René's URL Explorer Experiment


Title: GitHub - Jrmbt/APT_CyberCriminal_Campagin_Collections: APT & CyberCriminal Campaign Collection · GitHub

Open Graph Title: GitHub - Jrmbt/APT_CyberCriminal_Campagin_Collections: APT & CyberCriminal Campaign Collection

X Title: GitHub - Jrmbt/APT_CyberCriminal_Campagin_Collections: APT & CyberCriminal Campaign Collection

Description: APT & CyberCriminal Campaign Collection. Contribute to Jrmbt/APT_CyberCriminal_Campagin_Collections development by creating an account on GitHub.

Open Graph Description: APT & CyberCriminal Campaign Collection. Contribute to Jrmbt/APT_CyberCriminal_Campagin_Collections development by creating an account on GitHub.

X Description: APT & CyberCriminal Campaign Collection. Contribute to Jrmbt/APT_CyberCriminal_Campagin_Collections development by creating an account on GitHub.

Opengraph URL: https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections

X: @github

direct link

Domain: github.com

route-pattern/:user_id/:repository
route-controllerfiles
route-actiondisambiguate
fetch-noncev2:3cb3e1ba-1a3c-fe1d-8ab8-73e2407fc61e
current-catalog-service-hashf3abb0cc802f3d7b95fc8762b94bdcb13bf39634c40c357301c4aa1d67a256fb
request-idDE6E:35F95A:33FB36D:44F370E:6A654234
html-safe-nonce4502a72c557986fc10b8f9e62e9b113d426b7aec312f68cd4cfb12a24f5c150f
visitor-payloadeyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJERTZFOjM1Rjk1QTozM0ZCMzZEOjQ0RjM3MEU6NkE2NTQyMzQiLCJ2aXNpdG9yX2lkIjoiMTIyOTU3ODgzNDMxMDE1Mjc1NiIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9
visitor-hmacb45c45b049a201d348531447926387527c1a23358da551bf050898c12ac372dc
hovercard-subject-tagrepository:124049975
github-keyboard-shortcutsrepository,copilot
google-site-verificationApib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I
octolytics-urlhttps://collector.github.com/github/collect
analytics-location//
fb:app_id1401488693436528
apple-itunes-appapp-id=1477376905, app-argument=https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections
twitter:imagehttps://opengraph.githubassets.com/29f2fb19999db5ffcc73fb535c094f19edceb4533878fc36eaf610e3132c9511/Jrmbt/APT_CyberCriminal_Campagin_Collections
twitter:cardsummary_large_image
og:imagehttps://opengraph.githubassets.com/29f2fb19999db5ffcc73fb535c094f19edceb4533878fc36eaf610e3132c9511/Jrmbt/APT_CyberCriminal_Campagin_Collections
og:image:altAPT & CyberCriminal Campaign Collection. Contribute to Jrmbt/APT_CyberCriminal_Campagin_Collections development by creating an account on GitHub.
og:image:width1200
og:image:height600
og:site_nameGitHub
og:typeobject
hostnamegithub.com
expected-hostnamegithub.com
None52c76df668885aaff23b50bdca1fa1ea44ac9c1553e888ebc70ff1e4daa4625b
turbo-cache-controlno-cache
go-importgithub.com/Jrmbt/APT_CyberCriminal_Campagin_Collections git https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections.git
octolytics-dimension-user_id32325304
octolytics-dimension-user_loginJrmbt
octolytics-dimension-repository_id124049975
octolytics-dimension-repository_nwoJrmbt/APT_CyberCriminal_Campagin_Collections
octolytics-dimension-repository_publictrue
octolytics-dimension-repository_is_forktrue
octolytics-dimension-repository_parent_id81636686
octolytics-dimension-repository_parent_nwoCyberMonitor/APT_CyberCriminal_Campagin_Collections
octolytics-dimension-repository_network_root_id81636686
octolytics-dimension-repository_network_root_nwoCyberMonitor/APT_CyberCriminal_Campagin_Collections
turbo-body-classeslogged-out env-production page-responsive
disable-turbofalse
browser-stats-urlhttps://api.github.com/_private/browser/stats
browser-errors-urlhttps://api.github.com/_private/browser/errors
release309153364422b3c499922d1a2a6404910a58ed8e
ui-targetfull
theme-color#1e2327
color-schemelight dark

Links:

