| 2024 | Operation ShadowCat: Targeting Indian Political Observers via a Stealthy RAT | cyble |
| 2023 | A Look at the Nim-based Campaign Using Microsoft Word Docs to Impersonate the Nepali Government | Netskope |
| 2023 | A cascade of compromise: unveiling Lazarus' new campaign | Kaspersky |
| 2023 | APT28: From Initial Damage to Domain Controller Threats in an Hour | CERT-UA |
| 2023 | AeroBlade on the Hunt Targeting the U.S. Aerospace Industry | Blackberry |
| 2023 | Analysis of APT-C-56 (Transparent Tribe) camouflage resume attack campaign | CoreSec360 |
| 2023 | Analysis of activities of suspected APT-C-36 (Blind Eagle) organization launching Amadey botnet Trojan | CoreSec360 |
| 2023 | Blackfly: Espionage Group Targets Materials Technology | Symantec |
| 2023 | Blind Eagle Deploys Fake UUE Files and Fsociety to Target Colombia | Blackberry |
| 2023 | BlindEagle Targeting Ecuador With Sharpened Tools | checkpoint |
| 2023 | Dalbit (m00nlight): Chinese Hacker Group's APT Attack Campaign | Ahnlab |
| 2023 | Dark Pink: New APT hitting Asia-Pacific, Europe that goes deeper and darker | Group-ib |
| 2023 | Don't Answer That! Russia-Aligned TA499 Beleaguers Targets with Video Call Requests | Proofpoint |
| 2023 | ESET APT Activity Report Q2-Q3 2023 | ESET |
| 2023 | Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation | mandiant |
| 2023 | From Albania To The Middle East: The Scarred Manticore Is Listening | Checkpoint |
| 2023 | Gaza Cybergang Unified Front Targeting Hamas Opposition | Sentinelone |
| 2023 | Graphiron: New Russian Information Stealing Malware Deployed Against Ukraine | Symantec |
| 2023 | HWP Malware Using the Steganography Technique: RedEyes (ScarCruft) | AhnLab |
| 2023 | HrServ - Previously unknown web shell used in APT attack | Kaspersky |
| 2023 | Hydrochasma: Previously Unknown Group Targets Medical and Shipping Organizations in Asia | Symantec |
| 2023 | ITG05 operations leverage Israel-Hamas conflict lures to deliver Headlace malware | IBM |
| 2023 | Iron Tiger's SysUpdate Reappears, Adds Linux Targeting | Trend Micro |
| 2023 | Kimsuky Group Uses AutoIt to Create Malware (RftRAT, Amadey) | Ahnlab |
| 2023 | Lazarus group using public certificate vulnerability | Ahnlab |
| 2023 | MQsTTang: Mustang Panda's latest backdoor treads new ground with Qt and MQTT | ESET |
| 2023 | Modern Asia APT groups TTPs | Kaspersky |
| 2023 | MuddyWater eN-Able spear-phishing with new TTPs | deepinstinct |
| 2023 | Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware | Eclecticiq |
| 2023 | New APT34 Malware Targets The Middle East | Trend Micro |
| 2023 | New Tool Set Found Used Against Organizations in the Middle East, Africa and the US | Palo Alto Networks |
| 2023 | New UAC-0050 attack using RemcosRAT | CERT-UA |
| 2023 | OilRig's persistent attacks using cloud service-powered downloaders | ESET |
| 2023 | Operation Silent Watch: Desktop Surveillance in Azerbaijan and Armenia | Checkpoint |
| 2023 | Operation Triangulation: The last (hardware) mystery | Kaspersky |
| 2023 | Pandas with a Soul: Chinese Espionage Attacks Against Southeast Asian Government Entities | Checkpoint |
| 2023 | Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally | CISA |
| 2023 | Seedworm: Iranian Hackers Target Telecoms Orgs in North and East Africa | Symantec |
| 2023 | Stealing the LIGHTSHOW (Part One) - North Korea's UNC2970 | Mandiant |
| 2023 | Stealing the LIGHTSHOW (Part Two) - LIGHTSHIFT and LIGHTSHOW | Mandiant |
| 2023 | The slow Ticking time bomb: Tick APT group compromise of a DLP software developer in East Asia | ESET |
| 2023 | Threat Actor 'UAC-0099' Continues to Target Ukraine | Deepinstinct |
| 2023 | WinorDLL64: A backdoor from the vast Lazarus arsenal? | ESET |
| 2022 | A "Naver" ending game of Lazarus APT | zscaler |
| 2022 | A Summary of APT41 Targeting U.S. State Governments | Mandiant |
| 2022 | A detailed analysis of Lazarus APT malware disguised as Notepad++ Shell Extension | Cyber Geeks |
| 2022 | ACTINIUM targets Ukrainian organizations | microsoft |
| 2022 | APT Group LOREC53 (Lori Bear) Recently Launched A Large-Scale Cyber Attack On Ukraine | nsfocus |
| 2022 | APT attack disguised as North Korean defector resume format | Ahnlab |
| 2022 | APT35 Automates Initial Access Using ProxyShell | TheDFIRreport |
| 2022 | AcidRain: A Modem Wiper Rains Down on Europe | Sentinelone |
| 2022 | An Overview of UNC2891 | Mandiant |
| 2022 | Antlion Chinese APT Uses Custom Backdoor to Target Financial Institutions in Taiwan | Symantec |
| 2022 | Asylum Ambuscade: State Actor Uses Compromised Private Ukrainian Military Emails to Target European Governments and Refugee Movement | proofpoint |
| 2022 | BabaDeda and LorecCPL downloaders used to run Outsteel against Ukraine | telsy |
| 2022 | BfV Cyber-Brief Nr. 01/2022 | BfV |
| 2022 | Charting TA2541's Flight | proofpoint |
