APT & Cybercriminals Campaign Collection
This is collections of APT and cybercriminals campaign. Please fire issue to me if any lost APT/Malware events/campaigns.
🤷The password of malware samples could be 'virus' or 'infected'
URL to PDF Tool
Reference Resources
:small_blue_diamond: kbandla
:small_blue_diamond: APTnotes
:small_blue_diamond: Florian Roth - APT Groups
:small_blue_diamond: Attack Wiki
:small_blue_diamond: threat-INTel
:small_blue_diamond: targetedthreats
:small_blue_diamond: Raw Threat Intelligence
:small_blue_diamond: APT search
:small_blue_diamond: APT Sample by 0xffff0800 (https://iec56w4ibovnb4wc.onion.si/)
:small_blue_diamond: APT Map
:small_blue_diamond: sapphirex00 - Threat-Hunting
:small_blue_diamond: APTSimulator
:small_blue_diamond: MITRE Att&CK: Group
:small_blue_diamond: APT_REPORT collected by @blackorbird
:small_blue_diamond: Analysis of malware and Cyber Threat Intel of APT and cybercriminals groups
:small_blue_diamond: APT_Digital_Weapon
:small_blue_diamond: vx-underground
:small_blue_diamond: StrangerealIntel-EternalLiberty
2024
- July 19 - [Google] APT41 Has Arisen From the DUST | :closed_book:
- July 15 - [CheckPoint] New BugSleep Backdoor Deployed in Recent MuddyWater Campaigns | :closed_book:
- July 10 - [Zscaler] A deep dive into the updated arsenal of APT41 | :closed_book:
- Jun 24 - [Recorded Future] Chinese State-Sponsored RedJuliett Intensifies Taiwanese Cyber Espionage via Network Perimeter Exploitation | :closed_book:
- Jun 21 - [CISCO] SneakyChef espionage group targets government agencies with SugarGh0st and more infection techniques | :closed_book:
- Jun 16 - [Sygnia] China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence | :closed_book:
- Jun 13 - [ESET] Arid Viper poisons Android apps with AridSpy | :closed_book:
- Jun 10 - [BlackBerry] Kimsuky is targeting an arms manufacturer in Europe | :closed_book:
- May 23 - [Palo Alto Networks] Operation Diplomatic Specter: An Active Chinese Cyberespionage Campaign Leverages Rare Tool Set to Target Governmental Entities in the Middle East, Africa and Asia | :closed_book:
- May 16 - [Palo Alto Networks] Payload Trends in Malicious OneNote Samples | :closed_book:
- Mar 07 - [ESET] Evasive Panda leverages Monlam Festival to target Tibetans | :closed_book:
- Feb 27 - [Mandiant] When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors | :closed_book:
- Feb 26 - [Trend Micro] Earth Lusca Uses Geopolitical Lure to Target Taiwan Before Elections | :closed_book:
- Feb 23 - [Sophos] ConnectWise ScreenConnect attacks deliver malware | :closed_book:
- Feb 23 - [Palo Alto Networks] Data From Chinese Security Services Company i-Soon Linked to Previous Chinese APT Campaigns | :closed_book:
- Feb 16 - [---] inside I-Soon APT(Earth Lusca) operation center | :closed_book:
- Feb 14 - [Microsoft] Staying ahead of threat actors in the age of AI | :closed_book:
- Feb 13 - [Trend Micro] CVE-2024-21412: Water Hydra Targets Traders With Microsoft Defender SmartScreen Zero-Day | :closed_book:
- Jan 31 - [Trend Micro] Pawn Storm Uses Brute Force and Stealth Against High-Value Targets | :closed_book:
- Jan 25 - [KrCERT/CC] Lazarus Group’s Large-scale Threats via Watering Hole and Financial Software | :closed_book:
- Jan 24 - [itochuci] The Endless Struggle Against APT10: Insights from LODEINFO | :closed_book:
- Jan 10 - [Volexity] Active Exploitation of Two Zero-Day Vulnerabilities in Ivanti Connect Secure VPN | :closed_book:
- Jan 03 - [Greg Lesnewich] 100DaysofYARA - SpectralBlur | :closed_book:
2023
- Dec 27 - [Kaspersky] Operation Triangulation: The last (hardware) mystery | :closed_book:
- Dec 21 - [CISCO] Intellexa and Cytrox: From fixer-upper to Intel Agency-grade spyware | :closed_book:
- Dec 19 - [Symantec] Seedworm: Iranian Hackers Target Telecoms Orgs in North and East Africa | :closed_book:
- Nov 30 - [CISCO] New SugarGh0st RAT targets Uzbekistan government and South Korea | :closed_book:
- Nov 27 - [Intezer] WildCard: The APT Behind SysJoker Targets Critical Sectors in Israel | :closed_book:
- Nov 23 - [CheckPoint] ISRAEL-HAMAS WAR SPOTLIGHT: SHAKING THE RUST OFF SYSJOKER | :closed_book:
- Nov 14 - [HKUK] APT29 attacks Embassies using CVE-2023-38831 | :closed_book:
- Nov 09 - [Kaspersky] Modern Asian APT groups’ tactics, techniques and procedures (TTPs) | :closed_book:
- Nov 07 - [Palo Alto Networks] Chinese APT Targeting Cambodian Government | :closed_book:
- Nov 06 - [Palo Alto Networks] Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors | :closed_book:
- Oct 31 - [CheckPoint] FROM ALBANIA TO THE MIDDLE EAST: THE SCARRED MANTICORE IS LISTENING | :closed_book:
- Oct 26 - [Kaspersky] StripedFly: Perennially flying under the radar | :closed_book:
- Oct 13 - [Trend Micro] Void Rabisu Targets Female Political Leaders with New Slimmed-Down ROMCOM Variant | :closed_book:
- Sep 19 - [CISCO] New ShroudedSnooper actor targets telecommunications firms in the Middle East with novel Implants | :closed_book:
- Aug 24 - [Microsoft] Flax Typhoon using legitimate software to quietly access Taiwanese organizations | :closed_book:
- Jul 27 - [Recorded Future] BlueBravo Adapts to Target Diplomatic Entities with GraphicalProton Malware | :closed_book:
- May 24 - [Microsoft] Volt Typhoon targets US critical infrastructure with living-off-the-land techniques |