logo

Fox-IT blog

ID: c35efdcf-b291-5ae3-b5f4-8034517b9d61

STIX ID: identity--c35efdcf-b291-5ae3-b5f4-8034517b9d61

Feed Type: skeleton

Earliest post: -

Latest post: -

The Fox-IT blog shares technical cybersecurity research, news, and expert analysis on threats such as malware, ransomware, and defensive techniques, based on real-world investigations by Fox-IT specialists.

01/01/2020
05/31/2026
Title Date Published Describes IncidentAuthorVisible
Three Lazarus RATs coming for your cheese2025-09-01TrueTrue
Red Teaming in the age of EDR: Evasion of Endpoint Detection Through Malware Virtualisation2024-09-25TrueTrue
Sifting through the spines: identifying (potential) Cactus ransomware victims2024-04-25TrueTrue
From ERMAC to Hook: Investigating the technical differences between two Android malware variants2023-09-11TrueGlobal Threat IntelligenceTrue
Approximately 2000 Citrix NetScalers backdoored in mass-exploitation campaign2023-08-15TrueTrue
From Backup to Backdoor: Exploitation of CVE-2022-36537 in R1Soft Server Backup Manager2023-02-22TrueGlobal Threat IntelligenceTrue
Threat spotlight: Hydra2023-02-15TrueGlobal Threat IntelligenceTrue
CVE-2022-27510, CVE-2022-27518 – Measuring Citrix ADC & Gateway version adoption on the Internet2022-12-28TrueTrue
One Year Since Log4Shell: Lessons Learned for the next ‘code red’2022-12-12TrueTrue
Sharkbot is back in Google Play2022-09-02TrueGlobal Threat IntelligenceTrue
Detecting DNS implants: Old kitten, new tricks – A Saitama Case Study2022-08-11TrueJoost JansenTrue
Flubot: the evolution of a notorious Android Banking Malware2022-06-29TrueGlobal Threat IntelligenceTrue
Adventures in the land of BumbleBee2022-04-29TrueGlobal Threat IntelligenceTrue
SharkBot: a “new” generation Android banking Trojan being distributed on Google Play Store2022-03-03TrueJoost JansenTrue
log4j-jndi-be-gone: A simple mitigation for CVE-2021-442282021-12-14TrueJoost JansenTrue
Log4Shell: Reconnaissance and post exploitation network detection2021-12-12TrueJoost JansenTrue
Encryption Does Not Equal Invisibility – Detecting Anomalous TLS Certificates with the Half-Space-Trees Algorithm2021-12-07TrueJoost JansenTrue
Tracking a P2P network related to TA5052021-12-02TrueJoost JansenTrue
TA505 exploits SolarWinds Serv-U vulnerability (CVE-2021-35211) for initial access2021-11-08TrueFox ItTrue
Reverse engineering and decrypting CyberArk vault credential files2021-10-12TrueFox ItTrue
SnapMC skips ransomware, steals data2021-10-11TrueGlobal Threat IntelligenceTrue
RM3 – Curiosities of the wildest banking malware2021-05-04TrueTrue
TA505: A Brief History Of Their Time2020-11-16TrueAntonis TerefosTrue
Decrypting OpenSSH sessions for fun and profit2020-11-11TrueFox ItTrue
StreamDivert: Relaying (specific) network connections2020-09-10TrueFox ItTrue
A Second Look at CVE-2019-19781 (Citrix NetScaler / ADC)2020-07-01TrueFox ItTrue
WastedLocker: A New Ransomware Variant Developed By The Evil Corp Group2020-06-23TrueTrue
In-depth analysis of the new Team9 malware family2020-06-02TrueTrue
LDAPFragger: Command and Control over LDAP attributes2020-03-19TrueTrue

1–29 of 29