| 2022 | Cloud Atlas targets entities in Russia and Belarus amid the ongoing war in Ukraine | checkpoint |
| 2022 | Continued Targeting of Indian Power Grid Assets by Chinese State-Sponsored Activity Group | recordedfuture |
| 2022 | Cyber attack of UAC-0056 group on state organizations of Ukraine using malicious programs SaintBot and OutSteel (CERT-UA #3799) | CERT-UA |
| 2022 | Cyberattack by Sandworm Group (UAC-0082) on energy facilities of Ukraine using malicious programs INDUSTROYER2 and CADDYWIPER | CERT-UA |
| 2022 | Cyberattack on state organizations of Ukraine using the malicious program IcedID | CERT-UA |
| 2022 | Cyberattack on state organizations of Ukraine using the topic "Azovstal" | CERT-UA |
| 2022 | Destructive Malware Targeting Organizations in Ukraine | cisa |
| 2022 | Distribution of malicious Hangul documents disguised as press releases for the 20th presidential election | Ahnlab |
| 2022 | False flag or upgrade? Suspected sea lotus uses the Glitch platform to reproduce the attack sample | Blog |
| 2022 | Gamaredon (Primitive Bear) Russian APT Group Actively Targeting Ukraine | palo alto networks |
| 2022 | Gamaredon APT targets Ukrainian government agencies in new campaign | CiscoTalos |
| 2022 | Guard Your Drive from DriveGuard: Moses Staff Campaigns Against Israeli Organizations Span Several Months | fortinet |
| 2022 | HermeticWiper - New Destructive Malware Used In Cyber Attacks on Ukraine | sentinelone |
| 2022 | HermeticWiper and PartyTicket Targeting Computers in Ukraine | RecordedFuture |
| 2022 | Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks | cisa |
| 2022 | Iranian linked conglomerate MuddyWater comprised of regionally focused subgroups | talosintelligence |
| 2022 | Iranian-Aligned Threat Actor | SentinelOne |
| 2022 | IsaacWiper and HermeticWizard: New wiper and worm targeting Ukraine | ESET |
| 2022 | Kimsuky Group's APT Attacks (AppleSeed, PebbleDash) | Ahnlab |
| 2022 | LAPSUS$: Recent techniques, tactics and procedures | nccgroup |
| 2022 | Lazarus Targets Chemical Sector | Symantec |
| 2022 | Lazarus Trojanized DeFi app for delivering malware | Kaspersky |
| 2022 | Lazarus attack group that exploits the INITECH process | Ahnlab |
| 2022 | Modified Elephant APT and a Decade of Fabricating Evidence | SentinalOne |
| 2022 | New Milestones for Deep Panda: Log4Shell and Digitally Signed Fire Chili Rootkits | Fortinet |
| 2022 | New Sandworm Malware Cyclops Blink Replaces VPNFilter | CISA |
| 2022 | New espionage attack by Molerats APT targeting users in the Middle East | zscaler |
| 2022 | New spear phishing campaign targets Russian dissidents | malwarebytes |
| 2022 | Nobelium - Israeli Embassy Maldoc | Inquest |
| 2022 | Nobelium Returns to the Political World Stage | Fortinet |
| 2022 | North Korea's Lazarus APT leverages Windows Update client, GitHub in latest campaign | MalwareBytes |
| 2022 | North Korea-linked APT attack found disguised as a digital asset wallet service customer center | ESTSecurity |
| 2022 | Observations from the StellarParticle Campaign | crowdstrike |
| 2022 | Operation Dragon Castling: APT group targeting betting companies | Avast |
| 2022 | OutSteel, SaintBot Delivered by Spear Phishing Attacks Targeting Ukraine | Palo Alto Networks |
| 2022 | Prime Minister's Office Compromised: Details of Recent Espionage Campaign | Trellix |
| 2022 | Roaming Mantis reaches Europe | Kaspersky |
| 2022 | Russia's Trident Ursa (aka Gamaredon APT) Cyber Conflict Operations Unwavering Since Invasion of Ukraine | Palo Alto |
| 2022 | Russian State-Sponsored Cyber Actors Gain Network Access by Exploiting Default Multifactor Authentication Protocols and | CISA |
| 2022 | Serpent, No Swiping! New Backdoor Targets French Entities with Unique Attack Chain | Proofpoint |
| 2022 | Shuckworm Continues Cyber-Espionage Attacks Against Ukraine | Symantec |
| 2022 | Shuckworm: Espionage Group Continues Intense Campaign Against Ukraine | Symantec |
| 2022 | Snow abuse and gluttony: Analysis of suspected Lazarus attack activities against Korean companies | Qianxin |
| 2022 | SockDetour Backdoor Targets U.S. Defense Contractors | palo alto networks |
| 2022 | Stonefly: North Korea-linked Spying Operation Continues to Hit High-value Targets | Symantec |
| 2022 | Study of an APT attack on a telecommunications company in Kazakhstan | DrWeb |
| 2022 | Tarrask malware uses scheduled tasks for defense evasion | microsoft |
| 2022 | Telegram Malware Spotted in Latest Iranian Cyber Espionage Activity | mandiant |
| 2022 | The APT fallout of vulnerabilities such as ProxyLogon in Exchange (Hafnium), OGNL injection, and log4shell | HVS Consulting |
| 2022 | The ink-stained trail of GOLDBACKDOOR | stairwell |
| 2022 | Threat Actor UAC-0056 Targeting Ukraine with Fake Translation Software | Sentinelone |
| 2022 | TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies | CISA |
| 2022 | Transparent Tribe campaign uses new bespoke malware to target Indian government officials | Cisco |