Skip to contenthttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections#start-of-content
https://github.com/
Sign in https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2FJrmbt%2FAPT_CyberCriminal_Campagin_Collections
GitHub CopilotWrite better code with AIhttps://github.com/features/copilot
GitHub Copilot appDirect agents from issue to mergehttps://github.com/features/ai/github-app
MCP RegistryNewIntegrate external toolshttps://github.com/mcp
ActionsAutomate any workflowhttps://github.com/features/actions
CodespacesInstant dev environmentshttps://github.com/features/codespaces
IssuesPlan and track workhttps://github.com/features/issues
Code ReviewManage code changeshttps://github.com/features/code-review
Code QualityEnforce quality at mergehttps://github.com/features/code-quality
GitHub Advanced SecurityFind and fix vulnerabilitieshttps://github.com/security/advanced-security
Code securitySecure your code as you buildhttps://github.com/security/advanced-security/code-security
Secret protectionStop leaks before they starthttps://github.com/security/advanced-security/secret-protection
Why GitHubhttps://github.com/why-github
Documentationhttps://docs.github.com
Bloghttps://github.blog
Changeloghttps://github.blog/changelog
Marketplacehttps://github.com/marketplace
View all featureshttps://github.com/features
Enterpriseshttps://github.com/enterprise
Small and medium teamshttps://github.com/team
Startupshttps://github.com/enterprise/startups
Nonprofitshttps://github.com/solutions/industry/nonprofits
App Modernizationhttps://github.com/solutions/use-case/app-modernization
DevSecOpshttps://github.com/solutions/use-case/devsecops
DevOpshttps://github.com/solutions/use-case/devops
CI/CDhttps://github.com/solutions/use-case/ci-cd
View all use caseshttps://github.com/solutions/use-case
Healthcarehttps://github.com/solutions/industry/healthcare
Financial serviceshttps://github.com/solutions/industry/financial-services
Manufacturinghttps://github.com/solutions/industry/manufacturing
Governmenthttps://github.com/solutions/industry/government
View all industrieshttps://github.com/solutions/industry
View all solutionshttps://github.com/solutions
AIhttps://github.com/resources/articles?topic=ai
Software Developmenthttps://github.com/resources/articles?topic=software-development
DevOpshttps://github.com/resources/articles?topic=devops
Securityhttps://github.com/resources/articles?topic=security
View all topicshttps://github.com/resources/articles
Customer storieshttps://github.com/customer-stories
Events & webinarshttps://github.com/resources/events
Ebooks & reportshttps://github.com/resources/whitepapers
Business insightshttps://github.com/solutions/executive-insights
GitHub Skillshttps://skills.github.com
Documentationhttps://docs.github.com
Customer supporthttps://support.github.com
Community forumhttps://github.com/orgs/community/discussions
Trust centerhttps://github.com/trust-center
Partnershttps://github.com/partners
View all resourceshttps://github.com/resources
GitHub SponsorsFund open source developershttps://github.com/open-source/sponsors
Security Labhttps://securitylab.github.com
Maintainer Communityhttps://maintainers.github.com
Acceleratorhttps://github.com/open-source/accelerator
GitHub Starshttps://stars.github.com
Archive Programhttps://archiveprogram.github.com
Topicshttps://github.com/topics
Trendinghttps://github.com/trending
Collectionshttps://github.com/collections
Enterprise platformAI-powered developer platformhttps://github.com/enterprise
GitHub Advanced SecurityEnterprise-grade security featureshttps://github.com/security/advanced-security
Copilot for BusinessEnterprise-grade AI featureshttps://github.com/features/copilot/copilot-business
Premium SupportEnterprise-grade 24/7 supporthttps://github.com/enterprise/premium-support
Pricinghttps://github.com/pricing
Search syntax tipshttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
documentationhttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
Sign in https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2FJrmbt%2FAPT_CyberCriminal_Campagin_Collections
Sign up https://github.com/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E&source=header-repo&source_repo=Jrmbt%2FAPT_CyberCriminal_Campagin_Collections
Reloadhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections
Reloadhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections
Reloadhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections
Jrmbt https://github.com/Jrmbt
APT_CyberCriminal_Campagin_Collectionshttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections
CyberMonitor/APT_CyberCriminal_Campagin_Collectionshttps://github.com/CyberMonitor/APT_CyberCriminal_Campagin_Collections
Notifications https://github.com/login?return_to=%2FJrmbt%2FAPT_CyberCriminal_Campagin_Collections
Fork 0 https://github.com/login?return_to=%2FJrmbt%2FAPT_CyberCriminal_Campagin_Collections
Star 0 https://github.com/login?return_to=%2FJrmbt%2FAPT_CyberCriminal_Campagin_Collections
Code https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections
Pull requests 0 https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/pulls
Actions https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/actions
Projects https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/projects
Wiki https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/wiki
Security and quality 0 https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/security
Insights https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/pulse
Code https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections
Pull requests https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/pulls
Actions https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/actions
Projects https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/projects
Wiki https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/wiki
Security and quality https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/security
Insights https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/pulse
https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections
Brancheshttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/branches
Tagshttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tags
https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/branches
https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tags
154 Commitshttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/commits/master/
https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/commits/master/
2008https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tree/master/2008
2008https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tree/master/2008
2009https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tree/master/2009
2009https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tree/master/2009
2010https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tree/master/2010
2010https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tree/master/2010
2011https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tree/master/2011
2011https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tree/master/2011
2012https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tree/master/2012
2012https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tree/master/2012
2013https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tree/master/2013
2013https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tree/master/2013
2014https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tree/master/2014
2014https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tree/master/2014
2015https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tree/master/2015
2015https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tree/master/2015
2016https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tree/master/2016
2016https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tree/master/2016
2017https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tree/master/2017
2017https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tree/master/2017
2018https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tree/master/2018
2018https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tree/master/2018
historicalhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tree/master/historical
historicalhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/tree/master/historical
README.mdhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/README.md
README.mdhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/README.md
READMEhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections
https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections#apt--cybercriminal-campaign-collection
https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections#reference-resources
kbandlahttps://github.com/kbandla/APTnotes
APTnoteshttps://github.com/aptnotes/data
Florian Roth - APT Groupshttps://docs.google.com/spreadsheets/u/0/d/1H9_xaxQHpWaa4O_Son4Gx0YOIzlcBWMsdvePFX68EKU/pubhtml
Attack Wikihttps://attack.mitre.org/wiki/Groups
threat-INTelhttps://github.com/fdiskyou/threat-INTel
targetedthreatshttps://github.com/botherder/targetedthreats/wiki/Reports
Raw Threat Intelligencehttps://docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHDnV8VgmVqU5WoeErc/edit
https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections#2018
[McAfee] McAfee Uncovers Operation Honeybee, a Malicious Document Campaign Targeting Humanitarian Aid Groupshttps://securingtomorrow.mcafee.com/mcafee-labs/mcafee-uncovers-operation-honeybee-malicious-document-campaign-targeting-humanitarian-aid-groups/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.03.02.Operation_Honeybee
[Security 0wnage] A Quick Dip into MuddyWater's Recent Activityhttps://sec0wn.blogspot.tw/2018/03/a-quick-dip-into-muddywaters-recent.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.03.01.a-quick-dip-into-muddywaters-recent
[Palo Alto Networks] Sofacy Attacks Multiple Government Entitieshttps://researchcenter.paloaltonetworks.com/2018/02/unit42-sofacy-attacks-multiple-government-entities/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.02.28.sofacy-attacks-multiple-government-entities
[Symantec] Chafer: Latest Attacks Reveal Heightened Ambitionshttps://www.symantec.com/blogs/threat-intelligence/chafer-latest-attacks-reveal-heightened-ambitions
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.02.28.Chafer_Latest_Attacks_Reveal
[Avast] Avast tracks down Tempting Cedar Spywarehttps://blog.avast.com/avast-tracks-down-tempting-cedar-spyware
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.02.21.Tempting_Cedar
[Arbor] Musical Chairs Playing Tetrishttps://www.arbornetworks.com/blog/asert/musical-chairs-playing-tetris/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.02.20.musical-chairs-playing-tetris
[Kaspersky] A Slice of 2017 Sofacy Activityhttps://securelist.com/a-slice-of-2017-sofacy-activity/83930/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.02.20.a-slice-of-2017-sofacy-activity
[FireEye] APT37 (Reaper): The Overlooked North Korean Actorhttps://www2.fireeye.com/rs/848-DID-242/images/rpt_APT37.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.02.20.APT37
[CISCO] Targeted Attacks In The Middle Easthttp://blog.talosintelligence.com/2018/02/targeted-attacks-in-middle-east.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.02.07.targeted-attacks-in-middle-east_VBS_CAMPAIGN
[McAfee] Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systemshttps://securingtomorrow.mcafee.com/mcafee-labs/gold-dragon-widens-olympics-malware-attacks-gains-permanent-presence-on-victims-systems/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.02.02.gold-dragon-widens-olympics-malware
[Bitdefender] Operation PZChao: a possible return of the Iron Tiger APThttps://labs.bitdefender.com/2018/02/operation-pzchao-a-possible-return-of-the-iron-tiger-apt/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.02.01.operation-pzchao
[Palo Alto Networks] Comnie Continues to Target Organizations in East Asiahttps://researchcenter.paloaltonetworks.com/2018/01/unit42-comnie-continues-target-organizations-east-asia/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.01.31.Comnie_Continues_to_Target_Organizations_in_East_Asia
[RSA] APT32 Continues ASEAN Targetinghttps://community.rsa.com/community/products/netwitness/blog/2018/01/30/apt32-continues-asean-targeting
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.01.30.APT32_Continues_ASEAN_Targeting
[Palo Alto Networks] VERMIN: Quasar RAT and Custom Malware Used In Ukrainehttps://researchcenter.paloaltonetworks.com/2018/01/unit42-vermin-quasar-rat-custom-malware-used-ukraine/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.01.29.VERMIN_Quasar_RAT_and_Custom_Malware_Used_In_Ukraine
[Accenture] DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATEShttps://www.accenture.com/t20180127T003755Z__w__/us-en/_acnmedia/PDF-46/Accenture-Security-Dragonfish-Threat-Analysis.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.01.27.DRAGONFISH
[Palo Alto Networks] The TopHat Campaign: Attacks Within The Middle East Region Using Popular Third-Party Serviceshttps://researchcenter.paloaltonetworks.com/2018/01/unit42-the-tophat-campaign-attacks-within-the-middle-east-region-using-popular-third-party-services/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.01.26.TopHat_Campaign
[Palo Alto Networks] OilRig uses RGDoor IIS Backdoor on Targets in the Middle Easthttps://researchcenter.paloaltonetworks.com/2018/01/unit42-oilrig-uses-rgdoor-iis-backdoor-targets-middle-east/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.01.25.oilrig_Middle_East
[NCSC] Turla group update Neuron malwarehttps://www.ncsc.gov.uk/content/files/protected_files/article_files/Turla%20Neuron%20Malware%20Update.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.01.18.Turla_group_update_Neuron_malware
[Lookout] Dark Caracalhttps://info.lookout.com/rs/051-ESQ-475/images/Lookout_Dark-Caracal_srr_20180118_us_v.1.0.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.01.18.Dark_Caracal
[Kaspersky] Skygofree: Following in the footsteps of HackingTeamhttps://securelist.com/skygofree-following-in-the-footsteps-of-hackingteam/83603/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.01.16.skygofree
[Recorded Future] North Korea Targeted South Korean Cryptocurrency Users and Exchange in Late 2017 Campaignhttps://www.recordedfuture.com/north-korea-cryptocurrency-campaign/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.01.16.north-korea-cryptocurrency-campaign
[CISCO] Korea In The Crosshairshttp://blog.talosintelligence.com/2018/01/korea-in-crosshairs.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.01.16.korea-in-crosshairs
[Trend Micro] New KillDisk Variant Hits Financial Organizations in Latin Americahttps://blog.trendmicro.com/trendlabs-security-intelligence/new-killdisk-variant-hits-financial-organizations-in-latin-america/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.01.15.new-killdisk-variant-hits-financial-organizations-in-latin-america
[Trend Micro] Update on Pawn Storm: New Targets and Politically Motivated Campaignshttp://blog.trendmicro.com/trendlabs-security-intelligence/update-pawn-storm-new-targets-politically-motivated-campaigns/?utm_campaign=shareaholic&utm_medium=twitter&utm_source=socialnetwork
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.01.12.update-pawn-storm-new-targets-politically
[McAfee] North Korean Defectors and Journalists Targeted Using Social Networks and KakaoTalkhttps://securingtomorrow.mcafee.com/mcafee-labs/north-korean-defectors-journalists-targeted-using-social-networks-kakaotalk/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.01.11.North_Korean_Defectors_and_Journalists_Targeted
[ESET] Diplomats in Eastern Europe bitten by a Turla mosquitohttps://www.welivesecurity.com/wp-content/uploads/2018/01/ESET_Turla_Mosquito.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.01.09.Turla_Mosquito
[Clearsky] Operation DustySkyhttp://www.clearskysec.com/dustysky/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.01.07.Operation_DustySky
[McAfee] Malicious Document Targets Pyeongchang Olympicshttps://securingtomorrow.mcafee.com/mcafee-labs/malicious-document-targets-pyeongchang-olympics/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.01.06.malicious-document-targets-pyeongchang-olympics
[Carnegie] Iran’s Cyber Threat: Espionage, Sabotage, and Revengehttp://carnegieendowment.org/files/Iran_Cyber_Final_Full_v2.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2018/2018.01.04.Iran_Cyber_Threat_Carnegie
https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections#2017
[Proofpoint] North Korea Bitten by Bitcoin Bug: Financially motivated campaigns reveal new dimension of the Lazarus Grouphttps://www.proofpoint.com/us/threat-insight/post/north-korea-bitten-bitcoin-bug-financially-motivated-campaigns-reveal-new
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.12.19.North_Korea_Bitten_by_Bitcoin_Bug
[McAfee] Operation Dragonfly Analysis Suggests Links to Earlier Attackshttps://securingtomorrow.mcafee.com/mcafee-labs/operation-dragonfly-analysis-suggests-links-to-earlier-attacks/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.12.17.operation-dragonfly-analysis-suggests-links-to-earlier-attacks
[FireEye] Attackers Deploy New ICS Attack Framework “TRITON” and Cause Operational Disruption to Critical Infrastructurehttps://www.fireeye.com/blog/threat-research/2017/12/attackers-deploy-new-ics-attack-framework-triton.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.12.14.attackers-deploy-new-ics-attack-framework-triton
[Group-IB] MoneyTaker, revealed after 1.5 years of silent operations.https://www.group-ib.com/resources/reports/money-taker.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.12.11.MoneyTaker
[Trend Micro] Untangling the Patchwork Cyberespionage Grouphttp://blog.trendmicro.com/trendlabs-security-intelligence/untangling-the-patchwork-cyberespionage-group/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.12.11.Patchwork_APT
[FireEye] New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploithttps://www.fireeye.com/blog/threat-research/2017/12/targeted-attack-in-middle-east-by-apt34.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.12.07.New_Targeted_Attack_in_the_Middle_East_by_APT34
[ClearSky] Charming Kitten: Iranian Cyber Espionage Against Human Rights Activists, Academic Researchers and Media Outlets – And the HBO Hacker Connectionhttp://www.clearskysec.com/wp-content/uploads/2017/12/Charming_Kitten_2017.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.12.05.Charming_Kitten
