logo

Lab52 Blog

ID: c8475a7c-76d0-5d36-b8ef-23f7c4b1834d

STIX ID: identity--c8475a7c-76d0-5d36-b8ef-23f7c4b1834d

Feed Type: rss

Earliest post: 2025-06-19

Latest post: 2026-05-14

Cybersecurity research and technical threat intelligence insights from the threat intelligence division of S2 Grupo — covering malware analysis, exploit techniques, incident investigations, and practical defensive research.

01/01/2020
06/04/2026
Title Date Published Describes IncidentAuthorVisible
EasterBunny: advanced espionage artifacts attributed to APT292026-05-06TrueEr1c_CTrue
DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear2026-03-13True3722304989True
PlugX Meeting Invitation via MSBuild and GDATA2026-02-26True10baTrue
Operation MacroMaze: new APT28 campaign using basic tooling and legit infrastructure2026-02-13TrueDioTrue
Black Industry: IRGC-Linked offensive OT framework2026-01-28TrueDioTrue
From Dream Job to Malware: DreamLoaders in Lazarus’ Recent Campaign2025-10-24True10baTrue
Analyzing NotDoor: Inside APT28’s Expanding Arsenal2025-09-03True3722304989True
DeedRAT Backdoor Enhanced by Chinese APTs with Advanced Capabilities2025-07-18True3722304989True
Snake Keylogger in Geopolitical Affairs: Abuse of Trusted Java Utilities in Cybercrime Operations2025-06-27True3722304989True

1–9 of 9