| 2022 | UAC-0056 cyberattack on Ukrainian authorities using GraphSteel and GrimPlant malware | CERT_UA |
| 2022 | UNC2596 Observed Leveraging Vulnerabilities to Deploy Cuba Ransomware | Mandiant |
| 2022 | UNC3524: Eye Spy on Your Email | Mandiant |
| 2022 | Ugg Boots 4 Sale: A Tale of Palestinian-Aligned Espionage | proofpoint |
| 2022 | Ukraine: Disk-wiping Attacks Precede Russian Invasion | Symantec |
| 2022 | Understanding and Mitigating Russian State-Sponsored Cyber Threats to U.S. Critical Infrastructure | cisa |
| 2022 | Update: Destructive Malware Targeting Organizations in Ukraine | cisa |
| 2022 | VajraEleph from South Asia - Cyber espionage against Pakistani military personnel revealed | QAX |
| 2022 | Very very lazy Lazyscripter's scripts: double compromise in a single obfuscation | Lab52 |
| 2021 | APT Group Targets Indian Defense Officials Through Enhanced TTPs | Cyble |
| 2021 | APT41 Resurfaces as Earth Baku With New Cyberespionage Campaign | Trend Micro |
| 2021 | FIN7 Using Windows 11 Alpha-Themed Docs to Drop Javascript Backdoor | Anomali |
| 2021 | InSideCopy: How this APT continues to evolve its arsenal | Talos |
| 2021 | Kimsuky Espionage Campaign | Inquest |
| 2021 | LuminousMoth APT: Sweeping attacks for the chosen few | Kaspersky |
| 2021 | New nation-state cyberattacks | Microsoft |
| 2021 | North Korean APT InkySquid Infects Victims Using Browser Exploits | Volexity |
| 2021 | Operation Armor Piercer: Targeted attacks in the Indian subcontinent using commercial RATs | Cisco |
| 2021 | Phishing Campaign Targeting Korean to Deliver Agent Tesla New Variant | Fortinet |
| 2021 | PortDoor: New Chinese APT Backdoor Attack Targets Russian Defense Sector | Cybereason |
| 2021 | Targeted Attack Campaign Against ManageEngine ADSelfService Plus Delivers Godzilla Webshells, NGLite Trojan and KdcSponge Stealer | PaloAlto |
| 2020 | China Panda attacks supply chain against Vietnam Government Certification Authority - Part1 | Vincss |
| 2020 | Collaboration Between FIN7 and the RYUK Group | Truesec |
| 2020 | Current Iran-Associated Cyber Threats | Symantec |
| 2020 | Lazarus covets COVID-19-related intelligence | Kaspersky |
| 2020 | Lazarus supply-chain attack in South Korea | ESET |
| 2020 | Revenge RAT Targeting Users in South America | Uptycs |
| 2020 | SolarWinds Attribution: Are We Getting Ahead of Ourselves? | RecordedFuture |
| 2020 | This Is Not a Test: APT41 Initiates Global Intrusion Campaign Using Multiple Exploits | Fireeye |
| 2020 | Transparent Tribe: Evolution analysis, part 1 | Kaspersky |
| 2020 | Transparent Tribe: Evolution analysis, part 2 | Kaspersky |
| 2019 | A Peek into BRONZE UNION's Toolbox | Dell Secureworks |
| 2019 | APT41: A Dual Espionage and Cyber Crime Operation | FireEye |
| 2019 | APT41: A Dual Espionage and Cyber Crime Operation | FireEye |
| 2019 | AVIVORE - Hunting Global Aerospace through the Supply Chain | Contextis |
| 2019 | Attacks Of The Lazarus Cybercriminal Group Attended To Organizations In Russia | SecureSoft |
| 2019 | CARBANAK Week Part Four: The CARBANAK Desktop Video Player | FireEye |
| 2019 | CARBANAK Week Part One: A Rare Occurrence | FireEye |
| 2019 | CARBANAK Week Part Three: Behind the CARBANAK Backdoor | FireEye |
| 2019 | CARBANAK Week Part Two: Continuing the CARBANAK Source Code Analysis | FireEye |
| 2019 | Calypso APT: new group attacking state institutions | Positive Technologies |
| 2019 | Chafer used Remexi malware to spy on Iran-based foreign diplomatic entities | Kaspersky |
| 2019 | DNS Hijacking Abuses Trust In Core Internet Service | Cisco |
| 2019 | DarkUniverse - the mysterious APT framework 27 | Kaspersky |
| 2019 | GAME OVER: Detecting and Stopping an APT41 Operation | FireEye |
| 2019 | Hard Pass: Declining APT34's Invite to Join Their Professional Network | FireEye |
| 2019 | Huge Fan of Your Work: TURBINE PANDA C919 Passenger Jet | Crowdstrike |
| 2019 | OceanLotus APT Group Leveraging Steganography | Cylance |
| 2019 | Operation Ghost | ESET |
| 2019 | Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers | Cybereason |
| 2019 | Pat Bear (APT-C-37) | Qihoo 360 |
| 2019 | Recent Cloud Atlas activity | Kaspersky |
| 2019 | Sea Turtle keeps on swimming, finds new victims, DNS hijacking techniques | Cisco |
| 2019 | The Kittens Are Back in Town 2 | Clearsky |
| 2019 | Threat Group Cards: A Threat Actor Encyclopedia | ThaiCERT |
| 2019 | Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks | Symantec |
| 2019 | Untangling Legion Loader's Hornet Nest of Malware | Deepinstinct |
| 2019 | Waterbug: Espionage Group Rolls Out Brand-New Toolset in Attacks Against Governments | Symantec |
| 2018 | APT Trends Report Q2 2018 | Kaspersky |
| 2018 | APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS | NCC Group |
| 2018 | APT37 (Reaper): The Overlooked North Korean Actor | FireEye |
| 2018 | Burning Umbrella | 401TRG |
