npm supply-chain compromise moving through CI/CD pipelines and cloud credentials.

    Red Hat’s Miasma npm Compromise Shows Trusted Publishing Is Not a Control Boundary

    16 hours ago
  • Editorial illustration of AI-assisted ransomware tooling testing EDR evasion and Active Directory discovery workflows.

    AI-Assisted Ransomware Tooling Shows EDR Evasion Is Now an Iteration Problem

    1 day ago
  • Cyber threat intelligence illustration of macOS malvertising delivering a FlutterShell backdoor through fake desktop applications.

    FlutterBridge Shows Why macOS Malvertising Is Backdoor Delivery, Not Just Adware

    1 day ago
  • Editorial cybersecurity illustration of Mustang Panda PlugX fake browser updater intrusion chain

    Mustang Panda’s Fake Browser Updater Shows Why LNK Files Still Matter

    2 days ago
  • Editorial cybersecurity illustration of FortiClient EMS exploitation delivering an infostealer through endpoint management workflows.

    FortiClient EMS Exploitation Turns Endpoint Management Into an Infostealer Delivery System

    2 days ago
  • Editorial cybersecurity illustration of AI support bot account recovery abuse defended by passkeys and MFA

    Meta AI Support Bot Abuse Shows Account Recovery Is Part of the Identity Perimeter

    2 days ago
  • Abstract cybersecurity illustration of an information stealer moving endpoint data through webhook infrastructure.

    SolyxImmortal Shows Why Python Infostealers Are a Business Risk, Not Just Malware Noise

    3 days ago
  • Editorial cybersecurity illustration of telecom network intrusion using Linux and Windows backdoors with defender tracing covert proxy tunnels.

    Showboat and JFMBackdoor Show Telecom Intrusions Are Built for Pivoting

    3 days ago
  • Operational Technology (OT)

Iconics Suite SCADA Vulnerability Enables Denial-of-Service Through Privileged File Operations

acint4 months ago4 months ago02 mins

CVE-2025-0921 in Iconics Suite SCADA allows attackers to exploit privileged file operations to corrupt critical system binaries and crash Windows systems through symbolic link attacks.

Read More
  • Operational Technology (OT)

Global Energy Systems Exposed: Widespread Cybersecurity Gaps Found in Power Grid OT Networks

acint4 months ago4 months ago02 mins

A global study by OMICRON reveals critical cybersecurity weaknesses in power grid OT networks, including unpatched devices, weak segmentation, and asset blind spots that leave critical infrastructure vulnerable to attack.

Read More
  • General CTI

WinRAR CVE-2025-8088: Russia, China, and Cybercriminals Unite to Exploit Path Traversal Flaw

acint4 months ago02 mins

Google Threat Intelligence reveals widespread exploitation of CVE-2025-8088 by Russian APT groups, Chinese actors, and cybercriminals. The WinRAR path traversal flaw enables payload delivery via the Windows Startup folder, with active campaigns targeting Ukraine, LATAM, and financial sectors.

Read More
  • North Korean Cyber Threat Intelligence

North Korean Konni APT Deploys AI-Generated Malware to Target Blockchain Developers

acint4 months ago4 months ago02 mins

The North Korean threat group Konni has launched a new campaign using AI-generated PowerShell malware to target blockchain developers across the APAC region, marking a significant shift toward technical targets and cryptocurrency infrastructure.

Read More
  • General CTI

Microsoft to Disable 30-Year-Old NTLM Authentication Protocol by Default

acint4 months ago4 months ago02 mins

Microsoft announces NTLM will be disabled by default in upcoming Windows releases, marking the end of the 30-year-old authentication protocol that has been a persistent security vulnerability.

