logo

Binary Defense Blog

ID: 6a9b10fe-0158-502e-9ec2-79149fcf2ea1

STIX ID: identity--6a9b10fe-0158-502e-9ec2-79149fcf2ea1

Feed Type: skeleton

Earliest post: 2025-08-10

Latest post: 2026-02-27

The Binary Defense Blog delivers actionable threat research, malware analysis, and practical security insights to help defenders detect and respond to evolving cyber threats.

01/01/2020
06/04/2026
Title Date Published Describes IncidentAuthorVisible
Attackers Went Agentic First2026-05-27TrueTrue
Chasing Phantoms: How a Multi-Stage Stealer Abuses…2026-04-14TrueTrue
Remote Support to Ransomware Foothold: Stopping a…2026-04-08TrueTrue
Windows Defender ACL Blocking: A Silent Technique With Serious Impact2026-02-27TrueTrue
When Paychecks Become the Prize: A Deeper Look at…2026-02-12TrueTrue
When Access Brokers Go Interactive: ClickFixin’ to Python Your Network2026-02-06TrueTrue
Slivering Through The Cracks2026-02-04TrueTrue
What Defined Defense in 20252026-01-08TrueTrue
Evolutions in Offensive Toolkits: Phishing2026-01-08TrueTrue
DeedRAT: Unpacking a Modern Backdoor’s Playbook2025-12-30TrueTrue
GlytchC2: A Bug in the Livestream2025-11-05TrueTrue
A Practical Guide to Deobfuscating a Stupidly Long JavaScript Stealer2025-10-31TrueTrue
DON’T FREEZE ME OUT, BRO! ARC Labs Technical Analysis of EDR-Freeze2025-09-22TrueTrue
United States Postal Service Breached2025-09-21TrueTrue
Active Shellshock SMTP Botnet Campaign2025-09-21TrueTrue
Petya Ransomware Without The Fluff2025-09-10TrueTrue
DefendNot: Turning Windows Defender Against Itself2025-09-03TrueTrue
Threat Hunting AWS CloudTrail with Sentinel: Part 22025-08-12TrueTrue
Using Microsoft Sentinel to Detect Confluence…2025-08-12TrueTrue
War in Ukraine and Its Impact on Hackers2025-08-12TrueTrue
Russia may be Pressing Arrested Cyber Criminals into Service2025-08-12TrueTrue
An Updated ServHelper Tunnel Variant2025-08-12TrueTrue
The Insider Threat: Why Your Greatest Security Risk…2025-08-12TrueTrue
Cyber War: Hackers' Transformation from Cyber Criminals to Hacktivists2025-08-12TrueTrue
ThreadSleeper: Suspending Threads via GMER64 Driver2025-08-12TrueTrue
4 Tactics to Detect & Contain Emotet’s Latest Evolution2025-08-12TrueTrue
A Look at a Novel Discord Phishing Attack2025-08-12TrueTrue
Qakbot Strikes Back: Understanding the Threat2025-08-12TrueTrue
What is Carding?2025-08-12TrueTrue
Threat Hunting AWS CloudTrail with Sentinel: Part 12025-08-12TrueTrue
Technical Analysis: Killer Ultra Malware Targeting…2025-08-12TrueTrue
Qakbot Upgrades to Stealthier Persistence Method2025-08-12TrueTrue
Third party vendors present a security risk—how your…2025-08-12TrueTrue
Shining a Light in the Dark – How Binary Defense…2025-08-12TrueTrue
Rhadamanthys Stealer Analysis for Detection Opportunities2025-08-12TrueTrue
IcedID GZIPLOADER Analysis2025-08-12TrueTrue
Unemployment Fraud on the Rise2025-08-12TrueTrue
Understanding Sleep Obfuscation2025-08-12TrueTrue
Cybersecurity predictions for 2021 after an unpredictable 20202025-08-12TrueTrue
Attack on a water treatment plant highlights…2025-08-12TrueTrue
Mars-Deimos: From Jupiter to Mars and Back again (Part Two)2025-08-12TrueTrue
What Do Criminal Hackers and Scammers Discuss on Forums?2025-08-12TrueTrue
Cleo MFT Mass Exploitation Payload Analysis2025-08-12TrueTrue
Russian Cybercriminal Group Attempts to Steal…2025-08-12TrueTrue
Creating YARA Rules Based on Code2025-08-12TrueTrue
Hunting and Defeating Evasive Threats2025-08-12TrueTrue
Solarmarker: By Any Other Name (Mars-Deimos part 3)2025-08-12TrueTrue
Emotet Evolves With new Wi-Fi Spreader2025-08-12TrueTrue
Mars-Deimos: SolarMarker/Jupyter Infostealer (Part 1)2025-08-12TrueTrue
Analysis of Hancitor – When Boring Begets Beacon2025-08-12TrueTrue

1–50 of 119