| 2018 | Dark Caracal Cyber-espionage at a Global Scale | Lookout |
| 2018 | Domestic Kitten: An Iranian Surveillance Operation | Checkpoint |
| 2018 | Energetic Bear/Crouching Yeti: attacks on servers | Kaspersky |
| 2018 | Follow The Money: Dissecting the Operations of the Cyber Crime Group FIN | FireEye |
| 2018 | Hidden Cobra Targets Turkish Financial Sector With New Bankshot Implant | McAfee |
| 2018 | Industrial Control System Threats | Dragos |
| 2018 | Iran's Hacker Hierarchy Exposed | Recorded Future |
| 2018 | Lazarus Group Targets More Cryptocurrency Exchanges and FinTech Companies | Intezer |
| 2018 | LuckyMouse hits national data center to organize country-level waterholing campaign | Kaspersky |
| 2018 | M-TRENDS2018 | FireEye |
| 2018 | OPERATION "Rocket Man" | ESTSecurity |
| 2018 | Olympic Destroyer is still alive | Kaspersky |
| 2018 | Operation Oceansalt Delivers Wave After Wave | McAfee |
| 2018 | Russian Army Exhibition Decoy Leads to New BISKVIT Malware | Fortinet |
| 2018 | Shamoon 3 Targets Oil and Gas Organization | Palo Alto Networks |
| 2018 | The destruction of APT3 | Intrusiontruth |
| 2018 | Turla group update Neuron malware | NCSC |
| 2018 | Two Birds, One STONE PANDA | Crowdstrike |
| 2018 | Update on Pawn Storm: New Targets and Politically Motivated Campaigns | Trend Micro |
| 2018 | https://securingtomorrow.mcafee.com/blogs/other-blogs/mcafee-labs/operation-sharpshooter-targets-global-defense-critical-infrastructure/ | McAfee |
| 2017 | A Pretty Dope Story About Bears: Early Indicators of Continued World Anti-Doping Agency (WADA) Targeting | tr1adx |
| 2017 | APT Targets Financial Analysts with CVE-2017-0199 | Proofpoint |
| 2017 | APT29 Domain Fronting With TOR | FireEye |
| 2017 | Additional Insights on Shamoon2 | Arbor Networks |
| 2017 | An intrusion campaign targeting Chinese language news sites | Citizen Lab |
| 2017 | At the Center of the Storm: Russia's APT28 Strategically Evolves its Cyber Operations | FireEye |
| 2017 | Attackers Deploy New ICS Attack Framework "TRITON" and Cause Operational Disruption to Critical Infrastructure | FireEye |
| 2017 | Bear Spotting Vol. 1: Russian Nation State Targeting of Government and Military Interests | tr1adx |
| 2017 | BlackOasis APT and new targeted attacks leveraging zero-day exploit | Kaspersky |
| 2017 | Breaking The Weakest Link Of The Strongest Chain | Kaspersky |
| 2017 | Bronze Butler | Dell Secureworks |
| 2017 | CRASHOVERRIDE Analysis of the Threat to Electric Grid Operations | Dragos |
| 2017 | CVE-2017-8759: Zero-Day Used in the Wild to Distribute FINSPY | FireEye |
| 2017 | Carbon Paper: Peering into Turla second stage backdoor | ESET |
| 2017 | ChChes - Malware that Communicates with C&C Servers Using Cookie Headers | JPCERT |
| 2017 | Charming Kitten: CSV Data | Clearsky |
| 2017 | Charming Kitten: Iranian Cyber Espionage Against Human Rights Activists | Clearsky |
| 2017 | ChessMaster Makes its Move: A Look into the Campaign's Cyberespionage Arsenal | Trend Micro |
| 2017 | ChessMaster's New Strategy: Evolving Tools and Tactics | Trend Micro |
| 2017 | Cyber Attack Impersonating Identity Of Indian Think Tank To Target Central Bureau Of Investigation (cbi) And Possibly Indian Army Officials | Cysinfo |
| 2017 | Cyber Attack Targeting Indian Navy's Submarine And Warship Manufacturer | Cysinfo |
| 2017 | Cyber Conflict Decoy Document Used In Real Cyber Conflict | Cisco |
| 2017 | Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations | FireEye |
| 2017 | Cyberattacks Against Ukrainian ICS | Sentryo |
| 2017 | Dimnie: Hiding in Plain Sight | Palo Alto Networks |
| 2017 | Dissecting the APT28 Mac OS X Payload | Bitdefender |
| 2017 | DragonOK Updates Toolset and Targets Multiple Geographic Regions | Palo Alto Networks |
| 2017 | Dragonfly: Western energy sector targeted by sophisticated attack group | Symantec |
| 2017 | Enhanced Analysis of GRIZZLY STEPPE Activity | US-CERT |
| 2017 | Evidence Aurora Operation Still Active: Supply Chain Attack Through CCleaner | Intezer |
| 2017 | Evidence Aurora Operation Still Active: Supply Chain Attack Through CCleaner part2 | Intezer |
| 2017 | FIN7 Spear Phishing Campaign Targets Personnel Involved in SEC Filings | FireEye |
| 2017 | Foreign Cyber Threats to the United States | US Senate Committee on Armed Services |
| 2017 | From BlackEnergy to ExPetr | Kaspersky |
| 2017 | From Shamoon to StoneDrill | Kaspersky |
| 2017 | Gazing at Gazer | ESET |
| 2017 | Inexsmar: An unusual DarkHotel campaig | Bitdefender |
| 2017 | Inside the Response of a Unique CARBANAK Intrusion | RSA |
| 2017 | Introducing WhiteBear | Kaspersky |
| 2017 | Investigation: WannaCry cyber attack and the NHS | NAO UK |
| 2017 | Iranian PupyRAT Bites Middle Eastern Organizations | Secureworks |
| 2017 | Iranian Threat Agent Greenbug Impersonates Israeli High-Tech and Cyber Security Companies | Clearsky |