[RSA] The Shadows of Ghosts: Inside the Response of a Unique Carbanak Intrusionhttps://community.rsa.com/community/products/netwitness/blog/2017/12/04/anatomy-of-an-attack-carbanak
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.12.04.The_Shadows_of_Ghosts
[REAQTA] A dive into MuddyWater APT targeting Middle-Easthttps://reaqta.com/2017/11/muddywater-apt-targeting-middle-east/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.11.22.MuddyWater_APT
[Palo Alto Networks] Muddying the Water: Targeted Attacks in the Middle Easthttps://researchcenter.paloaltonetworks.com/2017/11/2017.11.14.Muddying_the_Water
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.11.14.Muddying_the_Water
[Palo Alto Networks] New Malware with Ties to SunOrcal Discoveredhttps://researchcenter.paloaltonetworks.com/2017/11/unit42-new-malware-with-ties-to-sunorcal-discovered/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.11.10.New_Malware_with_Ties_to_SunOrcal_Discovered
[McAfee] Threat Group APT28 Slips Office Malware into Doc Citing NYC Terror Attackhttps://securingtomorrow.mcafee.com/mcafee-labs/apt28-threat-group-adopts-dde-technique-nyc-attack-theme-in-latest-campaign/#sf151634298
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.11.07.APT28_Slips_Office_Malware
[Symantec] Sowbug: Cyber espionage group targets South American and Southeast Asian governmentshttps://www.symantec.com/connect/blogs/sowbug-cyber-espionage-group-targets-south-american-and-southeast-asian-governments
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.11.07.sowbug-cyber-espionage-group-targets
[Trend Micro] ChessMaster’s New Strategy: Evolving Tools and Tacticshttp://blog.trendmicro.com/trendlabs-security-intelligence/chessmasters-new-strategy-evolving-tools-tactics/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.11.06.ChessMaster_New_Strategy
[PwC] The KeyBoys are back in townhttp://www.pwc.co.uk/issues/cyber-security-data-privacy/research/the-keyboys-are-back-in-town.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.11.02.KeyBoys_are_back
[Clearsky] LeetMX – a Yearlong Cyber-Attack Campaign Against Targets in Latin Americahttp://www.clearskysec.com/leetmx/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.11.02.LeetMX
[Cybereason] Night of the Devil: Ransomware or wiper? A look into targeted attacks in Japan using MBR-ONIhttps://www.cybereason.com/blog/night-of-the-devil-ransomware-or-wiper-a-look-into-targeted-attacks-in-japan
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.10.31.MBR-ONI.Japan
[Kaspersky] Gaza Cybergang – updated activity in 2017https://securelist.com/gaza-cybergang-updated-2017-activity/82765/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.10.30.Gaza_Cybergang
[Bellingcat] Bahamut Revisited, More Cyber Espionage in the Middle East and South Asiahttps://www.bellingcat.com/resources/case-studies/2017/10/27/bahamut-revisited-cyber-espionage-middle-east-south-asia/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.10.27.bahamut-revisited
[ClearSky] Iranian Threat Agent Greenbug Impersonates Israeli High-Tech and Cyber Security Companieshttp://www.clearskysec.com/greenbug/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.10.02.Aurora_Operation_CCleaner_II
[BAE Systems] Taiwan Heist: Lazarus Tools And Ransomwarehttps://baesystemsai.blogspot.kr/2017/10/taiwan-heist-lazarus-tools.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.10.16.Taiwan-Heist
[Kaspersky] BlackOasis APT and new targeted attacks leveraging zero-day exploithttps://securelist.com/blackoasis-apt-and-new-targeted-attacks-leveraging-zero-day-exploit/82732/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.10.16.BlackOasis_APT
[Trustwave] Post Soviet Bank Heistshttps://www.trustwave.com/Resources/Library/Documents/Post-Soviet-Bank-Heists/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.10.02.Aurora_Operation_CCleaner_II
[intezer] Evidence Aurora Operation Still Active Part 2: More Ties Uncovered Between CCleaner Hack & Chinese Hackershttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.10.02.Aurora_Operation_CCleaner_II
[MITRE] APT3 Adversary Emulation Planhttps://attack.mitre.org/w/img_auth.php/6/6c/APT3_Adversary_Emulation_Plan.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.09.XX.APT3_Adversary_Emulation_Plan
[Palo Alto Networks] Threat Actors Target Government of Belarus Using CMSTAR Trojanhttps://researchcenter.paloaltonetworks.com/2017/09/unit42-threat-actors-target-government-belarus-using-cmstar-trojan/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.09.28.Belarus_CMSTAR_Trojan
[intezer] Evidence Aurora Operation Still Active: Supply Chain Attack Through CCleanerhttp://www.intezer.com/evidence-aurora-operation-still-active-supply-chain-attack-through-ccleaner/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.09.20.Aurora_Operation_CCleaner
[FireEye] Insights into Iranian Cyber Espionage: APT33 Targets Aerospace and Energy Sectors and has Ties to Destructive Malwarehttps://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.09.20.apt33-insights-into-iranian-cyber-espionage
[CISCO] CCleaner Command and Control Causes Concernhttp://blog.talosintelligence.com/2017/09/ccleaner-c2-concern.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.09.18.CCleanup
[CISCO] CCleanup: A Vast Number of Machines at Riskhttp://blog.talosintelligence.com/2017/09/avast-distributes-malware.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.09.18.CCleanup
[FireEye] FireEye Uncovers CVE-2017-8759: Zero-Day Used in the Wild to Distribute FINSPYhttps://www.fireeye.com/blog/threat-research/2017/09/zero-day-used-to-distribute-finspy.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.09.12.FINSPY_CVE-2017-8759
[Symantec] Dragonfly: Western energy sector targeted by sophisticated attack grouphttps://www.symantec.com/connect/blogs/dragonfly-western-energy-sector-targeted-sophisticated-attack-group
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.09.06.dragonfly-western-energy-sector-targeted-sophisticated-attack-group
[Treadstone 71] Intelligence Games in the Power Gridhttps://treadstone71llc.files.wordpress.com/2017/09/intelligence-games-in-the-power-grid-2016.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.09.06.intelligence-games-in-the-power-grid-2016
[ESET] Gazing at Gazer: Turla’s new second stage backdoorhttps://www.welivesecurity.com/2017/08/30/eset-research-cyberespionage-gazer/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.08.30.Gazing_at_Gazer
[Kaspersky] Introducing WhiteBearhttps://securelist.com/introducing-whitebear/81638/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.08.30.Introducing_WhiteBear
[Proofpoint] Operation RAT Cook: Chinese APT actors use fake Game of Thrones leaks as lureshttps://www.proofpoint.com/us/threat-insight/post/operation-rat-cook-chinese-apt-actors-use-fake-game-thrones-leaks-lures
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.08.25.operation-rat-cook
[RSA] Russian Bank Offices Hit with Broad Phishing Wavehttps://community.rsa.com/community/products/netwitness/blog/2017/08/18/russian-bank-offices-hit-with-broad-phishing-wave
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.08.18.Russian_Bank_Offices_Hit
[Proofpoint] Turla APT actor refreshes KopiLuwak JavaScript backdoor for use in G20-themed attackhttps://www.proofpoint.com/us/threat-insight/post/turla-apt-actor-refreshes-kopiluwak-javascript-backdoor-use-g20-themed-attack
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.08.17.turla-apt-actor-refreshes-kopiluwak-javascript-backdoor
[Palo Alto Networks] The Curious Case of Notepad and Chthonic: Exposing a Malicious Infrastructurehttps://researchcenter.paloaltonetworks.com/2017/08/unit42-the-curious-case-of-notepad-and-chthonic-exposing-a-malicious-infrastructure/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.08.15.Notepad_and_Chthonic
[FireEye] APT28 Targets Hospitality Sector, Presents Threat to Travelershttps://www.fireeye.com/blog/threat-research/2017/08/apt28-targets-hospitality-sector.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.08.11.apt28-targets-hospitality-sector
[Positive Research] Cobalt strikes back: an evolving multinational threat to financehttp://blog.ptsecurity.com/2017/08/cobalt-group-2017-cobalt-strikes-back.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.08.01.cobalt-group-2017-cobalt-strikes-back
[Trend Micro] ChessMaster Makes its Move: A Look into the Campaign’s Cyberespionage Arsenalhttp://blog.trendmicro.com/trendlabs-security-intelligence/chessmaster-cyber-espionage-campaign/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.07.27.chessmaster-cyber-espionage-campaign
[Palo Alto Networks] OilRig Uses ISMDoor Variant; Possibly Linked to Greenbug Threat Grouphttps://researchcenter.paloaltonetworks.com/2017/07/unit42-oilrig-uses-ismdoor-variant-possibly-linked-greenbug-threat-group/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.07.27.oilrig-uses-ismdoor-variant-possibly-linked-greenbug-threat-group
[Clearsky, TrendMicro] Operation Wilted Tuliphttp://www.clearskysec.com/wp-content/uploads/2017/07/Operation_Wilted_Tulip.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.07.27.Operation_Wilted_Tulip
[Palo Alto Networks] “Tick” Group Continues Attackshttps://researchcenter.paloaltonetworks.com/2017/07/unit42-tick-group-continues-attacks/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.07.24.Tick_group
[Clearsky] Recent Winnti Infrastructure and Sampleshttp://www.clearskysec.com/winnti/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.07.18.winnti
[Bitdefender] Inexsmar: An unusual DarkHotel campaignhttps://labs.bitdefender.com/wp-content/uploads/downloads/inexsmar-an-unusual-darkhotel-campaign/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.07.18.Inexsmar
[ProtectWise] Winnti Evolution - Going Open Sourcehttps://www.protectwise.com/blog/winnti-evolution-going-open-source.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.07.11.winnti-evolution-going-open-source
[Trend Micro] OSX Malware Linked to Operation Emmental Hijacks User Network Traffichttp://blog.trendmicro.com/trendlabs-security-intelligence/osx_dok-mac-malware-emmental-hijacks-user-network-traffic/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.07.10.osx_dok-mac-malware-emmental-hijacks-user-network-traffic
[Malware Party] Operation Desert Eaglehttp://mymalwareparty.blogspot.tw/2017/07/operation-desert-eagle.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.07.06.Operation_Desert_Eagle
[Citizen Lab] Insider Information: An intrusion campaign targeting Chinese language news siteshttps://citizenlab.org/2017/07/insider-information-an-intrusion-campaign-targeting-chinese-language-news-sites/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.07.05.insider-information
[ESET] TeleBots are back: supply-chain attacks against Ukrainehttps://www.welivesecurity.com/2017/06/30/telebots-back-supply-chain-attacks-against-ukraine/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.06.30.telebots-back-supply-chain
[Kaspersky] From BlackEnergy to ExPetrhttps://securelist.com/from-blackenergy-to-expetr/78937/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.06.30.From_BlackEnergy_to_ExPetr
[Dell] Threat Group-4127 Targets Google Accountshttps://www.secureworks.com/research/threat-group-4127-targets-google-accounts
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.06.26.Threat_Group-4127
[Palo Alto Networks] The New and Improved macOS Backdoor from OceanLotushttps://www.secureworks.com/research/threat-group-4127-targets-google-accounts
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.06.22.new-improved-macos-backdoor-oceanlotus
[Trend Micro] Following the Trail of BlackTech’s Cyber Espionage Campaignshttp://blog.trendmicro.com/trendlabs-security-intelligence/following-trail-blacktech-cyber-espionage-campaigns/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.06.22.following-trail-blacktech-cyber-espionage-campaigns
[root9B] SHELLTEA + POSLURP MALWARE: memory resident point-of-sale malware attacks industryhttps://www.root9b.com/sites/default/files/whitepapers/PoS%20Malware%20ShellTea%20PoSlurp_0.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.06.19.SHELLTEA_POSLURP_MALWARE
[Palo Alto Networks] APT3 Uncovered: The code evolution of Pirpihttps://recon.cx/2017/montreal/resources/slides/RECON-MTL-2017-evolution_of_pirpi.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.06.18.APT3_Uncovered_The_code_evolution_of_Pirpi
[Recorded Future] North Korea Is Not Crazyhttps://www.recordedfuture.com/north-korea-cyber-activity/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.06.15.north-korea-cyber-activity
[ThreatConnect] KASPERAGENT Malware Campaign resurfaces in the run up to May Palestinian Authority Electionshttps://www.threatconnect.com/blog/kasperagent-malware-campaign/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.06.14.KASPERAGENT
[US-CERT] HIDDEN COBRA – North Korea’s DDoS Botnet Infrastructurehttps://www.us-cert.gov/ncas/alerts/TA17-164A
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.06.13.HIDDEN_COBRA
[Dragos] CRASHOVERRIDE Analysis of the Threat to Electric Grid Operationshttps://dragos.com/blog/crashoverride/CrashOverride-01.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.06.12.CRASHOVERRIDE
[ESET] WIN32/INDUSTROYER A new threat for industrial control systemshttps://www.welivesecurity.com/wp-content/uploads/2017/06/Win32_Industroyer.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.06.12.INDUSTROYER
[Group-IB] Lazarus Arisen: Architecture, Techniques and Attributionhttp://www.group-ib.com/lazarus.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.05.30.Lazarus_Arisen
[Palo Alto Networks] Kazuar: Multiplatform Espionage Backdoor with API Accesshttp://researchcenter.paloaltonetworks.com/2017/05/unit42-kazuar-multiplatform-espionage-backdoor-api-acces
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.05.03.kazuar-multiplatform-espionage-backdoor-api-access
[CISCO] KONNI: A Malware Under The Radar For Yearshttp://blog.talosintelligence.com/2017/05/konni-malware-under-radar-for-years.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/konni-malware-under-radar-for-years
[Morphisec] Iranian Fileless Attack Infiltrates Israeli Organizationshttp://blog.morphisec.com/iranian-fileless-cyberattack-on-israel-word-vulnerability
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.04.27.iranian-fileless-cyberattack-on-israel-word-vulnerability
[F-SECURE] Callisto Grouphttps://www.f-secure.com/documents/996508/1030745/callisto-group
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.04.13.callisto-group
[Palo Alto Networks, Clearsky] Targeted Attacks in the Middle East Using KASPERAGENT and MICROPSIAhttps://researchcenter.paloaltonetworks.com/2017/04/unit42-targeted-attacks-middle-east-using-kasperagent-micropsia/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.04.05.KASPERAGENT_and_MICROPSIA
[Clearsky] Operation Electric Powder – Who is targeting Israel Electric Company?http://www.clearskysec.com/iec/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.03.14.Operation_Electric_Powder
[Kaspersky] From Shamoon to StoneDrillhttps://securelist.com/blog/research/77725/from-shamoon-to-stonedrill/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.03.06.from-shamoon-to-stonedrill
[IBM] Dridex’s Cold War: Enter AtomBombinghttps://securityintelligence.com/dridexs-cold-war-enter-atombombing/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.02.28.dridexs-cold-war-enter-atombombing
[Palo Alto Networks] The Gamaredon Group Toolset Evolutionhttp://researchcenter.paloaltonetworks.com/2017/02/unit-42-title-gamaredon-group-toolset-evolution/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.02.27.gamaredon-group-toolset-evolution
[Bitdefender] Dissecting the APT28 Mac OS X Payloadhttps://download.bitdefender.com/resources/files/News/CaseStudies/study/143/Bitdefender-Whitepaper-APT-Mac-A4-en-EN-web.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.02.23.APT28_Mac_OS_X_Payload
[FireEye] Spear Phishing Techniques Used in Attacks Targeting the Mongolian Governmenthttps://www.fireeye.com/blog/threat-research/2017/02/spear_phishing_techn.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.02.22.Spear_Phishing_Mongolian_Government
[Arbor] Additional Insights on Shamoon2https://www.arbornetworks.com/blog/asert/additional-insights-on-shamoon2/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.02.21.Additional_Insights_on_Shamoon2
[BAE Systems] azarus' False Flag Malwarehttp://baesystemsai.blogspot.tw/2017/02/lazarus-false-flag-malware.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.02.20.Lazarus_False_Flag_Malware
[JPCERT] ChChes - Malware that Communicates with C&C Servers Using Cookie Headershttp://blog.jpcert.or.jp/2017/02/chches-malware--93d6.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.02.17.chches-malware
[BadCyber] Technical analysis of recent attacks against Polish bankshttps://badcyber.com/technical-analysis-of-recent-attacks-against-polish-banks/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.02.16.Technical_analysis_Polish_banks
[Morphick] Deep Dive On The DragonOK Rambo Backdoorhttp://www.morphick.com/resources/news/deep-dive-dragonok-rambo-backdoor
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.02.15.deep-dive-dragonok-rambo-backdoor
[IBM] The Full Shamoon: How the Devastating Malware Was Inserted Into Networkshttps://securityintelligence.com/the-full-shamoon-how-the-devastating-malware-was-inserted-into-networks/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.02.15.the-full-shamoon
[Dell] Iranian PupyRAT Bites Middle Eastern Organizationshttps://www.secureworks.com/blog/iranian-pupyrat-bites-middle-eastern-organizations
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.02.15.iranian-pupyrat-bites-middle-eastern-organizations
[Palo Alto Networks] Magic Hound Campaign Attacks Saudi Targetshttp://researchcenter.paloaltonetworks.com/2017/02/unit42-magic-hound-campaign-attacks-saudi-targets/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.02.15.magic-hound-campaign
[Medium Corporation] Operation Kingphish: Uncovering a Campaign of Cyber Attacks against Civil Society in Qatar and Nepalhttps://medium.com/amnesty-insights/operation-kingphish-uncovering-a-campaign-of-cyber-attacks-against-civil-society-in-qatar-and-aa40c9e08852#.cly4mg1g8
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.02.14.Operation_Kingphish
