logo

Sekoia.io Blog

ID: ca02d40e-2389-51b4-b883-744c86e6736b

STIX ID: identity--ca02d40e-2389-51b4-b883-744c86e6736b

Feed Type: rss

Earliest post: 2024-02-22

Latest post: 2026-06-01

Actionable threat intelligence insights, cybersecurity research, and updates from the Sekoia.io team.

01/01/2020
06/01/2026
Title Date Published Describes IncidentAuthorVisible
FSB’s matryoshka #1/3 – Gamaredon’s gifts that keeps unpacking – GammaPhish and GammaWorm2026-06-01TrueAmaury G. and Sekoia TDRTrue
From APT28 to RePythonNET: automating .NET malware analysis2026-04-16TrueSekoia TDRTrue
EvilTokens: an AI-augmented Phishing-as-a-Service for automating BEC fraud – Part 22026-04-07TrueQuentin Bourgue and Sekoia TDRTrue
New widespread EvilTokens kit: device code phishing as-a-service – Part 12026-03-30TrueQuentin Bourgue and Sekoia TDRTrue
Shadow IT: The Initial Access You Didn’t Log2026-03-06TrueDavid GreenwoodTrue
OysterLoader Unmasked: The Multi-Stage Evasion Loader2026-02-12TruePierre Le BourhisTrue
Meet IClickFix: a widespread WordPress-targeting framework using the ClickFix tactic2026-01-29TrueQuentin Bourgue, Amaury G. and Sekoia TDRTrue
Advent Of Configuration Extraction – Part 4: Turning capa Into A Configuration Extractor For TinyShell variant2025-12-22TruePierre Le Bourhis, Jeremy Scion and Sekoia TDRTrue
Advent of Configuration Extraction – Part 3: Mapping GOT/PLT and Disassembling the SNOWLIGHT Loader2025-12-15TrueJeremy Scion, Pierre Le Bourhis and Sekoia TDRTrue
Advent of Configuration Extraction – Part 2: Unwrapping QuasarRAT’s Configuration2025-12-08TruePierre Le Bourhis, Sekoia TDR and Jeremy ScionTrue
French NGO Reporters Without Borders targeted by Calisto in recent campaign2025-12-03TrueSekoia TDRTrue
Advent of Configuration Extraction – Part 1: Pipeline Overview – First Steps with Kaiji Configuration Unboxing2025-12-01TrueJeremy Scion, Pierre Le Bourhis and Sekoia TDRTrue
Phishing Campaigns “I Paid Twice” Targeting Booking.com Hotels and Customers2025-11-06TrueJeremy Scion, Quentin Bourgue and Sekoia TDRTrue
TransparentTribe targets Indian military organisations with DeskRAT2025-10-23TrueAmaury G., Coline Chavane and Sekoia TDRTrue
Defrosting PolarEdge’s Backdoor2025-10-14TrueSekoia TDRTrue
Silent Smishing : The Hidden Abuse of Cellular Router APIs2025-09-30TrueJeremy Scion and Marc N.True
APT28 Operation Phantom Net Voxel2025-09-16TrueAmaury G., Charles M. and Sekoia TDRTrue
Predators for Hire: A Global Overview of Commercial Surveillance Vendors2025-09-02TrueSekoia TDR, Maxime A., Coline Chavane and Felix AiméTrue
The Sharp Taste of Mimo’lette: Analyzing Mimo’s Latest Campaign targeting Craft CMS2025-05-27TrueJeremy Scion, Pierre Le Bourhis and Sekoia TDRTrue
ViciousTrap – Infiltrate, Control, Lure: Turning edge devices into honeypots en masse. 2025-05-22TrueFelix Aimé, Jeremy Scion and Sekoia TDRTrue
Detecting Multi-Stage Infection Chains Madness2025-04-22TrueSekoia TDR and Erwan ChevalierTrue
Interlock ransomware evolving under the radar2025-04-16TrueSekoia TDRTrue
From Contagious to ClickFake Interview: Lazarus leveraging the ClickFix tactic2025-03-31TrueAmaury G., Coline Chavane, Felix Aimé and Sekoia TDRTrue
ClearFake’s New Widespread Variant: Increased Web3 Exploitation for Malware Delivery2025-03-18TruePierre Le Bourhis, Quentin Bourgue and Sekoia TDRTrue