| 2017 | Iranian Threat Agent OilRig Delivers Digitally Signed Malware, Impersonates University of Oxford | Clearsky |
| 2017 | KASPERAGENT Malware Campaign resurfaces in May Election | ThreatConnect |
| 2017 | KingSlayer A Supply chain attack | RSA |
| 2017 | Lazarus & Watering-Hole Attacks | BAE Systems |
| 2017 | Lazarus Under The Hood | Kaspersky |
| 2017 | Lazarus' False Flag Malware | BAE Systems |
| 2017 | Longhorn: Tools used by cyberespionage group | Symantec |
| 2017 | Magic Hound Campaign Attacks Saudi Targets | Palo Alto Networks |
| 2017 | Mm Core In-Memory Backdoor Returns As Bigboss And Sillygoose | Forcepoint |
| 2017 | Nile Phish: Large-Scale Phishing Campaign Targeting Egyptian Civil Society | Citizen Lab |
| 2017 | North Korea Bitten by Bitcoin Bug | Proofpoint |
| 2017 | North Korea Is Not Crazy | Recorded Future |
| 2017 | OceanLotus Blossoms: Mass Digital Surveillance and Attacks Targeting ASEAN | Volexity |
| 2017 | OilRig Deploys "ALMA Communicator" - DNS Tunneling Trojan | Palo Alto Networks |
| 2017 | Operation Bugdrop: Cyberx Discovers Large-Scale Cyber-Reconnaissance Operation Targeting Ukrainian Organizations | CyberX |
| 2017 | Operation Cloud Hopper | PWC |
| 2017 | Operation Cobalt Kitty Threat Actor Profile & IOC | Cybereason |
| 2017 | Operation Cobalt Kitty: A large-scale APT in Asia carried out by the OceanLotus Group | Cybereason |
| 2017 | Operation Electric Powder - Who is targeting Israel Electric Company? | Clearsky |
| 2017 | Operation Wilted Tulip | Clearsky |
| 2017 | PLATINUM continues to evolve, find ways to maintain invisibility | Microsoft |
| 2017 | Privileges and Credentials: Phished at the Request of Counsel | FireEye |
| 2017 | Recorded Future Research Concludes Chinese Ministry of State Security Behind APT3 | Recorded Future |
| 2017 | Remote Control Interloper: Analyzing New Chinese htpRAT Attacks Against ASEAN | RiskIQ |
| 2017 | Russian Bank Offices Hit with Broad Phishing Wave | RSA |
| 2017 | Several Polish banks hacked, information stolen by unknown attackers | Badcyber |
| 2017 | Spear Phishing Techniques Used in Attacks Targeting the Mongolian Government | FireEye |
| 2017 | TAINTED LEAKS Disinformation and Phishing With a Russian Nexus | Citizen Lab |
| 2017 | TRISIS Malware | Dragos |
| 2017 | Taiwan Heist: Lazarus Tools And Ransomware | BAE Systems |
| 2017 | TeleBots are back: supply-chain attacks against Ukraine | ESET |
| 2017 | The Blockbuster Sequel | Palo Alto Networks |
| 2017 | The Carbanak/Fin7 syndicate | RSA |
| 2017 | The Deception Project: A New Japanese-Centric Threat | Cylance |
| 2017 | The Digital Plagiarist Campaign: TelePorting the Carbanak Crew to a New Dimension | tr1adx |
| 2017 | The Full Shamoon: How the Devastating Malware Was Inserted Into Networks | IBM |
| 2017 | The Gamaredon Group Toolset Evolution | Palo Alto Networks |
| 2017 | The KeyBoys are back in town | PWC |
| 2017 | Threat Actors Target Government of Belarus Using CMSTAR Trojan | Palo Alto Networks |
| 2017 | Threat Group APT28 Slips Office Malware into Doc Citing NYC Terror Attack | McAfee |
| 2017 | Tracking Subaat: Targeted Phishing Attack Leads to Threat Actor's Repository | Palo Alto Networks |
| 2017 | Turla group using Neuron and Nautilus tools alongside Snake malware | NCSC |
| 2017 | URI Terror Attack & Kashmir Protest Themed Spear Phishing Emails Targeting Indian Embassies And Indian Ministry Of External Affairs | Cysinfo |
| 2017 | ViperRAT: The mobile APT targeting the Israeli Defense Force that should be on your radar | Lookout |
| 2017 | WIN32/INDUSTROYER A new threat for industrial control systems | ESET |
| 2016 | A Look Into Fysbis: Sofacy's Linux Backdoor | Palo Alto |
| 2016 | APT Case RUAG Technical Report | GovCERT.ch |
| 2016 | APT Group Sends Spear Phishing Emails to Indian Government Officials | FireEye |
| 2016 | Apt Group Sends Spear Phishing Emails To Indian Government Officials | FireEye |
| 2016 | Apt Reports And Opsec Evolution, Or: These Are Not The Apt Reports You Are Looking For | Virus Bulletin |
| 2016 | Asruex: Malware Infecting through Shortcut Files | JPCERT |
| 2016 | Attack On French Diplomat Linked To Operation Lotus Blossom | Palo Alto |
| 2016 | Attacks on SWIFT Banking System Benefit From Insider Knowledge | McAfee |
| 2016 | BITTER: A Targeted attack against Pakistan | Forcepoint |
| 2016 | BLACKGEAR Espionage Campaign Evolves, Adds Japan To Target List | Trend Micro |
| 2016 | Bear Hunting Season: Tracking APT28 | tr1adx |
| 2016 | Bears in the Midst: Intrusion into the Democratic National Committee | Crowdstrike |
| 2016 | Belling the BEAR | ThreatConnect |
| 2016 | Between Hong Kong and Burma: Tracking UP007 and SLServer Espionage Campaign | Citizen Lab |
| 2016 | BlackEnergy APT Attacks in Ukraine employ spearphishing with Word documents | Kaspersky |
| 2016 | BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry | ESET |