[BAE Systems] Lazarus & Watering-Hole Attackshttps://baesystemsai.blogspot.tw/2017/02/lazarus-watering-hole-attacks.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.02.12.lazarus-watering-hole-attacks
[Cysinfo] Cyber Attack Targeting Indian Navy's Submarine And Warship Manufacturerhttps://cysinfo.com/cyber-attack-targeting-indian-navys-submarine-warship-manufacturer/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.02.10.cyber-attack-targeting-indian-navys-submarine-warship-manufacturer
[DHS] Enhanced Analysis of GRIZZLY STEPPE Activityhttps://www.us-cert.gov/sites/default/files/publications/AR-17-20045_Enhanced_Analysis_of_GRIZZLY_STEPPE_Activity.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.02.10.Enhanced_Analysis_of_GRIZZLY_STEPPE
[RSA] KingSlayer A Supply chain attackhttps://www.rsa.com/content/dam/pdfs/2-2017/kingslayer-a-supply-chain-attack.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.02.03.kingslayer-a-supply-chain-attack
[BadCyber] Several Polish banks hacked, information stolen by unknown attackershttps://badcyber.com/several-polish-banks-hacked-information-stolen-by-unknown-attackers/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.02.03.several-polish-banks-hacked
[Proofpoint] Oops, they did it again: APT Targets Russia and Belarus with ZeroT and PlugXhttps://www.proofpoint.com/us/threat-insight/post/APT-targets-russia-belarus-zerot-plugx
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.02.02.APT_Targets_Russia_and_Belarus_with_ZeroT_and_PlugX
[Palo Alto Networks] Downeks and Quasar RAT Used in Recent Targeted Attacks Against Governmentshttp://researchcenter.paloaltonetworks.com/2017/01/unit42-downeks-and-quasar-rat-used-in-recent-targeted-attacks-against-governments/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.01.30.downeks-and-quasar-rat-used-in-recent-targeted-attacks-against-governments
[Cysinfo] URI Terror Attack & Kashmir Protest Themed Spear Phishing Emails Targeting Indian Embassies And Indian Ministry Of External Affairshttps://cysinfo.com/uri-terror-attack-spear-phishing-emails-targeting-indian-embassies-and-indian-mea/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.01.19.uri-terror-attack
[Trustwave] Operation Grand Mars: Defending Against Carbanak Cyber Attackshttps://www.trustwave.com/Resources/Library/Documents/Operation-Grand-Mars--Defending-Against-Carbanak-Cyber-Attacks/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.01.18.Operation-Grand-Mars
[tr1adx] Bear Spotting Vol. 1: Russian Nation State Targeting of Government and Military Interestshttps://www.tr1adx.net/intel/TIB-00003.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.01.15.Bear_Spotting_Vol.1
[Kaspersky] The “EyePyramid” attackshttps://securelist.com/blog/incidents/77098/the-eyepyramid-attacks/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.01.12.EyePyramid.attacks
[FireEye] APT28: AT THE CENTER OF THE STORMhttps://www.fireeye.com/blog/threat-research/2017/01/apt28_at_the_center.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.01.11.apt28_at_the_center
[Palo Alto Networks] Second Wave of Shamoon 2 Attacks Identifiedhttp://researchcenter.paloaltonetworks.com/2017/01/unit42-second-wave-shamoon-2-attacks-identified/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.01.09.second-wave-shamoon-2-attacks-identified
[Clearsky] Iranian Threat Agent OilRig Delivers Digitally Signed Malware, Impersonates University of Oxfordhttp://www.clearskysec.com/oilrig/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2017/2017.01.05.Iranian_Threat_Agent_OilRig
https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections#2016
[Microsoft] PROMETHIUM and NEODYMIUM APT groups on Turkish citizens living in Turkey and various other European countries.http://download.microsoft.com/download/E/B/0/EB0F50CC-989C-4B66-B7F6-68CD3DC90DE3/Microsoft_Security_Intelligence_Report_Volume_21_English.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.12.15.PROMETHIUM_and_NEODYMIUM
[ESET] The rise of TeleBots: Analyzing disruptive KillDisk attackshttp://www.welivesecurity.com/2016/12/13/rise-telebots-analyzing-disruptive-killdisk-attacks/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.12.13.rise-telebots-analyzing-disruptive-killdisk-attacks
[Palo Alto Networks] Tropic Trooper Targets Taiwanese Government and Fossil Fuel Provider With Poison Ivyhttp://researchcenter.paloaltonetworks.com/2016/11/unit42-tropic-trooper-targets-taiwanese-government-and-fossil-fuel-provider-with-poison-ivy/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.11.22.tropic-trooper-targets-taiwanese-government-and-fossil-fuel-provider-with-poison-ivy
[Fidelis] Down the H-W0rm Hole with Houdini's RAThttps://www.fidelissecurity.com/threatgeek/2016/11/down-h-w0rm-hole-houdinis-rat
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.11.09_down-the-h-w0rm-hole-with-houdinis-rat
[Booz Allen] When The Lights Went Out: Ukraine Cybersecurity Threat Briefinghttp://www.boozallen.com/content/dam/boozallen/documents/2016/09/ukraine-report-when-the-lights-went-out.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.11.03.Ukraine_Cybersecurity_Threat_Briefing
[Palo Alto Networks] Emissary Trojan Changelog: Did Operation Lotus Blossom Cause It to Evolve?http://researchcenter.paloaltonetworks.com/2016/02/emissary-trojan-changelog-did-operation-lotus-blossom-cause-it-to-evolve/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.10.31.Emissary_Trojan_Changelog
[ESET] En Route with Sednit Part 3: A Mysterious Downloaderhttp://www.welivesecurity.com/wp-content/uploads/2016/10/eset-sednit-part3.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.10.27.En_Route_Part3
[Trend Micro] BLACKGEAR Espionage Campaign Evolves, Adds Japan To Target Listhttp://blog.trendmicro.com/trendlabs-security-intelligence/blackgear-espionage-campaign-evolves-adds-japan-target-list/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.10.27.BLACKGEAR_Espionage_Campaign_Evolves
[Vectra Networks] Moonlight – Targeted attacks in the Middle Easthttp://blog.vectranetworks.com/blog/moonlight-middle-east-targeted-attacks
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.10.26.Moonlight_Middle_East
[Palo Alto Networks] Houdini’s Magic Reappearancehttp://researchcenter.paloaltonetworks.com/2016/10/unit42-houdinis-magic-reappearance/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.10.25.Houdini_Magic_Reappearance
[ESET] En Route with Sednit Part 2: Lifting the lid on Sednit: A closer look at the software it useshttp://www.welivesecurity.com/wp-content/uploads/2016/10/eset-sednit-part-2.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.10.25.Lifting_the_lid_on_Sednit
[ESET] En Route with Sednit Part 1: Approaching the Targethttp://www.welivesecurity.com/wp-content/uploads/2016/10/eset-sednit-part1.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.10.20.En_Route_with_Sednit
[ThreatConnect] ThreatConnect identifies Chinese targeting of two companies. Economic espionage or military intelligence? https://www.threatconnect.com/blog/threatconnect-discovers-chinese-apt-activity-in-europe/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.10.16.A_Tale_of_Two_Targets
[Kaspersky] Wave your false flagshttps://securelist.com/files/2016/10/Bartholomew-GuerreroSaade-VB2016.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.10.05_Wave_Your_False_flag
[Kaspersky] On the StrongPity Waterhole Attacks Targeting Italian and Belgian Encryption Usershttps://securelist.com/blog/research/76147/on-the-strongpity-waterhole-attacks-targeting-italian-and-belgian-encryption-users/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.10.03.StrongPity
[NATO CCD COE] China and Cyber: Attitudes, Strategies, Organisationhttps://ccdcoe.org/sites/default/files/multimedia/pdf/CS_organisation_CHINA_092016.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.09.29.China_and_Cyber_Attitudes_Strategies_Organisation
[ThreatConnect] Belling the BEAR: russia-hacks-bellingcat-mh17-investigationhttps://www.threatconnect.com/blog/russia-hacks-bellingcat-mh17-investigation/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.09.28.russia-hacks-bellingcat-mh17-investigation
[Palo Alto Networks] Sofacy’s ‘Komplex’ OS X Trojanhttp://researchcenter.paloaltonetworks.com/2016/09/unit42-sofacys-komplex-os-x-trojan/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.09.26_Sofacy_Komplex_OSX_Trojan
[Cyberkov] Hunting Libyan Scorpionshttps://cyberkov.com/wp-content/uploads/2016/09/Hunting-Libyan-Scorpions-EN.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.09.18.Hunting-Libyan-Scorpions
[Palo Alto Networks] MILE TEA: Cyber Espionage Campaign Targets Asia Pacific Businesses and Government Agencieshttp://researchcenter.paloaltonetworks.com/2016/09/mile-tea-cyber-espionage-campaign-targets-asia-pacific-businesses-and-government-agencies/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.09.14.MILE_TEA
[Symantec] Buckeye cyberespionage group shifts gaze from US to Hong Konghttp://www.symantec.com/connect/blogs/buckeye-cyberespionage-group-shifts-gaze-us-hong-kong
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.09.06.buckeye-cyberespionage-group-shifts-gaze-us-hong-kong
[IRAN THREATS] MALWARE POSING AS HUMAN RIGHTS ORGANIZATIONS AND COMMERCIAL SOFTWARE TARGETING IRANIANS, FOREIGN POLICY INSTITUTIONS AND MIDDLE EASTERN COUNTRIEShttps://iranthreats.github.io/resources/human-rights-impersonation-malware/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.09.01.human-rights-impersonation-malware
[Lookout] Technical Analysis of Pegasus Spywarehttps://info.lookout.com/rs/051-ESQ-475/images/lookout-pegasus-technical-analysis.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.08.25.lookout-pegasus-technical-analysis
[Citizen Lab] The Million Dollar Dissident: NSO Group’s iPhone Zero-Days used against a UAE Human Rights Defenderhttps://citizenlab.org/2016/08/million-dollar-dissident-iphone-zero-day-nso-group-uae/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.08.24.million-dollar-dissident-iphone-zero-day-nso-group-uae
[ThreatConnect] Russian Cyber Operations on Steroidshttps://www.threatconnect.com/blog/fancy-bear-anti-doping-agency-phishing/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.08.19.fancy-bear-anti-doping-agency-phishing
[Kaspersky] Operation Ghoul: targeted attacks on industrial and engineering organizationshttps://securelist.com/blog/research/75718/operation-ghoul-targeted-attacks-on-industrial-and-engineering-organizations/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.08.17_operation-ghoul
[Palo Alto Networks] Aveo Malware Family Targets Japanese Speaking Usershttp://researchcenter.paloaltonetworks.com/2016/08/unit42-aveo-malware-family-targets-japanese-speaking-users/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.08.16.aveo-malware-family-targets-japanese
[IRAN THREATS] Iran and the Soft War for Internet Dominancehttps://iranthreats.github.io/us-16-Guarnieri-Anderson-Iran-And-The-Soft-War-For-Internet-Dominance-paper.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.08.11.Iran-And-The-Soft-War-For-Internet-Dominance
[Forcepoint] MONSOONhttps://blogs.forcepoint.com/security-labs/monsoon-analysis-apt-campaign
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.08.08.monsoon-analysis-apt-campaign
[Kaspersky] ProjectSauron: top level cyber-espionage platform covertly extracts encrypted government commshttps://securelist.com/analysis/publications/75533/faq-the-projectsauron-apt/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.08.08.ProjectSauron
[Symantec] Strider: Cyberespionage group turns eye of Sauron on targetshttp://www.symantec.com/connect/blogs/strider-cyberespionage-group-turns-eye-sauron-targets
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.08.07.Strider_Cyberespionage_group_turns_eye_of_Sauron_on_targets
[Recorded Future] Running for Office: Russian APT Toolkits Revealedhttps://www.recordedfuture.com/russian-apt-toolkits/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.08.04.russian-apt-toolkits
[EFF] Operation Manul: I Got a Letter From the Government the Other Day...Unveiling a Campaign of Intimidation, Kidnapping, and Malware in Kazakhstanhttps://www.eff.org/files/2016/08/03/i-got-a-letter-from-the-government.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.08.03.i-got-a-letter-from-the-government
[Citizen Lab] Group5: Syria and the Iranian Connectionhttps://citizenlab.org/2016/08/group5-syria/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.08.02.group5-syria
[ICIT] China’s Espionage Dynastyhttp://icitech.org/wp-content/uploads/2016/07/ICIT-Brief-China-Espionage-Dynasty.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.07.28.China_Espionage_Dynasty
[Palo Alto Networks] Attack Delivers ‘9002’ Trojan Through Google Drivehttp://researchcenter.paloaltonetworks.com/2016/07/unit-42-attack-delivers-9002-trojan-through-google-drive/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.07.26.Attack_Delivers_9002_Trojan_Through_Google_Drive
[360] Sphinx (APT-C-15) Targeted cyber-attack in the Middle Easthttps://ti.360.com/upload/report/file/rmsxden20160721.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.07.21.Sphinx_Targeted_cyber-attack_in_the_Middle_East
[RSA] Hide and Seek: How Threat Actors Respond in the Face of Public Exposurehttps://www.rsaconference.com/writable/presentations/file_upload/tta1-f04_hide-and-seek-how-threat-actors-respond-in-the-face-of-public-exposure.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.07.21.Hide_and_Seek
[SentinelOne] State-Sponsored SCADA Malware targeting European Energy Companieshttps://sentinelone.com/blogs/sfg-furtims-parent/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.07.13.State-Sponsored_SCADA_Malware_targeting_European_Energy_Companies
[F-SECURE] NanHaiShu: RATing the South China Seahttps://www.f-secure.com/documents/996508/1030745/nanhaishu_whitepaper.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.07.12.NanHaiShu_RATing_the_South_China_Sea
[Kaspersky] The Dropping Elephant – aggressive cyber-espionage in the Asian regionhttps://securelist.com/blog/research/75328/the-dropping-elephant-actor/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.07.08.The_Dropping_Elephant
[Proofpoint] NetTraveler APT Targets Russian, European Interestshttps://www.proofpoint.com/us/threat-insight/post/nettraveler-apt-targets-russian-european-interests
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.07.07.nettraveler-apt-targets-russian-european-interests
[Cymmetria] UNVEILING PATCHWORK: THE COPY-PASTE APThttps://www.cymmetria.com/wp-content/uploads/2016/07/Unveiling-Patchwork.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.07.07.UNVEILING_PATCHWORK
[Check Point] From HummingBad to Worse http://blog.checkpoint.com/wp-content/uploads/2016/07/HummingBad-Research-report_FINAL-62916.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.07.03_From_HummingBad_to_Worse
[Bitdefender] Pacifier APThttp://download.bitdefender.com/resources/files/News/CaseStudies/study/115/Bitdefender-Whitepaper-PAC-A4-en-EN1.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.07.01.Bitdefender_Pacifier_APT
[ESET] Espionage toolkit targeting Central and Eastern Europe uncoveredhttp://www.welivesecurity.com/2016/07/01/espionage-toolkit-targeting-central-eastern-europe-uncovered/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.07.01.SBDH_toolkit_targeting_Central_and_Eastern_Europe
[JPCERT] Asruex: Malware Infecting through Shortcut Fileshttp://blog.jpcert.or.jp/2016/06/asruex-malware-infecting-through-shortcut-files.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.06.30.Asruex
[Proofpoint] MONSOON – ANALYSIS OF AN APT CAMPAIGNhttps://www.forcepoint.com/sites/default/files/resources/files/forcepoint-security-labs-monsoon-analysis-report.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.06.29.MonSoon
[Palo Alto Networks] Prince of Persia – Game Overhttp://researchcenter.paloaltonetworks.com/2016/06/unit42-prince-of-persia-game-over/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.06.28.prince-of-persia-game-over
[JPCERT] (Japan)Attack Tool Investigationhttps://www.jpcert.or.jp/research/20160628ac-ir_research.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.06.28.Attack_Tool_Investigation
[Trend Micro] The State of the ESILE/Lotus Blossom Campaignhttp://blog.trendmicro.com/trendlabs-security-intelligence/the-state-of-the-esilelotus-blossom-campaign/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.06.26.The_State_of_the_ESILE_Lotus_Blossom_Campaign
[Cylance] Nigerian Cybercriminals Target High-Impact Industries in India via Ponyhttps://blog.cylance.com/threat-update-nigerian-cybercriminals-target-high-impact-indian-industries-via-pony
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.06.26.Nigerian_Cybercriminals_Target_High_Impact_Industries_in_India
[Palo Alto Networks] Tracking Elirks Variants in Japan: Similarities to Previous Attackshttp://researchcenter.paloaltonetworks.com/2016/06/unit42-tracking-elirks-variants-in-japan-similarities-to-previous-attacks/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.06.23.Tracking_Elirks_Variants_in_Japan
[Fortinet] The Curious Case of an Unknown Trojan Targeting German-Speaking Usershttps://blog.fortinet.com/2016/06/21/the-curious-case-of-an-unknown-trojan-targeting-german-speaking-users
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.06.21.Unknown_Trojan_Targeting_German_Speaking_Users
[FireEye] Redline Drawn: China Recalculates Its Use of Cyber Espionagehttps://www.fireeye.com/content/dam/fireeye-www/current-threats/pdfs/rpt-china-espionage.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.06.21.Redline_Drawn_China_Recalculates_Its_Use_of_Cyber_Espionage
[ESET] Visiting The Bear Denhttp://www.welivesecurity.com/wp-content/uploads/2016/06/visiting_the_bear_den_recon_2016_calvet_campos_dupuy-1.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.06.21.visiting_the_bear_den_recon_2016_calvet_campos_dupuy
[Dell] Threat Group-4127 Targets Hillary Clinton Presidential Campaignhttps://www.secureworks.com/research/threat-group-4127-targets-hillary-clinton-presidential-campaign
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.06.16.DNC
[CrowdStrike] Bears in the Midst: Intrusion into the Democratic National Committeehttps://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.06.09.Operation_DustySky_II
[Clearsky] Operation DustySky Part 2http://www.clearskysec.com/wp-content/uploads/2016/06/Operation-DustySky2_-6.2016_TLP_White.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.06.09.Operation_DustySky_II
[Trend Micro] FastPOS: Quick and Easy Credit Card Thefthttp://documents.trendmicro.com/assets/fastPOS-quick-and-easy-credit-card-theft.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.06.02.fastpos-quick-and-easy-credit-card-theft