PolarEdge: Unveiling an uncovered ORB network2025-02-25TrueJeremy Scion, Felix Aimé and Sekoia TDRTrue
Cyber threats impacting the financial sector in 2024 – focus on the main actors2025-02-20TrueLivia Tibirna, Coline Chavane and Sekoia TDRTrue
RATatouille: Cooking Up Chaos in the I2P Kitchen2025-02-11TruePierre Le BourhisTrue
Targeted supply chain attack against Chrome browser extensions2025-01-22TrueQuentin Bourgue and Sekoia TDRTrue
Sneaky 2FA: exposing a new AiTM Phishing-as-a-Service2025-01-16TrueQuentin Bourgue, Grégoire Clermont and Sekoia TDRTrue
Double-Tap Campaign: Russia-nexus APT possibly related to APT28 conducts cyber espionage on Central Asia and Kazakhstan diplomatic relations2025-01-13TrueAmaury G., Maxime A., Erwan Chevalier, Felix Aimé and Sekoia TDRTrue
PlugX worm disinfection campaign feedbacks2024-12-26TrueSekoia TDRTrue
Helldown Ransomware: an overview of this emerging threat2024-11-19TrueJeremy Scion and Sekoia TDRTrue
ClickFix tactic: Revenge of detection2024-11-05TrueJeremy Scion and Sekoia TDRTrue
ClickFix tactic: The Phantom Meet2024-10-17TrueQuentin Bourgue and Sekoia TDRTrue
Mamba 2FA: A new contender in the AiTM phishing ecosystem2024-10-07TrueGrégoire Clermont and Sekoia TDRTrue
Bulbature, beneath the waves of GobRAT2024-10-02TrueSekoia TDR, Amaury G. and Felix AiméTrue
Hadooken and K4Spreader: The 8220 Gang’s Latest Arsenal2024-09-30TrueJeremy ScionTrue
SilentSelfie: Uncovering a major watering hole campaign against Kurdish websites2024-09-25TrueSekoia TDR, Felix Aimé and Maxime A.True
WebDAV-as-a-Service: Uncovering the infrastructure behind Emmenhtal loader distribution2024-09-19TrueMarc N. and Sekoia TDRTrue
Emulating and Detecting Scattered Spider-like Attacks2024-07-24TrueSekoia TDR, Mitigant, Guillaume C., Erwan Chevalier and Kennedy TorkuraTrue
Solving the 7777 Botnet enigma: A cybersecurity quest2024-07-23TrueSekoia TDR, Felix Aimé, Pierre-Antoine D., Charles M., Grégoire Clermont and Jeremy ScionTrue
MuddyWater replaces Atera by custom MuddyRot implant in a recent campaign2024-07-15TrueSekoia TDRTrue
Exposing FakeBat loader: distribution methods and adversary infrastructure2024-07-02TrueQuentin Bourgue and Sekoia TDRTrue
Master of Puppets: Uncovering the DoppelGänger pro-Russian influence campaign2024-05-21TrueSekoia TDR, Coline Chavane, Amaury G. and Kilian SeznecTrue
Tycoon 2FA: an in-depth analysis of the latest version of the AiTM phishing kit2024-03-25TrueQuentin Bourgue and TDR (Threat Detection & Research)True
Unveiling the depths of Residential Proxies providers2024-03-14TrueTDR (Threat Detection & Research), Amaury G., Livia Tibirna, Grégoire Clermont and CERT OCD - World Watch teamTrue
The Architects of Evasion: a Crypters Threat Landscape2024-03-07TrueLivia Tibirna and TDR (Threat Detection & Research)True
NoName057(16)’s DDoSia project: 2024 updates and behavioural shifts2024-03-01TrueAmaury G., Maxime A. and TDR (Threat Detection & Research)True
The Predator spyware ecosystem is not dead2024-02-28TrueFelix Aimé, Maxime A. and TDR (Threat Detection & Research)True
Scattered Spider laying new eggs2024-02-22TruePierre-Antoine D., Quentin Bourgue, Livia Tibirna and TDR (Threat Detection & Research)True

1–50 of 50