Read More
  • Operational Technology (OT)

CVE-2026-24061: 11-Year-Old GNU Telnetd Vulnerability Grants Instant Root Access

acint4 months ago03 mins

CVE-2026-24061 is a critical 11-year-old vulnerability in GNU InetUtils telnetd that allows unauthenticated attackers to gain instant root shell access. With a CVSS score of 9.8 and active exploitation confirmed, this flaw affects over 200,000 devices running Telnet servers globally, including embedded systems, IoT devices, and OT infrastructure.

Read More
Mobile device security concept with digital vulnerabilities
  • General CTI

Ivanti Patches Two Critical EPMM Zero-Day Vulnerabilities Under Active Exploitation

acint4 months ago02 mins

Two critical CVSS 9.8 vulnerabilities in Ivanti Endpoint Manager Mobile (CVE-2026-1281, CVE-2026-1340) are under active exploitation, allowing unauthenticated remote code execution. CISA has added them to the KEV catalog with a February 1 federal deadline.

Read More
  • General CTI

Ivanti EPMM Zero-Days Actively Exploited: Pre-Auth RCE via Bash Arithmetic Expansion

acint4 months ago4 months ago02 mins

Two actively exploited pre-auth RCE vulnerabilities (CVE-2026-1281 and CVE-2026-1340) in Ivanti Endpoint Manager Mobile allow attackers to execute arbitrary commands via Bash arithmetic expansion. CISA has added these to the KEV catalog.

Read More
  • Malware

Android Malware Campaign Abuses Hugging Face AI Platform to Distribute RAT

acint4 months ago4 months ago02 mins

Threat actors are abusing the Hugging Face AI platform to host Android malware, using server-side polymorphism to generate thousands of RAT variants every 15 minutes.

Read More
  • General CTI

SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score

acint4 months ago02 mins

SmarterTools patches critical CVE-2026-24423 (CVSS 9.3) unauthenticated RCE vulnerability in SmarterMail email server. Two other flaws including one under active exploitation also addressed. Update immediately.

Read More
  • 1
  • …
  • 23
  • 24
  • 25
  • 26
  • 27
  • …
  • 34

File Search

2
📁 Home → 📁 IOCs_YARA_TTPs_Posted_Articles ↓
ThumbNameSizeDate
Thumb AsyncRAT-loader-URL-Check.txt AsyncRAT loader URL Check.txt

text/plainAsyncRAT loader URL Check.txt

Open Download Copy Link 2.46 KB 2024-01-12 January 12, 2024 2024-01-07 January 7, 2024
2.46 KBJanuary 7, 2024
Thumb AsyncRAT-loader-hashes.txt AsyncRAT loader hashes.txt

text/plainAsyncRAT loader hashes.txt

Open Download Copy Link 662 B 2024-01-12 January 12, 2024 2024-01-07 January 7, 2024
662 BJanuary 7, 2024
Thumb Hackers-Modifying-Registry-Keys-to-Establish-Persistence-via-Scheduled-Tasks.txt Hackers Modifying Registry Keys to Establish Persistence via Scheduled Tasks.txt

text/plainHackers Modifying Registry Keys to Establish Persistence via Scheduled Tasks.txt

Open Download Copy Link 945 B 2024-01-12 January 12, 2024 2024-01-06 January 6, 2024
945 BJanuary 6, 2024
Thumb Hackers-target-Apache-RocketMQ-servers-vulnerable-to-RCE-attack.txt Hackers target Apache RocketMQ servers vulnerable to RCE attack.txt

text/plainHackers target Apache RocketMQ servers vulnerable to RCE attack.txt

Open Download Copy Link 77 B 2024-01-12 January 12, 2024 2024-01-05 January 5, 2024
77 BJanuary 5, 2024
Thumb IOC-and-TTPs-Backdoor_Win32-Carbanak-Anunak-Named-Pipe-Null-DACL.txt IOC and TTPs Backdoor.Win32 Carbanak (Anunak) - Named Pipe Null DACL.txt

text/plainIOC and TTPs Backdoor.Win32 Carbanak (Anunak) - Named Pipe Null DACL.txt