[Trend Micro] IXESHE Derivative IHEATE Targets Users in Americahttp://blog.trendmicro.com/trendlabs-security-intelligence/ixeshe-derivative-iheate-targets-users-america/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.05.27.IXESHE_Derivative_IHEATE_Targets_Users_in_America
[Palo Alto Networks] The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoorhttp://researchcenter.paloaltonetworks.com/2016/05/the-oilrig-campaign-attacks-on-saudi-arabian-organizations-deliver-helminth-backdoor/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.05.26.OilRig_Campaign
[Kaspersky] CVE-2015-2545: overview of current threatshttps://securelist.com/analysis/publications/74828/cve-2015-2545-overview-of-current-threats/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.05.25.CVE-2015-2545
[Palo Alto Networks] New Wekby Attacks Use DNS Requests As Command and Control Mechanismhttp://researchcenter.paloaltonetworks.com/2016/05/unit42-new-wekby-attacks-use-dns-requests-as-command-and-control-mechanism/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.05.24.New_Wekby_Attacks
[MELANI:GovCERT] APT Case RUAG Technical Reporthttps://www.melani.admin.ch/dam/melani/en/dokumente/2016/technical%20report%20ruag.pdf.download.pdf/Report_Ruag-Espionage-Case.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.05.23.APT_Case_RUAG
[FireEye] TARGETED ATTACKS AGAINST BANKS IN THE MIDDLE EASThttps://www.fireeye.com/blog/threat-research/2016/05/targeted_attacksaga.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.05.22.Targeted_Attacks_Against_Banks_in_Middle_East
[Palo Alto Networks] Operation Ke3chang Resurfaces With New TidePool Malwarehttp://researchcenter.paloaltonetworks.com/2016/05/operation-ke3chang-resurfaces-with-new-tidepool-malware/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.05.22.Operation_Ke3chang_Resurfaces_With_New_TidePool_Malware
[ESET] Operation Groundbait: Analysis of a surveillance toolkithttp://www.welivesecurity.com/wp-content/uploads/2016/05/Operation-Groundbait.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.05.18.Operation_Groundbait
[FOX-IT] Mofang: A politically motivated information stealing adversaryhttps://foxitsecurity.files.wordpress.com/2016/06/fox-it_mofang_threatreport_tlp-white.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.05.17.Mofang
[Symantec] Indian organizations targeted in Suckfly attackshttp://www.symantec.com/connect/ko/blogs/indian-organizations-targeted-suckfly-attacks
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.05.17.Indian_organizations_targeted_in_Suckfly_attacks
[Trend Micro] Backdoor as a Software Suite: How TinyLoader Distributes and Upgrades PoS Threatshttp://blog.trendmicro.com/trendlabs-security-intelligence/how-tinyloader-distributes-and-upgrades-pos-threats/
paperhttp://documents.trendmicro.com/assets/tinypos-abaddonpos-ties-to-tinyloader.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.05.10.tinyPOS_tinyloader
[CMU SEI] Using Honeynets and the Diamond Model for ICS Threat Analysishttp://resources.sei.cmu.edu/asset_files/TechnicalReport/2016_005_001_454247.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.05.09_ICS_Threat_Analysis
[PwC] Exploring CVE-2015-2545 and its usershttp://pwc.blogs.com/cyber_security_updates/2016/05/exploring-cve-2015-2545-and-its-users.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.05.06_Exploring_CVE-2015-2545
[Forcepoint] Jaku: an on-going botnet campaignhttps://www.forcepoint.com/sites/default/files/resources/files/report_jaku_analysis_of_botnet_campaign_en_0.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.05.05_Jaku_botnet_campaign
[Team Cymru] GOZNYM MALWARE target US, AT, DE https://blog.team-cymru.org/2016/05/goznym-malware/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.05.02.GOZNYM_MALWARE
[Palo Alto Networks] Prince of Persia: Infy Malware Active In Decade of Targeted Attackshttp://researchcenter.paloaltonetworks.com/2016/05/prince-of-persia-infy-malware-active-in-decade-of-targeted-attacks/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.05.02.Prince_of_Persia_Infy_Malware
[Kaspersky] Repackaging Open Source BeEF for Tracking and Morehttps://securelist.com/blog/software/74503/freezer-paper-around-free-meat/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.04.27.Repackaging_Open_Source_BeEF
[Financial Times] Cyber warfare: Iran opens a new fronthttp://www.ft.com/intl/cms/s/0/15e1acf0-0a47-11e6-b0f1-61f222853ff3.html#axzz478cZz3ao
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.04.26.Iran_Opens_a_New_Front
[Arbor] New Poison Ivy Activity Targeting Myanmar, Asian Countrieshttps://www.arbornetworks.com/blog/asert/recent-poison-iv/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.04.26.New_Poison_Ivy_Activity_Targeting_Myanmar_Asian_Countries
[Cylance] The Ghost Dragonhttps://blog.cylance.com/the-ghost-dragon
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.04.22.the-ghost-dragon
[SentinelOne] Teaching an old RAT new trickshttps://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.04.21.Teaching_an_old_RAT_new_tricks
[Palo Alto Networks] New Poison Ivy RAT Variant Targets Hong Kong Pro-Democracy Activistshttp://researchcenter.paloaltonetworks.com/2016/04/unit42-new-poison-ivy-rat-variant-targets-hong-kong-pro-democracy-activists/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.04.21.New_Poison_Ivy_RAT_Variant_Targets_Hong_Kong
[Citizen Lab] Between Hong Kong and Burma: Tracking UP007 and SLServer Espionage Campaignshttps://citizenlab.org/2016/04/between-hong-kong-and-burma/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.04.18.UP007
[SANS] Detecting and Responding Pandas and Bearshttp://files.sans.org/summit/Threat_Hunting_Incident_Response_Summit_2016/PDFs/Detecting-and-Responding-to-Pandas-and-Bears-Christopher-Scott-CrowdStrike-and-Wendi-Whitmore-IBM.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.04.15.pandas_and_bears
[Microsoft] PLATINUM: Targeted attacks in South and Southeast Asiahttp://download.microsoft.com/download/2/2/5/225BFE3E-E1DE-4F5B-A77B-71200928D209/Platinum%20feature%20article%20-%20Targeted%20attacks%20in%20South%20and%20Southeast%20Asia%20April%202016.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.04.12.PLATINUM_Targeted_attacks_in_South_and_Southeast_Asia
[Palo Alto Networks] ProjectM: Link Found Between Pakistani Actor and Operation Transparent Tribehttp://researchcenter.paloaltonetworks.com/2016/03/unit42-projectm-link-found-between-pakistani-actor-and-operation-transparent-tribe/?utm_medium=email&utm_source=Adobe%20Campaign&utm_campaign=Unit%2042%20Blog%20Updates%2031Mar16
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.03.25.ProjectM
[Trend Micro] Operation C-Major: Information Theft Campaign Targets Military Personnel in Indiahttp://blog.trendmicro.com/trendlabs-security-intelligence/indian-military-personnel-targeted-by-information-theft-campaign/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.03.23.Operation_C_Major
[SANS] Analysis of the Cyber Attack on the Ukrainian Power Grid: Defense Use Casehttps://ics.sans.org/media/E-ISAC_SANS_Ukraine_DUC_5.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.03.18.Analysis_of_the_Cyber_Attack_on_the_Ukrainian_Power_Grid
[PwC] Taiwan Presidential Election: A Case Study on Thematic Targetinghttp://pwc.blogs.com/cyber_security_updates/2016/03/taiwant-election-targetting.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.03.17.Taiwan-election-targetting
[Symantec] Suckfly: Revealing the secret life of your code signing certificateshttp://www.symantec.com/connect/blogs/suckfly-revealing-secret-life-your-code-signing-certificates
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.03.15.Suckfly
[Proofpoint] Bank robbery in progress: New attacks from Carbanak group target banks in Middle East and UShttps://www.proofpoint.com/us/threat-insight/post/carbanak-cybercrime-group-targets-executives-of-financial-organizations-in-middle-east
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.03.14.Carbanak_cybercrime_group
[Citizen Lab] Shifting Tactics: Tracking changes in years-long espionage campaign against Tibetanshttps://citizenlab.org/2016/03/shifting-tactics/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.03.10.shifting-tactics
[FireEye] LESSONS FROM OPERATION RUSSIANDOLLhttps://www.fireeye.com/blog/threat-research/2016/03/lessons-from-operation-russian-doll.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.03.09.Operation_RussianDoll
[360] Operation OnionDog: A 3 Year Old APT Focused On the Energy and Transportation Industries in Korean-language Countrieshttp://www.prnewswire.com/news-releases/onion-dog-a-3-year-old-apt-focused-on-the-energy-and-transportation-industries-in-korean-language-countries-is-exposed-by-360-300232441.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.03.08.OnionDog
[Recorded Future] Shedding Light on BlackEnergy With Open Source Intelligencehttps://www.recordedfuture.com/blackenergy-malware-analysis/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.03.03.Shedding_Light_BlackEnergy
[Proofpoint] Operation Transparent Tribe - APT Targeting Indian Diplomatic and Military Interestshttps://www.proofpoint.com/us/threat-insight/post/Operation-Transparent-Tribe
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.03.01.Operation_Transparent_Tribe
[Fidelis] The Turbo Campaign, Featuring Derusbi for 64-bit Linuxhttps://www.fidelissecurity.com/sites/default/files/TA_Fidelis_Turbo_1602_0.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.02.24.Operation_Blockbuster
[NOVETTA] Operation Blockbusterhttps://www.operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Report.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.02.24.Operation_Blockbuster
[Cylance] OPERATION DUST STORMhttps://www.cylance.com/hubfs/2015_cylance_website/assets/operation-dust-storm/Op_Dust_Storm_Report.pdf?t=1456355696065
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.02.23.Operation_Dust_Storm
[Palo Alto Networks] A Look Into Fysbis: Sofacy’s Linux Backdoorhttp://researchcenter.paloaltonetworks.com/2016/02/a-look-into-fysbis-sofacys-linux-backdoor/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.02.12.Fysbis_Sofacy_Linux_Backdoor
[Recorded Future] Hacktivism: India vs. Pakistanhttps://www.recordedfuture.com/india-pakistan-cyber-rivalry/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.02.11.Hacktivism_India_vs_Pakistan
[Kaspersky] Poseidon Group: a Targeted Attack Boutique specializing in global cyber-espionagehttps://securelist.com/blog/research/73673/poseidon-group-a-targeted-attack-boutique-specializing-in-global-cyber-espionage/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.02.09_Poseidon_APT_Boutique
[ICIT] Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groupshttp://icitech.org/know-your-enemies-2-0/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.02.08.Know_Your_Enemies_2.0
[Palo Alto Networks] T9000: Advanced Modular Backdoor Uses Complex Anti-Analysis Techniqueshttp://researchcenter.paloaltonetworks.com/2016/02/t9000-advanced-modular-backdoor-uses-complex-anti-analysis-techniques/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.02.04_PaloAlto_T9000-Advanced-Modular-Backdoor
[Palo Alto Networks] Emissary Trojan Changelog: Did Operation Lotus Blossom Cause It to Evolve?http://researchcenter.paloaltonetworks.com/2016/02/emissary-trojan-changelog-did-operation-lotus-blossom-cause-it-to-evolve/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016.02.03.Emissary_Trojan_Changelog
[Sucuri] Massive Admedia/Adverting iFrame Infectionhttps://blog.sucuri.net/2016/02/massive-admedia-iframe-javascript-infection.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.02.01.Massive_Admedia_Adverting_iFrame_Infection
[IBM] Organized Cybercrime Big in Japan: URLZone Now on the Scenehttps://securityintelligence.com/organized-cybercrime-big-in-japan-urlzone-now-on-the-scene/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.02.01.URLzone_Team
[F5] Tinbapore: Millions of Dollars at Riskhttps://devcentral.f5.com/d/tinbapore-millions-of-dollars-at-risk?download=true
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.01.29.Tinbapore_Attack
[Zscaler] Malicious Office files dropping Kasidet and Dridexhttp://research.zscaler.com/2016/01/malicious-office-files-dropping-kasidet.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.01.29.Malicious_Office_files_dropping_Kasidet_and_Dridex
[Kaspersky] BlackEnergy APT Attacks in Ukraine employ spearphishing with Word documentshttps://securelist.com/blog/research/73440/blackenergy-apt-attacks-in-ukraine-employ-spearphishing-with-word-documents/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.01.28.BlackEnergy_APT
[Fidelis] Dissecting the Malware Involved in the INOCNATION Campaignhttps://www.fidelissecurity.com/sites/default/files/FTA_1020_Fidelis_Inocnation_FINAL.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.01.27.Hi-Zor.RAT
[SentinelOne] Analyzing a New Variant of BlackEnergy 3https://www.sentinelone.com/wp-content/uploads/2016/01/BlackEnergy3_WP_012716_1c.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.01.26.BlackEnergy3
[Palo Alto Networks] Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activistshttp://researchcenter.paloaltonetworks.com/2016/01/scarlet-mimic-years-long-espionage-targets-minority-activists/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.01.24_Scarlet_Minic
[Palo Alto Networks] NetTraveler Spear-Phishing Email Targets Diplomat of Uzbekistanhttp://researchcenter.paloaltonetworks.com/2016/01/nettraveler-spear-phishing-email-targets-diplomat-of-uzbekistan/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.01.21.NetTraveler_Uzbekistan
[360] 2015 APT Annual Reporthttps://ti.360.com/upload/report/file/2015.APT.Annual_Report.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.01.19.360_APT_Report
[CISCO] RESEARCH SPOTLIGHT: NEEDLES IN A HAYSTACKhttp://blog.talosintel.com/2016/01/haystack.html#more
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.01.14_Cisco_Needles_in_a_Haystack
[Symantec] The Waterbug attack grouphttps://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/waterbug-attack-group.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.01.14.The.Waterbug.Attack.Group
[Clearsky] Operation DustySkyhttp://www.clearskysec.com/wp-content/uploads/2016/01/Operation%20DustySky_TLP_WHITE.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.01.07.Operation_DustySky
[CISCO] RIGGING COMPROMISE - RIG EXPLOIT KIThttp://blog.talosintel.com/2016/01/rigging-compromise.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.01.07.rigging-compromise
[ESET] BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industryhttp://www.welivesecurity.com/2016/01/03/blackenergy-sshbeardoor-details-2015-attacks-ukrainian-news-media-electric-industry/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2016/2016.01.03.BlackEnergy_Ukrainian
https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections#2015
[PwC] ELISE: Security Through Obesityhttp://pwc.blogs.com/cyber_security_updates/2015/12/elise-security-through-obesity.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.12.13.ELISE
[Palo Alto Networks] BBSRAT Attacks Targeting Russian Organizations Linked to Roaming Tigerhttp://researchcenter.paloaltonetworks.com/2015/12/bbsrat-attacks-targeting-russian-organizations-linked-to-roaming-tiger/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.12.22.BBSRAT_Roaming_Tiger
[FireEye] The EPS Awakens - Part 2https://www.fireeye.com/blog/threat-research/2015/12/the-eps-awakens-part-two.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.12.20.EPS_Awakens_Part_II
[Palo Alto Networks] Attack on French Diplomat Linked to Operation Lotus Blossomhttp://researchcenter.paloaltonetworks.com/2015/12/attack-on-french-diplomat-linked-to-operation-lotus-blossom/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.12.18.Attack_on_Frence_Diplomat_Linked_To_Operation_Lotus_Blossom
[Bitdefender] APT28 Under the Scope - A Journey into Exfiltrating Intelligence and Government Informationhttp://download.bitdefender.com/resources/media/materials/white-papers/en/Bitdefender_In-depth_analysis_of_APT28%E2%80%93The_Political_Cyber-Espionage.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.12.17.APT28_Under_The_Scope
[Trend Micro] Operation Black Atlas, Part 2: Tools and Malware Used and How to Detect Themhttp://documents.trendmicro.com/assets/Operation_Black%20Atlas_Technical_Brief.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.12.16.INOCNATION.Campaign
[Fidelis] Dissecting the Malware Involved in the INOCNATION Campaignhttps://www.fidelissecurity.com/sites/default/files/FTA_1020_Fidelis_Inocnation_FINAL.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.12.16.INOCNATION.Campaign
[AirBus] Newcomers in the Derusbi familyhttp://blog.airbuscybersecurity.com/post/2015/11/Newcomers-in-the-Derusbi-family
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.12.15.Newcomers_in_the_Derusbi_family
[Citizen Lab] Packrat: Seven Years of a South American Threat Actorhttps://citizenlab.org/2015/12/packrat-report/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.12.08.Packrat
[FireEye] Financial Threat Group Targets Volume Boot Recordhttps://www.fireeye.com/blog/threat-research/2015/12/fin1-targets-boot-record.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.12.07.Thriving_Beyond_The_Operating_System
[Symantec] Iran-based attackers use back door threats to spy on Middle Eastern targetshttp://www.symantec.com/connect/blogs/iran-based-attackers-use-back-door-threats-spy-middle-eastern-targets
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.12.07.Iran-based
[Kaspersky] Sofacy APT hits high profile targets with updated toolsethttps://securelist.com/blog/research/72924/sofacy-apt-hits-high-profile-targets-with-updated-toolset/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.12.04.Sofacy_APT
[FireEye] China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outletshttps://www.fireeye.com/blog/threat-research/2015/11/china-based-threat.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.12.01.China-based_Cyber_Threat_Group_Uses_Dropbox_for_Malware_Communications_and_Targets_Hong_Kong_Media_Outlets
[FOX-IT] Ponmocup A giant hiding in the shadowshttps://foxitsecurity.files.wordpress.com/2015/12/foxit-whitepaper_ponmocup_1_1.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.11.30.Ponmocup
