RSS
Threat Research
cobalt strike
DLL sideloading
minhook
Finding Minhook in a sideloading attack – and Sweden too
April 29, 2025
asyncrat
CVE-2024-1708
CVE-2024-1709
featured
IR
Lockbit
MDR
Ransomware
rust
ScreenConnect
Sophos X-Ops
ConnectWise ScreenConnect attacks deliver malware
February 23, 2024
Brute Ratel
Havok
Meterpreter
post-exploitation tools
Sliver
The Phantom Menace: Brute Ratel remains rare and targeted
May 18, 2023
Security Operations
Cryptomining
cve-2017-11317
cve-2017-11357
cve-2019-18935
Featured
Powershell
SophosLabs Uncut
telerik
XMRig
Telerik UI exploitation leads to cryptominer, Cobalt Strike infections
June 15, 2022
active adversary
Active Adversary Report
Artifacts
Attack Tools
cyberattacks
cyberthreats
dwell time
Exploit
initial access broker
malware delivery system
MITRE
ProxyLogon
ProxyShell
ransomware as a service
Sophos Rapid Response
vulnerability
The Active Adversary Playbook 2022
June 7, 2022
Bazar
Conti
Karma
Conti and Karma actors attack healthcare provider at same time through ProxyShell exploits
February 28, 2022
Applied Threat Intelligence
human-led threat hunting
Sophos MTR
Zloader
Zloader Installs Remote Access Backdoors and Delivers Cobalt Strike
January 19, 2022
Naked Security
“Cobalt Strike” network attack tool patches crashtastic server bug
August 5, 2021
DarkSide
Mega
pCloud
SystemBC
A defender’s view inside a DarkSide ransomware attack
May 11, 2021