Open Download Copy Link 5.02 KB 2024-01-12 January 12, 2024 2024-01-11 January 11, 2024
5.02 KBJanuary 11, 2024
Thumb IOCs-Chapter-84-In-depth-analysis-and-technical-analysis-of-LockBit-the-top-encryption-ransomware-organization-Part-1.txt IOCs Chapter 84 In-depth analysis and technical analysis of LockBit the top encryption ransomware organization Part 1.txt

text/plainIOCs Chapter 84 In-depth analysis and technical analysis of LockBit the top encryption ransomware organization Part 1.txt

Open Download Copy Link 236 B 2024-01-12 January 12, 2024 2024-01-07 January 7, 2024
236 BJanuary 7, 2024
Thumb IOCs-and-TTPs-Financially-motivated-threat-actors-misusing-App-Installer.txt IOCs and TTPs Financially motivated threat actors misusing App Installer.txt

text/plainIOCs and TTPs Financially motivated threat actors misusing App Installer.txt

Open Download Copy Link 7.26 KB 2024-01-12 January 12, 2024 2024-01-09 January 9, 2024
7.26 KBJanuary 9, 2024
Thumb IOCs-and-TTPs_-Analysis-of-OT-cyberattacks-and-malwares.txt IOCs and TTPs_ Analysis of OT cyberattacks and malwares.txt

text/plainIOCs and TTPs_ Analysis of OT cyberattacks and malwares.txt

Open Download Copy Link 8.82 KB 2024-01-12 January 12, 2024 2024-01-09 January 9, 2024
8.82 KBJanuary 9, 2024
Thumb IOCs-and-Yara-Hundreds-of-Thousands-of-Dollars-Worth-of-Solana-Cryptocurrency-Assets-Stolen-in-Recent-CLINKSINK-Drainer-Campaigns.txt IOCs and Yara Hundreds of Thousands of Dollars Worth of Solana Cryptocurrency Assets Stolen in Recent CLINKSINK Drainer Campaigns.txt

text/plainIOCs and Yara Hundreds of Thousands of Dollars Worth of Solana Cryptocurrency Assets Stolen in Recent CLINKSINK Drainer Campaigns.txt

Open Download Copy Link 1.38 KB 2024-01-12 January 12, 2024 2024-01-11 January 11, 2024
1.38 KBJanuary 11, 2024
Thumb IOCs-and-other-AsyncRat.txt IOCs and other AsyncRat.txt

text/plainIOCs and other AsyncRat.txt

Open Download Copy Link 1.04 KB 2024-01-12 January 12, 2024 2024-01-07 January 7, 2024
1.04 KBJanuary 7, 2024
Thumb IOCs-Deceptive-Cracked-Software-Spreads-Lumma-Variant-on-YouTube.txt IOCs Deceptive Cracked Software Spreads Lumma Variant on YouTube.txt

text/plainIOCs Deceptive Cracked Software Spreads Lumma Variant on YouTube.txt

Open Download Copy Link 1.16 KB 2024-01-12 January 12, 2024 2024-01-08 January 8, 2024
1.16 KBJanuary 8, 2024
Thumb IOCs-DreamBus-Unleashes-Metabase-Mayhem-With-New-Exploit-Module.txt IOCs DreamBus Unleashes Metabase Mayhem With New Exploit Module.txt

text/plainIOCs DreamBus Unleashes Metabase Mayhem With New Exploit Module.txt

Open Download Copy Link 1.65 KB 2024-01-12 January 12, 2024 2024-01-11 January 11, 2024
1.65 KBJanuary 11, 2024
Thumb IOCs-Hide-and-Seek-in-Windows-Closet-Unmasking-the-WinSxS-Hijacking-Hideout.txt IOCs Hide and Seek in Windows' Closet Unmasking the WinSxS Hijacking Hideout.txt

text/plainIOCs Hide and Seek in Windows' Closet Unmasking the WinSxS Hijacking Hideout.txt