[Palo Alto Networks] Attack Campaign on the Government of Thailand Delivers Bookworm Trojanhttp://researchcenter.paloaltonetworks.com/2015/11/attack-campaign-on-the-government-of-thailand-delivers-bookworm-trojan/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.11.24.Attack_Campaign_on_the_Government_of_Thailand_Delivers_Bookworm_Trojan
[Minerva Labs, ClearSky] CopyKittens Attack Grouphttps://s3-eu-west-1.amazonaws.com/minervaresearchpublic/CopyKittens/CopyKittens.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.11.23.CopyKittens_Attack_Group
[RSA] PEERING INTO GLASSRAThttps://blogs.rsa.com/wp-content/uploads/2015/11/GlassRAT-final.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.11.23.PEERING_INTO_GLASSRAT
[Trend Micro] Prototype Nation: The Chinese Cybercriminal Underground in 2015http://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/prototype-nation-the-chinese-cybercriminal-underground-in-2015/?utm_source=siblog&utm_medium=referral&utm_campaign=2015-cn-ug
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.11.23.Prototype_Nation_The_Chinese_Cybercriminal_Underground_in_2015
[Kaspersky] Russian financial cybercrime: how it workshttps://securelist.com/analysis/publications/72782/russian-financial-cybercrime-how-it-works/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.11.18.Russian_financial_cybercrime_how_it_works
[JPCERT] Decrypting Strings in Emdivihttp://blog.jpcert.or.jp/2015/11/decrypting-strings-in-emdivi.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.11.19.decrypting-strings-in-emdivi
[Palo Alto Networks] TDrop2 Attacks Suggest Dark Seoul Attackers Returnhttp://researchcenter.paloaltonetworks.com/2015/11/tdrop2-attacks-suggest-dark-seoul-attackers-return/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.11.18.tdrop2
[CrowdStrike] Sakula Reloadedhttp://blog.crowdstrike.com/sakula-reloaded/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.11.18.Sakula_Reloaded
[Damballa] Damballa discovers new toolset linked to Destover Attacker’s arsenal helps them to broaden attack surfacehttps://paper.seebug.org/papers/APT/APT_CyberCriminal_Campagin/2015/2015.11.18.Destover/amballa-discovers-new-toolset-linked-to-destover-attackers-arsenal-helps-them-to-broaden-attack-surface.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.11.18.Destover
[FireEye] WitchCoven: Exploiting Web Analytics to Ensnare Victimshttps://www2.fireeye.com/threat-intel-report-WITCHCOVEN.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.11.17.Pinpointing_Targets_Exploiting_Web_Analytics_to_Ensnare_Victims
[Palo Alto Networks] Bookworm Trojan: A Model of Modular Architecturehttp://researchcenter.paloaltonetworks.com/2015/11/bookworm-trojan-a-model-of-modular-architecture/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.11.10.bookworm-trojan-a-model-of-modular-architecture
[Check Point] Rocket Kitten: A Campaign With 9 Liveshttp://blog.checkpoint.com/wp-content/uploads/2015/11/rocket-kitten-report.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.11.09.Rocket_Kitten_A_Campaign_With_9_Lives
[RSA] Evolving Threats:dissection of a CyberEspionage attackhttp://www.rsaconference.com/writable/presentations/file_upload/cct-w08_evolving-threats-dissection-of-a-cyber-espionage-attack.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.11.04_Evolving_Threats
[Citizen Lab] Targeted Malware Attacks against NGO Linked to Attacks on Burmese Government Websiteshttps://citizenlab.org/2015/10/targeted-attacks-ngo-burma/
https://otx.alienvault.com/pulse/5621208f4637f21ecf2aac36/https://otx.alienvault.com/pulse/5621208f4637f21ecf2aac36/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.10.targeted-attacks-ngo-burma.pdf
[Citizen Lab] Pay No Attention to the Server Behind the Proxy: Mapping FinFisher’s Continuing Proliferationhttps://citizenlab.org/2015/10/mapping-finfishers-continuing-proliferation/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/Mapping%20FinFisher%E2%80%99s%20Continuing%20Proliferation.pdf
[Recorded Future] Proactive Threat Identification Neutralizes Remote Access Trojan Efficacyhttp://go.recordedfuture.com/hubfs/reports/threat-identification.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.10.05.Proactive_Threat_Identification
[Cybereason] Webmail Server APT: A New Persistent Attack Methodology Targeting Microsoft Outlook Web Application (OWA)http://go.cybereason.com/rs/996-YZT-709/images/Cybereason-Labs-Analysis-Webmail-Sever-APT.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/Cybereason-Labs-Analysis-Webmail-Sever-APT.pdf
[ThreatConnect] PROJECT CAMERASHY: CLOSING THE APERTURE ON CHINA’S UNIT 78020https://www.threatconnect.com/camerashy-intro/
PDFhttps://cdn2.hubspot.net/hubfs/454298/Project_CAMERASHY_ThreatConnect_Copyright_2015.pdf
localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.09.23.CAMERASHY_ThreatConnect
[F-SECURE] The Dukes 7 Years of Russian Cyber Espionagehttps://labsblog.f-secure.com/2015/09/17/the-dukes-7-years-of-russian-cyber-espionage/
PDFhttps://www.f-secure.com/documents/996508/1030745/dukes_whitepaper.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.09.17.duke_russian
[Proofpoint] The shadow knows: Malvertising campaigns use domain shadowing to pull in Angler EKhttps://www.proofpoint.com/us/threat-insight/post/The-Shadow-Knows
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.09.16.The-Shadow-Knows
[Trend Micro] Operation Iron Tiger: How China-Based Actors Shifted Attacks from APAC to US Targetshttp://newsroom.trendmicro.com/blog/operation-iron-tiger-attackers-shift-east-asia-united-states
IOChttps://otx.alienvault.com/pulse/55f9910967db8c6fb35179bd/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.09.17.Operation_Iron_Tiger
[Proofpoint] In Pursuit of Optical Fibers and Troop Intel: Targeted Attack Distributes PlugX in Russiahttps://www.proofpoint.com/us/threat-insight/post/PlugX-in-Russia
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.09.15.PlugX_in_Russia
[Kaspersky] Satellite Turla: APT Command and Control in the Skyhttps://securelist.com/blog/research/72081/satellite-turla-apt-command-and-control-in-the-sky/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.09.09.satellite-turla-apt
[Palo Alto Networks] Musical Chairs: Multi-Year Campaign Involving New Variant of Gh0st Malwarehttp://researchcenter.paloaltonetworks.com/2015/09/musical-chairs-multi-year-campaign-involving-new-variant-of-gh0st-malware/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.09.08.Musical_Chairs_Gh0st_Malware
[Trend Micro, Clearsky] The Spy Kittens Are Back: Rocket Kitten 2http://www.trendmicro.tw/vinfo/us/security/news/cyber-attacks/rocket-kitten-continues-attacks-on-middle-east-targets
PDFhttp://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp-the-spy-kittens-are-back.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.09.01.Rocket_Kitten_2
[Arbor] PlugX Threat Activity in Myanmarhttp://pages.arbornetworks.com/rs/082-KNA-087/images/ASERT%20Threat%20Intelligence%20Brief%202015-05%20PlugX%20Threat%20Activity%20in%20Myanmar.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/Sep.01.PlugX_Threat_Activity_in_Myanmar
[Kaspersky] New activity of the Blue Termite APThttps://securelist.com/blog/research/71876/new-activity-of-the-blue-termite-apt/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.08.20.new-activity-of-the-blue-termite-apt
[Symantec] New Internet Explorer zero-day exploited in Hong Kong attackshttp://www.symantec.com/connect/blogs/new-internet-explorer-zero-day-exploited-hong-kong-attacks
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.08.19.new-internet-explorer-zero-day-exploited-hong-kong-attacks
[ShadowServer] The Italian Connection: An analysis of exploit supply chains and digital quartermastershttp://blog.shadowserver.org/2015/08/10/the-italian-connection-an-analysis-of-exploit-supply-chains-and-digital-quartermasters/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/Aug.10.The_Italian_Connection_An_analysis_of_exploit_supply_chains_and_digital_quartermasters
[cyint.dude] Threat Analysis: Poison Ivy and Links to an Extended PlugX Campaignhttp://www.cyintanalysis.com/threat-analysis-poison-ivy-and-links-to-an-extended-plugx-campaign/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/Aug.08.Threat_Analysis:Poison_Ivy_and_Links_to_an_Extended_PlugX_Campaign
[Dell] Threat Group-3390 Targets Organizations for Cyberespionagehttp://www.secureworks.com/cyber-threat-intelligence/threats/threat-group-3390-targets-organizations-for-cyberespionage/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/Aug.05.Threat_Group-3390_Targets_Organizations_for_Cyberespionage
[RSA] Terracotta VPN: Enabler of Advanced Threat Anonymityhttps://blogs.rsa.com/terracotta-vpn-enabler-of-advanced-threat-anonymity/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.08.04.Terracotta_VPN
[ESET] Operation Potao Expresshttp://www.welivesecurity.com/2015/07/30/operation-potao-express/
IOChttps://github.com/eset/malware-ioc/tree/master/potao
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.07.30.Operation-Potao-Express
[Symantec] Black Vine: Formidable cyberespionage group targeted aerospace, healthcare since 2012http://www.symantec.com/connect/blogs/black-vine-formidable-cyberespionage-group-targeted-aerospace-healthcare-2012
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.07.28.Black_Vine
[FireEye] HAMMERTOSS: Stealthy Tactics Define a Russian Cyber Threat Grouphttps://www.fireeye.com/blog/threat-research/2015/07/hammertoss_stealthy.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.07.27.HAMMERTOSS
[F-SECURE] Duke APT group's latest tools: cloud services and Linux supporthttps://www.f-secure.com/weblog/archives/00002822.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.07.22.Duke_APT_groups_latest_tools
[ThreatConnect] China Hacks the Peace Palace: All Your EEZ’s Are Belong to Ushttp://www.threatconnect.com/news/china-hacks-the-peace-palace-all-your-eezs-are-belong-to-us/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.07.20.China_Peace_Palace
[Palo Alto Networks] Watering Hole Attack on Aerospace Firm Exploits CVE-2015-5122 to Install IsSpace Backdoorhttp://researchcenter.paloaltonetworks.com/2015/07/watering-hole-attack-on-aerospace-firm-exploits-cve-2015-5122-to-install-isspace-backdoor/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.07.20.IsSpace_Backdoor
[Palo Alto Networks] Tracking MiniDionis: CozyCar’s New Ride Is Related to Seadukehttp://researchcenter.paloaltonetworks.com/2015/07/tracking-minidionis-cozycars-new-ride-is-related-to-seaduke/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.07.14.tracking-minidionis-cozycars
[Trend Micro] An In-Depth Look at How Pawn Storm’s Java Zero-Day Was Usedhttp://blog.trendmicro.com/trendlabs-security-intelligence/an-in-depth-look-at-how-pawn-storms-java-zero-day-was-used/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.07.14.How_Pawn_Storm_Java_Zero-Day_Was_Used
[Symantec] "Forkmeiamfamous": Seaduke, latest weapon in the Duke armoryhttp://www.symantec.com/connect/blogs/forkmeiamfamous-seaduke-latest-weapon-duke-armory
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.07.13.Forkmeiamfamous
[FireEye] Demonstrating Hustle, Chinese APT Groups Quickly Use Zero-Day Vulnerability CVE-2015-5119 Following Hacking Team Leakhttps://www.fireeye.com/blog/threat-research/2015/07/demonstrating_hustle.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.07.13.Demonstrating_Hustle
[Palo Alto Networks] APT Group UPS Targets US Government with Hacking Team Flash Exploithttp://researchcenter.paloaltonetworks.com/2015/07/apt-group-ups-targets-us-government-with-hacking-team-flash-exploit/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.07.10.APT_Group_UPS_Targets_US_Government
[Symantec] Butterfly: Corporate spies out for financial gainhttp://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/butterfly-corporate-spies-out-for-financial-gain.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.07.09.Butterfly
[Kaspersky] Wild Neutron – Economic espionage threat actor returns with new trickshttps://securelist.com/blog/research/71275/wild-neutron-economic-espionage-threat-actor-returns-with-new-tricks/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.07.08.Wild_Neutron
[Volexity] APT Group Wekby Leveraging Adobe Flash Exploit (CVE-2015-5119)http://www.volexity.com/blog/?p=158
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.07.08.APT_CVE-2015-5119
[ESET] Dino – the latest spying malware from an allegedly French espionage group analyzedhttp://www.welivesecurity.com/2015/06/30/dino-spying-malware-analyzed
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.06.30.dino-spying-malware-analyzed
[Dragon Threat Labs] APT on Taiwan - insight into advances of adversary TTPshttp://blog.dragonthreatlabs.com/2015/07/dtl-06282015-01-apt-on-taiwan-insight.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.06.28.APT_on_Taiwan
[FireEye] Operation Clandestine Wolf – Adobe Flash Zero-Day in APT3 Phishing Campaignhttps://www.fireeye.com/blog/threat-research/2015/06/operation-clandestine-wolf-adobe-flash-zero-day.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.06.26.operation-clandestine-wolf
[PwC] UnFIN4ished Business (FIN4)http://pwc.blogs.com/cyber_security_updates/2015/06/unfin4ished-business.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.06.24.unfin4ished-business
[Kaspersky] Winnti targeting pharmaceutical companieshttps://securelist.com/blog/research/70991/games-are-over/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.06.22.Winnti_targeting_pharmaceutical_companies
[Palo Alto Networks] Operation Lotus Bloomhttps://www.paloaltonetworks.com/resources/research/unit42-operation-lotus-blossom.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.06.16.operation-lotus-blossom
[Citizen Lab] Targeted Attacks against Tibetan and Hong Kong Groups Exploiting CVE-2014-4114https://citizenlab.org/2015/06/targeted-attacks-against-tibetan-and-hong-kong-groups-exploiting-cve-2014-4114/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.06.15.Targeted-Attacks-against-Tibetan-and-Hong-Kong-Groups
[Volexity] Afghan Government Compromise: Browser Bewarehttp://www.volexity.com/blog/?p=134
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.06.12.Afghan_Government_Compromise
[Kaspersky] The_Mystery_of_Duqu_2_0https://securelist.com/files/2015/06/The_Mystery_of_Duqu_2_0_a_sophisticated_cyberespionage_actor_returns.pdf
IOChttps://securelist.com/files/2015/06/7c6ce6b6-fee1-4b7b-b5b5-adaff0d8022f.ioc
Yarahttps://securelist.com/files/2015/06/Duqu_2_Yara_rules.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.06.10.The_Mystery_of_Duqu_2_0
[Crysys Lab] Duqu 2.0http://blog.crysys.hu/2015/06/duqu-2-0/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.06.10.Duqu_2.0
[Microsoft] Duqu 2.0 Win32k Exploit Analysishttps://www.virusbtn.com/pdf/conference_slides/2015/OhFlorio-VB2015.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.06.09.Duqu_2.0_Win32k_Exploit_Analysis
[JP Internet Watch] Blue Thermite targeting Japan (CloudyOmega)http://internet.watch.impress.co.jp/docs/news/20150604_705541.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.06.09.Duqu_2.0_Win32k_Exploit_Analysis
[ClearSky] Thamar Reservoirhttp://www.clearskysec.com/thamar-reservoir/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.06.03.thamar-reservoir
OceanLotusReporthttp://blogs.360.cn/blog/oceanlotus-apt/
Grabit and the RATshttps://securelist.com/blog/research/70087/grabit-and-the-rats/
Analysis On Apt-To-Be Attack That Focusing On China's Government Agency'http://www.antiy.net/p/analysis-on-apt-to-be-attack-that-focusing-on-chinas-government-agency/
BlackEnergy 3 – Exfiltration of Data in ICS Networkshttp://cyberx-labs.com/wp-content/uploads/2015/05/BlackEnergy-CyberX-Report_27_May_2015_FINAL.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.05.27.BlackEnergy3
Dissecting-Linux/Moosehttp://www.welivesecurity.com/wp-content/uploads/2015/05/Dissecting-LinuxMoose.pdf
The Naikon APT and the MsnMM Campaignshttps://securelist.com/blog/research/70029/the-naikon-apt-and-the-msnmm-campaigns/
Operation 'Oil Tanker'http://www.pandasecurity.com/mediacenter/src/uploads/2015/05/oil-tanker-en.pdf
Cmstar Downloader: Lurid and Enfal’s New Cousinhttp://researchcenter.paloaltonetworks.com/2015/05/cmstar-downloader-lurid-and-enfals-new-cousin/
Operation Tropic Trooperhttp://blog.trendmicro.com/trendlabs-security-intelligence/operation-tropic-trooper-old-vulnerabilities-still-pack-a-punch/
The Naikon APThttps://securelist.com/analysis/publications/69953/the-naikon-apt/
SPEAR: A Threat Actor Resurfaceshttp://blog.cylance.com/spear-a-threat-actor-resurfaces
root9B Uncovers Planned Sofacy Cyber Attack Targeting Several International and Domestic Financial Institutionshttp://www.prnewswire.com/news-releases/root9b-uncovers-planned-sofacy-cyber-attack-targeting-several-international-and-domestic-financial-institutions-300081634.html
Dissecting the Krakenhttps://blog.gdatasoftware.com/blog/article/dissecting-the-kraken.html
Targeted attack on France’s TV5Mondehttp://global.ahnlab.com/global/upload/download/documents/1506306551185339.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.05.05.Targeted_attack_on_France_TV5Monde
Attacks against Israeli & Palestinian interestshttp://pwc.blogs.com/cyber_security_updates/2015/04/attacks-against-israeli-palestinian-interests.html
CozyDukehttps://www.f-secure.com/documents/996508/1030745/CozyDuke
The CozyDuke APThttp://securelist.com/blog/69731/the-cozyduke-apt
Sofacy II – Same Sofacy, Different Dayhttp://pwc.blogs.com/cyber_security_updates/2015/04/the-sofacy-plot-thickens.html
Operation RussianDoll: Adobe & Windows Zero-Day Exploits Likely Leveraged by Russia’s APT28 in Highly-Targeted Attackhttps://www.fireeye.com/blog/threat-research/2015/04/probable_apt28_useo.html
Operation Pawn Storm Ramps Up its Activities; Targets NATO, White Househttp://blog.trendmicro.com/trendlabs-security-intelligence/operation-pawn-storm-ramps-up-its-activities-targets-nato-white-house
The Chronicles of the Hellsing APT: the Empire Strikes Backhttp://securelist.com/analysis/publications/69567/the-chronicles-of-the-hellsing-apt-the-empire-strikes-back/
APT 30 and the Mechanics of a Long-Running Cyber Espionage Operationhttps://www.fireeye.com/blog/threat-research/2015/04/apt_30_and_the_mecha.html
Volatile Cedar – Analysis of a Global Cyber Espionage Campaignhttp://blog.checkpoint.com/2015/03/31/volatilecedar/
Rocket Kitten Showing Its Claws: Operation Woolen-GoldFish and the GHOLE campaignhttp://www.trendmicro.com/vinfo/us/security/news/cyber-attacks/operation-woolen-goldfish-when-kittens-go-phishing
Inside the EquationDrug Espionage Platformhttp://securelist.com/blog/research/69203/inside-the-equationdrug-espionage-platform/
