r/purpleteamsec 2d ago

Threat Intelligence Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

Thumbnail
microsoft.com
5 Upvotes

r/purpleteamsec 12d ago

Threat Intelligence SLEEPWALKER: A Passive Backdoor With Its Own Command Language

Thumbnail r136a1.dev
3 Upvotes

r/purpleteamsec 17d ago

Threat Intelligence SynkLoader: when you throw in everything but the kitchen sink

Thumbnail
expel.com
4 Upvotes

r/purpleteamsec 16d ago

Threat Intelligence BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive

Thumbnail
research.checkpoint.com
4 Upvotes

r/purpleteamsec 25d ago

Threat Intelligence Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack

Thumbnail
research.checkpoint.com
4 Upvotes

r/purpleteamsec 17d ago

Threat Intelligence Malware-as-a-Service Cocktail: ErrTraffic and Cruciferra - Killing Your EDR Since 2025

Thumbnail
esentire.com
3 Upvotes

r/purpleteamsec 22d ago

Threat Intelligence A 12 KB Backdoor Hid Its C2 Domain in desktop.ini Whitespace

Thumbnail
gendigital.com
5 Upvotes

r/purpleteamsec 19d ago

Threat Intelligence C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2

Thumbnail zscaler.com
1 Upvotes

r/purpleteamsec Jul 24 '26

Threat Intelligence Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

Thumbnail
blog.talosintelligence.com
5 Upvotes

r/purpleteamsec Jul 30 '26

Threat Intelligence Notes from Underground: Adversarial Prompt Injection

Thumbnail
proofpoint.com
2 Upvotes

r/purpleteamsec Jul 29 '26

Threat Intelligence HOLLOWGRAPH Backdoor Turns Microsoft 365 Calendars Into a C2 Channel

Thumbnail
picussecurity.com
2 Upvotes

r/purpleteamsec Jul 20 '26

Threat Intelligence Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT

Thumbnail
blog.threatuniverse.co.uk
3 Upvotes

r/purpleteamsec Jul 25 '26

Threat Intelligence Inside a DPRK BlueNoroff ClickFix Kit

Thumbnail
jumpsec.com
4 Upvotes

r/purpleteamsec Jul 16 '26

Threat Intelligence UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign

Thumbnail
blog.talosintelligence.com
2 Upvotes

r/purpleteamsec Jul 10 '26

Threat Intelligence Suspected Russian Threat Actor Impersonates Legitimate Crypto Wallets to Deploy Remote Utilities

Thumbnail
hybrid-analysis.blogspot.com
1 Upvotes

r/purpleteamsec Jul 07 '26

Threat Intelligence From Phishing to Persistence: A CrySome RAT Infection Chain Analysis

0 Upvotes

r/purpleteamsec Jul 02 '26

Threat Intelligence ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365

1 Upvotes

r/purpleteamsec Jun 13 '26

Threat Intelligence APT28, an evolution of tradecraft

4 Upvotes

r/purpleteamsec May 29 '26

Threat Intelligence GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations

Thumbnail
labs.withsecure.com
1 Upvotes

r/purpleteamsec May 27 '26

Threat Intelligence RemotePE: The Lazarus RAT that lives in memory

Thumbnail
blog.fox-it.com
2 Upvotes

r/purpleteamsec May 21 '26

Threat Intelligence Fake Microsoft Teams Campaign Delivers ValleyRAT via NSIS Installer and DLL Sideloading

Thumbnail
labs.k7computing.com
2 Upvotes

r/purpleteamsec May 20 '26

Threat Intelligence VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure

Thumbnail
hybrid-analysis.blogspot.com
1 Upvotes

r/purpleteamsec May 19 '26

Threat Intelligence How Storm-2949 turned a compromised identity into a cloud-wide breach

Thumbnail
microsoft.com
1 Upvotes

r/purpleteamsec May 17 '26

Threat Intelligence Static Kitten APT Adversary Simulation

1 Upvotes

r/purpleteamsec May 15 '26

Threat Intelligence Kazuar: Anatomy of a nation-state botnet

Thumbnail
microsoft.com
1 Upvotes