Open Download Copy Link 415 B 2024-01-12 January 12, 2024 2024-01-05 January 5, 2024
415 BJanuary 5, 2024
Thumb IOCs-TTPs-and-yara-Opening-a-Can-of-Whoop-Ads-Detecting-and-Disrupting-a-Malvertising-Campaign-Distributing-Backdoors.txt IOCs TTPs and yara Opening a Can of Whoop Ads Detecting and Disrupting a Malvertising Campaign Distributing Backdoors.txt

text/plainIOCs TTPs and yara Opening a Can of Whoop Ads Detecting and Disrupting a Malvertising Campaign Distributing Backdoors.txt

Open Download Copy Link 15.56 KB 2024-01-12 January 12, 2024 2024-01-09 January 9, 2024
15.56 KBJanuary 9, 2024
Thumb IOCs-Tackling-Anti-Analysis-Techniques-of-GuLoader-and-RedLine-Stealer.txt IOCs Tackling Anti-Analysis Techniques of GuLoader and RedLine Stealer.txt

text/plainIOCs Tackling Anti-Analysis Techniques of GuLoader and RedLine Stealer.txt

Open Download Copy Link 143 B 2024-01-12 January 12, 2024 2024-01-05 January 5, 2024
143 BJanuary 5, 2024
Thumb Prior-to-Cyber-Attack-Russian-Attackers-Spent-Months-Inside-the-Ukraine-Telecoms-Giant.txt Prior to Cyber Attack, Russian Attackers Spent Months Inside the Ukraine Telecoms Giant.txt

text/plainPrior to Cyber Attack, Russian Attackers Spent Months Inside the Ukraine Telecoms Giant.txt

Open Download Copy Link 168 B 2024-01-12 January 12, 2024 2024-01-07 January 7, 2024
168 BJanuary 7, 2024
Thumb yara-rules-from-100-Days-of-Yara-and-other-infor.txt yara rules from 100 Days of Yara and other infor.txt

text/plainyara rules from 100 Days of Yara and other infor.txt

Open Download Copy Link 49.69 KB 2024-01-12 January 12, 2024 2024-01-05 January 5, 2024
49.69 KBJanuary 5, 2024
Thumb Pig-butchering-is-an-evolution-of-a-social-engineering-tactic-weve-seen-for-years.txt Pig butchering is an evolution of a social engineering tactic we’ve seen for years.txt

text/plainPig butchering is an evolution of a social engineering tactic we’ve seen for years.txt

Open Download Copy Link 770 B 2024-03-22 March 22, 2024 2024-03-22 March 22, 2024
770 BMarch 22, 2024
Thumb IOCs-Curious-Serpens-FalseFont-Backdoor-Technical-Analysis-Detection-and-Prevention.txt IOCs Curious Serpens FalseFont Backdoor Technical Analysis Detection and Prevention.txt

text/plainIOCs Curious Serpens FalseFont Backdoor Technical Analysis Detection and Prevention.txt

Open Download Copy Link 501 B 2024-03-22 March 22, 2024 2024-03-22 March 22, 2024
501 BMarch 22, 2024
Thumb IOCs-The-Updated-APT-Playbook-Tales-from-the-Kimsuky-threat-actor-group.txt IOCs The Updated APT Playbook Tales from the Kimsuky threat actor group.txt

text/plainIOCs The Updated APT Playbook Tales from the Kimsuky threat actor group.txt

Open Download Copy Link 1.44 KB 2024-03-22 March 22, 2024 2024-03-22 March 22, 2024
1.44 KBMarch 22, 2024
https://bulwarkblack.com/page/25?ee=1&eeFolder=IOCs_YARA_TTPs_Posted_Articles&eeListID=2 0 1

1 - 20 21 - 21

Page: 1 of 2

20

93b89fe487

2026 Powered By BlazeThemes.