Tibetan Uprising Day Malware Attackshttps://citizenlab.org/2015/03/tibetan-uprising-day-malware-attacks/
Is Babar a Bunny?https://www.f-secure.com/weblog/archives/00002794.html
Animals in the APT Farmhttp://securelist.com/blog/research/69114/animals-in-the-apt-farm/
Casper Malware: After Babar and Bunny, Another Espionage Cartoonhttp://www.welivesecurity.com/2015/03/05/casper-malware-babar-bunny-another-espionage-cartoon
A deeper look into Scanboxhttp://pwc.blogs.com/cyber_security_updates/2015/02/a-deeper-look-into-scanbox.html
The Anthem Hack: All Roads Lead to Chinahttp://www.threatconnect.com/news/the-anthem-hack-all-roads-lead-to-china/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.02.27.The_Anthem_Hack_All_Roads_Lead_to_China
Southeast Asia: An Evolving Cyber Threat Landscapehttps://www.fireeye.com/content/dam/fireeye-www/current-threats/pdfs/rpt-southeast-asia-threat-landscape.pdf
PlugX goes to the registry (and India)http://blogs.sophos.com/2015/02/25/sophoslabs-research-uncovers-new-developments-in-plugx-apt-malware/
[G DATA] Babar: espionage software finally found and put under the microscopehttps://blog.gdatasoftware.com/blog/article/babar-espionage-software-finally-found-and-put-under-the-microscope.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.02.18.Babar
[CIRCL Luxembourg] Shooting Elephantshttps://drive.google.com/file/d/0B9Mrr-en8FX4dzJqLWhDblhseTA/view
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.02.18.Shooting_Elephants
[Kaspersky] Desert Falcons APThttps://securelist.com/blog/research/68817/the-desert-falcons-targeted-attacks/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.02.17.Desert_Falcons_APT
[Kaspersky] A Fanny Equation: "I am your father, Stuxnet"http://securelist.com/blog/research/68787/a-fanny-equation-i-am-your-father-stuxnet/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.02.17.A_Fanny_Equation
[Trend Micro] Operation Arid Viperhttp://www.trendmicro.com/vinfo/us/security/news/cyber-attacks/operation-arid-viper-bypassing-the-iron-dome
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.02.16.Operation_Arid_Viper
[Kaspersky] The Carbanak APThttps://securelist.com/blog/research/68732/the-great-bank-robbery-the-carbanak-apt/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.02.16.Carbanak.APT
[Kaspersky] Equation: The Death Star of Malware Galaxyhttps://securelist.com/blog/research/68750/equation-the-death-star-of-malware-galaxy/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.02.16.equation-the-death-star
[CrowdStrike] CrowdStrike Global Threat Intel Report for 2014http://go.crowdstrike.com/rs/crowdstrike/images/GlobalThreatIntelReport.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.02.10.CrowdStrike_GlobalThreatIntelReport_2014
[Trend Micro] Pawn Storm Update: iOS Espionage App Foundhttp://blog.trendmicro.com/trendlabs-security-intelligence/pawn-storm-update-ios-espionage-app-found/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.02.04.Pawn_Storm_Update_iOS_Espionage
[FireEye] Behind the Syrian Conflict’s Digital Frontlineshttps://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-behind-the-syria-conflict.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.02.02.behind-the-syria-conflict
[JPCERT] Analysis of PlugX Variant - P2P PlugX http://blog.jpcert.or.jp/.s/2015/01/analysis-of-a-r-ff05.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.01.29.P2P_PlugX
[Symantec] Backdoor.Winnti attackers and Trojan.Skelkyhttp://www.symantec.com/connect/blogs/backdoorwinnti-attackers-have-skeleton-their-closet
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.01.29.Backdoor.Winnti_attackers
[Kaspersky] Comparing the Regin module 50251 and the "Qwerty" keyloggerhttp://securelist.com/blog/research/68525/comparing-the-regin-module-50251-and-the-qwerty-keylogger/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.01.27.QWERTY_keylog_Regin_compare
[Kaspersky] Regin's Hopscotch and Legspinhttp://securelist.com/blog/research/68438/an-analysis-of-regins-hopscotch-and-legspin/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.01.22.Regin_Hopscotch_and_Legspin
[Symantec] Scarab attackers Russian targetshttp://www.symantec.com/connect/blogs/scarab-attackers-took-aim-select-russian-targets-2012
IOCshttp://www.symantec.com/content/en/us/enterprise/media/security_response/docs/Scarab_IOCs_January_2015.txt
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.01.22.Scarab_attackers_Russian_targets
[Symantec] The Waterbug attack grouphttp://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/waterbug-attack-group.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.01.22.Waterbug.group
[BlueCoat] Reversing the Inception APT malwarehttps://www.bluecoat.com/security-blog/2015-01-20/reversing-inception-apt-malware
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.01.20.Reversing_the_Inception_APT_malware
[G DATA] Analysis of Project Cobrahttps://blog.gdatasoftware.com/blog/article/analysis-of-project-cobra.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.01.20.Project_Cobra
[G DATA] Evolution of Agent.BTZ to ComRAThttps://blog.gdatasoftware.com/blog/article/evolution-of-sophisticated-spyware-from-agentbtz-to-comrat.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.01.15.Evolution_of_Agent.BTZ_to_ComRAT
[Dell] Skeleton Key Malware Analysishttp://www.secureworks.com/cyber-threat-intelligence/threats/skeleton-key-malware-analysis/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.01.12.skeleton-key-malware-analysis
[Dragon Threat Labs] Hong Kong SWC attackhttp://blog.dragonthreatlabs.com/2015/01/dtl-12012015-01-hong-kong-swc-attack.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2015/2015.01.11.Hong_Kong_SWC_Attack
https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections#2014
Anunak: APT against financial institutionshttp://www.group-ib.com/files/Anunak_APT_against_financial_institutions.pdf
Operation Poisoned Helmandhttp://www.threatconnect.com/news/operation-poisoned-helmand/
TA14-353A: Targeted Destructive Malware (wiper)https://www.us-cert.gov/ncas/alerts/TA14-353A
Malware Attack Targeting Syrian ISIS Criticshttps://citizenlab.org/2014/12/malware-attack-targeting-syrian-isis-critics/
Wiper Malware – A Detection Deep Divehttp://blogs.cisco.com/security/talos/wiper-malware
Bots, Machines, and the Matrixhttp://www.fidelissecurity.com/sites/default/files/FTA_1014_Bots_Machines_and_the_Matrix.pdf
Vinself now with steganographyhttp://blog.cybersecurity-airbusds.com/post/2014/12/Vinself
South Korea MBR Wiperhttp://asec.ahnlab.com/1015
W64/Regin, Stage #1https://www.f-secure.com/documents/996508/1030745/w64_regin_stage_1.pdf
W32/Regin, Stage #1https://www.f-secure.com/documents/996508/1030745/w32_regin_stage_1.pdf
Cloud Atlas: RedOctober APThttp://securelist.com/blog/research/68083/cloud-atlas-redoctober-apt-is-back-in-style/
The Inception Frameworkhttps://www.bluecoat.com/security-blog/2014-12-09/blue-coat-exposes-%E2%80%9C-inception-framework%E2%80%9D-very-sophisticated-layered-malware
The 'Penquin' Turlahttp://securelist.com/blog/research/67962/the-penquin-turla-2/
Operation Cleaver: The Notepad Fileshttp://blog.cylance.com/operation-cleaver-the-notepad-files
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2014/2014.12.03_operation-cleaver-the-notepad-files
Operation Cleaverhttp://cdn2.hubspot.net/hubfs/270968/assets/Cleaver/Cylance_Operation_Cleaver_Report.pdf
IOCshttp://www.cylance.com/assets/Cleaver/cleaver.yar
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2014/2014.12.02.Operation_Cleaver
FIN4: Stealing Insider Information for an Advantage in Stock Trading?https://www.fireeye.com/blog/threat-research/2014/11/fin4_stealing_insid.html
Deep Panda Uses Sakula Malwarehttp://blog.crowdstrike.com/ironman-deep-panda-uses-sakula-malware-target-organizations-multiple-sectors/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2014/2014.11.24.Ironman
TheIntercept's report on The Regin Platformhttps://firstlook.org/theintercept/2014/11/24/secret-regin-malware-belgacom-nsa-gchq/
Kaspersky's report on The Regin Platformhttp://securelist.com/blog/research/67741/regin-nation-state-ownage-of-gsm-networks/
Symantec's report on Reginhttp://www.symantec.com/connect/blogs/regin-top-tier-espionage-tool-enables-stealthy-surveillance
[FireEye] Operation Double Taphttps://www.fireeye.com/blog/threat-research/2014/11/operation_doubletap.html
IOCshttps://github.com/fireeye/iocs/tree/master/APT3
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2014/2014.11.21.Operation_Double_Tap
EvilBunny: Suspect #4http://0x1338.blogspot.co.uk/2014/11/hunting-bunnies.html
Roaming Tiger (Slides)http://2014.zeronights.ru/assets/files/slides/roaming_tiger_zeronights_2014.pdf
OnionDuke: APT Attacks Via the Tor Networkhttp://www.f-secure.com/weblog/archives/00002764.html
Operation CloudyOmega: Ichitaro 0-day targeting Japanhttp://www.symantec.com/connect/blogs/operation-cloudyomega-ichitaro-zero-day-and-ongoing-cyberespionage-campaign-targeting-japan
Korplug military targeted attacks: Afghanistan & Tajikistanhttp://www.welivesecurity.com/2014/11/12/korplug-military-targeted-attacks-afghanistan-tajikistan/
The Uroburos case- Agent.BTZ’s successor, ComRAThttp://blog.gdatasoftware.com/blog/article/the-uroburos-case-new-sophisticated-rat-identified.html
The Darkhotel APT - A Story of Unusual Hospitalityhttps://securelist.com/blog/research/66779/the-darkhotel-apt/
Operation Poisoned Handover: Unveiling Ties Between APT Activity in Hong Kong’s Pro-Democracy Movementhttp://www.fireeye.com/blog/technical/2014/11/operation-poisoned-handover-unveiling-ties-between-apt-activity-in-hong-kongs-pro-democracy-movement.html
New observations on BlackEnergy2 APT activityhttps://securelist.com/blog/research/67353/be2-custom-plugins-router-abuse-and-target-profiles/
Operation TooHashhttps://blog.gdatasoftware.com/blog/article/operation-toohash-how-targeted-attacks-work.html
The Rotten Tomato Campaignhttp://blogs.sophos.com/2014/10/30/the-rotten-tomato-campaign-new-sophoslabs-research-on-apts/
Group 72, Opening the ZxShellhttp://blogs.cisco.com/talos/opening-zxshell/
APT28 - A Window Into Russia's Cyber Espionage Operationshttps://www.fireeye.com/resources/pdfs/apt28.pdf
Micro-Targeted Malvertising via Real-time Ad Biddinghttp://www.invincea.com/wp-content/uploads/2014/10/Micro-Targeted-Malvertising-WP-10-27-14-1.pdf
ScanBox framework – who’s affected, and who’s using it?http://pwc.blogs.com/cyber_security_updates/2014/10/scanbox-framework-whos-affected-and-whos-using-it-1.html
Full Disclosure of Havex Trojans - ICS Havex backdoorshttp://www.netresec.com/?page=Blog&month=2014-10&post=Full-Disclosure-of-Havex-Trojans
LeoUncia and OrcaRathttp://blog.airbuscybersecurity.com/post/2014/10/LeoUncia-and-OrcaRat
Modified Tor Binarieshttp://www.leviathansecurity.com/blog/the-case-of-the-modified-binaries/
Sofacy Phishing by PWChttp://pwc.blogs.com/files/tactical-intelligence-bulletin---sofacy-phishing-.pdf
Operation Pawn Storm: The Red in SEDNIThttp://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp-operation-pawn-storm.pdf
OrcaRAT - A whale of a talehttp://pwc.blogs.com/cyber_security_updates/2014/10/orcarat-a-whale-of-a-tale.html
Sandworm - CVE-2104-4114http://www.isightpartners.com/2014/10/cve-2014-4114/
Group 72 (Axiom)http://blogs.cisco.com/security/talos/threat-spotlight-group-72/
Derusbi Preliminary Analysishttp://www.novetta.com/wp-content/uploads/2014/11/Derusbi.pdf
Hikit Preliminary Analysishttp://www.novetta.com/wp-content/uploads/2014/11/HiKit.pdf
ZoxPNG Preliminary Analysishttp://www.novetta.com/wp-content/uploads/2014/11/ZoxPNG.pdf
Democracy in Hong Kong Under Attackhttp://www.volexity.com/blog/?p=33
New indicators for APT group Nitrohttp://researchcenter.paloaltonetworks.com/2014/10/new-indicators-compromise-apt-group-nitro-uncovered/
BlackEnergy & Quedaghhttps://www.f-secure.com/documents/996508/1030745/blackenergy_whitepaper.pdf
Aided Frame, Aided Direction (Sunshop Digital Quartermaster)http://www.fireeye.com/blog/technical/2014/09/aided-frame-aided-direction-because-its-a-redirect.html
Ukraine and Poland Targeted by BlackEnergy (video)https://www.youtube.com/watch?v=I77CGqQvPE4
Watering Hole Attacks using Poison Ivy by "th3bug" grouphttp://researchcenter.paloaltonetworks.com/2014/09/recent-watering-hole-attacks-attributed-apt-group-th3bug-using-poison-ivy/
COSMICDUKE: Cosmu with a twist of MiniDukehttp://www.f-secure.com/documents/996508/1030745/cosmicduke_whitepaper.pdf
Chinese intrusions into key defense contractorshttp://www.armed-services.senate.gov/press-releases/sasc-investigation-finds-chinese-intrusions-into-key-defense-contractors
Operation Quantum Entanglementhttp://www.fireeye.com/resources/pdfs/white-papers/fireeye-operation-quantum-entanglement.pdf
When Governments Hack Opponents: A Look at Actors and Technologyhttps://www.usenix.org/system/files/conference/usenixsecurity14/sec14-paper-marczak.pdf
videohttps://www.usenix.org/conference/usenixsecurity14/technical-sessions/presentation/marczak
Targeted Threat Index: Characterizingand Quantifying Politically-MotivatedTargeted Malwarehttps://www.usenix.org/system/files/conference/usenixsecurity14/sec14-paper-hardy.pdf
videohttps://www.usenix.org/conference/usenixsecurity14/technical-sessions/presentation/hardy
Gholee – a “Protective Edge” themed spear phishing campaignhttp://www.clearskysec.com/gholee-a-protective-edge-themed-spear-phishing-campaign/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2014/2014.09.04.Gholee
Forced to Adapt: XSLCmd Backdoor Now on OS Xhttp://www.fireeye.com/blog/technical/malware-research/2014/09/forced-to-adapt-xslcmd-backdoor-now-on-os-x.html
Darwin’s Favorite APT Group (APT12)http://www.fireeye.com/blog/technical/botnet-activities-research/2014/09/darwins-favorite-apt-group-2.html
Syrian Malware Team Uses BlackWorm for Attackshttp://www.fireeye.com/blog/technical/2014/08/connecting-the-dots-syrian-malware-team-uses-blackworm-for-attacks.html
Scanbox: A Reconnaissance Framework Used with Watering Hole Attackshttps://www.alienvault.com/open-threat-exchange/blog/scanbox-a-reconnaissance-framework-used-on-watering-hole-attacks
North Korea’s cyber threat landscapehttp://h30499.www3.hp.com/hpeb/attachments/hpeb/off-by-on-software-security-blog/388/2/HPSR%20SecurityBriefing_Episode16_NorthKorea.pdf
NetTraveler APT Gets a Makeover for 10th Birthdayhttps://securelist.com/blog/research/66272/nettraveler-apt-gets-a-makeover-for-10th-birthday/
Vietnam APT Campaignhttp://blog.malwaremustdie.org/2014/08/another-country-sponsored-malware.html
El Machetehttps://securelist.com/blog/research/66108/el-machete/
The Syrian Malware House of Cardshttps://securelist.com/blog/research/66051/the-syrian-malware-house-of-cards/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2014/2014.08.18.Syrian_Malware_House_of_Cards
A Look at Targeted Attacks Through the Lense of an NGOhttp://www.mpi-sws.org/~stevens/pubs/sec14.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2014/2014.08.13.TargetAttack.NGO
New York Times Attackers Evolve Quickly (Aumlib/Ixeshe/APT12)http://www.fireeye.com/blog/technical/2013/08/survival-of-the-fittest-new-york-times-attackers-evolve-quickly.html
The Epic Turla Operation Appendixhttps://securelist.com/files/2014/08/KL_Epic_Turla_Technical_Appendix_20140806.pdf
Operation Poisoned Hurricanehttp://www.fireeye.com/blog/technical/targeted-attack/2014/08/operation-poisoned-hurricane.html
Operation Arachnophobiahttp://threatc.s3-website-us-east-1.amazonaws.com/?/arachnophobia
Sidewinder Targeted Attack Against Androidhttp://www.fireeye.com/resources/pdfs/fireeye-sidewinder-targeted-attack.pdf
Energetic Bear/Crouching Yeti Appendixhttp://25zbkz3k00wn2tp5092n6di7b5k.wpengine.netdna-cdn.com/files/2014/07/Kaspersky_Lab_crouching_yeti_appendixes_eng_final.pdf
Energetic Bear/Crouching Yetihttps://kasperskycontenthub.com/securelist/files/2014/07/EB-YetiJuly2014-Public.pdf
Sayad (Flying Kitten) Analysis & IOCshttp://vinsula.com/2014/07/20/sayad-flying-kitten-infostealer-malware/
Pitty Tigerhttps://bitbucket.org/cybertools/whitepapers/downloads/Pitty%20Tiger%20Final%20Report.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2014/2014.07.11.Pitty_Tiger
TR-25 Analysis - Turla / Pfinet / Snake/ Uroburoshttp://www.circl.lu/pub/tr-25/
Deep Pandas, Deep in Thought: Chinese Targeting of National Security Think Tankshttp://blog.crowdstrike.com/deep-thought-chinese-targeting-national-security-think-tanks/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2014/2014.07.07.Deep_in_Thought
Anatomy of the Attack: Zombie Zerohttp://www.trapx.com/wp-content/uploads/2014/07/TrapX_ZOMBIE_Report_Final.pdf
Dragonfly: Cyberespionage Attacks Against Energy Suppliershttp://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/Dragonfly_Threat_Against_Western_Energy_Suppliers.pdf
Embassy of Greece Beijinghttp://thegoldenmessenger.blogspot.de/2014/06/blitzanalysis-embassy-of-greece-beijing.html
Putter Pandahttp://cdn0.vox-cdn.com/assets/4589853/crowdstrike-intelligence-report-putter-panda.original.pdf
Illuminating The Etumbot APT Backdoor (APT12)http://www.arbornetworks.com/asert/wp-content/uploads/2014/06/ASERT-Threat-Intelligence-Brief-2014-07-Illuminating-Etumbot-APT.pdf
NewsCaster_An_Iranian_Threat_Within_Social_Networkshttps://www.isightpartners.com/2014/05/newscaster-iranian-threat-inside-social-media/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2014/2014.05.28.NewsCaster_An_Iranian_Threat_Within_Social_Networks
RAT in jar: A phishing campaign using Unrecomhttp://www.fidelissecurity.com/sites/default/files/FTA_1013_RAT_in_a_jar.pdf
Miniduke Twitter C&Chttp://www.welivesecurity.com/2014/05/20/miniduke-still-duking/
CrowdStrike's report on Flying Kittenhttp://blog.crowdstrike.com/cat-scratch-fever-crowdstrike-tracks-newly-reported-iranian-actor-flying-kitten/
Operation Saffron Rose (aka Flying Kitten)http://www.fireeye.com/resources/pdfs/fireeye-operation-saffron-rose.pdf
CVE-2014-1776: Operation Clandestine Foxhttps://www.fireeye.com/blog/threat-research/2014/05/operation-clandestine-fox-now-attacking-windows-xp-using-recently-discovered-ie-vulnerability.html
Russian spyware Turlahttp://www.reuters.com/article/2014/03/07/us-russia-cyberespionage-insight-idUSBREA260YI20140307
Snake Campaign & Cyber Espionage Toolkithttp://info.baesystemsdetica.com/rs/baesystems/images/snake_whitepaper.pdf
The Siesta Campaignhttp://blog.trendmicro.com/trendlabs-security-intelligence/the-siesta-campaign-a-new-targeted-attack-awakens/
Uroburos: Highly complex espionage software with Russian rootshttps://public.gdatasoftware.com/Web/Content/INT/Blog/2014/02_2014/documents/GData_Uroburos_RedPaper_EN_v1.pdf