| 2016 | Buckeye cyberespionage group shifts gaze from US to Hong Kong | Symantec |
| 2016 | CVE-2015-2545: overview of current threats | Kaspersky |
| 2016 | Carbanak Oracle Breach | Visa |
| 2016 | Danger Close: Fancy Bear Tracking of Ukrainian Field Artillery Units | Crowdstrike |
| 2016 | Emissary Trojan Changelog: Did Operation Lotus Blossom Cause It To Evolve | Palo Alto |
| 2016 | En Route with Sednit Part 1: Approaching the Target | ESET |
| 2016 | En Route with Sednit Part 2: Observing the Comings and Goings | ESET |
| 2016 | En Route with Sednit Part 3: A Mysterious Downloader | ESET |
| 2016 | Espionage toolkit targeting Central and Eastern Europe uncovered | ESET |
| 2016 | Exploring CVE-2015-2545 and its users | PWC |
| 2016 | FROM SEOUL TO SONY: THE HISTORY OF THE DARKSEOUL GROUP AND THE SONY INTRUSION MALWARE DESTOVER | Bluecoat |
| 2016 | Findings from Analysis of DNC Intrusion Malware | Fidelis |
| 2016 | Flash zero-day exploit deployed by the ScarCruft APT Group | Kaspersky |
| 2016 | GRIZZLY STEPPE - Russian Malicious Cyber Activity | US-CERT |
| 2016 | Group5: Syria and the Iranian Connection | Citizen Lab |
| 2016 | Houdini's Magic Reappearance | Palo Alto Networks |
| 2016 | Hunting Libyan Scorpions | Cyberkov Security |
| 2016 | IRONGATE ICS Malware: Nothing to See Here...Masking Malicious Activity on SCADA Systems | FireEye |
| 2016 | IXESHE Derivative IHEATE Targets Users in America | Trend Micro |
| 2016 | Indian organizations targeted in Suckfly attacks | Symantec |
| 2016 | It's Parliamentary: KeyBoy and the targeting of the Tibetan Community | Citizen Lab |
| 2016 | Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups | ICIT |
| 2016 | Let It Ride: The Sofacy Group's DealersChoice Attacks Continue | Palo Alto Networks |
| 2016 | Looking Into a Cyber-Attack Facilitator in the Netherlands | Trend Micro |
| 2016 | Looking Into a Cyber-Attack Facilitator in the Netherlands (Appendix) | Trend Micro |
| 2016 | Malware Actors Using Nic Cyber Security Themed Spear Phishing To Target Indian Government Organizations | Cysinfo |
| 2016 | Mofang: A politically motivated information stealing adversary | Fox-IT |
| 2016 | Moonlight - Targeted attacks in the Middle East | Vectra Networks |
| 2016 | Moonsoon - Analysis of an APT Campaign | Forcepoint |
| 2016 | NetTraveler APT Targets Russian, European Interests | ProofPoint |
| 2016 | New Carbanak / Anunak Attack Methodology | Trustwave |
| 2016 | New Sofacy Attacks Against US Government Agency | Palo Alto |
| 2016 | New Wekby Attacks Use DNS Requests As Command and Control Mechanism | Palo Alto |
| 2016 | New wave of cyberattacks against Ukrainian power industry | ESET |
| 2016 | On the StrongPity Waterhole Attacks Targeting Italian and Belgian Encryption Users | Kaspersky |
| 2016 | Operation Blockbuster | Novetta |
| 2016 | Operation C-Major Actors Also Used Android BlackBerry Mobile Spyware Against Targets | Trend Micro |
| 2016 | Operation Daybreak | Kaspersky |
| 2016 | Operation Duststorm | Cylance |
| 2016 | Operation Dusty Sky | Clearsky |
| 2016 | Operation Dusty Sky (indicators) | Clearsky |
| 2016 | Operation DustySky Part 2 | Clearsky |
| 2016 | Operation DustySky Part 2 Indicators | Clearsky |
| 2016 | Operation Groundbait:Analysis of a surveillance toolkit | ESET |
| 2016 | Operation Ke3chang Resurfaces With New TidePool Malware | Palo Alto |
| 2016 | Operation Manul | EFF |
| 2016 | Operation Transparent Tribe | Proofpoint |
| 2016 | PLATINUM Targeted attacks in South and Southeast Asia | Microsoft |
| 2016 | PROMETHIUM and NEODYMIUM: Parallel zero-day attacks targeting individuals in Europe | Microsoft |
| 2016 | Pacifier APT | Bitdefender |
| 2016 | Patchwork cyberespionage group expands targets from governments to wide range of industries | Symantec |
| 2016 | Poseidon Group | Kaspersky |
| 2016 | PowerDuke: Widespread Post-Election Spear Phishing Campaigns Targeting Think Tanks and NGOs | Volexity |
| 2016 | Prince of Persia Game Over | Palo Alto |
| 2016 | Prince of Persia: Infy Malware Active In Decade of Targeted Attacks | Palo Alto |
| 2016 | RESEARCH SPOTLIGHT: NEEDLES IN A HAYSTACK | Cisco |
| 2016 | Red Line Drawn: China Recalculates Its Use Of Cyber Espionage | FireEye |
| 2016 | Reverse-engineering DUBNIUM | Microsoft |
| 2016 | Reverse-engineering DUBNIUM's Flash-targeting exploit | Microsoft |
| 2016 | SWIFT attackers' malware linked to more financial attacks | Symantec |
| 2016 | Scarlet Mimic | Palo Alto |
| 2016 | Shifting Tactics Tracking Changes In Years Long Espionage Campaign Against Tibetans | Citizen Lab |
| 2016 | Sofacy's Komplex OS X Trojan | Palo Alto |
| 2016 | Stealth Falcon | Citizen Lab |
| 2016 | Strider: Cyberespionage group turns eye of Sauron on targets | Symantec |
| 2016 | Suckfly: Revealing the secret life of your code signing certificates | Symantec |
| 2016 | T9000: Advanced Modular Backdoor Uses Complex Anti Analysis Techniques | Palo Alto |
