logo

LevelBlue SpiderLabs Blog

ID: 9f9267fd-0707-5078-b951-6540ac6dc523

STIX ID: identity--9f9267fd-0707-5078-b951-6540ac6dc523

Feed Type: rss

Earliest post: 2025-10-29

Latest post: 2026-06-03

The security community's go-to destination for technical breakdowns of the latest threats, critical vulnerability disclosures and cutting-edge research.

01/01/2020
06/04/2026
Title Date Published Describes IncidentAuthorVisible
The Demon Arrives Later: A Havoc Stager Hides Behind Microsoft Defender DLP2026-06-03TrueJose MartinTrue
Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign2026-05-28TrueMaor GabayTrue
From WinRE to SYSTEM: Hunting the YellowKey and MiniPlasma Attack Chain2026-05-22TrueTrue
YellowKey and GreenPlasma: Two New Windows Zero-Days Unveiled2026-05-19TrueJames BallantyneTrue
A Closer Look at The Gentlemen’s Alleged Leak2026-05-18TrueArthur ErzbergerTrue
Threat Analysis: Backdoored Electron Apps Evading Defenses2026-05-08TrueMichael MoroseTrue
Unmasking a Multi-Stage Loader: AutoIt Abuse Leading to Vidar Stealer Command-and-Control Communication2026-05-07TrueMahadev JoshiTrue
LevelBlue TTP Briefing Q1 2026: Trust Abuse Exposes Weaknesses2026-05-05TrueTrue
Inside Vect Ransomware-as-a-Service2026-04-30TrueSpiderLabs ResearcherTrue
Hacking Hotels via Smart Stationary Bikes: How Unsecured Gym Equipment Can Lead to RCE2026-04-29TrueJohn LopezTrue
Crypto Drainers as a Converging Threat: Insights into Emerging Hybrid Attack Ecosystems2026-04-23TrueSerhii Melnyk, King Orande, Cris Tomboc, Sean ShirleyTrue
A Closer Look at the Novel and Stealthy KarstoRAT Malware2026-04-21TrueChen AvianiTrue
Go With the Flow: Abusing OAuth Device Code Flow2026-04-20TrueJakub WiewiorskiTrue
RedSun and the Expanding Risk Window: Why Microsoft Defender Patching Can’t Wait2026-04-17TrueTrue
Why Attackers Are Bypassing Phishing Emails and Targeting Identity Instead2026-04-13TrueJamie MamroeTrue
Trojanized CPUID HWMonitor Installer Delivers Fileless .NET Payload via Obfuscated IPv6 Scriptlet2026-04-10TrueSean ShirleyTrue
Axios NPM Package Supply Chain Compromise Leads to RAT Deployment2026-04-09TrueMahadev Joshi and Sho KishimotoTrue
Err-Hiding and Seek: How ErrTraffic v3 Leverages EtherHiding in ClickFix Campaign2026-04-09TrueKing Orande and Cris TombocTrue
Major Supply Chain Compromise in the Popular axios npm Package2026-04-03TrueKarl SiglerTrue
Using RF Power Levels to Defeat MAC Address Randomization Enabling Passive Device Tracking2026-03-31TrueTom NeavesTrue
Azure ServiceBus WebSockets as a C2 Channel2026-03-24TrueStuart WhiteTrue
Tracing a Multi-Vector Malware Campaign: From VBS to Open Infrastructure 2026-03-23TrueSean ShirleyTrue
“Say My Name”: How MioLab is building MacOS Stealer Empire2026-03-20TrueMark Tsipershtein and Evgeny AnaninTrue
Fake CAPTCHA Campaign: Inside a Multi-Stage Stealer Assault2026-03-19TrueShabtay Barel, Serhii Melnyk, Rodel MendrezTrue
KongTuke: A King Among Threat Groups2026-03-18TrueTrue
How LevelBlue OTX and Cybereason XDR Detected a North Korea-Linked Remote IT Worker2026-03-17TrueTue LuuTrue
Epic Fury Update: Stryker Attack Highlights Handala's Shift from Espionage to Disruption2026-03-12TrueArthur ErzbergerTrue
Weaponizing Safe Links: Abuse of Multi-Layered URL Rewriting in Phishing Attacks2026-03-12TrueJohn Kevin AdrianoTrue
Beware the ClickFix Trap: REMCOS RAT Hiding in “Helpful” PUAs2026-03-09TrueHema LoganathanTrue
CVE-2025-61915: Buffer Underflow Vulnerability Leads to Memory Corruption in CUPS2026-03-05TrueAriel SilverTrue
LevelBlue SpiderLabs Breaks Down the Role of Cyber Operations Taken in the Iran Crisis2026-03-04TrueGal RomanoTrue
Operation Epic Fury: From Regional Escalation to Global Cyber Risk2026-03-03TrueLevelBlue SpiderLabsTrue
Pwning Malware with Ninjas and Unicorns2026-02-16TrueCade WriglesworthTrue
How ClickFix Opens the Door to Stealthy StealC Information Stealer2026-02-12TrueRodel MendrezTrue
Stealerium Unmasked: Inside a Multi-Lure, Multi-Stage Stealer Campaign2026-02-11TrueBernard BautistaTrue
Notepad-Plus Fuss: Notepad++ Supply Chain Attack Analysis2026-02-10TrueKing OrandeTrue
19 Shades of LockBit 5.0, Inside the Latest Cross-Platform Ransomware: Part 32026-02-05TrueAlexander Sevtsov, Chen AvianiTrue
19 Shades of LockBit 5.0, Inside the Latest Cross-Platform Ransomware: Part 22026-02-04TrueMark Tsipershtein, Evgeny Ananin, Nikita KazymirskyiTrue
The Godfather of Ransomware? Inside DragonForce’s Cartel Ambitions2026-02-03TrueMark Tsipershtein and Evgeny AnaninTrue
LockBit 5.0 Introduces New Features: ChaCha20 Encryption, Stealthy Installation, and Anti-Analysis to Target Windows, Linux, and ESXi Environments2026-01-30TrueSpiderLabs ResearcherTrue
19 Shades of LockBit5.0, Inside the Latest Cross-Platform Ransomware: Part 12026-01-30TrueMark Tsipershtein, Evgeny Ananin, Nikita KazymirskyiTrue
Scenario 3: SOC/SIEM Takes in and Summarizes Windows Events (Log Files)2026-01-29TrueTom NeavesTrue
The Hard Lessons Learned by Analyzing Education Sector Cyberattacks2026-01-26TrueTrue
The Hard Lessons Learned by Analyzing Education Sector Cyberattacks2026-01-26TrueTrue
CVE-2009-0556: The 2009 PowerPoint But that Refuses to Die2026-01-23TrueMessiah Dela CruzTrue
CVE-2009-0556: The 2009 PowerPoint But that Refuses to Die2026-01-23TrueMessiah Dela CruzTrue
Ni8mare on Automation Street: When Workflows Turn Into an Attack Path2026-01-15TrueNikita KazymirskyiTrue
Ni8mare on Automation Street: When Workflows Turn Into an Attack Path2026-01-15TrueNikita KazymirskyiTrue
BEC Email Trends: Attacks up 15% in 20252026-01-13TrueKatrina UdquinTrue
BEC Email Trends: Attacks up 15% in 20252026-01-13TrueKatrina UdquinTrue

1–50 of 68