The French Connection: French Aerospace-Focused CVE-2014-0322 Attack Shares Similarities with 2012 Capstone Turbine Activityhttp://blog.crowdstrike.com/french-connection-french-aerospace-focused-cve-2014-0322-attack-shares-similarities-2012/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2014/2014.02.25.The_French_Connection
Gathering in the Middle East, Operation STTEAMhttp://www.fidelissecurity.com/sites/default/files/FTA%201012%20STTEAM%20Final.pdf
Mo' Shells Mo' Problems - Deep Panda Web Shellshttp://www.crowdstrike.com/blog/mo-shells-mo-problems-deep-panda-web-shells/
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2014/2014.02.20.deep-panda-webshells
Operation GreedyWonk: Multiple Economic and Foreign Policy Sites Compromised, Serving Up Flash Zero-Day Exploithttp://www.fireeye.com/blog/technical/targeted-attack/2014/02/operation-greedywonk-multiple-economic-and-foreign-policy-sites-compromised-serving-up-flash-zero-day-exploit.html
XtremeRAT: Nuisance or Threat?http://www.fireeye.com/blog/technical/2014/02/xtremerat-nuisance-or-threat.html
The Monju Incidenthttp://contextis.com/resources/blog/context-threat-intelligence-monju-incident/
Operation SnowMan: DeputyDog Actor Compromises US Veterans of Foreign Wars Websitehttp://www.fireeye.com/blog/technical/cyber-exploits/2014/02/operation-snowman-deputydog-actor-compromises-us-veterans-of-foreign-wars-website.html
Unveiling "Careto" - The Masked APThttp://www.securelist.com/en/downloads/vlpdfs/unveilingthemask_v1.0.pdf
Intruder File Report- Sneakernet Trojanhttp://www.fidelissecurity.com/sites/default/files/FTA%201011%20Follow%20UP.pdf
[RSA] Shell_Crew (Deep Panda)http://www.emc.com/collateral/white-papers/h12756-wp-shell-crew.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2014/2014.01.21.Shell_Crew
“New'CDTO:'A'Sneakernet'Trojan'Solutionhttp://www.fidelissecurity.com/sites/default/files/FTA%201001%20FINAL%201.15.14.pdf
The Icefog APT Hits US Targets With Java Backdoorhttps://www.securelist.com/en/blog/208214213/The_Icefog_APT_Hits_US_Targets_With_Java_Backdoor
Targeted attacks against the Energy Sectorhttp://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/targeted_attacks_against_the_energy_sector.pdf
PlugX: some uncovered pointshttp://blog.cassidiancybersecurity.com/2014/01/plugx-some-uncovered-points.html
https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections#2013
THE LITTLE MALWARE THAT COULD: Detecting and Defeating the China Chopper Web Shellhttps://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-china-chopper.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2013/2013.China_Chopper_Web_Shell
Deep Pandahttp://www.crowdstrike.com/sites/default/files/AdversaryIntelligenceReport_DeepPanda_0.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2013/2013.Deep.Panda
ETSO APT Attacks Analysishttp://image.ahnlab.com/global/upload/download/documents/1401223631603288.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2013/2013.12.20.ETSO
Operation "Ke3chang"http://www.fireeye.com/resources/pdfs/fireeye-operation-ke3chang.pdf
njRAT, The Saga Continueshttp://www.fidelissecurity.com/files/files/FTA%201010%20-%20njRAT%20The%20Saga%20Continues.pdf
Supply Chain Analysishttp://www.fireeye.com/resources/pdfs/fireeye-malware-supply-chain.pdf
Operation Ephemeral Hydra: IE Zero-Day Linked to DeputyDog Uses Diskless Methodhttp://www.fireeye.com/blog/technical/cyber-exploits/2013/11/operation-ephemeral-hydra-ie-zero-day-linked-to-deputydog-uses-diskless-method.html
Terminator RAThttps://www.fireeye.com/blog/threat-research/2013/10/evasive-tactics-terminator-rat.html
FakeM RAThttp://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp-fakem-rat.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2013/2013.10.24
World War C: State of affairs in the APT worldhttps://www.fireeye.com/blog/threat-research/2013/09/new-fireeye-report-world-war-c.html
The 'ICEFROG' APT: A Tale of cloak and three daggershttp://www.securelist.com/en/downloads/vlpdfs/icefog.pdf
Hidden Lynx - Professional Hackers for Hirehttp://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/hidden_lynx.pdf
Operation DeputyDog: Zero-Day (CVE-2013-3893) Attack Against Japanese Targetshttp://www.fireeye.com/blog/technical/cyber-exploits/2013/09/operation-deputydog-zero-day-cve-2013-3893-attack-against-japanese-targets.html
The "Kimsuky" Operationhttps://securelist.com/analysis/57915/the-kimsuky-operation-a-north-korean-apt/
Evasive Tactics: Taidoorhttps://www.fireeye.com/blog/threat-research/2013/09/evasive-tactics-taidoor-3.html
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2013/2013.09.06.EvasiveTactics_Taidoor
Feature: EvilGrab Campaign Targets Diplomatic Agencieshttp://about-threats.trendmicro.com/cloud-content/us/ent-primers/pdf/2q-report-on-targeted-attack-campaigns.pdf
Operation Molerats: Middle East Cyber Attacks Using Poison Ivyhttp://www.fireeye.com/blog/technical/2013/08/operation-molerats-middle-east-cyber-attacks-using-poison-ivy.html
POISON IVY: Assessing Damage and Extracting Intelligencehttp://www.fireeye.com/resources/pdfs/fireeye-poison-ivy-report.pdf
ByeBye Shell and the targeting of Pakistanhttps://community.rapid7.com/community/infosec/blog/2013/08/19/byebye-and-the-targeting-of-pakistan
Surtr: Malware Family Targeting the Tibetan Communityhttps://citizenlab.org/2013/08/surtr-malware-family-targeting-the-tibetan-community/
Where There is Smoke, There is Fire: South Asian Cyber Espionage Heats Uphttp://www.threatconnect.com/news/where-there-is-smoke-there-is-fire-south-asian-cyber-espionage-heats-up/
APT Attacks on Indian Cyber Spacehttp://g0s.org/wp-content/uploads/2013/downloads/Inside_Report_by_Infosec_Consortium.pdf
Operation Hangover - Unveiling an Indian Cyberattack Infrastructurehttp://normanshark.com/wp-content/uploads/2013/08/NS-Unveiling-an-Indian-Cyberattack-Infrastructure_FINAL_Web.pdf
Blackhat: In-Depth Analysis of Escalated APT Attacks (Lstudio,Elirks)https://media.blackhat.com/us-13/US-13-Yarochkin-In-Depth-Analysis-of-Escalated-APT-Attacks-Slides.pdf
videohttps://www.youtube.com/watch?v=SoFVRsvh8s0
Secrets of the Comfoo Mastershttp://www.secureworks.com/cyber-threat-intelligence/threats/secrets-of-the-comfoo-masters/
PlugX revisited: "Smoaler"http://sophosnews.files.wordpress.com/2013/07/sophosszappanosplugxrevisitedintroducingsmoaler-rev1.pdf
Dark Seoul Cyber Attack: Could it be worse?http://cisak.perpika.kr/wp-content/uploads/2013/07/2013-08.pdf
Targeted Campaign Steals Credentials in Gulf States and Caribbeanhttps://blogs.mcafee.com/mcafee-labs/targeted-campaign-steals-credentials-in-gulf-states-and-caribbean
njRAT Uncoveredhttp://threatgeek.typepad.com/files/fta-1009---njrat-uncovered-1.pdf
A Call to Harm: New Malware Attacks Target the Syrian Oppositionhttps://citizenlab.org/wp-content/uploads/2013/07/19-2013-acalltoharm.pdf
Trojan.APT.Seinup Hitting ASEANhttp://www.fireeye.com/blog/technical/malware-research/2013/06/trojan-apt-seinup-hitting-asean.html
KeyBoy, Targeted Attacks against Vietnam and Indiahttps://community.rapid7.com/community/infosec/blog/2013/06/07/keyboy-targeted-attacks-against-vietnam-and-india
The NetTraveller (aka 'Travnet')http://www.securelist.com/en/downloads/vlpdfs/kaspersky-the-net-traveler-part1-final.pdf
Crude Faux: An analysis of cyber conflict within the oil & gas industrieshttps://www.cerias.purdue.edu/assets/pdf/bibtex_archive/2013-9.pdf
The Chinese Malware Complexes: The Maudi Surveillance Operationhttps://bluecoat.com/documents/download/2c832f0f-45d2-4145-bdb7-70fc78c22b0f&ei=ZGP-VMCbMsuxggSThYDgDg&usg=AFQjCNFjXSkn_AIiXge1X9oWZHzQOiNDJw&sig2=B6e2is0sCnGEbLPL9q0eZg&bvm=bv.87611401,d.eXY
TR-14 - Analysis of a stage 3 Miniduke malware samplehttp://www.circl.lu/pub/tr-14/
Operation Hangoverhttps://www.bluecoat.com/security-blog/2013-05-20/hangover-report
Operation Hangoverhttp://normanshark.com/pdf/Norman_HangOver%20report_Executive%20Summary_042513.pdf
MiniDuke - The Final Cuthttp://labs.bitdefender.com/2013/04/miniduke-the-final-cut
"Winnti" More than just a gamehttp://www.securelist.com/en/downloads/vlpdfs/winnti-more-than-just-a-game-130410.pdf
Trojan.APT.BaneChanthttp://www.fireeye.com/blog/technical/malware-research/2013/04/trojan-apt-banechant-in-memory-trojan-that-observes-for-multiple-mouse-clicks.html
TR-12 - Analysis of a PlugX malware variant used for targeted attackshttp://www.circl.lu/pub/tr-12/
APT1: technical backstage (Terminator/Fakem RAT)http://www.malware.lu/assets/files/articles/RAP002_APT1_Technical_backstage.1.0.pdf
Darkseoul/Jokra Analysis And Recoveryhttp://www.fidelissecurity.com/sites/default/files/FTA%201008%20-%20Darkseoul-Jokra%20Analysis%20and%20Recovery.pdf
The TeamSpy Crew Attackshttp://securelist.com/blog/incidents/35520/the-teamspy-crew-attacks-abusing-teamviewer-for-cyberespionage-8/
Dissecting Operation Troyhttp://www.mcafee.com/sg/resources/white-papers/wp-dissecting-operation-troy.pdf
Safe: A Targeted Threathttp://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp-safe-a-targeted-threat.pdf
You Only Click Twice: FinFisher’s Global Proliferationhttps://citizenlab.org/wp-content/uploads/2013/07/15-2013-youonlyclicktwice.pdf
Miniduke: Indicators v1http://www.crysys.hu/miniduke/miniduke_indicators_public.pdf
The MiniDuke Mystery: PDF 0-day Government Spy Assembler 0x29A Micro Backdoorhttps://www.securelist.com/en/downloads/vlpdfs/themysteryofthepdf0-dayassemblermicrobackdoor.pdf
Stuxnet 0.5: The Missing Linkhttp://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/stuxnet_0_5_the_missing_link.pdf
Comment Crew: Indicators of Compromisehttp://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/comment_crew_indicators_of_compromise.pdf
Mandiant APT1 Reporthttp://intelreport.mandiant.com/Mandiant_APT1_Report.pdf
Targeted cyber attacks: examples and challenges aheadhttp://www.ait.ac.at/uploads/media/Presentation_Targeted-Attacks_EN.pdf
Operation Red Octoberhttps://kc.mcafee.com/resources/sites/MCAFEE/content/live/PRODUCT_DOCUMENTATION/24000/PD24250/en_US/McAfee_Labs_Threat_Advisory_Exploit_Operation_Red_Oct.pdf
Red October Diplomatic Cyber Attacks Investigationhttp://securelist.com/analysis/publications/36740/red-october-diplomatic-cyber-attacks-investigation
The Red October Campaignhttps://securelist.com/blog/incidents/57647/the-red-october-campaign
https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections#2012
Systematic cyber attacks against Israeli and Palestinian targets going on for a yearhttp://cyber-peace.org/wp-content/uploads/2014/01/Cyberattack_against_Israeli_and_Palestinian_targets.pdf
RECOVERING FROM SHAMOONhttp://www.fidelissecurity.com/sites/default/files/FTA%201007%20-%20Shamoon.pdf
CYBER ESPIONAGE Against Georgian Government (Georbot Botnet)http://dea.gov.ge/uploads/CERT%20DOCS/Cyber%20Espionage.pdf
Trojan.Taidoor: Targeting Think Tankshttp://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/trojan_taidoor-targeting_think_tanks.pdf
Matasano notes on DarkComet, Bandook, CyberGate and Xtreme RAThttp://matasano.com/research/PEST-CONTROL.pdf
The Mirage Campaignhttp://www.secureworks.com/cyber-threat-intelligence/threats/the-mirage-campaign/
The VOHO Campaign: An in depth analysishttp://blogsdev.rsa.com/wp-content/uploads/VOHO_WP_FINAL_READY-FOR-Publication-09242012_AC.pdf
IEXPLORE RAThttps://citizenlab.org/wp-content/uploads/2012/09/IEXPL0RE_RAT.pdf
The Elderwood Projecthttp://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/the-elderwood-project.pdf
The Taidoor Campaign AN IN-DEPTH ANALYSIS http://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp_the_taidoor_campaign.pdf
Localhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/blob/master/2012/2012.08.18.Taidoor_Campaign
Gauss: Abnormal Distributionhttp://kasperskycontenthub.com/wp-content/uploads/sites/43/vlpdfs/kaspersky-lab-gauss.pdf
The Madi Campaignhttps://securelist.com/analysis/36609/the-madi-infostealers-a-detailed-analysis/
From Bahrain With Love: FinFisher’s Spy Kit Exposed?https://citizenlab.org/2012/07/from-bahrain-with-love-finfishers-spy-kit-exposed/
Wired article on DarkComet creatorhttp://www.wired.com/2012/07/dark-comet-syrian-spy-tool/
Advanced Social Engineering for the Distribution of LURK Malwarehttps://citizenlab.org/wp-content/uploads/2012/07/10-2012-recentobservationsintibet.pdf
sKyWIper (Flame/Flamer)http://www.crysys.hu/skywiper/skywiper.pdf
IXESHE An APT Campaignhttp://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp_ixeshe.pdf
Analysis of Flamer C&C Serverhttp://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/w32_flamer_newsforyou.pdf
OSX.SabPub & Confirmed Mac APT attackshttp://securelist.com/blog/incidents/33208/new-version-of-osx-sabpub-confirmed-mac-apt-attacks-19/
Anatomy of a Gh0st RAThttp://www.mcafee.com/us/resources/white-papers/foundstone/wp-know-your-digital-enemy.pdf
Luckycat Reduxhttp://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp_luckycat_redux.pdf
Reversing DarkComet RAT's cryptohttp://www.arbornetworks.com/asert/wp-content/uploads/2012/07/Crypto-DarkComet-Report.pdf
Crouching Tiger, Hidden Dragon, Stolen Datahttp://www.contextis.com/services/research/white-papers/crouching-tiger-hidden-dragon-stolen-data/
The Sin Digoo Affairhttp://www.secureworks.com/cyber-threat-intelligence/threats/sindigoo/
Command and Control in the Fifth Domainhttp://www.commandfive.com/papers/C5_APT_C2InTheFifthDomain.pdf
The HeartBeat APThttp://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp_the-heartbeat-apt-campaign.pdf
https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections#2011
Palebot trojan harvests Palestinian online credentialshttps://web.archive.org/web/20130308090454/http://blogs.norman.com/2011/malware-detection-team/palebot-trojan-harvests-palestinian-online-credentials
The Nitro Attacks: Stealing Secrets from the Chemical Industryhttp://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/the_nitro_attacks.pdf
Duqu Trojan Questions and Answershttp://www.secureworks.com/cyber-threat-intelligence/threats/duqu/
Alleged APT Intrusion Set: "1.php" Grouphttp://www.zscaler.com/pdf/technicalbriefs/tb_advanced_persistent_threats.pdf
The "LURID" Downloaderhttp://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp_dissecting-lurid-apt.pdf
SK Hack by an Advanced Persistent Threathttp://www.commandfive.com/papers/C5_APT_SKHack.pdf
The RSA Hackhttp://www.fidelissecurity.com/sites/default/files/FTA1001-The_RSA_Hack.pdf
HTran and the Advanced Persistent Threathttp://www.secureworks.com/cyber-threat-intelligence/threats/htran/
Operation Shady rat : Vanityhttp://www.vanityfair.com/culture/features/2011/09/operation-shady-rat-201109
Operation Shady RAThttp://www.mcafee.com/us/resources/white-papers/wp-operation-shady-rat.pdf
Stuxnet Under the Microscopehttp://www.eset.com/us/resources/white-papers/Stuxnet_Under_the_Microscope.pdf
Night Dragon Specific Protection Measures for Considerationhttp://www.nerc.com/pa/rrm/bpsa/Alerts%20DL/2011%20Alerts/A-2011-02-18-01%20Night%20Dragon%20Attachment%201.pdf
Global Energy Cyberattacks: Night Dragonhttp://www.mcafee.com/us/resources/white-papers/wp-global-energy-cyberattacks-night-dragon.pdf
https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections#2010
The Stuxnet Computer Worm: Harbinger of an Emerging Warfare Capability http://www.fas.org/sgp/crs/natsec/R41524.pdf
W32.Stuxnet Dossierhttp://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/w32_stuxnet_dossier.pdf
The "MSUpdater" Trojan And Ongoing Targeted Attackshttp://www.seculert.com/reports/MSUpdaterTrojanWhitepaper.pdf
Shadows in the cloud: Investigating Cyber Espionage 2.0http://www.nartv.org/mirror/shadows-in-the-cloud.pdf
In-depth Analysis of Hydraqhttp://www.totaldefense.com/Core/DownloadDoc.aspx?documentID=1052
How Can I Tell if I Was Infected By Aurora? (IOCs)http://www.crowdstrike.com/sites/default/files/AdversaryIntelligenceReport_DeepPanda_0.pdf
HB Gary Threat Report: Operation Aurorahttp://hbgary.com/sites/default/files/publications/WhitePaper%20HBGary%20Threat%20Report,%20Operation%20Aurora.pdf
Case Study: Operation Aurora - Triumfanthttp://www.triumfant.com/pdfs/Case_Study_Operation_Aurora_V11.pdf
Operation Aurora Detect, Diagnose, Respondhttp://albertsblog.stickypatch.org/files/3/5/1/4/7/282874-274153/Aurora_HBGARY_DRAFT.pdf
McAfee Labs: Combating Aurorahttps://kc.mcafee.com/resources/sites/MCAFEE/content/live/CORP_KNOWLEDGEBASE/67000/KB67957/en_US/Combating%20Threats%20-%20Operation%20Aurora.pdf
The Command Structure of the Aurora Botnet - Damballahttps://www.damballa.com/downloads/r_pubs/Aurora_Botnet_Command_Structure.pdf
Operation Aurorahttp://en.wikipedia.org/wiki/Operation_Aurora
https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections#2009
Tracking GhostNethttp://www.nartv.org/mirror/ghostnet.pdf
Impact of Alleged Russian Cyber Attackshttps://www.baltdefcol.org/files/files/documents/Research/BSDR2009/1_%20Ashmore%20-%20Impact%20of%20Alleged%20Russian%20Cyber%20Attacks%20.pdf
https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections#2008
Agent.BTZhttp://www.wired.com/dangerroom/2008/11/army-bans-usb-d/
China's Electronic Long-Range Reconnaissancehttp://fmso.leavenworth.army.mil/documents/chinas-electronic.pdf
How China will use cyber warfare to leapfrog in military competitivenesshttp://www.international-relations.com/CM8-1/Cyberwar.pdf
Russian Invasion of Georgia Russian Cyberwar on Georgiahttp://www.mfa.gov.ge/files/556_10535_798405_Annex87_CyberAttacks.pdf
https://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections#2006
"Wicked Rose" and the NCPH Hacking Grouphttp://krebsonsecurity.com/wp-content/uploads/2012/11/WickedRose_andNCPH.pdf
Readmehttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections#readme-ov-file
Activityhttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/activity
0 starshttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/stargazers
0 watchinghttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/watchers
0 forkshttps://github.com/Jrmbt/APT_CyberCriminal_Campagin_Collections/forks
Report repositoryhttps://github.com/contact/report-content?content_url=https%3A%2F%2Fgithub.com%2FJrmbt%2FAPT_CyberCriminal_Campagin_Collections&report=Jrmbt+%28user%29
https://github.com
Termshttps://docs.github.com/site-policy/github-terms/github-terms-of-service
Privacyhttps://docs.github.com/site-policy/privacy-policies/github-privacy-statement
Securityhttps://github.com/security
Statushttps://www.githubstatus.com/
Communityhttps://github.community/
Docshttps://docs.github.com/
Contacthttps://support.github.com?tags=dotcom-footer

Viewport: width=device-width


URLs of crawlers that visited me.