| 2016 | Taiwan Presidential Election: A Case Study on Thematic Targeting | PWC |
| 2016 | Taiwan targeted with new cyberespionage back door Trojan | Symantec |
| 2016 | Targeted Attacks against Banks in the Middle East | FireEye |
| 2016 | The Dropping Elephant - aggressive cyber-espionage in the Asian region | Kaspersky |
| 2016 | The Four Element Sword Engagement | Arbor |
| 2016 | The Ghost Dragon | Cylance |
| 2016 | The Million Dollar Dissident: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender | Citizen Lab |
| 2016 | The ProjectSauron APT | Kaspersky |
| 2016 | Threat Group 4127 Targets Hillary Clinton Presidential Campaign | Dell Secureworks |
| 2016 | Threat Group-4127 Targets Google Accounts | Secureworks |
| 2016 | Threat Group-4127 Targets Hillary Clinton Presidential Campaign | Secureworks |
| 2016 | Tracking Elirks Variants in Japan: Similarities to Previous Attacks | Palo Alto |
| 2016 | Turbo Twist: Two 64-bit Derusbi Strains Converge | Fidelis |
| 2016 | Two Bytes to $951M | BAE Systems |
| 2016 | Uncovering the Seven Pointed Dagger | Arbor Networks |
| 2016 | Unveiling Patchwork the Copy Paste APT | Cymmetria |
| 2016 | Use of Fancy Bear Android Malware tracking of Ukrainian Artillery Units | Crowdstrike |
| 2016 | Visa Alert and Update on the Oracle Breach | Brian Krebs |
| 2016 | Visiting The Bear Den A Journey in the Land of (Cyber-)Espionage | ESET |
| 2016 | Wave your false flags! Deception tactics muddying attribution in targeted attacks | Kaspersky |
| 2016 | When The Lights Went Out: Ukraine Cybersecurity Threat Briefing | Booz Allen |
| 2015 | "Forkmeiamfamous": Seaduke, Latest Weapon In The Duke Armory | Symantec |
| 2015 | APT28 Targets Financial Markets: Zero Day Hashes Released | root9b |
| 2015 | APT30 And The Mechanics Of A Long-Running Cyber Espionage Operation | FireEye |
| 2015 | An Analysis Of Regin's Hopscotch And Legspin | Kaspersky |
| 2015 | An Iranian Cyber-Attack Campaign Against Targets In The Middle East | Clearsky |
| 2015 | Analysis Of A Recent Plugx Variant - P2P Plugx | JPCERT |
| 2015 | Analysis Of Project Cobra | Gdata |
| 2015 | Analysis On APT-To-Be Attack That Focusing On China's Government Agency | Antiy CERT |
| 2015 | Attacks Against Israeli & Palestinian Interests | PWC |
| 2015 | BBSRAT Attacks Targeting Russian Organizations Linked to Roaming Tiger | Palo Alto |
| 2015 | Backdoor.Cadelspy and Backdoor.Remexi indicators of compromise | Symantec |
| 2015 | Backdoor.Winnti Attackers Have A Skeleton In Their Closet? | Symantec |
| 2015 | Behind The Syrian Conflict's Digital Front Lines | FireEye |
| 2015 | Blue Termite (Internet Watch) | Kaspersky |
| 2015 | Butterfly: Corporate Spies Out For Financial Gain | Symantec |
| 2015 | Carbanak APT The Great Bank Robbery | Kaspersky |
| 2015 | Carbanak is packing new guns | ESET |
| 2015 | China Hacks The Peace Palace: All Your Eez's Are Belong To Us | ThreatConnect |
| 2015 | Cmstar Downloader: Lurid And Enfal's New Cousin | Palo Alto |
| 2015 | Cozyduke | F-Secure |
| 2015 | Cyber war in perspective: Russian aggression against Ukraine | NATO |
| 2015 | Cylance Spear Team: A Threat Actor Resurfaces | Cylance |
| 2015 | Darkhotel's attacks in 2015 | Kaspersky |
| 2015 | Dino: The Latest Spying Malware From An Allegedly French Espionage Group Analyzed | ESET |
| 2015 | Dissecting Linux/Moose: The Analysis Of A Linux Router-Based Worm Hungry For Social Networks | ESET |
| 2015 | Dissecting The Kraken | Gdata |
| 2015 | Dissecting the Malware Involved in the INOCNATION Campaign | Fidelis |
| 2015 | Duke APT Group's Latest Tools: Cloud Services And Linux Support | F-Secure |
| 2015 | Duqu 2.0: A Comparison To Duqu | CrySyS Lab |
| 2015 | Duqu 2.0: Reemergence of an aggressive cyberespionage threat | Symantec |
| 2015 | ELISE: Security Through Obesity | PWC |
| 2015 | Equation Group: Questions And Answers | Kaspersky |
| 2015 | Evolution Of Sophisticated Spyware: From Agent.Btz To Comrat | Gdata |
| 2015 | Evolution of Cyber Threats in the Corporate Sector | Kaspersky |
| 2015 | Games Are Over: Winnti Is Now Targeting Pharmaceutical Companies | Kaspersky |
| 2015 | Global Threat Intel Report | Crowdstrike |
| 2015 | Grabit And The Rats | Kaspersky |
| 2015 | Hacker Group Creates Network of Fake LinkedIn Profiles | Secureworks |
| 2015 | Hammertoss: Stealthy Tactics Define A Russian Cyber Threat Group | FireEye |
| 2015 | Hellsing Indicators Of Compromise | Kaspersky |
| 2015 | Inside The Equationdrug Espionage Platform | Kaspersky |
| 2015 | Insight In To A Strategic Web Compromise And Attack Campaign Against Hong Kong Infrastructure | Dragon Threat Labs |
| 2015 | Iran-based attackers use back door threats to spy on Middle Eastern targets | Symantec |
| 2015 | Microsoft Security Intelligence Report (Volume 19) | Microsoft |
| 2015 | Oceanlotus | SkyEye |
| 2015 | Operation Arid Viper: Bypassing The Iron Dome | Trend Micro |
| 2015 | Operation Clandestine Wolf _ Adobe Flash Zero-Day In APT3 Phishing Campaign | FireEye |
| 2015 | Operation Lotusblossom | Palo Alto |
| 2015 | Operation Oil Tanker: The Phantom Menace | Pandalabs |
| 2015 | Operation Potao Express: Analysis Of A Cyber-Espionage Toolkit | ESET |
| 2015 | Operation Russiandoll: Adobe & Windows ZeroDay Exploits Likely leveraged By Russia's APT28 | FireEye |
| 2015 | Operation Tropic Trooper: Relying On Tried-And-Tested Flaws To Infiltrate Secret Keepers | Trend Micro |
| 2015 | Operation Woolen-Goldfish When Kittens Go Phishing | Trend Micro |
| 2015 | PEERING INTO GLASSRAT: A Zero Detection Trojan from China | RSA |
| 2015 | Pawn Storm Update: Ios Espionage App Found | Trend Micro |
| 2015 | Pay No Attention to the Server Behind the Proxy: Mapping FinFisher's Continuing Proliferation | Citizen Lab |
| 2015 | Plugx Goes To The Registry (And India) | Sophos |
| 2015 | RSA Incident Response: An APT Case Study | RSA |
| 2015 | RSA Research Terracotta VPN: Enabler Of Advanced Threat Anonymity | RSA |
| 2015 | Reversing The Inception APT Malware | Bluecoat |
| 2015 | Rocket Kitten: A Campaign With 9 Lives | Checkpoint |
| 2015 | Scanbox Ii | PWC |
| 2015 | Scarab Attackers Took Aim At Select Russian Targets Since 2012 | Symantec |
| 2015 | Shooting Elephants | Netzpolitik |
| 2015 | Skeleton Key Malware Analysis | Dell Secureworks |
| 2015 | Sofacy II_ Same Sofacy, Different Day | PWC |
| 2015 | Southeast Asia: An Evolving Cyber Threat Landscape | FireEye, Singtel |
| 2015 | THE DUKES: 7 years of Russian cyberespionage | F-Secure |
| 2015 | Target Attacks Against Tibetan And Hong Kong Groups Exploiting CVE-2014-4114 | Citizen Lab |
| 2015 | Targeted Attack on France's TV5Monde | Ahnlab |
| 2015 | The Anthem Hack: All Roads Lead To China | ThreatConnect |
| 2015 | The Black Vine Cyberespionage Group | Symantec |
| 2015 | The Chronicles Of The Hellsing APT: The Empire Strikes Back | Kaspersky |
| 2015 | The Cozyduke APT | Kaspersky |
| 2015 | The Desert Falcons Targeted Attacks | Kaspersky |
| 2015 | The Duqu 2.0 Technical Details | Kaspersky |
| 2015 | The Msnmm Campaigns: The Earliest Naikon APT Campaigns | Kaspersky |
| 2015 | The Naikon APT: Tracking Down Geo-Political Intelligence Across APAC, One Nation At A Time | Kaspersky |
| 2015 | The Waterbug Attack Group | Symantec |
| 2015 | Threat Group-3390 Targets Organizations For Cyberespionage | Dell Secureworks |
| 2015 | Tibetan Uprising Day Malware Attacks | Citizen Lab |
| 2015 | Tracking Minidionis: Cozycar's New Ride Is Related To Seaduke | Palo Alto |
| 2015 | Unfin4Ished Business | PWC |
| 2015 | Volatile Cedar Threat Intelligence And Research | Checkpoint |
| 2015 | WINNTI Analysis | Novetta |
| 2015 | Watering Hole Attack On Aerospace Firm Exploits CVE-2015-5122 To Install Isspace Backdoor | Palo Alto |
| 2015 | Wild Neutron _ Economic Espionage Threat Actor Returns With New Tricks | Kaspersky |
| 2014 | #9 Blitzanalysis: Embassy Of Greece Beijing - Compromise | R136a1 |
| 2014 | Aided Frame, Aided Direction (Because It's A Redirect) | FireEye |
| 2014 | Alert (Ta14-353A) Targeted Destructive Malware | US-CERT |
| 2014 | Analysis Of Chinese Mitm On Google | Netresec |
| 2014 | Anatomy Of The Attack: Zombie Zero | Trapx |
| 2014 | Anunak: Apt Against Financial Institutions | Group-IB, FOX-IT |
| 2014 | Apt28: A Window Into Russia's Cyber Espionage Operations | FireEye |
| 2014 | Be2 Custom Plugins, Router Abuse, And Target Profiles | Kaspersky |
| 2014 | Blackenergy & Quedagh: The Convergence Of Crimeware And Apt Attacks | F-Secure |
| 2014 | Bots, Machines, And The Matrix | Fidelis |
| 2014 | Cat Scratch Fever: Crowdstrike Tracks Newly Reported Iranian Actor As Flying Kitten | Crowdstrike |
| 2014 | Cloud Atlas: Redoctober Apt Is Back In Style | Kaspersky |
| 2014 | Connecting The Dots: Syrian Malware Team Uses Blackworm For Attacks | FireEye |
| 2014 | Cosmicduke Cosmu With A Twist Of Miniduke | F-Secure |
| 2014 | Crouching Yeti: Appendixes | Kaspersky |
| 2014 | Darkhotel Indicators Of Compromise | Kaspersky |
| 2014 | Darwin's Favorite Apt Group | FireEye |
| 2014 | Democracy In Hong Kong Under Attack | Volexity |
| 2014 | Derusbi (Server Variant) Analysis | Novetta |
| 2014 | Dragonfly: Cyberespionage Attacks Against Energy Suppliers | Symantec |
| 2014 | El Machete | Kaspersky |
| 2014 | Emerging Threat Profile Shell_Crew | RSA |
| 2014 | Energetic Bear _ Crouching Yeti | Kaspersky |
| 2014 | Evil Bunny: Suspect #4 | Marion Marschalek |
| 2014 | Forced To Adapt: Xslcmd Backdoor Now On Os X | FireEye |
| 2014 | Full Disclosure Of Havex Trojans | Netresec |
| 2014 | Gathering In The Middle East, Operation Stteam | Fidelis |
| 2014 | Gholee Protective Edge Themed Spear Phishing Campaign | Clearsky |
| 2014 | Hacking The Street? Fin4 Likely Playing The Market | FireEye |
| 2014 | Hikit Analysis | Novetta |